<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Username Attributes sent from ISE to PA FW for URL Filtering in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/username-attributes-sent-from-ise-to-pa-fw-for-url-filtering/m-p/3430281#M524297</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tim,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will validate that if they are doing BYOD flow they aren't using 802.1x or EAP-TLS. If they aren't then your response makes perfect sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the quick response. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 15 Jun 2017 19:33:48 GMT</pubDate>
    <dc:creator>rroulhac</dc:creator>
    <dc:date>2017-06-15T19:33:48Z</dc:date>
    <item>
      <title>Username Attributes sent from ISE to PA FW for URL Filtering</title>
      <link>https://community.cisco.com/t5/network-access-control/username-attributes-sent-from-ise-to-pa-fw-for-url-filtering/m-p/3430279#M524294</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;All,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;I have this request from a partner that is facing a &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;scenario where there is a school that is using ISE to allow students to register their devices, up to three, to get access to the network. Once they register there is no re-registration process. They are attempting to send user information to their Palo Alto which they use for URL filtering and only provides &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;IP&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt; addresses. They had integrated with ISE to pull the identity information but for the self-registered &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;devices&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;, they are only receiving the mac address and not the &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;student's&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt; name. According to the below, for wireless devices, Cisco ISE sends the user-id information only on the Authentication logs. Since the students are not forced to re-register it sounds like the log overwrites and there is no username.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They are currently running ISE 1.4 so wanted to know if this behavior has changed in the newer versions or if there is another option to pull data from somewhere other than the log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://live.paloaltonetworks.com/t5/Integration-Articles/Integrating-Cisco-ISE-Guest-Authentication-with-PAN-OS/ta-p/98295" rel="nofollow" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Integration-Articles/Integrating-Cisco-ISE-Guest-Authentication-with-PAN-OS/ta-p/98295&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-- &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Grace and Peace,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Robert E Roulhac Jr&lt;/P&gt;&lt;P&gt;Virtual Systems Engineer II&lt;/P&gt;&lt;P&gt;Cisco TSN (Technical Solutions Network)&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-email-small" href="mailto:rroulhac@cisco.com"&gt;rroulhac@cisco.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Office: 919.5745455&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Jun 2017 19:25:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/username-attributes-sent-from-ise-to-pa-fw-for-url-filtering/m-p/3430279#M524294</guid>
      <dc:creator>rroulhac</dc:creator>
      <dc:date>2017-06-15T19:25:23Z</dc:date>
    </item>
    <item>
      <title>Re: Username Attributes sent from ISE to PA FW for URL Filtering</title>
      <link>https://community.cisco.com/t5/network-access-control/username-attributes-sent-from-ise-to-pa-fw-for-url-filtering/m-p/3430280#M524296</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Robert,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't think so.&amp;nbsp; It sounds like the authentication type is MAB.&amp;nbsp; With a MAB authentication, you will only get the L2 address.&amp;nbsp; To get the username, you would need to do 802.1X which would include the username.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;-Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Jun 2017 19:30:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/username-attributes-sent-from-ise-to-pa-fw-for-url-filtering/m-p/3430280#M524296</guid>
      <dc:creator>Timothy Abbott</dc:creator>
      <dc:date>2017-06-15T19:30:30Z</dc:date>
    </item>
    <item>
      <title>Re: Username Attributes sent from ISE to PA FW for URL Filtering</title>
      <link>https://community.cisco.com/t5/network-access-control/username-attributes-sent-from-ise-to-pa-fw-for-url-filtering/m-p/3430281#M524297</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tim,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will validate that if they are doing BYOD flow they aren't using 802.1x or EAP-TLS. If they aren't then your response makes perfect sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the quick response. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Jun 2017 19:33:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/username-attributes-sent-from-ise-to-pa-fw-for-url-filtering/m-p/3430281#M524297</guid>
      <dc:creator>rroulhac</dc:creator>
      <dc:date>2017-06-15T19:33:48Z</dc:date>
    </item>
    <item>
      <title>Re: Username Attributes sent from ISE to PA FW for URL Filtering</title>
      <link>https://community.cisco.com/t5/network-access-control/username-attributes-sent-from-ise-to-pa-fw-for-url-filtering/m-p/3430282#M524298</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Makes sense that this might not be possible to achieve using syslog.&lt;/P&gt;&lt;P&gt;I think with ISE APIs you can fetch the username from the MAC address which is populated in &amp;lt;PortalUser&amp;gt; field. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Jun 2017 15:45:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/username-attributes-sent-from-ise-to-pa-fw-for-url-filtering/m-p/3430282#M524298</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2017-06-19T15:45:18Z</dc:date>
    </item>
  </channel>
</rss>

