<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: · Guest portal use for VPN in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/guest-portal-use-for-vpn/m-p/3548699#M525094</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This should work as you aren't using guest users. You should be using normal local accounts in ISE to authenticate non-AD VPN users.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Configure local group in ISE, Allowed_VPN_Users&lt;/P&gt;&lt;P&gt;2) Configure local users in ISE and assign them to Alllowed_VPN_Users group.&lt;/P&gt;&lt;P&gt;3) Build a sponsor group, VPN_Password_Change, and strip away all of its rights to build any accounts.&lt;/P&gt;&lt;P&gt;4) Assign Allowed_VPN_Users to the sponsor group&lt;/P&gt;&lt;P&gt;5) Build sponsor portal, VPN_Password_Change, and strip everything out of it.&amp;nbsp; You can even use Java script to hid buttons.&lt;/P&gt;&lt;P&gt;6) Assign FQDN so the sponsor portal to make it easily accessible, changemypassword.mycompany.com.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could even make this accessible over the Internet, but that may be going too far.&amp;nbsp; If you have never used the sponsor portal to change password it is a bit hidden.&amp;nbsp; You need click in the upper right corner where it says "Welcome &amp;lt;username&amp;gt;".&amp;nbsp; I have used this similar method when I was using the local database for TACACS admins.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't remember if the API support local user account password changes.&amp;nbsp; I haven't explored that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 03 May 2017 20:21:24 GMT</pubDate>
    <dc:creator>paul</dc:creator>
    <dc:date>2017-05-03T20:21:24Z</dc:date>
    <item>
      <title>· Guest portal use for VPN</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-portal-use-for-vpn/m-p/3548697#M525092</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Customer has this requirement:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Every 90 days non-employees&amp;nbsp; change their password, so we need a self service portal for non employee users of VPN through ACS as we move them to ISE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would think we can do this through the guest access portal but I'm used to that being around Wireless access. Any reason we can't do this for VPN? Outside of security risks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lou&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 May 2017 17:21:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-portal-use-for-vpn/m-p/3548697#M525092</guid>
      <dc:creator>lnorman</dc:creator>
      <dc:date>2017-05-03T17:21:13Z</dc:date>
    </item>
    <item>
      <title>Re: · Guest portal use for VPN</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-portal-use-for-vpn/m-p/3548698#M525093</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Guest accounts will work with wired wireless or VPN connectivity just need to make sure that identity source for VPN includes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However the only way to change guest password is through the guest flow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The recommendation would be to use this option:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-thread-small" data-containerid="5301" data-containertype="14" data-objectid="73087" data-objecttype="1" href="https://communities.cisco.com/thread/73087"&gt;https://communities.cisco.com/thread/73087&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please give me the company name and contact info (offline) so I can put this in our feature request&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 May 2017 17:26:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-portal-use-for-vpn/m-p/3548698#M525093</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-05-03T17:26:48Z</dc:date>
    </item>
    <item>
      <title>Re: · Guest portal use for VPN</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-portal-use-for-vpn/m-p/3548699#M525094</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This should work as you aren't using guest users. You should be using normal local accounts in ISE to authenticate non-AD VPN users.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Configure local group in ISE, Allowed_VPN_Users&lt;/P&gt;&lt;P&gt;2) Configure local users in ISE and assign them to Alllowed_VPN_Users group.&lt;/P&gt;&lt;P&gt;3) Build a sponsor group, VPN_Password_Change, and strip away all of its rights to build any accounts.&lt;/P&gt;&lt;P&gt;4) Assign Allowed_VPN_Users to the sponsor group&lt;/P&gt;&lt;P&gt;5) Build sponsor portal, VPN_Password_Change, and strip everything out of it.&amp;nbsp; You can even use Java script to hid buttons.&lt;/P&gt;&lt;P&gt;6) Assign FQDN so the sponsor portal to make it easily accessible, changemypassword.mycompany.com.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could even make this accessible over the Internet, but that may be going too far.&amp;nbsp; If you have never used the sponsor portal to change password it is a bit hidden.&amp;nbsp; You need click in the upper right corner where it says "Welcome &amp;lt;username&amp;gt;".&amp;nbsp; I have used this similar method when I was using the local database for TACACS admins.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't remember if the API support local user account password changes.&amp;nbsp; I haven't explored that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 May 2017 20:21:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-portal-use-for-vpn/m-p/3548699#M525094</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2017-05-03T20:21:24Z</dc:date>
    </item>
    <item>
      <title>Re: · Guest portal use for VPN</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-portal-use-for-vpn/m-p/3548700#M525095</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, missed your link Jason.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 May 2017 20:25:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-portal-use-for-vpn/m-p/3548700#M525095</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2017-05-03T20:25:38Z</dc:date>
    </item>
    <item>
      <title>Re: · Guest portal use for VPN</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-portal-use-for-vpn/m-p/3548701#M525096</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;paul did you see the scripted portal i shared out? It changes a My devices portal into a UCP password change portal?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 May 2017 20:25:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-portal-use-for-vpn/m-p/3548701#M525096</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-05-03T20:25:50Z</dc:date>
    </item>
    <item>
      <title>Re: · Guest portal use for VPN</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-portal-use-for-vpn/m-p/3548702#M525097</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;well that answers that! &lt;IMG src="https://community.cisco.com/legacyfs/online/emoticons/happy.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 May 2017 20:26:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-portal-use-for-vpn/m-p/3548702#M525097</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-05-03T20:26:08Z</dc:date>
    </item>
    <item>
      <title>Re: · Guest portal use for VPN</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-portal-use-for-vpn/m-p/4997471#M586360</link>
      <description>&lt;P&gt;And now I have ISE 3.3, can I use the Sponsor portal to create users for Anyconnect VPN Access?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2024 08:32:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-portal-use-for-vpn/m-p/4997471#M586360</guid>
      <dc:creator>startx001</dc:creator>
      <dc:date>2024-01-16T08:32:08Z</dc:date>
    </item>
  </channel>
</rss>

