<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: BYOD - AUP login tracking in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/device-registration-portal-for-internal-endpoints-that-captures/m-p/3545322#M526528</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The only way to capture information with ise is through self registration guest flow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can have a special SSID for them to connect and register their device as part of this flow, you would have to keep a guest account long enough for the employee and to purge these guests devices after X amount of time , you would authorize the device after registration in this guest endpoint flow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the problem here is you problem don't want it to work this way&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our my devices flow for byod (supplicant and certificate provisioning) doesn't capture this either&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You would need to do the following&lt;/P&gt;&lt;P&gt;Create your own portal that captures needed info&lt;/P&gt;&lt;P&gt;This portal would capture the info and add it to ISE via API, the device Mac would be added to a group that is authorized access&lt;/P&gt;&lt;P&gt;This portal could be used before connecting the device to the network&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want as part of the flow&lt;/P&gt;&lt;P&gt;Device connects and not part of endpoint group&lt;/P&gt;&lt;P&gt;Redirect to portal and register&lt;/P&gt;&lt;P&gt;Portal will register device and call a COA to change device access&lt;/P&gt;&lt;P&gt;Device would reconnect with proper access&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 19 Sep 2017 23:20:25 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2017-09-19T23:20:25Z</dc:date>
    <item>
      <title>device registration portal for internal endpoints that captures name phone etc</title>
      <link>https://community.cisco.com/t5/network-access-control/device-registration-portal-for-internal-endpoints-that-captures/m-p/3545321#M526527</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin-bottom: .0001pt; background: #F5F5F6;"&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Segoe UI Semilight',sans-serif; color: #343537;"&gt;I am looking to capture BYOD end-user login information with ISE.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-top: 12.0pt; margin-bottom: .0001pt; background: #F5F5F6;"&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Segoe UI Semilight',sans-serif; color: #343537;"&gt;This project wants to track BYOD devices by user names that are not in Active Directory or local users on the ISE server. &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-top: 12.0pt; margin-bottom: .0001pt; background: #F5F5F6;"&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Segoe UI Semilight',sans-serif; color: #343537;"&gt;They are looking to have a splash screen that will require the guest to enter valid:&amp;nbsp; Name, Email, Phone and have it mapped to the device &lt;SPAN style="font-size: 10.5pt; font-family: 'Segoe UI Semilight',sans-serif; color: #343537;"&gt;and user information visible in live log.&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-top: 12.0pt; margin-bottom: .0001pt; background: #F5F5F6;"&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Segoe UI Semilight',sans-serif; color: #343537;"&gt;I have questions on how they would validate information provided and I have not seen a AUP that will provide that service.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-top: 12.0pt; margin-bottom: .0001pt; background: #F5F5F6;"&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Segoe UI Semilight',sans-serif; color: #343537;"&gt;Can you assist with locating information or a resource I can talk this through with.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-top: 12.0pt; margin-bottom: .0001pt; background: #F5F5F6;"&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Segoe UI Semilight',sans-serif; color: #343537;"&gt;Thank you,&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Sep 2017 21:46:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-registration-portal-for-internal-endpoints-that-captures/m-p/3545321#M526527</guid>
      <dc:creator>jpilchar</dc:creator>
      <dc:date>2017-09-19T21:46:23Z</dc:date>
    </item>
    <item>
      <title>Re: BYOD - AUP login tracking</title>
      <link>https://community.cisco.com/t5/network-access-control/device-registration-portal-for-internal-endpoints-that-captures/m-p/3545322#M526528</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The only way to capture information with ise is through self registration guest flow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can have a special SSID for them to connect and register their device as part of this flow, you would have to keep a guest account long enough for the employee and to purge these guests devices after X amount of time , you would authorize the device after registration in this guest endpoint flow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the problem here is you problem don't want it to work this way&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our my devices flow for byod (supplicant and certificate provisioning) doesn't capture this either&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You would need to do the following&lt;/P&gt;&lt;P&gt;Create your own portal that captures needed info&lt;/P&gt;&lt;P&gt;This portal would capture the info and add it to ISE via API, the device Mac would be added to a group that is authorized access&lt;/P&gt;&lt;P&gt;This portal could be used before connecting the device to the network&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want as part of the flow&lt;/P&gt;&lt;P&gt;Device connects and not part of endpoint group&lt;/P&gt;&lt;P&gt;Redirect to portal and register&lt;/P&gt;&lt;P&gt;Portal will register device and call a COA to change device access&lt;/P&gt;&lt;P&gt;Device would reconnect with proper access&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Sep 2017 23:20:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-registration-portal-for-internal-endpoints-that-captures/m-p/3545322#M526528</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-09-19T23:20:25Z</dc:date>
    </item>
  </channel>
</rss>

