<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Guest Wi-Fi returning users and Session identity persistence in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/guest-wi-fi-returning-users-and-session-identity-persistence/m-p/3578891#M528624</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct behavior&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;https://communities.cisco.com/message/256994?mobileredirect=true&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ise 2.3 will correct the live log issue but not the guest reporting issues&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 10 Jul 2017 14:02:51 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2017-07-10T14:02:51Z</dc:date>
    <item>
      <title>Guest Wi-Fi returning users and Session identity persistence</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-wi-fi-returning-users-and-session-identity-persistence/m-p/3578890#M528623</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ISE fans&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think I am missing some fundamental concepts to the workings of Guest web auth.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I authenticated a wifi guest user on the guest portal and in Live Logs I can see the Session Status is "Started"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="jive-image image-2" src="https://community.cisco.com/legacyfs/online/fusion/109020_pastedImage_0.png" style="max-height: 900px; max-width: 1200px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/109019_pastedImage_0.png" style="max-height: 900px; max-width: 1200px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Username is mapped to &lt;A href="mailto:jane@email.com"&gt;jane@email.com&lt;/A&gt; because ISE was overwriting the MAC address during the portal authentication flow.&lt;/P&gt;&lt;P&gt;Next thing ...&lt;/P&gt;&lt;P&gt;If WLC session has timed out (e.g. after 8 hours), and the WLC sends Acct Stop to ISE, then ISE marks that Session as Terminated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="jive-image image-3" src="https://community.cisco.com/legacyfs/online/fusion/109021_pastedImage_1.png" style="max-height: 900px; max-width: 1200px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not generally a problem, because the returning user will be automatically be authorised by my AuthZ policy since I look up the MAC address in the GuestEndpoints Identity Group. The Guest is working and happy again.&amp;nbsp; And the problem is that ISE no longer has any clue who this user is, since GuestEndpoints only contains MAC addresses. And this time around the Access-Accept replies with the MAC address only, and not with the actual username. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="jive-image image-4" src="https://community.cisco.com/legacyfs/online/fusion/109022_pastedImage_2.png" style="max-height: 900px; max-width: 1200px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is a problem for me because I need to know the Identity (e.g. &lt;A href="mailto:jane@email.com"&gt;jane@email.com&lt;/A&gt;) without forcing them to authenticate on the portal again.&amp;nbsp; In other words, I wanted ISE to cache the MAC&amp;lt;-&amp;gt;UserName for the entire duration of the validity of the guest account. Is this possible?&amp;nbsp;&amp;nbsp; I don't want to have a WLC session timeout of 30 days to force this behaviour. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't have Profiling licenses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please show me the error of my way ... &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Jul 2017 05:54:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-wi-fi-returning-users-and-session-identity-persistence/m-p/3578890#M528623</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2017-07-10T05:54:40Z</dc:date>
    </item>
    <item>
      <title>Re: Guest Wi-Fi returning users and Session identity persistence</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-wi-fi-returning-users-and-session-identity-persistence/m-p/3578891#M528624</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct behavior&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;https://communities.cisco.com/message/256994?mobileredirect=true&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ise 2.3 will correct the live log issue but not the guest reporting issues&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Jul 2017 14:02:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-wi-fi-returning-users-and-session-identity-persistence/m-p/3578891#M528624</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-07-10T14:02:51Z</dc:date>
    </item>
    <item>
      <title>Re: Guest Wi-Fi returning users and Session identity persistence</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-wi-fi-returning-users-and-session-identity-persistence/m-p/3578892#M528625</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jason&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for confirming.&amp;nbsp; As a Cisco Partner I have limited visibility into the bug ID's - does the fix in 2.3 release also ensure that the Accounting Requests contain the mapped User-Name instead of the MAC address?&amp;nbsp; And if so, is that a patch/hotfix that I can apply to 2.2p1 ?&amp;nbsp; Our solution is meant to go live in a month.&lt;/P&gt;&lt;P&gt;My customer's solution involves a transparent web proxy solution that seeks to apply proxying policies based on the Radius accounting requests.&amp;nbsp; They look in the User-Name attribute and then perform an LDAP lookup etc.&amp;nbsp; The User-Name has to contain a valid identity.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Arne&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Jul 2017 22:34:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-wi-fi-returning-users-and-session-identity-persistence/m-p/3578892#M528625</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2017-07-10T22:34:47Z</dc:date>
    </item>
    <item>
      <title>Re: Guest Wi-Fi returning users and Session identity persistence</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-wi-fi-returning-users-and-session-identity-persistence/m-p/3578893#M528626</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The fix is in ise 2.3 for live logs only and doesn't address your use case as it's treated as straight mab&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please reach out to the ise product management team through your sales channel to address your use case&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from my iPhone&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Jul 2017 23:31:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-wi-fi-returning-users-and-session-identity-persistence/m-p/3578893#M528626</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-07-10T23:31:40Z</dc:date>
    </item>
  </channel>
</rss>

