<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.2 - CISE_Guest in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-2-cise-guest/m-p/3509409#M530281</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok from ISE side i don't see any issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just checked with our PXgrid integration team and they noted that the guest information is consumable this way as well. If Palo Alto would integrated that way it might be easier for all&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 11 Apr 2017 21:47:40 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2017-04-11T21:47:40Z</dc:date>
    <item>
      <title>ISE 2.2 - CISE_Guest</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-cise-guest/m-p/3509403#M530275</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our customer would like 2 years record of Guest Traffic.&amp;nbsp; The Guest traffic is going out via a Palo Alto, which is all working, but the issue is capturing logs.&lt;/P&gt;&lt;P&gt;I've looked at the Palo Alto ISE doc and followed, but doesn't work, think this is because its portal guest authentication.&amp;nbsp; So I'm sending the Syslog for Authentications to a Kiwi server, this is configured Facility Code Local 6.&amp;nbsp; I can capture the initial creation and log on user in the logs under heading of CISE_Guest so I the IP and MAC, but after that, there is no more data captured for when that account logs in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can see on PAN live logs the user authenticating, but this is not in the logs.&lt;/P&gt;&lt;P&gt;I'm logging against category&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Guest&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Accounting&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; RADIUS Accounting&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Passed Authentications&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This log will be captured and imported to sawmill, so the data manager can pair up the web logs from Palo Alto and ISE for guest.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any one got any hints?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Apr 2017 08:51:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-cise-guest/m-p/3509403#M530275</guid>
      <dc:creator>craiglebutt</dc:creator>
      <dc:date>2017-04-07T08:51:59Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 - CISE_Guest</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-cise-guest/m-p/3509404#M530276</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't completely understand the issue&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you setup us through what happens on ise guest now&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And what you would like to happen?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also what are your authorization rules?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Apr 2017 11:11:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-cise-guest/m-p/3509404#M530276</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-04-07T11:11:31Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 - CISE_Guest</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-cise-guest/m-p/3509405#M530277</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 13.3333px;"&gt;Hi&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Mobility Anchor created, the guest traffic goes out via port 2 of wlc to DMZ. A rule on the PA to allow traffic to interact with ISE for sponsored guest.&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;This all works,&amp;nbsp; but on the Palo Alto, it just show the web traffic with IP address, doesn't display the authentication of the user.&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;So I need to export this from the ISE to a separate syslog so the data manager can merge the web traffic and auth traffic to one log&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;BR /&gt;What I would like integrate the ISE Guest Authentication on to the Palo Alto to display the web traffic with the guest details.&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;There is a link for this, but doesn't seem to work for 2.1 &amp;amp; 2.2&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt; &lt;A href="https://live.paloaltonetworks.com/t5/Integration-Articles/Integrating-Cisco-ISE-Guest-Authentication-with-PAN-OS/ta-p/98295" title="https://live.paloaltonetworks.com/t5/Integration-Articles/Integrating-Cisco-ISE-Guest-Authentication-with-PAN-OS/ta-p/98295"&gt;https://live.paloaltonetworks.com/t5/Integration-Articles/Integrating-Cisco-ISE-Guest-Authentication-with-PAN-OS/ta-p/98295&lt;/A&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Authorization rules allow sponsored users to be authenticated to use the portal, this all works, it's just logs having issues with, as it is a hospital, they want to keep 2 years data, even though it is only a visitor, not for patients.&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;cheers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Apr 2017 11:58:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-cise-guest/m-p/3509405#M530277</guid>
      <dc:creator>craiglebutt</dc:creator>
      <dc:date>2017-04-07T11:58:29Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 - CISE_Guest</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-cise-guest/m-p/3509406#M530278</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok you can send ise guest login via syslog to external server as well&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can't these be correlated?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Apr 2017 13:32:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-cise-guest/m-p/3509406#M530278</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-04-07T13:32:32Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 - CISE_Guest</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-cise-guest/m-p/3509407#M530279</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You may need a tac case to debug why the logs are not being sent or incorrectly from ise&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you send screenshot of your authz profile for guest as well&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Apr 2017 13:39:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-cise-guest/m-p/3509407#M530279</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-04-07T13:39:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 - CISE_Guest</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-cise-guest/m-p/3509408#M530280</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Looking at the syslog going to the Palo, the instructions say this, bellow but after further investigation, as the passed auth is coming from CISE_Guest, I'm guessing should look more like below (2.2) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.3&lt;/P&gt;&lt;P&gt;Event Regex&lt;/P&gt;&lt;P&gt;([A-Za-z0-9].*CISE_Passed_Authentications.*Framed-IP-Address=.*)|([A-Za-z0-9].*CISE_RADIUS_Accounting.*Framed-IP-Address=.*)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Username Regex&lt;/P&gt;&lt;P&gt;User-Name=([a-zA-Z0-9\@\-\\/\\\._]+)|UserName=([a-zA-Z0-9\@\-\\/\\\._]+)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Address Regex&lt;/P&gt;&lt;P&gt;Framed-IP-Address=([0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3})&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;******************&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2..2&lt;/P&gt;&lt;P&gt;Event Regex&lt;/P&gt;&lt;P&gt;([A-Za-z0-9].*CISE_Guest.*NADAddress=.*)|([A-Za-z0-9].*CISE_Guest.*GuestUserName=.*)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Username Regex&lt;/P&gt;&lt;P&gt;User-Name=([a-zA-Z0-9\@\-\\/\\\._]+)|UserName=([a-zA-Z0-9\@\-\\/\\\._]+)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Address Regex&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;NADAddresss=([0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3})&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cheers&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture.JPG" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/106122_Capture.JPG" style="height: 323px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Apr 2017 13:57:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-cise-guest/m-p/3509408#M530280</guid>
      <dc:creator>craiglebutt</dc:creator>
      <dc:date>2017-04-07T13:57:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 - CISE_Guest</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-cise-guest/m-p/3509409#M530281</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok from ISE side i don't see any issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just checked with our PXgrid integration team and they noted that the guest information is consumable this way as well. If Palo Alto would integrated that way it might be easier for all&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Apr 2017 21:47:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-cise-guest/m-p/3509409#M530281</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-04-11T21:47:40Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 - CISE_Guest</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-cise-guest/m-p/3509410#M530282</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Craig,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you mean by 1.3 and below 2.2. Are those the ISE versions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Aug 2017 16:13:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-cise-guest/m-p/3509410#M530282</guid>
      <dc:creator>ajc</dc:creator>
      <dc:date>2017-08-16T16:13:54Z</dc:date>
    </item>
  </channel>
</rss>

