<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Single Click Guest Questions in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/single-click-guest-questions/m-p/3562338#M530631</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;OL style="font-size: 12px; font-family: arial; color: #3d3d3d;"&gt;&lt;LI&gt;&lt;SPAN style="font-style: inherit; font-size: 10pt; font-family: inherit;"&gt;How does Single Click Guest choose what PSN to encode in the URL.&amp;nbsp; I was assuming it would use the PSN that authenticated the guest session.&amp;nbsp; In our testing that doesn't seem to be the case. The have the in country PSN as the primary RADIUS servers for guests in that country and would like it to be used for the single click guest as well for the sponsors in that country.&amp;nbsp; Not sure if we have enough control to do that.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN style="font-style: inherit; font-size: 10pt; font-family: inherit;"&gt;&lt;STRONG&gt;JAK - the URL returned is that of the portal test url on the 1st sponsor portal it matched. &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-style: inherit; font-size: 10pt; font-family: inherit;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;OL style="font-size: 12px; font-family: arial; color: #3d3d3d;"&gt;&lt;LI&gt;&lt;SPAN style="font-style: inherit; font-size: 10pt; font-family: inherit;"&gt;In the URL that gets sent to the sponsor, ISE is putting the IP address of the PSN.&amp;nbsp; Is there a spot to make is use a DNS name?&amp;nbsp; I know there is a spot to tie in a sponsor portal. Is that what would drive the FQDN in the link?&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN style="font-style: inherit; font-size: 10pt; font-family: inherit;"&gt;&lt;STRONG&gt;JAK - You would need to use the EASY URL (FQDN) option in the sponsor portal settings to have control on what PSNs &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-style: inherit; font-size: 10pt; font-family: inherit;"&gt;&lt;STRONG&gt;Example: sponsorportal.domain.com maps to psn1,psn2 in DNS as CNAME alias records&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-style: inherit; font-size: 10pt; font-family: inherit;"&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;OL style="font-size: 12px; font-family: arial; color: #3d3d3d;"&gt;&lt;LI&gt;&lt;SPAN style="font-style: inherit; font-size: 10pt; font-family: inherit;"&gt;In our testing my user from Singapore is getting the following message when he clicks on the tokenized link."Sponsor does not have enough privilege to approve/deny guests."&amp;nbsp; That tells me it must be matching some AD account, but how do I tell which one?&amp;nbsp; I have it setup to allow all Domain Users to sponsor accounts for their own guests.&amp;nbsp; If this user goes directly to the sponsor portal and signs in with his AD credentials he can see the guest in a pending state.&amp;nbsp; So it seems to be matching a different account in AD.&amp;nbsp; Maybe he has more than one account in AD with that email. &lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN style="font-style: inherit; font-size: 10pt; font-family: inherit;"&gt;&lt;STRONG&gt;JAK - paul opened bug - &lt;/STRONG&gt;&lt;SPAN style="color: #343537; font-family: CiscoSans, sans-serif; font-size: 14px; background-color: #f5f5f6;"&gt;&lt;STRONG&gt;CSCvd29533&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 03 Apr 2017 16:02:56 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2017-04-03T16:02:56Z</dc:date>
    <item>
      <title>Single Click Guest Questions</title>
      <link>https://community.cisco.com/t5/network-access-control/single-click-guest-questions/m-p/3562337#M530630</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am working on a large international ISE install.&amp;nbsp; We are deploying 2.2 to get single click guest acceptance and have a couple questions.&amp;nbsp; I am working on their APAC deployment now.&amp;nbsp; They have PSNs in the various countries in APAC and the Admin/M&amp;amp;Ts are in their Singapore datacenter.&amp;nbsp; Here are my questions:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10pt;"&gt;How does Single Click Guest choose what PSN to encode in the URL.&amp;nbsp; I was assuming it would use the PSN that authenticated the guest session.&amp;nbsp; In our testing that doesn't seem to be the case. The have the in country PSN as the primary RADIUS servers for guests in that country and would like it to be used for the single click guest as well for the sponsors in that country.&amp;nbsp; Not sure if we have enough control to do that.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10pt;"&gt;In the URL that gets sent to the sponsor, ISE is putting the IP address of the PSN.&amp;nbsp; Is there a spot to make is use a DNS name?&amp;nbsp; I know there is a spot to tie in a sponsor portal. Is that what would drive the FQDN in the link?&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10pt;"&gt;In our testing my user from Singapore is getting the following message when he clicks on the tokenized link."Sponsor does not have enough privilege to approve/deny guests."&amp;nbsp; That tells me it must be matching some AD account, but how do I tell which one?&amp;nbsp; I have it setup to allow all Domain Users to sponsor accounts for their own guests.&amp;nbsp; If this user goes directly to the sponsor portal and signs in with his AD credentials he can see the guest in a pending state.&amp;nbsp; So it seems to be matching a different account in AD.&amp;nbsp; Maybe he has more than one account in AD with that email.&amp;nbsp; &lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Mar 2017 14:22:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/single-click-guest-questions/m-p/3562337#M530630</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2017-03-21T14:22:20Z</dc:date>
    </item>
    <item>
      <title>Re: Single Click Guest Questions</title>
      <link>https://community.cisco.com/t5/network-access-control/single-click-guest-questions/m-p/3562338#M530631</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;OL style="font-size: 12px; font-family: arial; color: #3d3d3d;"&gt;&lt;LI&gt;&lt;SPAN style="font-style: inherit; font-size: 10pt; font-family: inherit;"&gt;How does Single Click Guest choose what PSN to encode in the URL.&amp;nbsp; I was assuming it would use the PSN that authenticated the guest session.&amp;nbsp; In our testing that doesn't seem to be the case. The have the in country PSN as the primary RADIUS servers for guests in that country and would like it to be used for the single click guest as well for the sponsors in that country.&amp;nbsp; Not sure if we have enough control to do that.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN style="font-style: inherit; font-size: 10pt; font-family: inherit;"&gt;&lt;STRONG&gt;JAK - the URL returned is that of the portal test url on the 1st sponsor portal it matched. &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-style: inherit; font-size: 10pt; font-family: inherit;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;OL style="font-size: 12px; font-family: arial; color: #3d3d3d;"&gt;&lt;LI&gt;&lt;SPAN style="font-style: inherit; font-size: 10pt; font-family: inherit;"&gt;In the URL that gets sent to the sponsor, ISE is putting the IP address of the PSN.&amp;nbsp; Is there a spot to make is use a DNS name?&amp;nbsp; I know there is a spot to tie in a sponsor portal. Is that what would drive the FQDN in the link?&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN style="font-style: inherit; font-size: 10pt; font-family: inherit;"&gt;&lt;STRONG&gt;JAK - You would need to use the EASY URL (FQDN) option in the sponsor portal settings to have control on what PSNs &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-style: inherit; font-size: 10pt; font-family: inherit;"&gt;&lt;STRONG&gt;Example: sponsorportal.domain.com maps to psn1,psn2 in DNS as CNAME alias records&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-style: inherit; font-size: 10pt; font-family: inherit;"&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;OL style="font-size: 12px; font-family: arial; color: #3d3d3d;"&gt;&lt;LI&gt;&lt;SPAN style="font-style: inherit; font-size: 10pt; font-family: inherit;"&gt;In our testing my user from Singapore is getting the following message when he clicks on the tokenized link."Sponsor does not have enough privilege to approve/deny guests."&amp;nbsp; That tells me it must be matching some AD account, but how do I tell which one?&amp;nbsp; I have it setup to allow all Domain Users to sponsor accounts for their own guests.&amp;nbsp; If this user goes directly to the sponsor portal and signs in with his AD credentials he can see the guest in a pending state.&amp;nbsp; So it seems to be matching a different account in AD.&amp;nbsp; Maybe he has more than one account in AD with that email. &lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN style="font-style: inherit; font-size: 10pt; font-family: inherit;"&gt;&lt;STRONG&gt;JAK - paul opened bug - &lt;/STRONG&gt;&lt;SPAN style="color: #343537; font-family: CiscoSans, sans-serif; font-size: 14px; background-color: #f5f5f6;"&gt;&lt;STRONG&gt;CSCvd29533&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Apr 2017 16:02:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/single-click-guest-questions/m-p/3562338#M530631</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-04-03T16:02:56Z</dc:date>
    </item>
  </channel>
</rss>

