<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple devices when phone number used as the username in ISE Guest Self-Registration in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/multiple-devices-when-phone-number-used-as-the-username-in-ise/m-p/3480008#M535885</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Seems to me why not just create accounts that are good for longer than the user needs them? Then they would be purged at later date?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Otherwise you're trying to do too much work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems like they are free accounts so what is the problem if the accounts last longer so you don't have collisions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also have you looked at CMX or EMSP products? They might already do what you need.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me think about the other line items here&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 01 May 2017 15:50:10 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2017-05-01T15:50:10Z</dc:date>
    <item>
      <title>Multiple devices when phone number used as the username in ISE Guest Self-Registration</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-devices-when-phone-number-used-as-the-username-in-ise/m-p/3480005#M535882</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 12pt; font-family: 'Times New Roman'; color: #000000; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;SPAN style="font-size: 10pt; background-color: rgba(255, 255, 255, 0); font-family: arial,helvetica,sans-serif;"&gt;Hello All,&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Times New Roman'; color: #000000; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;SPAN style="font-size: 10pt; background-color: rgba(255, 255, 255, 0); font-family: arial,helvetica,sans-serif;"&gt;Thanks to Jason and others, solution described in&amp;nbsp; &lt;A href="https://community.cisco.com/docs/DOC-68265"&gt;ISE Guest Self-Registration phone number as the username&lt;/A&gt; is working perfectly in ISE 2.1&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Times New Roman'; color: #000000; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Times New Roman'; color: #000000; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;SPAN style="font-size: 10pt; background-color: rgba(255, 255, 255, 0); font-family: arial,helvetica,sans-serif;"&gt;The major issue I cannot find a way to solve is the following: &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Times New Roman'; color: #000000; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;SPAN style="font-size: 10pt; background-color: rgba(255, 255, 255, 0); font-family: arial,helvetica,sans-serif;"&gt;Customer wants to allow up to 3 devices to be connected via the same username. That is, to me, a very common scenario which, for example, a typical hotel hotspot will provide (say, a Phone, an IPAD and a business laptop).&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Times New Roman'; color: #000000; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;SPAN style="font-size: 10pt; background-color: rgba(255, 255, 255, 0); font-family: arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Times New Roman'; color: #000000; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;SPAN style="font-size: 10pt; background-color: rgba(255, 255, 255, 0); font-family: arial,helvetica,sans-serif;"&gt;The "single username" collision issue is unavoidable in the following scenario:&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Times New Roman'; color: #000000; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;SPAN style="font-size: 10pt; background-color: rgba(255, 255, 255, 0); font-family: arial,helvetica,sans-serif;"&gt;- Username has expired at, say 3 pm and is not purged yet - waiting for &lt;A dir="ltr" style="color: #3778c7; text-decoration: underline;"&gt;1 am&lt;/A&gt;;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Times New Roman'; color: #000000; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;SPAN style="font-size: 10pt; background-color: rgba(255, 255, 255, 0); font-family: arial,helvetica,sans-serif;"&gt;- User connects via a new device (say, using his laptop while previous he was using his cell);&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Times New Roman'; color: #000000; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;SPAN style="font-size: 10pt; background-color: rgba(255, 255, 255, 0); font-family: arial,helvetica,sans-serif;"&gt;- We are making AuthZ rules based on endpoints but as this a new endpoint for this user, it has not been allocated to a group, hence we redirect to a Portal where Customer tries to authenticate and fails as user is expired...&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Times New Roman'; color: #000000; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Times New Roman'; color: #000000; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;SPAN style="font-size: 10pt; background-color: rgba(255, 255, 255, 0); font-family: arial,helvetica,sans-serif;"&gt;Trying to think of any workarounds but cannot think of any?&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Times New Roman'; color: #000000; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;SPAN style="font-size: 10pt; background-color: rgba(255, 255, 255, 0); font-family: arial,helvetica,sans-serif;"&gt;Also, thing with auto-generated usernames allows user to keep sensing SMS/create usernames nearly indefinitely which does not seems correct either (in case Customer wants to limit to only several devices - that also allows to keep username/SMS explosion to a minimum)?&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Times New Roman'; color: #000000; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;SPAN style="font-size: 10pt; background-color: rgba(255, 255, 255, 0); font-family: arial,helvetica,sans-serif;"&gt;Limiting user to a single device without allowing user to control them (will be also impossible with expired username) is not an option either...&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Times New Roman'; color: #000000; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;SPAN style="font-size: 10pt; background-color: rgba(255, 255, 255, 0); font-family: arial,helvetica,sans-serif;"&gt;Any ideas how to approach this?&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Times New Roman'; color: #000000; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;SPAN style="font-size: 10pt; background-color: rgba(255, 255, 255, 0); font-family: arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Times New Roman'; color: #000000; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;SPAN style="font-size: 10pt; background-color: rgba(255, 255, 255, 0); font-family: arial,helvetica,sans-serif;"&gt;Thank you!&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Times New Roman'; color: #000000; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;SPAN style="font-size: 10pt; background-color: rgba(255, 255, 255, 0); font-family: arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Times New Roman'; color: #000000; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;SPAN style="background-color: rgba(255, 255, 255, 0); font-family: UICTFontTextStyleBody; font-size: 10pt;"&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;Amir&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 29 Apr 2017 20:48:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-devices-when-phone-number-used-as-the-username-in-ise/m-p/3480005#M535882</guid>
      <dc:creator>Amir Asfandyarov</dc:creator>
      <dc:date>2017-04-29T20:48:58Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple devices when phone number used as the username in ISE Guest Self-Registration</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-devices-when-phone-number-used-as-the-username-in-ise/m-p/3480006#M535883</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I understand the problem however I am not really have have an easy solution for that&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you stated the unique username has expired but not yet purged. And there is no way to reinstate an account (accept by a sponsor or specialized portal via API class?). So if you set to daily then unless you expired the account at midnight the user is stuck&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And there is no way to set when it expires via self registration as it's by hours or days but not set time&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Trying to do special flows without facilities in the box sometimes doesn't work out all of what's needed but we try our best to come up with workarounds that maybe works most of the time, granted we would like to address the more use cases the better&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How about an external registration portal to manage it via API this way you're able to control and track the username as the phone number if the user has expired but they should still have access because they are valid patrons of the hotel then the system can decide that logic and reinstate the account&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not really sure how you're managing who's able to register or not&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What we need are the following features&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ability for user to reinstate themselves via self-reg portal? may need to tie into some sortof external data base via ODBC or LDAP To look up if a person is still a valid patron as well&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ability to only allow registration via a cell number 1 time in x hours perhaps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Missed anything?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 30 Apr 2017 00:04:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-devices-when-phone-number-used-as-the-username-in-ise/m-p/3480006#M535883</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-04-30T00:04:51Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple devices when phone number used as the username in ISE Guest Self-Registration</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-devices-when-phone-number-used-as-the-username-in-ise/m-p/3480007#M535884</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jason,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank&amp;nbsp; you for your answer - yes, I understood that there are no workarounds for us here &lt;IMG src="https://community.cisco.com/legacyfs/online/emoticons/sad.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt;How about an external registration portal to manage it via API this way you're able to control and track the username as the phone number if the user has expired but they should still have access because they are valid patrons of the hotel then the system can decide that logic and reinstate the account&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Amir] Well, our case is a large venue (exposition complex), so it is close to a stadium/event type of thing. Although Guest API is a possible solution, Customer wanted so much to keep things local on ISE ("you have portal on ISE anyway, don't you?) and also reinstating the account will mean extending it for another period of validity which defeats the whole purpose of providing 1,2 or 3-day access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt;I'm not really sure how you're managing who's able to register or not&lt;/P&gt;&lt;P&gt;[Amit] Well, just any user with a valid cell phone #- that is the way authorities track the user identity. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt;Ability for user to reinstate themselves via self-reg portal? may need to tie into some sortof external data base via ODBC or LDAP To look up if a person is still a valid patron as well&lt;/P&gt;&lt;P&gt;Ability to only allow registration via a cell number 1 time in x hours perhaps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Amir] In a typical event/stadium/etc environment a possibility to reinstate the account is a possible option indeed. In our case we do not care too much if person will get "lengthier" access as long as he is authenticated via his cell phone.&lt;/P&gt;&lt;P&gt;With this we could avoid collision. Another thing is to somehow rework internal logic and provide a tickbox (per guest user type) to purge user immediately after expiry, but I bet that might not be possible on platform due to some hidden DB/logic-related limitations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I could not find a way to programmatically purge Guest User Database - I guess that is not possible and moreover, is not really possible to do it frequently (otherwise why do we do this at 3 am)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you, as always.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards, Amir&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 30 Apr 2017 21:13:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-devices-when-phone-number-used-as-the-username-in-ise/m-p/3480007#M535884</guid>
      <dc:creator>Amir Asfandyarov</dc:creator>
      <dc:date>2017-04-30T21:13:52Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple devices when phone number used as the username in ISE Guest Self-Registration</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-devices-when-phone-number-used-as-the-username-in-ise/m-p/3480008#M535885</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Seems to me why not just create accounts that are good for longer than the user needs them? Then they would be purged at later date?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Otherwise you're trying to do too much work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems like they are free accounts so what is the problem if the accounts last longer so you don't have collisions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also have you looked at CMX or EMSP products? They might already do what you need.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me think about the other line items here&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 May 2017 15:50:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-devices-when-phone-number-used-as-the-username-in-ise/m-p/3480008#M535885</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-05-01T15:50:10Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple devices when phone number used as the username in ISE Guest Self-Registration</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-devices-when-phone-number-used-as-the-username-in-ise/m-p/3480009#M535886</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I haven't tried this before but was just playing around with this.&amp;nbsp; The multiple devices per username should work.&amp;nbsp; I am testing on 2.2 and I only used the java script on the self-registration portal.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;So the user comes into the standard self-registration and has the option to enter the username/password or click the "Don't have an Account?" link.&amp;nbsp; I modified the username text to say "Phone Number" on the customization.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;User clicks on the "Don't have an Account?" link and goes to self registration.&amp;nbsp; I have removed all fields except username and phone number.&amp;nbsp; The java script hides the username.&amp;nbsp; User types in their phone number and clicks Register.&amp;nbsp; The user ID with their phone number is generated and credentials texted to them.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;As part of the success message or text you can let the user know that the username/password can be used to register up to 3 devices.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Now they click sign-in and use their information that was texted to them.&amp;nbsp; The portal is tied to a guest type that allows 3 registered devices.&amp;nbsp; I set the expiry time for the user credentials to 8 hours after creation..&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;As you said this is a convention.&amp;nbsp; I shouldn't need to handle people registering at all hours of the night.&amp;nbsp; Let's say I want to accommodate someone registering up to 8:00 p.m.&amp;nbsp; That means the guest user would expire at 4:00 a.m and configure my guest purge job to run at 4:30 a.m.&amp;nbsp; I configure my endpoint purge to run at 5:00 a.m.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;So after the endpoint purge runs at 5 everything is ready for the new day.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;I haven't fully tested this, but wouldn't that work.&amp;nbsp; I know in a hotel scenario where guests are registering 24/7 this wouldn't work but for a convention scenario it should work.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 May 2017 16:02:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-devices-when-phone-number-used-as-the-username-in-ise/m-p/3480009#M535886</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2017-05-01T16:02:24Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple devices when phone number used as the username in ISE Guest Self-Registration</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-devices-when-phone-number-used-as-the-username-in-ise/m-p/3480010#M535887</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Other products won't work as we're given ISE and requirement to create Guest Portal so this is something outside of my control &lt;IMG src="https://community.cisco.com/legacyfs/online/emoticons/happy.png" /&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've probably confused everyone, apologies - this is NOT a hotel, that was just an analogy. This is a WiFi service at exhibition center. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Correct, this is a free service - my concerns with longer account duration are:&lt;/P&gt;&lt;P&gt;1) Maximum amount of Guest Users in the DB (I remember something like 1,5M ?) which we can hit if we create users for the duration of the event and won't purge them. I could end up creating users which are lasting for 90+ days and forget about that issue but scalability will be an issue then.&lt;/P&gt;&lt;P&gt;2) If I make duration of the Guest User account smaller than event itself&amp;nbsp; but still longer than a typical use-case (visitor coming maybe once or twice within 1 week) then we can hit an issue with visitor coming several times outside of the period and he will still hit this corner-case scenario with expired user (that is possible).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think Paul has given a very good idea in the answer below - we may end up with 1-day accounts and purge them daily, I will need to test this though.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 May 2017 19:51:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-devices-when-phone-number-used-as-the-username-in-ise/m-p/3480010#M535887</guid>
      <dc:creator>Amir Asfandyarov</dc:creator>
      <dc:date>2017-05-01T19:51:29Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple devices when phone number used as the username in ISE Guest Self-Registration</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-devices-when-phone-number-used-as-the-username-in-ise/m-p/3480011#M535888</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Amir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me ask you a question on the exact requirements of the customer.  The fact that this is an open SSID it sounds like they are basically saying “Anyone within Wi-Fi range with a valid cell phone number can get on and potentially register multiple devices.”.  There is no verification that the cell phone is registered to a user at the conference.  It could be someone just wanting free Wi-Fi.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do they have a requirement that the user accept an AUP?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If there is no AUP then why not just do a PSK that is given out during registration?  Then shut down the SSID at night when the convention is not on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If they require AUP, in the newest WLC code you can do PSK with AUP as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These are discussion I usually have with customers.  Just curious.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hopefully my previous suggestion works.  I would be interested to see how your testing goes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paul Haferman&lt;/P&gt;&lt;P&gt;Office- 920.996.3011&lt;/P&gt;&lt;P&gt;Cell- 920.284.9250&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 May 2017 22:26:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-devices-when-phone-number-used-as-the-username-in-ise/m-p/3480011#M535888</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2017-05-01T22:26:16Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple devices when phone number used as the username in ISE Guest Self-Registration</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-devices-when-phone-number-used-as-the-username-in-ise/m-p/3480012#M535889</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Paul,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First of all, thanks for all your suggestions.&lt;/P&gt;&lt;P&gt;So, the important thing with SMS is that authorities mandate ALL accounts to be tied to a mobile number - that is, password should arrive via SMS and that is a method to actually track WiFi user (another option will be sponsored access which by definition tracks the identity of the user). We cannot just have AUP - that would be much-much-much simpler in that case of course), same answer for PSK.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will update the thread after the testing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amir&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 May 2017 07:11:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-devices-when-phone-number-used-as-the-username-in-ise/m-p/3480012#M535889</guid>
      <dc:creator>Amir Asfandyarov</dc:creator>
      <dc:date>2017-05-02T07:11:51Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple devices when phone number used as the username in ISE Guest Self-Registration</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-devices-when-phone-number-used-as-the-username-in-ise/m-p/3480013#M535891</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, this idea has failed &lt;IMG src="https://community.cisco.com/legacyfs/online/emoticons/happy.png" /&gt; Customer will have this even opened from 9 am to 1 am during some of the days, so that won't work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another one came to your mind which we want to test now:&lt;/P&gt;&lt;P&gt;- create a script which gets all users from a particular User Type (via API);&lt;/P&gt;&lt;P&gt;- suspend all those users 1 or 2 hours before purging (2 or 3 am); As far as I can see, suspension marks users for purging.&lt;/P&gt;&lt;P&gt;- configure purging to run at, say, 4 am.&lt;/P&gt;&lt;P&gt;- run this script daiy on external server - that will first suspend all "1-day users" and then hopefully will clean them up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Guys, do you see any flaws here, will that work? To me it should, will write a script now and test.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards, Amir&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 May 2017 10:10:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-devices-when-phone-number-used-as-the-username-in-ise/m-p/3480013#M535891</guid>
      <dc:creator>Amir Asfandyarov</dc:creator>
      <dc:date>2017-05-02T10:10:27Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple devices when phone number used as the username in ISE Guest Self-Registration</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-devices-when-phone-number-used-as-the-username-in-ise/m-p/3480014#M535895</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sounds good ultimately wondering what type of solution we could offer in box if any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please when you're done let's work offline through email&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 May 2017 11:59:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-devices-when-phone-number-used-as-the-username-in-ise/m-p/3480014#M535895</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-05-02T11:59:47Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple devices when phone number used as the username in ISE Guest Self-Registration</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-devices-when-phone-number-used-as-the-username-in-ise/m-p/3480015#M535898</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, reporting on the progress so community could benefit from it (and contribute &lt;IMG src="https://community.cisco.com/legacyfs/online/emoticons/happy.png" /&gt;).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Idea from &lt;A href="https://community.cisco.com/docs/DOC-68265"&gt;ISE Guest Self-Registration phone number as the username&lt;/A&gt; does not work well for us as it seems that behavior has been changed. Previously, as described in the article above, you could base the authorization rule off the endpoint group (EP) and purge EP group later. However, in 2.1p3 endpoint is immediately removed from EP once associated username expires (we do not wait until purge time comes), so user cannot access network anymore from previously registered MAC.&lt;/P&gt;&lt;P&gt;So, unique username combination + authorization rule based on EP does not work in 2.1p2 (at least for us).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. I've written an ISE ERS API script which a) retrieves users of a particular Guest Type b) parses the list and composes XML c) sends XML in a bulk deletion request towards ISE to delete users.&lt;/P&gt;&lt;P&gt;This script has been installed as a cron job in a separate Linux server and runs at ~2am. I've also written a script to bulk create users (to test deletion script) - so, with 10K users on a portal it takes about 35 mins to delete them (via bulk job, a batch of 4500 users). So need to account for it - 30K will be deleted in roughly&amp;nbsp; 2 hours, then endpoint purge will happen, than EP purge, then backup and ideally I do not want all these to overlap as ISE is s sensitive beast (I think &lt;IMG src="https://community.cisco.com/legacyfs/online/emoticons/sad.png" /&gt;).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are about to test how scripted workaround works, I am expecting the following caveats:&lt;/P&gt;&lt;P&gt;- we may hit CSCvd16176 so I need to test;&lt;/P&gt;&lt;P&gt;- I still do not know how to deal with PAN failover - if that happens, script (which is tied to primary PAN IP) will not work and next morning we will have a nightmare &lt;IMG src="https://community.cisco.com/legacyfs/online/emoticons/happy.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ah and yes, suspension was not marking users for purging to had to use delete operation directly.&lt;/P&gt;&lt;P&gt;Will report results later.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amir&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 May 2017 16:52:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-devices-when-phone-number-used-as-the-username-in-ise/m-p/3480015#M535898</guid>
      <dc:creator>Amir Asfandyarov</dc:creator>
      <dc:date>2017-05-08T16:52:14Z</dc:date>
    </item>
  </channel>
</rss>

