<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.1 Wired Guest Flow VLAN IP Release/Renew Issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-1-wired-guest-flow-vlan-ip-release-renew-issue/m-p/3443310#M536299</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Its not recommended to do VLAN changes for guest as there are issues with java active X applets and you have no control of guest devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is no supplicant like dot1x to control the IP change&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you must change IP addresses, then the recommendation would be to do either of the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;·         Don’t use the applets&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;·         Setup a low DHCP lease time for the initial VLAN so when the user moves its updates quickly&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;·         Have the user login with CWA and then Register the endpoints by redirecting to a hotspot portal that will disconnect them after registration and cause a new connection on the new VLAN coming through&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;·         Use dot1x for the guests by pre-registration or have them register for an account (make sure you use an account that’s activated immediately (from first login or make sure to check the bypass guest portal in the guest type)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 01 Feb 2017 17:37:21 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2017-02-01T17:37:21Z</dc:date>
    <item>
      <title>ISE 2.1 Wired Guest Flow VLAN IP Release/Renew Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-wired-guest-flow-vlan-ip-release-renew-issue/m-p/3443309#M536298</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI Experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have implemented a rule for my customer to have Guest users go through CWA redirect and after authorization get placed into the Guest VLAN.&amp;nbsp; The entire flow works as expected the Guest user is first in the Corp VLAN (obtains ip from that VLAN) to access the CWA portal and then gets put into the Guest VLAN. The issue I am seeing is that once the user is put into the Guest VLAN the IP Address release/renew does not occur right away. It takes 10-15 minutes if nothing is done.Manual renewal of IP works right away.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I enable the "VLAN DHCP Release Page" setting on the portal&amp;nbsp; then the user gets prompted for installing the applet and then the ip is renewed automatically. &lt;SPAN style="font-size: 10pt;"&gt;I have tested the applet on Windows and it works. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My questions are below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Is there another way to handle this without user intervention. Some way that once put into the Guest VLAN the DHCP renew would automatically be initiated?&lt;/P&gt;&lt;P&gt;2. I have tested the Java Applet on Windows and it seems to work what about other guest endpoints&amp;nbsp; OSX etc. Any known issues or gotchas for non windows devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nadeem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Feb 2017 17:16:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-wired-guest-flow-vlan-ip-release-renew-issue/m-p/3443309#M536298</guid>
      <dc:creator>nadeekha</dc:creator>
      <dc:date>2017-02-01T17:16:30Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.1 Wired Guest Flow VLAN IP Release/Renew Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-wired-guest-flow-vlan-ip-release-renew-issue/m-p/3443310#M536299</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Its not recommended to do VLAN changes for guest as there are issues with java active X applets and you have no control of guest devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is no supplicant like dot1x to control the IP change&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you must change IP addresses, then the recommendation would be to do either of the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;·         Don’t use the applets&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;·         Setup a low DHCP lease time for the initial VLAN so when the user moves its updates quickly&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;·         Have the user login with CWA and then Register the endpoints by redirecting to a hotspot portal that will disconnect them after registration and cause a new connection on the new VLAN coming through&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;·         Use dot1x for the guests by pre-registration or have them register for an account (make sure you use an account that’s activated immediately (from first login or make sure to check the bypass guest portal in the guest type)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Feb 2017 17:37:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-wired-guest-flow-vlan-ip-release-renew-issue/m-p/3443310#M536299</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-02-01T17:37:21Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.1 Wired Guest Flow VLAN IP Release/Renew Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-wired-guest-flow-vlan-ip-release-renew-issue/m-p/3443311#M536300</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jason!!&lt;/P&gt;&lt;P&gt;Those were great alternative solutions. I will ask the customer to give those a try and see how it goes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nadeem Khan CISSP, CRISC&lt;/P&gt;&lt;P&gt;Network Consulting Engineer&lt;/P&gt;&lt;P&gt;Cisco Services&lt;/P&gt;&lt;P&gt;Cisco Security Solutions - Integration&lt;/P&gt;&lt;P&gt;nadeekha@cisco.com&lt;/P&gt;&lt;P&gt;Mobile: +1 416 8199934&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco.com - http://www.cisco.com&lt;/P&gt;&lt;P&gt;This email may contain confidential and privileged material for the sole use of the intended recipient. Any review, use, distribution or disclosure by others is strictly prohibited. If you are not the intended recipient (or authorized to receive for the recipient), please contact the sender by reply email and delete all copies of this message.&lt;/P&gt;&lt;P&gt;For corporate legal information go to:&lt;/P&gt;&lt;P&gt;http://www.cisco.com/web/about/doing_business/legal/cri/index.html&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Feb 2017 17:45:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-wired-guest-flow-vlan-ip-release-renew-issue/m-p/3443311#M536300</guid>
      <dc:creator>nadeekha</dc:creator>
      <dc:date>2017-02-01T17:45:45Z</dc:date>
    </item>
  </channel>
</rss>

