<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to add an attribute in the authentication phase? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/how-to-add-an-attribute-in-the-authentication-phase/m-p/3440528#M538497</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The easiest way to rate limit guests is to use BDRL (Bidirectional Rate Limiting).&lt;/P&gt;&lt;P&gt;In AuthZ policy return the attributes shown on the screenshot below. The values are in kbits/sec&lt;IMG alt="image001.png" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/97013_image001.png" style="height: 271px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 27 Jun 2016 13:41:43 GMT</pubDate>
    <dc:creator>vibobrov</dc:creator>
    <dc:date>2016-06-27T13:41:43Z</dc:date>
    <item>
      <title>How to add an attribute in the authentication phase?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-add-an-attribute-in-the-authentication-phase/m-p/3440523#M538491</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 13.3333px;"&gt;I am trying to limit traffic profiles to users via radius.&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;I have found that in the documentation:&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;A href="http://www.cisco.com/en/US/docs/wireless/controller/7.4/configuration/guides/system_management/config_system_management_chapter_01110.html#ID3093" title="http://www.cisco.com/en/US/docs/wireless/controller/7.4/configuration/guides/system_management/config_system_management_chapter_01110.html#ID3093"&gt;Configuring Controller Settings - Configuring Quality of Service&amp;nbsp; [Cisco 5500 Series Wireless Controllers] - Cisco Syste…&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;EM&gt;“&lt;/EM&gt;&lt;STRONG&gt;&lt;EM style="color: #333333; background: white; font-size: 8pt; font-family: Arial, sans-serif;"&gt;If you choose to create an entry on the RADIUS server for a guest user and enable RADIUS authentication&lt;/EM&gt;&lt;/STRONG&gt;&lt;EM style="color: #333333; font-family: Arial, sans-serif;"&gt;&lt;BR /&gt; &lt;/EM&gt;&lt;STRONG&gt;&lt;EM style="color: #333333; background: white; font-size: 8pt; font-family: Arial, sans-serif;"&gt;for the WLAN on which web authentication is performed rather than adding a guest user to the local user&lt;/EM&gt;&lt;/STRONG&gt;&lt;EM style="color: #333333; font-family: Arial, sans-serif;"&gt;&lt;BR /&gt; &lt;/EM&gt;&lt;STRONG&gt;&lt;EM style="color: #333333; background: white; font-size: 8pt; font-family: Arial, sans-serif;"&gt;database from the controller, you need to assign the QoS role on the RADIUS server itself. To do so, a&lt;/EM&gt;&lt;/STRONG&gt;&lt;EM style="color: #333333; font-family: Arial, sans-serif;"&gt;&lt;BR /&gt; &lt;/EM&gt;&lt;STRONG&gt;&lt;EM style="color: #333333; background: white; font-size: 8pt; font-family: Arial, sans-serif;"&gt;“guest-role” Airespace attribute needs to be added on the RADIUS server with a datatype of “string” and&lt;/EM&gt;&lt;/STRONG&gt;&lt;EM style="color: #333333; font-family: Arial, sans-serif;"&gt;&lt;BR /&gt; &lt;/EM&gt;&lt;STRONG&gt;&lt;EM style="color: #333333; background: white; font-size: 8pt; font-family: Arial, sans-serif;"&gt;a return value of “11.” This attribute is sent to the controller when authentication occurs. If a role with the&lt;/EM&gt;&lt;/STRONG&gt;&lt;EM style="color: #333333; font-family: Arial, sans-serif;"&gt;&lt;BR /&gt; &lt;/EM&gt;&lt;STRONG&gt;&lt;EM style="color: #333333; background: white; font-size: 8pt; font-family: Arial, sans-serif;"&gt;name returned from the RADIUS server is found configured on the controller, the bandwidth associated&lt;/EM&gt;&lt;/STRONG&gt;&lt;EM style="color: #333333; font-family: Arial, sans-serif;"&gt;&lt;BR /&gt; &lt;/EM&gt;&lt;STRONG&gt;&lt;EM style="color: #333333; background: white; font-size: 8pt; font-family: Arial, sans-serif;"&gt;to that role is enforced for the guest user after authentication completes successfully.”&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;STRONG style="color: #333333; background: white; font-size: 8pt; font-family: Arial, sans-serif;"&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;It says that this is send in the authentication phase but I am not able to see in ISE how to do it in the authentication phase only I am able to send it in the authorization phase.&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Is it possible to do that in ISE 2.0?&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;In case of yes. How is that done?&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;I am using internal users in ISE.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Jun 2016 14:02:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-add-an-attribute-in-the-authentication-phase/m-p/3440523#M538491</guid>
      <dc:creator>Jaime Salcedo</dc:creator>
      <dc:date>2016-06-24T14:02:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to add an attribute in the authentication phase?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-add-an-attribute-in-the-authentication-phase/m-p/3440524#M538492</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I believe it refers to the Local Web Authentication (LWA) rather than the Central Web Authentication (CWA).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In LWA, the WLC may authenticate a webauth user against an ISE PSN and the ISE PSN would evaluate both the authentication and authorization policies in the process. See &lt;A href="http://www.cisco.com/c/en/us/support/docs/wireless-mobility/wlan-security/115951-web-auth-wlc-guide-00.html#anc18"&gt;External User Authentication (RADIUS)&lt;/A&gt; for more info. Thus, it's done by adding such attribute in the matched ISE authorization profile.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As to how this guest-role Airespace attribute works, please consult with our wireless support and/or product teams.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Jun 2016 15:50:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-add-an-attribute-in-the-authentication-phase/m-p/3440524#M538492</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2016-06-24T15:50:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to add an attribute in the authentication phase?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-add-an-attribute-in-the-authentication-phase/m-p/3440525#M538493</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 13.3333px;"&gt;Hi,&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;I am not talking here about any web authentication.&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;I am talking about PEAP with an user and password. For the explanation seems is in the first phase of the peap before the 4-way where this guess user information has to go from ISE to WLC.&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;cheers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jun 2016 08:17:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-add-an-attribute-in-the-authentication-phase/m-p/3440525#M538493</guid>
      <dc:creator>Jaime Salcedo</dc:creator>
      <dc:date>2016-06-27T08:17:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to add an attribute in the authentication phase?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-add-an-attribute-in-the-authentication-phase/m-p/3440526#M538494</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Problem I am geting is that I am receiving that message from WLC:&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="ES" style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #1f497d; background: white;"&gt;“ &lt;/SPAN&gt;&lt;SPAN lang="ES" style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #333333; background: white;"&gt;Unknown Airespace / Attribute 11”&amp;nbsp; when using &lt;SPAN lang="ES" style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #333333; background: white;"&gt;Airespace-Guest-Role-Name” (atributo ID 11)&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="ES" style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #333333; background: white;"&gt;&lt;SPAN lang="ES" style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #333333; background: white;"&gt;Cheers&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="ES" style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #333333; background: white;"&gt;&lt;SPAN lang="ES" style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #333333; background: white;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jun 2016 08:24:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-add-an-attribute-in-the-authentication-phase/m-p/3440526#M538494</guid>
      <dc:creator>Jaime Salcedo</dc:creator>
      <dc:date>2016-06-27T08:24:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to add an attribute in the authentication phase?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-add-an-attribute-in-the-authentication-phase/m-p/3440527#M538495</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please consult the wireless support teams for that. It may or may not be supported in the recent AireOS releases.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even with PEAP, ISE will evaluate both authentication and authorization policies and returns with the matched authorization profiles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jun 2016 10:41:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-add-an-attribute-in-the-authentication-phase/m-p/3440527#M538495</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2016-06-27T10:41:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to add an attribute in the authentication phase?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-add-an-attribute-in-the-authentication-phase/m-p/3440528#M538497</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The easiest way to rate limit guests is to use BDRL (Bidirectional Rate Limiting).&lt;/P&gt;&lt;P&gt;In AuthZ policy return the attributes shown on the screenshot below. The values are in kbits/sec&lt;IMG alt="image001.png" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/97013_image001.png" style="height: 271px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jun 2016 13:41:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-add-an-attribute-in-the-authentication-phase/m-p/3440528#M538497</guid>
      <dc:creator>vibobrov</dc:creator>
      <dc:date>2016-06-27T13:41:43Z</dc:date>
    </item>
  </channel>
</rss>

