<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Guest Flow with Multiple Endpoint Identities in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-guest-flow-with-multiple-endpoint-identities/m-p/3500201#M539222</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This was on the guest network so no permission differences. Customer wanted to have execs renew AUP every 365 days and Employees using the Guest Wifi every 8 days.&amp;nbsp; Needed a way to purge devices that were using the Guest WiFi.&amp;nbsp; Once purged, AUP was redisplayed.&amp;nbsp; Also a way to clean up the DB clutter.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 07 Jul 2016 21:29:24 GMT</pubDate>
    <dc:creator>scamarda</dc:creator>
    <dc:date>2016-07-07T21:29:24Z</dc:date>
    <item>
      <title>ISE Guest Flow with Multiple Endpoint Identities</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-flow-with-multiple-endpoint-identities/m-p/3500190#M539207</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Customer has guest wireless controlled via ISE.&amp;nbsp; Employees are allowed to use the guest wireless with their personal devices when they log in through active directory.&amp;nbsp;&amp;nbsp; Once the employee logs in via the portal page, they are registering the device so the system does a MAB on the second and subsequent logins for that device.&amp;nbsp; What they are asking is to be able put certain users in separate identity groups.&amp;nbsp; This is to be able to purge the registered devices at specific intervals.&amp;nbsp; For example, Executives would log in one time and not have to enter credentials&amp;nbsp; again for 365 days (after the device is purged).&amp;nbsp; Employees would log in from the guest portal and their device would be purged out after 30 days.&amp;nbsp; In the guest portal and byod portals it only shows 1 identity group to assign the user.&amp;nbsp; Can I assign more then one identity group in a guest flow?&amp;nbsp; I think what I am looking for is DRW with multiple identity groups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there another way to be able to assign guest users to different policies and then purge them at a specific interval?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Apr 2016 17:19:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-flow-with-multiple-endpoint-identities/m-p/3500190#M539207</guid>
      <dc:creator>scamarda</dc:creator>
      <dc:date>2016-04-11T17:19:52Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest Flow with Multiple Endpoint Identities</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-flow-with-multiple-endpoint-identities/m-p/3500191#M539208</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Since both of these type of users are in the same Identity store and considered employees to the guest portal thank I think you could do it the following way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This would assume you have an AD group for execs vs employees or perhaps LDAP attribute?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Create endpoint groups for employees and another for execs. Purging policy as needed.&lt;/LI&gt;&lt;LI&gt;Create a hotspot portal for employee devices and another for executives and choose the corresponding endpoint groups.&lt;/LI&gt;&lt;LI&gt;Setup authorization rule above the standard redirect rule to say if guest flow and employees then redirect to employee hotspot portal. Make another rule above that for Executives group.&lt;/LI&gt;&lt;/OL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Apr 2016 17:26:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-flow-with-multiple-endpoint-identities/m-p/3500191#M539208</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2016-04-11T17:26:06Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest Flow with Multiple Endpoint Identities</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-flow-with-multiple-endpoint-identities/m-p/3500192#M539210</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Followed your instructions below.  I have three rules plus the CWA.  Hotspot 1, Hotspot 2 and a Guest Access depending on the Hotspot assigned identity.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've enabled the policy - user hits CWA then is redirected to appropriate Hotspot portal.  The hotspot portal is set up to put the endpoint in a specific endpoint identity.  Flow goes through hotspot but the endpoint assignment does not happen. The endpoint identity stays as Unknown and I loop back to CWA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What am I missing ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Apr 2016 17:07:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-flow-with-multiple-endpoint-identities/m-p/3500192#M539210</guid>
      <dc:creator>scamarda</dc:creator>
      <dc:date>2016-04-12T17:07:22Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest Flow with Multiple Endpoint Identities</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-flow-with-multiple-endpoint-identities/m-p/3500193#M539212</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What version of ise ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have heard something similar where endpoint is not being registered into group&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is regular hotspot working?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Apr 2016 17:27:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-flow-with-multiple-endpoint-identities/m-p/3500193#M539212</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2016-04-12T17:27:46Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest Flow with Multiple Endpoint Identities</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-flow-with-multiple-endpoint-identities/m-p/3500194#M539214</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ISE 2.0 no patch. Will have to test regular hotspot functionality.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Apr 2016 17:36:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-flow-with-multiple-endpoint-identities/m-p/3500194#M539214</guid>
      <dc:creator>scamarda</dc:creator>
      <dc:date>2016-04-12T17:36:10Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest Flow with Multiple Endpoint Identities</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-flow-with-multiple-endpoint-identities/m-p/3500195#M539216</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I know there was a problem with ISE 2.0 with no patch not registering correctly&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you apply latest patch and then make sure you are sending to an AUP page where they have to hit accept?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Apr 2016 17:42:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-flow-with-multiple-endpoint-identities/m-p/3500195#M539216</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2016-04-12T17:42:19Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest Flow with Multiple Endpoint Identities</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-flow-with-multiple-endpoint-identities/m-p/3500196#M539217</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Upgrading to 2.0.1.130 seems to have fixed the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Apr 2016 11:15:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-flow-with-multiple-endpoint-identities/m-p/3500196#M539217</guid>
      <dc:creator>scamarda</dc:creator>
      <dc:date>2016-04-13T11:15:25Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest Flow with Multiple Endpoint Identities</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-flow-with-multiple-endpoint-identities/m-p/3500197#M539218</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is a very interesting setup.&amp;nbsp; Could you share a quick screen capture of your Auth policies?&amp;nbsp; I am looking at applying the same method. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jun 2016 20:41:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-flow-with-multiple-endpoint-identities/m-p/3500197#M539218</guid>
      <dc:creator>ajamerica</dc:creator>
      <dc:date>2016-06-28T20:41:49Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest Flow with Multiple Endpoint Identities</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-flow-with-multiple-endpoint-identities/m-p/3500198#M539219</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://community.cisco.com//u1/26947"&gt;scamarda&lt;/A&gt; can you share&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jul 2016 19:03:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-flow-with-multiple-endpoint-identities/m-p/3500198#M539219</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2016-07-06T19:03:24Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest Flow with Multiple Endpoint Identities</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-flow-with-multiple-endpoint-identities/m-p/3500199#M539220</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Usernames are loaded in AD.&amp;nbsp; Originally the use CWA.&amp;nbsp; The different AD user types are directed to their respective hotspot portal.&amp;nbsp; Once they hit the portal there are assigned a unique identity.&amp;nbsp; There is an AUP in between CWA and the Hotspot.&amp;nbsp; Other than that, not interaction.&amp;nbsp; The identities are defined with different purge times.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Hotspot Category.png" class="image-1 jive-image" src="/legacyfs/online/fusion/97431_Hotspot Category.png" style="height: 91px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jul 2016 21:16:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-flow-with-multiple-endpoint-identities/m-p/3500199#M539220</guid>
      <dc:creator>scamarda</dc:creator>
      <dc:date>2016-07-07T21:16:29Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest Flow with Multiple Endpoint Identities</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-flow-with-multiple-endpoint-identities/m-p/3500200#M539221</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok assuming you have authz rules above that with the different endpoint groups&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if executiveEndpoint then permitExecutive permissions&lt;/P&gt;&lt;P&gt;if UserEndpoint then permitUser permissions&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jul 2016 21:23:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-flow-with-multiple-endpoint-identities/m-p/3500200#M539221</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2016-07-07T21:23:25Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest Flow with Multiple Endpoint Identities</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-flow-with-multiple-endpoint-identities/m-p/3500201#M539222</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This was on the guest network so no permission differences. Customer wanted to have execs renew AUP every 365 days and Employees using the Guest Wifi every 8 days.&amp;nbsp; Needed a way to purge devices that were using the Guest WiFi.&amp;nbsp; Once purged, AUP was redisplayed.&amp;nbsp; Also a way to clean up the DB clutter.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jul 2016 21:29:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-flow-with-multiple-endpoint-identities/m-p/3500201#M539222</guid>
      <dc:creator>scamarda</dc:creator>
      <dc:date>2016-07-07T21:29:24Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest Flow with Multiple Endpoint Identities</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-flow-with-multiple-endpoint-identities/m-p/3500202#M539223</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for sharing!&amp;nbsp; I am working on setting up the same scenario for a customer as well.&amp;nbsp; We are now trying to configure identity mapping to identify the users on these open connections.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Jul 2016 19:42:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-flow-with-multiple-endpoint-identities/m-p/3500202#M539223</guid>
      <dc:creator>ajamerica</dc:creator>
      <dc:date>2016-07-11T19:42:18Z</dc:date>
    </item>
  </channel>
</rss>

