<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Once authenticated through CWA, want certain AD groups to be DeviceRegistered without using BYOD:  How to? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/once-authenticated-through-cwa-want-certain-ad-groups-to-be/m-p/4017459#M542453</link>
    <description>&lt;P&gt;Situation:&amp;nbsp; Open SSID for Guests Sponsored Access.&amp;nbsp;&amp;nbsp;Either guests or Employees can authenticate on CWA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Requirement: Once an AD:IT user is authenticated via CWA, customers wants MAC address of device be automatically added to RegisteredDevices.&amp;nbsp; Goal: when the device reassociate with the Guest-Net, it will be automatically accepted on the Guest network without any further cwa.&amp;nbsp; &amp;nbsp;The customer doesn't want to use BYOD for its employees, and wants the AD:IT employees to remain on the Guest-Net.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, customer would like that, following CWA, if an AD:Employee is &lt;STRONG&gt;NOT&lt;/STRONG&gt; from the IT group, then customer wants the MAC address to be put in Blacklist.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Summary:&amp;nbsp; the customer wants that, for users authenticating via CWA and OU=IT, the MAC address be put in the RegisteredDevices, and that those devices when re-connecting to the Guest-Net, be automatically recognized without prompting the user for CWA, but only for users from OU=IT.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Thu, 23 Jan 2020 23:24:08 GMT</pubDate>
    <dc:creator>cpaquet</dc:creator>
    <dc:date>2020-01-23T23:24:08Z</dc:date>
    <item>
      <title>Once authenticated through CWA, want certain AD groups to be DeviceRegistered without using BYOD:  How to?</title>
      <link>https://community.cisco.com/t5/network-access-control/once-authenticated-through-cwa-want-certain-ad-groups-to-be/m-p/4017459#M542453</link>
      <description>&lt;P&gt;Situation:&amp;nbsp; Open SSID for Guests Sponsored Access.&amp;nbsp;&amp;nbsp;Either guests or Employees can authenticate on CWA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Requirement: Once an AD:IT user is authenticated via CWA, customers wants MAC address of device be automatically added to RegisteredDevices.&amp;nbsp; Goal: when the device reassociate with the Guest-Net, it will be automatically accepted on the Guest network without any further cwa.&amp;nbsp; &amp;nbsp;The customer doesn't want to use BYOD for its employees, and wants the AD:IT employees to remain on the Guest-Net.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, customer would like that, following CWA, if an AD:Employee is &lt;STRONG&gt;NOT&lt;/STRONG&gt; from the IT group, then customer wants the MAC address to be put in Blacklist.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Summary:&amp;nbsp; the customer wants that, for users authenticating via CWA and OU=IT, the MAC address be put in the RegisteredDevices, and that those devices when re-connecting to the Guest-Net, be automatically recognized without prompting the user for CWA, but only for users from OU=IT.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2020 23:24:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/once-authenticated-through-cwa-want-certain-ad-groups-to-be/m-p/4017459#M542453</guid>
      <dc:creator>cpaquet</dc:creator>
      <dc:date>2020-01-23T23:24:08Z</dc:date>
    </item>
    <item>
      <title>Re: Once authenticated through CWA, want certain AD groups to be DeviceRegistered without using BYOD:  How to?</title>
      <link>https://community.cisco.com/t5/network-access-control/once-authenticated-through-cwa-want-certain-ad-groups-to-be/m-p/4022013#M542469</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291184"&gt;@cpaquet&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Situation:&amp;nbsp; Open SSID for Guests Sponsored Access.&amp;nbsp;&amp;nbsp;Either guests or Employees can authenticate on CWA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Requirement: Once an AD:IT user is authenticated via CWA, customers wants MAC address of device be automatically added to RegisteredDevices.&amp;nbsp; Goal: when the device reassociate with the Guest-Net, it will be automatically accepted on the Guest network without any further cwa.&amp;nbsp; &amp;nbsp;The customer doesn't want to use BYOD for its employees, and wants the AD:IT employees to remain on the Guest-Net.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, customer would like that, following CWA, if an AD:Employee is &lt;STRONG&gt;NOT&lt;/STRONG&gt; from the IT group, then customer wants the MAC address to be put in Blacklist.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Summary:&amp;nbsp; the customer wants that, for users authenticating via CWA and OU=IT, the MAC address be put in the RegisteredDevices, and that those devices when re-connecting to the Guest-Net, be automatically recognized without prompting the user for CWA, but only for users from OU=IT.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Check out special flows.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-guest-amp-web-authentication/ta-p/3657224#toc-hId--1778324119" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-guest-amp-web-authentication/ta-p/3657224#toc-hId--1778324119&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is no way to choose on login which groups do what. however you can play with this. Look at the &lt;A title="prescriptive guest guide" href="https://community.cisco.com/t5/security-documents/ise-guest-access-prescriptive-deployment-guide/ta-p/3640475" target="_blank" rel="noopener"&gt;prescriptive guest guide&lt;/A&gt; for more details on some configurations . you can tweak around with this&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;You can however to do the following:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;setup multiple endpoint groups for guest endpoints&lt;/P&gt;
&lt;P&gt;allowedEndpoint&lt;/P&gt;
&lt;P&gt;Denied endpoint&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;setup allowedhotspot portal mapped to allowedEndpoint&lt;/P&gt;
&lt;P&gt;do similiar for denyportal&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;setup authorization flows&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;if mab and guestflow and adGroupAllowed then redirect to allowedHotspotPortal (device will be assigned correct group)&lt;/P&gt;
&lt;P&gt;if mab and guestflow and deniedGroup ( or no groups) then redirect go denieDportal&lt;/P&gt;
&lt;P&gt;if mab and GuestEndpoint group then permit access&lt;/P&gt;
&lt;P&gt;if mab and deniedEndpoint then deny access&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if mab then redirect to guest portal&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 01 Feb 2020 04:28:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/once-authenticated-through-cwa-want-certain-ad-groups-to-be/m-p/4022013#M542469</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2020-02-01T04:28:51Z</dc:date>
    </item>
  </channel>
</rss>

