<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE CWA in foreign / anchor WLC deployment - usernames missing in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-cwa-in-foreign-anchor-wlc-deployment-usernames-missing/m-p/2683913#M54733</link>
    <description>&lt;P&gt;I'm not quite sure if this belongs to the mobility section or security - I'll just give it a try here.&lt;BR /&gt;I implemented wireless guest access with Cisco ISE 1.3 (patch 2) and a WLC foreign / anchor deployment (7.6.130.0).&lt;BR /&gt;So far nearly everything is working very good - but I have probably an issue with the Cisco ISE logging.&lt;/P&gt;&lt;P&gt;In the "Live Authentications" logging, I can see successful authentications, but in the column identity it just shows the MAC address of the endpoint.&lt;BR /&gt;If browsing to the endpoint identity store the guest endpoint is in the correct group (guestendpoints) and when looking at the endpoint details I can see the "portalusername" who created the user.&lt;/P&gt;&lt;P&gt;If I click on the active endpoints view (see attachment), I can see all active guests (Authz profil "PermitAccess"). I guess the username of the guest should be filled out there as well, right?&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/endpoint_view.png" class="migrated-markup-image" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anybody got an idea what the root cause for this is? Or is the normal behavior?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;My Authentication rules are:&lt;/STRONG&gt;&lt;BR /&gt;if "wireless_mab" and "Radius:Called-Station-ID ENDS WITH Guest-SSID" then use "internal endpoints" and continue if "user not found"&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;My Authorization rules are:&lt;/STRONG&gt;&lt;BR /&gt;1.) if GuestEndpoints AND (Wireless_MAB AND Radius:Called-Station-ID ENDS_WITH Guest-SSID ) then PermitAccess&lt;BR /&gt;2.) if (Wireless_MAB AND Radius:Called-Station-ID ENDS_WITH Guest-SSID ) then GUEST_WEBAUTH&lt;BR /&gt;The Authz Profile GUEST_WEBAUTH defined the CWA and the preAuth ACL for the WLC&lt;/P&gt;&lt;P&gt;On the WLC I just configured the foreign WLC with the RADIUS Server (ISE) and enabled MAC Authentication in the SSID.&lt;BR /&gt;All the settings like aaa-override and RADIUS NAC are set. The RADIUS delimited is set to "colon" to comply with the ISE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 05:54:57 GMT</pubDate>
    <dc:creator>Johannes Luther</dc:creator>
    <dc:date>2019-03-11T05:54:57Z</dc:date>
    <item>
      <title>ISE CWA in foreign / anchor WLC deployment - usernames missing</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cwa-in-foreign-anchor-wlc-deployment-usernames-missing/m-p/2683913#M54733</link>
      <description>&lt;P&gt;I'm not quite sure if this belongs to the mobility section or security - I'll just give it a try here.&lt;BR /&gt;I implemented wireless guest access with Cisco ISE 1.3 (patch 2) and a WLC foreign / anchor deployment (7.6.130.0).&lt;BR /&gt;So far nearly everything is working very good - but I have probably an issue with the Cisco ISE logging.&lt;/P&gt;&lt;P&gt;In the "Live Authentications" logging, I can see successful authentications, but in the column identity it just shows the MAC address of the endpoint.&lt;BR /&gt;If browsing to the endpoint identity store the guest endpoint is in the correct group (guestendpoints) and when looking at the endpoint details I can see the "portalusername" who created the user.&lt;/P&gt;&lt;P&gt;If I click on the active endpoints view (see attachment), I can see all active guests (Authz profil "PermitAccess"). I guess the username of the guest should be filled out there as well, right?&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/endpoint_view.png" class="migrated-markup-image" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anybody got an idea what the root cause for this is? Or is the normal behavior?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;My Authentication rules are:&lt;/STRONG&gt;&lt;BR /&gt;if "wireless_mab" and "Radius:Called-Station-ID ENDS WITH Guest-SSID" then use "internal endpoints" and continue if "user not found"&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;My Authorization rules are:&lt;/STRONG&gt;&lt;BR /&gt;1.) if GuestEndpoints AND (Wireless_MAB AND Radius:Called-Station-ID ENDS_WITH Guest-SSID ) then PermitAccess&lt;BR /&gt;2.) if (Wireless_MAB AND Radius:Called-Station-ID ENDS_WITH Guest-SSID ) then GUEST_WEBAUTH&lt;BR /&gt;The Authz Profile GUEST_WEBAUTH defined the CWA and the preAuth ACL for the WLC&lt;/P&gt;&lt;P&gt;On the WLC I just configured the foreign WLC with the RADIUS Server (ISE) and enabled MAC Authentication in the SSID.&lt;BR /&gt;All the settings like aaa-override and RADIUS NAC are set. The RADIUS delimited is set to "colon" to comply with the ISE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:54:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cwa-in-foreign-anchor-wlc-deployment-usernames-missing/m-p/2683913#M54733</guid>
      <dc:creator>Johannes Luther</dc:creator>
      <dc:date>2019-03-11T05:54:57Z</dc:date>
    </item>
    <item>
      <title>From my experience, this is</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cwa-in-foreign-anchor-wlc-deployment-usernames-missing/m-p/2683914#M54736</link>
      <description>&lt;P&gt;From my experience, this is expected behavior.&amp;nbsp; The new flow for the guest use case starting in ISE 1.3 typically includes registering the endpoint, like it sounds you are doing.&amp;nbsp; Your authz policy for post-portal authentication (following the CoA) requires the MAC address to be used as the identity for guest permissions, not the guest credential used at the portal.&amp;nbsp;&lt;/P&gt;&lt;P&gt;That being said, I too would like to be able to see the Portal User username each time that a registered endpoint authenticates (until it is purged using the Endpoint Purge Policies of course).&lt;/P&gt;&lt;P&gt;Tim&lt;/P&gt;</description>
      <pubDate>Sun, 23 Aug 2015 00:38:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cwa-in-foreign-anchor-wlc-deployment-usernames-missing/m-p/2683914#M54736</guid>
      <dc:creator>Tim Steele</dc:creator>
      <dc:date>2015-08-23T00:38:33Z</dc:date>
    </item>
    <item>
      <title>You will only see the</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cwa-in-foreign-anchor-wlc-deployment-usernames-missing/m-p/2683915#M54737</link>
      <description>&lt;P&gt;You will only see the username on the initial CWA authentication, once the client disconnects and then mab hits the top rule you will not see the username again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also if you are trying to restrict the maximum number of devices a guest user can connect, this also breaks also since there is no username to keep track of active sessions against.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks,&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2015 04:07:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cwa-in-foreign-anchor-wlc-deployment-usernames-missing/m-p/2683915#M54737</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2015-08-25T04:07:58Z</dc:date>
    </item>
    <item>
      <title>Thank you guys for the</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cwa-in-foreign-anchor-wlc-deployment-usernames-missing/m-p/2683916#M54738</link>
      <description>&lt;P&gt;Thank you guys for the feedback. The answer is exactely what I'm experiencing (with ISE 1.4 as well). I just wanted to know If I do something wrong &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Too sad, that the username is not displayed when the MAB rule is hit after the endpoint is registered. ISE knows the portal user name of the registered MAC address if you check in the "endpoint identities". If someone from Cisco sees this, please consider adding this information in the guest reports and the live authentication log.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2015 06:42:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cwa-in-foreign-anchor-wlc-deployment-usernames-missing/m-p/2683916#M54738</guid>
      <dc:creator>Johannes Luther</dc:creator>
      <dc:date>2015-09-04T06:42:27Z</dc:date>
    </item>
  </channel>
</rss>

