<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Guest re authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3405207#M548238</link>
    <description>&lt;P&gt;802.1x requires an entire reauthentication (not reassociation)&amp;nbsp;when roaming. Not sure if the same happens on CWA. Just to be safe, do you have session timeout enabled on that SSID?&lt;/P&gt;</description>
    <pubDate>Mon, 25 Jun 2018 20:15:32 GMT</pubDate>
    <dc:creator>ajc</dc:creator>
    <dc:date>2018-06-25T20:15:32Z</dc:date>
    <item>
      <title>ISE Guest re authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3404386#M548220</link>
      <description>&lt;P&gt;Hello Community,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a customer that wants guest users expire be blocked for some time (one day) after that time they get authorize to reauthenticate again through the captive portal.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It’s possible?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks a lot&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:59:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3404386#M548220</guid>
      <dc:creator>Leonardo Pena Aristizabal</dc:creator>
      <dc:date>2020-02-21T18:59:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest re authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3404418#M548222</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Never had such request before but I'm quite sure this isn't possible. I mean an account is valid for x days and during this x days, the guest user can authenticate without issues.&lt;/P&gt;
&lt;P&gt;There's no option saying block the user and then re-authenticate him again.&lt;/P&gt;
&lt;P&gt;Can you check maybe on api if there's something to activate again expired users. If yes, you will need to have them for 1 day and execute a scheduled script that will allow them again 2 days after.&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jun 2018 01:12:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3404418#M548222</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2018-06-24T01:12:06Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest re authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3404495#M548224</link>
      <description>&lt;DIV dir="auto" data-removefontsize="true" data-originalcomputedfontsize="16"&gt;Ok, so if a guest wants to gain access they just re authenticate and when expires again reauthenticate and expires and basically they just can repeat the same process?&lt;/DIV&gt;
&lt;DIV dir="auto"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV dir="auto" data-removefontsize="true" data-originalcomputedfontsize="16"&gt;That’s what my customer don’t want?&lt;/DIV&gt;
&lt;DIV dir="auto"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV dir="auto" data-removefontsize="true" data-originalcomputedfontsize="16"&gt;Thanks for your time.&lt;/DIV&gt;</description>
      <pubDate>Sun, 24 Jun 2018 13:55:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3404495#M548224</guid>
      <dc:creator>Leonardo Pena Aristizabal</dc:creator>
      <dc:date>2018-06-24T13:55:16Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest re authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3404604#M548226</link>
      <description>&lt;P&gt;Ok what your customer wants is not possible in ISE, i mean i don't see any workaround making it working.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Usually you allow guest for x days and if they come back they'll go through the same process again. And more than that if you granted them access for 2 days, they can connect as much as they want.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe there's another solution but can you detail the real use case?&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jun 2018 22:45:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3404604#M548226</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2018-06-24T22:45:58Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest re authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3405151#M548227</link>
      <description>&lt;P&gt;hay que aclarar algo, la cuenta guest dura un periodo especifico de dias luego de lo cual expira y NO se puede reusar porque ya no esta vigente. PERO esa cuenta se puede "reinstate" manualmente por el administrador del ISE. Tendrias que investigar si se puede crear un script que busque por ese usuario en la base de datos y reinstale/reactive esa cuenta de invitado que estaba expirada luego de un numero X de dias a tu criterio SINO, hacerlo a mano como te senale antes.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 19:18:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3405151#M548227</guid>
      <dc:creator>ajc</dc:creator>
      <dc:date>2018-06-25T19:18:07Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest re authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3405156#M548228</link>
      <description>&lt;P&gt;Hola&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Si claro tienes toda la razón el tema es que yo monté un Script sobre un portal auto register para que funcionara como Hot Spot pero solicitando datos. (Nombre y correo)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Entonces la idea es que esos usuarios que se autoregistran no lo hagan constantemente, si no que duren bloqueados cierto tiempo.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Muchas gracias por tu tiempo.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 19:20:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3405156#M548228</guid>
      <dc:creator>Leonardo Pena Aristizabal</dc:creator>
      <dc:date>2018-06-25T19:20:40Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest re authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3405161#M548229</link>
      <description>&lt;P&gt;No le encuentro sentido a que permitas un autoregistro&amp;nbsp;y que no puedan usar la cuenta de inmediato.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 19:25:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3405161#M548229</guid>
      <dc:creator>ajc</dc:creator>
      <dc:date>2018-06-25T19:25:54Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest re authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3405167#M548230</link>
      <description>&lt;P&gt;No, mira el tema es así:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. El usuario usa el portal, se registra e inmediatamente brinda acceso a internet por una hora.&lt;/P&gt;
&lt;P&gt;2. Al terminarse la hora la cuenta expira y el usuario ya no tiene acceso.&lt;/P&gt;
&lt;P&gt;3. Nuevamente el usuario va a intentar conectarse, nuevamente se despliega el portal cautivo donde el usuario nuevamente hace el proceso con otro nombre y le da acceso a internet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Lo que quiere el cliente es que el paso 3 solo sea permitido un día después, es decir que el mismo usuario (PC-Celular) no pueda reconectarse nuevamente.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Gracias&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 19:30:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3405167#M548230</guid>
      <dc:creator>Leonardo Pena Aristizabal</dc:creator>
      <dc:date>2018-06-25T19:30:19Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest re authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3405169#M548231</link>
      <description>&lt;P&gt;I'm sorry to disturb but if the post starts in English, it would be appreciated to continue in the same&amp;nbsp;language, then everybody can help and understand what's going on.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 19:31:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3405169#M548231</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2018-06-25T19:31:16Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest re authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3405176#M548232</link>
      <description>&lt;P&gt;Yes, I agree.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sorry about that.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was explaining the process that my customer want's to blocked or not permit.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The flow is something like this:&lt;/P&gt;
&lt;P&gt;1. Users connect to the SSID with CWA (Auto register with HTML mod for Hot Spot) fill the form a get access to Internet for one hour.&lt;/P&gt;
&lt;P&gt;2. After that hour the users get expired and finally kick out.&lt;/P&gt;
&lt;P&gt;3. The users try to reconnect and again the CWA is displayed, then the user fill again the form with another name and get access to Internet for another hour.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What my customer wants is to block for certain time that user (PC-Smartphone) to get reconnected.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks and again sorry for the language.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 19:40:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3405176#M548232</guid>
      <dc:creator>Leonardo Pena Aristizabal</dc:creator>
      <dc:date>2018-06-25T19:40:47Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest re authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3405180#M548233</link>
      <description>&lt;P&gt;Hi Leo,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I suspect you will have to create an AUTHZ Policy using MAB.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not sure if the following helps:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1.-Initial Guest Account creation, 1 hour use. Successful access. MAC address enduser device automatically added to an&amp;nbsp;ISE Endpoint Group.&lt;/P&gt;
&lt;P&gt;2.-1 hour later, account expired but the MAC is still in the DB&lt;/P&gt;
&lt;P&gt;3.-User tries to create another Guest account with different username/email, hits an AUTHZ policy that says IF MAC in GuestEndpoint DB then deny access OR redirect to a warning page that could say something like: "you have reach the maximum amount of allowed wireless internet service".&lt;/P&gt;
&lt;P&gt;4.-You purge the Guest Endpoint Group every 24 hours.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 19:47:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3405180#M548233</guid>
      <dc:creator>ajc</dc:creator>
      <dc:date>2018-06-25T19:47:30Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest re authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3405185#M548234</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I already did that but for some reason after a couple of minutes I get kick off, maybe the ISE check's time to time something about policies matching or some process that make me hits that rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks a lot for your time.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 19:50:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3405185#M548234</guid>
      <dc:creator>Leonardo Pena Aristizabal</dc:creator>
      <dc:date>2018-06-25T19:50:36Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest re authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3405194#M548235</link>
      <description>&lt;P&gt;When you say for certain time, does this means specific hours in the day or wait x minutes/hours after its last login?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 20:01:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3405194#M548235</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2018-06-25T20:01:16Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest re authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3405195#M548236</link>
      <description>&lt;P&gt;x minutes/hours after its last login.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 20:04:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3405195#M548236</guid>
      <dc:creator>Leonardo Pena Aristizabal</dc:creator>
      <dc:date>2018-06-25T20:04:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest re authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3405198#M548237</link>
      <description>&lt;P&gt;I know there is something called ELAPSEDdays for the MAC address in the ISE Endpoint DB. Not sure if there is something called ElapsedHours, let me check&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;UPDATE: Only the first one. What if you try something like&amp;nbsp;an AUTHZ policy that says:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If Endpoint ElapsedDays equal or greater to 1 day, then CWA&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let's see why you are getting disconnected.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 20:09:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3405198#M548237</guid>
      <dc:creator>ajc</dc:creator>
      <dc:date>2018-06-25T20:09:45Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest re authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3405207#M548238</link>
      <description>&lt;P&gt;802.1x requires an entire reauthentication (not reassociation)&amp;nbsp;when roaming. Not sure if the same happens on CWA. Just to be safe, do you have session timeout enabled on that SSID?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 20:15:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3405207#M548238</guid>
      <dc:creator>ajc</dc:creator>
      <dc:date>2018-06-25T20:15:32Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest re authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3405209#M548239</link>
      <description>&lt;P&gt;Yes, the default 1.800.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 20:17:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3405209#M548239</guid>
      <dc:creator>Leonardo Pena Aristizabal</dc:creator>
      <dc:date>2018-06-25T20:17:19Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest re authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3405219#M548240</link>
      <description>Yes the only thing possible is in terms of days and not hours.&lt;BR /&gt;</description>
      <pubDate>Mon, 25 Jun 2018 20:24:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3405219#M548240</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2018-06-25T20:24:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest re authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3405227#M548242</link>
      <description>&lt;P&gt;So you think is possible to block a MAC/User within a day?&lt;/P&gt;
&lt;P&gt;If yes can you please explain me how?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 20:36:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3405227#M548242</guid>
      <dc:creator>Leonardo Pena Aristizabal</dc:creator>
      <dc:date>2018-06-25T20:36:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest re authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3405236#M548243</link>
      <description>Nope, I was answering regarding Elapsed time expressed only in days and not hours.&lt;BR /&gt;&lt;BR /&gt;For your issue, does a user has to sign a AUP? If so, you can maybe play with the condition EndPoints·LastAUPAcceptanceHours and block the user. Usually this is used to force a user re-sign AUP but in your case, you can use it to deny access with the following example:&lt;BR /&gt;rule 1: if EndPoints·LastAUPAcceptanceHours is less than 240 accept&lt;BR /&gt;rule 2: if EndPoints·LastAUPAcceptanceHours is less than 120 deny&lt;BR /&gt;&lt;BR /&gt;I mean you can play with it and test if it can make working what you're trying to achieve.&lt;BR /&gt;</description>
      <pubDate>Mon, 25 Jun 2018 20:49:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-re-authentication/m-p/3405236#M548243</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2018-06-25T20:49:58Z</dc:date>
    </item>
  </channel>
</rss>

