<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE guest access in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-guest-access/m-p/3199887#M552443</link>
    <description>&lt;P&gt;Thanks everyone for your cooperation on this!!!&lt;/P&gt;
&lt;P&gt;I solved it by myself. Despite that I used this method on ISE 2.0 successfully but now with ISE 2.2, it doesn't work&amp;nbsp;this way (I downgraded switch IOS to a version mentioned on Cisco official website too). As I knew the combination of "&lt;STRONG&gt;authentication priority dot1x mab&lt;/STRONG&gt;"and "&lt;STRONG&gt;authentication order mab dot1x&lt;/STRONG&gt; " on a switch port should gave priority to dot1x, while any dot1x start/request packet is received by switch port. But it seems that this behavior is changed either on ISE or switch IOS.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I only changed authentication order to dot1x then mab and it worked well.&lt;/P&gt;</description>
    <pubDate>Tue, 17 Oct 2017 07:38:22 GMT</pubDate>
    <dc:creator>ciscoworlds</dc:creator>
    <dc:date>2017-10-17T07:38:22Z</dc:date>
    <item>
      <title>ISE guest access</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-access/m-p/3196296#M552438</link>
      <description>&lt;P&gt;Hi. I configured ISE and switch for guest access. while assigning IP address to the client statically, he is redirected to the guest portal and get the configured access to the network as configured. But he cannot get IP address dynamically from DHCP server. I changed the dACL to only contain "&lt;STRONG&gt;permit ip any any&lt;/STRONG&gt;" and he managed to get the IP. Even after I edited ACL and added entries which allowed everything (IP any any) to default gateway, DNS and DHCP servers, he didn't managed to get IP again! Also with "&lt;STRONG&gt;authentication open&lt;/STRONG&gt;" command on the port, the client was able to get the IP from DHCP without any problem. my port configuration is as follows:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;switchport mode access&lt;BR /&gt;authentication host-mode multi-auth&lt;BR /&gt;authentication order mab dot1x&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;mab&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 10&lt;BR /&gt;spanning-tree portfast&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:35:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-access/m-p/3196296#M552438</guid>
      <dc:creator>ciscoworlds</dc:creator>
      <dc:date>2020-02-21T18:35:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE guest access</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-access/m-p/3199480#M552440</link>
      <description>&lt;P&gt;Hi again;&lt;/P&gt;
&lt;P&gt;After all, I assigned IP address statically and then configure a dot1x authentication rule, put it up at the top of the table (before MAB) and as seen above, gave priority to dot1x over MAB on that switch port. but the traffic matched MAB and not Dot1x rule. I disabled MAB rule on the ISE and after that point the traffic matched Dot1x on ISE. After re-enabling the MAB, the traffic again matched MAB rule again. my Dot1x rule has been configured as this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;if **(Wired_802.1X OR Wireless_802.1X) ---- **Allow Protocols&lt;/STRONG&gt;: PEAP-ONLY&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Am I missing something?&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 15:18:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-access/m-p/3199480#M552440</guid>
      <dc:creator>ciscoworlds</dc:creator>
      <dc:date>2017-10-16T15:18:05Z</dc:date>
    </item>
    <item>
      <title>Re: ISE guest access</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-access/m-p/3199887#M552443</link>
      <description>&lt;P&gt;Thanks everyone for your cooperation on this!!!&lt;/P&gt;
&lt;P&gt;I solved it by myself. Despite that I used this method on ISE 2.0 successfully but now with ISE 2.2, it doesn't work&amp;nbsp;this way (I downgraded switch IOS to a version mentioned on Cisco official website too). As I knew the combination of "&lt;STRONG&gt;authentication priority dot1x mab&lt;/STRONG&gt;"and "&lt;STRONG&gt;authentication order mab dot1x&lt;/STRONG&gt; " on a switch port should gave priority to dot1x, while any dot1x start/request packet is received by switch port. But it seems that this behavior is changed either on ISE or switch IOS.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I only changed authentication order to dot1x then mab and it worked well.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2017 07:38:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-access/m-p/3199887#M552443</guid>
      <dc:creator>ciscoworlds</dc:creator>
      <dc:date>2017-10-17T07:38:22Z</dc:date>
    </item>
  </channel>
</rss>

