<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VLAN change based on guest user type in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/vlan-change-based-on-guest-user-type/m-p/4062134#M559479</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm new in ISE, doing some test and PoC's right now and I have a question - is it possible to move a guest user (authenticated on a webauth page) to a specific VLAN based on the guest type?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My idea is to create different guest types with different "network access levels" - for example "new guests" are moved to a "limited access" VLAN, but "known guests" are put into a "full access" one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it doable in ISE 2.7 or the only option is to use a different SSID's?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Piotr&lt;/P&gt;</description>
    <pubDate>Wed, 08 Apr 2020 20:35:38 GMT</pubDate>
    <dc:creator>Piotr Grabowski</dc:creator>
    <dc:date>2020-04-08T20:35:38Z</dc:date>
    <item>
      <title>VLAN change based on guest user type</title>
      <link>https://community.cisco.com/t5/network-access-control/vlan-change-based-on-guest-user-type/m-p/4062134#M559479</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm new in ISE, doing some test and PoC's right now and I have a question - is it possible to move a guest user (authenticated on a webauth page) to a specific VLAN based on the guest type?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My idea is to create different guest types with different "network access levels" - for example "new guests" are moved to a "limited access" VLAN, but "known guests" are put into a "full access" one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it doable in ISE 2.7 or the only option is to use a different SSID's?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Piotr&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2020 20:35:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vlan-change-based-on-guest-user-type/m-p/4062134#M559479</guid>
      <dc:creator>Piotr Grabowski</dc:creator>
      <dc:date>2020-04-08T20:35:38Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN change based on guest user type</title>
      <link>https://community.cisco.com/t5/network-access-control/vlan-change-based-on-guest-user-type/m-p/4062230#M559486</link>
      <description>&lt;P&gt;Dynamic VLAN assignment is possible on a Cisco WLC. See this &lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/99121-vlan-acs-ad-config.html" target="_self"&gt;TechNote&lt;/A&gt; for an example.&lt;/P&gt;
&lt;P&gt;The difficulty with your scenario is answering questions like:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;What constitutes a 'new guest' vs. a 'known guest'?&lt;/LI&gt;
&lt;LI&gt;When does a 'new' become a 'known' and what attribute can ISE use to differentiate between them?&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;There are various examples of Guest configuration and scenarios at &lt;A title="cs.co/ise-guest" href="http://cs.co/ise-guest" target="_blank" rel="nofollow noopener noreferrer noreferrer"&gt;cs.co/ise-guest&lt;/A&gt; that might give you some ideas.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2020 23:01:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vlan-change-based-on-guest-user-type/m-p/4062230#M559486</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2020-04-08T23:01:06Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN change based on guest user type</title>
      <link>https://community.cisco.com/t5/network-access-control/vlan-change-based-on-guest-user-type/m-p/4062431#M559495</link>
      <description>&lt;P&gt;Let me explain the baseline - one of our clients has a network (wireless VLAN) with a lot of restrictions regarding applications (e.g. YouTube is completely blocked). When any of employees wants to use YouTube, has to ask for it and there is a different SSID temporarily enabled (different VLAN) with full Internet access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My idea was to create (manually) a guest user for anyone who wants to use YouTube and put this user into a "YouTube' user group. After webauth, such user is being switched to a full access VLAN (based on the group). Is it a good idea?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know that there is a lot of features which help to control users, but in this case the network admin want's to have a manual control over full Internet access. I'm just trying to find a best solution having C9800 as a controller, 3 FlexConnect locations, AD and ISE 2.7&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2020 06:21:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vlan-change-based-on-guest-user-type/m-p/4062431#M559495</guid>
      <dc:creator>Piotr Grabowski</dc:creator>
      <dc:date>2020-04-09T06:21:11Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN change based on guest user type</title>
      <link>https://community.cisco.com/t5/network-access-control/vlan-change-based-on-guest-user-type/m-p/4062452#M559497</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;As long as the required policy are already in place (i mean to which resources does the WIFi user get access to), and ISE just needs to put the user in the proper VLAN, this is a simple task. You'll be having two different groups of users, and based on the group membership, ISE assign a different VLAN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cristian Matei.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2020 07:02:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vlan-change-based-on-guest-user-type/m-p/4062452#M559497</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2020-04-09T07:02:13Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN change based on guest user type</title>
      <link>https://community.cisco.com/t5/network-access-control/vlan-change-based-on-guest-user-type/m-p/4062480#M559500</link>
      <description>&lt;P&gt;Yes, but is it possible regarding guest users that are not in the AD?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2020 07:44:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vlan-change-based-on-guest-user-type/m-p/4062480#M559500</guid>
      <dc:creator>Piotr Grabowski</dc:creator>
      <dc:date>2020-04-09T07:44:15Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN change based on guest user type</title>
      <link>https://community.cisco.com/t5/network-access-control/vlan-change-based-on-guest-user-type/m-p/4065047#M559564</link>
      <description>&lt;P&gt;There are two typical associations related to Guest services... Guest Type and Endpoint Identity Group.&lt;/P&gt;
&lt;P&gt;The Guest Type is assigned by the Sponsor at the time of the Guest account creation. A Sponsor with the right permissions (e.g. Sponsor All with 'can create accounts' with the relevant Guest Types) can also change the Guest Type after the initial account creation. ISE automatically creates a User Identity Group for each Guest Type.&lt;/P&gt;
&lt;P&gt;The endpoint MAC Address is associated with the Endpoint Identity Group as part of the Guest Registration flow (default is GuestEndpoints). The common documented Guest flows use this EIG association to allow registered endpoints to connect without the Guest user having to constantly login to the Guest Portal.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You could use either (or both) of these attributes in your AuthZ Policy to provide differentiated access between your 'limited' and 'full' access guests/endpoints.&lt;/P&gt;
&lt;P&gt;Example:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-04-14 at 10.21.16 am.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/71569iA247DF28D2EC2BB6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2020-04-14 at 10.21.16 am.png" alt="Screen Shot 2020-04-14 at 10.21.16 am.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2020 00:22:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vlan-change-based-on-guest-user-type/m-p/4065047#M559564</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2020-04-14T00:22:54Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN change based on guest user type</title>
      <link>https://community.cisco.com/t5/network-access-control/vlan-change-based-on-guest-user-type/m-p/4066219#M559638</link>
      <description>&lt;P&gt;Thank you Greg, that is what I was looking for &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I will try to test it now and check the result.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2020 08:49:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vlan-change-based-on-guest-user-type/m-p/4066219#M559638</guid>
      <dc:creator>Piotr Grabowski</dc:creator>
      <dc:date>2020-04-15T08:49:51Z</dc:date>
    </item>
  </channel>
</rss>

