<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ISE CWA Guest Access with Sponsor Portal in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-cwa-guest-access-with-sponsor-portal/m-p/4095104#M560783</link>
    <description>&lt;P&gt;Dear Collegues,&lt;/P&gt;&lt;P&gt;I experiencing very strange situation. First of all, I have 2xISE 2.6 in HA:&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://daveonsecurity.files.wordpress.com/2016/08/cisco-ise-two-node-deployment.png?w=640" border="0" alt="Upgrading Cisco ISE 2.0 to 2.1 in Two-Node Deployment – Dave On ..." /&gt;&lt;/P&gt;&lt;P&gt;I implemented Guest Portal with Sponsor Portal where, Sponsors create account for guest, then guest has limited access to network. Everything working good only where:&lt;/P&gt;&lt;P&gt;1. In Authorization profile I use static IP mapping for one PSN or FQDN of Guest Portal (where DNS server has only one record A mapping to PSN)&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://integratingit.files.wordpress.com/2020/01/011920_1621_iseguestacc4.png" border="0" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please be aware that above screenshot is from official cisco documentation. In my scenerio I have set value: Guest Portal (not Self-Registered Portal)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. In WLC I have set only one Radius Auth/Acc:&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://wrmem.net/wp-content/uploads/2018/09/Screen-Shot-2018-09-10-at-5.42.29-PM.png" border="0" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For above configuration (Rest of all configuration I skip because it has not impact for my problem) as I said everything workig good.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Problem appear where:&lt;/P&gt;&lt;P&gt;I set in WLC for section AAA Server second PSN and where I set second PSN address IP (record A in DNS Server) for FQDN Guest Portal.&lt;/P&gt;&lt;P&gt;I think that problem is related with SessionID when ISE transfer authorization profile to guest.&lt;/P&gt;&lt;P&gt;Guest send request to DNS, and DNS return other IP address of PSN which transfer authorization profile before. So guest trying to reach Guest Portal on PSN which not know about this session.&lt;/P&gt;&lt;P&gt;How can I resolve the problem ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to configure Guest Portal where I have 2 PSN ? Or I need LB (for example F5) ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 31 May 2020 14:54:27 GMT</pubDate>
    <dc:creator>mikiNet</dc:creator>
    <dc:date>2020-05-31T14:54:27Z</dc:date>
    <item>
      <title>Cisco ISE CWA Guest Access with Sponsor Portal</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-cwa-guest-access-with-sponsor-portal/m-p/4095104#M560783</link>
      <description>&lt;P&gt;Dear Collegues,&lt;/P&gt;&lt;P&gt;I experiencing very strange situation. First of all, I have 2xISE 2.6 in HA:&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://daveonsecurity.files.wordpress.com/2016/08/cisco-ise-two-node-deployment.png?w=640" border="0" alt="Upgrading Cisco ISE 2.0 to 2.1 in Two-Node Deployment – Dave On ..." /&gt;&lt;/P&gt;&lt;P&gt;I implemented Guest Portal with Sponsor Portal where, Sponsors create account for guest, then guest has limited access to network. Everything working good only where:&lt;/P&gt;&lt;P&gt;1. In Authorization profile I use static IP mapping for one PSN or FQDN of Guest Portal (where DNS server has only one record A mapping to PSN)&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://integratingit.files.wordpress.com/2020/01/011920_1621_iseguestacc4.png" border="0" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please be aware that above screenshot is from official cisco documentation. In my scenerio I have set value: Guest Portal (not Self-Registered Portal)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. In WLC I have set only one Radius Auth/Acc:&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://wrmem.net/wp-content/uploads/2018/09/Screen-Shot-2018-09-10-at-5.42.29-PM.png" border="0" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For above configuration (Rest of all configuration I skip because it has not impact for my problem) as I said everything workig good.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Problem appear where:&lt;/P&gt;&lt;P&gt;I set in WLC for section AAA Server second PSN and where I set second PSN address IP (record A in DNS Server) for FQDN Guest Portal.&lt;/P&gt;&lt;P&gt;I think that problem is related with SessionID when ISE transfer authorization profile to guest.&lt;/P&gt;&lt;P&gt;Guest send request to DNS, and DNS return other IP address of PSN which transfer authorization profile before. So guest trying to reach Guest Portal on PSN which not know about this session.&lt;/P&gt;&lt;P&gt;How can I resolve the problem ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to configure Guest Portal where I have 2 PSN ? Or I need LB (for example F5) ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 31 May 2020 14:54:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-cwa-guest-access-with-sponsor-portal/m-p/4095104#M560783</guid>
      <dc:creator>mikiNet</dc:creator>
      <dc:date>2020-05-31T14:54:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE CWA Guest Access with Sponsor Portal</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-cwa-guest-access-with-sponsor-portal/m-p/4095119#M560786</link>
      <description>Hi,&lt;BR /&gt;You need to associate the Guest portal with the PSN that authenticated the session, normally in this situation a load balancer would be recommended. You can achieve this without a LB by creating multiple authorisation profiles/rules for each PSN.&lt;BR /&gt;&lt;BR /&gt;- Create 2 Guest FQDNs for each PSN&lt;BR /&gt;- Create 2 authorisation profiles, in the frist profile reference the PSN1 FQDN and in the other reference the PSN2 FQDN&lt;BR /&gt;- Create 2 authoration rules, match on condition "Network Access ISE Host Name EQUALS &amp;lt;PSN1&amp;gt;" and reference the PSN1 authorisation profile. Create a second authorisation rule, match on condition match on condition "Network Access ISE Host Name EQUALS &amp;lt;PSN2&amp;gt;" and reference the PSN2 authorisation profile.&lt;BR /&gt;&lt;BR /&gt;HTH</description>
      <pubDate>Sun, 31 May 2020 16:21:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-cwa-guest-access-with-sponsor-portal/m-p/4095119#M560786</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-05-31T16:21:26Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE CWA Guest Access with Sponsor Portal</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-cwa-guest-access-with-sponsor-portal/m-p/4095154#M560788</link>
      <description>&lt;P&gt;Thanks Rob!! About "&lt;SPAN&gt;Create 2 Guest FQDNs for each PSN" - is it related to create two Guest Portal ? Additionaly, if I must create two DNS record A ? One for PSN1 and other to PSN2 ?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 31 May 2020 18:39:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-cwa-guest-access-with-sponsor-portal/m-p/4095154#M560788</guid>
      <dc:creator>mikiNet</dc:creator>
      <dc:date>2020-05-31T18:39:23Z</dc:date>
    </item>
  </channel>
</rss>

