<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need policy set of Cisco ISE CWA ISE 2.4 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/need-policy-set-of-cisco-ise-cwa-ise-2-4/m-p/4118855#M561705</link>
    <description>Glad it worked. Can't tell what you faced and TAC would have been able to help. Anyways you've installed a new ise and your issue is now solved</description>
    <pubDate>Wed, 15 Jul 2020 01:53:42 GMT</pubDate>
    <dc:creator>Francesco Molino</dc:creator>
    <dc:date>2020-07-15T01:53:42Z</dc:date>
    <item>
      <title>Need policy set of Cisco ISE CWA ISE 2.4</title>
      <link>https://community.cisco.com/t5/network-access-control/need-policy-set-of-cisco-ise-cwa-ise-2-4/m-p/4112046#M561491</link>
      <description>&lt;P&gt;Can anyone share me a screenshot of Wireless Authentication and Authorization policy set in ISE 2.4+ for a user to get Permit all, right after he enters username and password inside the CWA portal?&lt;BR /&gt;&lt;BR /&gt;Lab minute CWA video policy doesn't work with ISE 2.4+ Radius username is not working unless I specify the name which is not practical.&lt;BR /&gt;&lt;BR /&gt;Right now the user gets redirected to CWA portal there he enters username password of AD then CWA portal check with local AD once Auth success shows a new page says "you will get the Internet" but I am not getting internet since I don't have a policy set to give permitall&amp;nbsp; please help me it is Urgent.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2020 18:45:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-policy-set-of-cisco-ise-cwa-ise-2-4/m-p/4112046#M561491</guid>
      <dc:creator>pcno</dc:creator>
      <dc:date>2020-07-01T18:45:16Z</dc:date>
    </item>
    <item>
      <title>Re: Need policy set of Cisco ISE CWA ISE 2.4</title>
      <link>https://community.cisco.com/t5/network-access-control/need-policy-set-of-cisco-ise-cwa-ise-2-4/m-p/4112222#M561495</link>
      <description>Hi&lt;BR /&gt;&lt;BR /&gt;So you're able to authenticate your users over a CWA?&lt;BR /&gt;When they get authenticated, what authorization are you pushing?&lt;BR /&gt;Can you share your config to see what you're missing?&lt;BR /&gt;</description>
      <pubDate>Thu, 02 Jul 2020 03:10:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-policy-set-of-cisco-ise-cwa-ise-2-4/m-p/4112222#M561495</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2020-07-02T03:10:40Z</dc:date>
    </item>
    <item>
      <title>Re: Need policy set of Cisco ISE CWA ISE 2.4</title>
      <link>https://community.cisco.com/t5/network-access-control/need-policy-set-of-cisco-ise-cwa-ise-2-4/m-p/4112497#M561506</link>
      <description>&lt;P&gt;Thank you,&amp;nbsp;&lt;SPAN class="UserName lia-user-name lia-user-rank-VIP-Advisor lia-component-message-view-widget-author-username"&gt;&lt;A href="https://community.cisco.com/t5/user/viewprofilepage/user-id/321306" target="_self"&gt;&lt;SPAN class=""&gt;Francesco,&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;Please check the attached screenshot of my current policy and guest portal details.&lt;BR /&gt;Right now redirection works and the user enters their username password in the CWA portal and Authentication is a success with AD also device is registered in the particular group as well. But after all these process users still, doesn't have a permit all access.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2020 15:08:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-policy-set-of-cisco-ise-cwa-ise-2-4/m-p/4112497#M561506</guid>
      <dc:creator>pcno</dc:creator>
      <dc:date>2020-07-02T15:08:04Z</dc:date>
    </item>
    <item>
      <title>Re: Need policy set of Cisco ISE CWA ISE 2.4</title>
      <link>https://community.cisco.com/t5/network-access-control/need-policy-set-of-cisco-ise-cwa-ise-2-4/m-p/4113451#M561525</link>
      <description>&lt;P&gt;Is there any solution for this ??&amp;nbsp; It's been more than 4 days.&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jul 2020 06:43:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-policy-set-of-cisco-ise-cwa-ise-2-4/m-p/4113451#M561525</guid>
      <dc:creator>pcno</dc:creator>
      <dc:date>2020-07-05T06:43:25Z</dc:date>
    </item>
    <item>
      <title>Re: Need policy set of Cisco ISE CWA ISE 2.4</title>
      <link>https://community.cisco.com/t5/network-access-control/need-policy-set-of-cisco-ise-cwa-ise-2-4/m-p/4113608#M561526</link>
      <description>Sorry for the delay, I didn't had time this week due to work schedule.&lt;BR /&gt;Can you share the authentication result please? I believe you have at least a condition not matching from your policies.&lt;BR /&gt;To validate this, you can create a simple authorization policy matching only your AD group and see if you get a permit result.</description>
      <pubDate>Sun, 05 Jul 2020 17:51:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-policy-set-of-cisco-ise-cwa-ise-2-4/m-p/4113608#M561526</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2020-07-05T17:51:10Z</dc:date>
    </item>
    <item>
      <title>Re: Need policy set of Cisco ISE CWA ISE 2.4</title>
      <link>https://community.cisco.com/t5/network-access-control/need-policy-set-of-cisco-ise-cwa-ise-2-4/m-p/4113781#M561528</link>
      <description>&lt;P&gt;Thank you, Francesco, we all are busy with Job I do understand the pressure &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;I have tried with a simple AD group as well but it is still not hitting permit all policy.&lt;BR /&gt;Once the CWA portal comes and the user enters their user name and password in it then the user gets a prompt saying you have internet access now and then if I type anything in the web portal it took me back to redirect page again where it asks for the username &amp;amp; password it is like a loop.&lt;BR /&gt;&lt;BR /&gt;Please check the attached screenshot of the live log and the policy set (I tried with web auth as well no output).&amp;nbsp;&lt;BR /&gt;if possible please send me a screenshot of a policy that is normally used in a CWA method for Portal redirection and Permit all access.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 08:11:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-policy-set-of-cisco-ise-cwa-ise-2-4/m-p/4113781#M561528</guid>
      <dc:creator>pcno</dc:creator>
      <dc:date>2020-07-06T08:11:46Z</dc:date>
    </item>
    <item>
      <title>Re: Need policy set of Cisco ISE CWA ISE 2.4</title>
      <link>https://community.cisco.com/t5/network-access-control/need-policy-set-of-cisco-ise-cwa-ise-2-4/m-p/4115020#M561561</link>
      <description>&lt;P&gt;Please review &lt;A title="ISE Guest Access Prescriptive Deployment Guide " href="https://community.cisco.com/t5/security-documents/ise-guest-access-prescriptive-deployment-guide/ta-p/3640475" target="_blank" rel="noopener"&gt;ISE Guest Access Prescriptive Deployment Guide&lt;/A&gt;&amp;nbsp;if not already done and start with simpler authorization policy rules.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2020 03:14:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-policy-set-of-cisco-ise-cwa-ise-2-4/m-p/4115020#M561561</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2020-07-08T03:14:34Z</dc:date>
    </item>
    <item>
      <title>Re: Need policy set of Cisco ISE CWA ISE 2.4</title>
      <link>https://community.cisco.com/t5/network-access-control/need-policy-set-of-cisco-ise-cwa-ise-2-4/m-p/4115265#M561580</link>
      <description>&lt;P&gt;Hslai, I am able to get redirection which means my WLC, ACL, and ISE redirection policy is correct... Can you tell me where we are specifying Permit access ACL for the user after successful login in the CWA portal?&lt;BR /&gt;I tried a lot of policy set as above for permit all but none of them get a Hit.&lt;BR /&gt;&lt;BR /&gt;In portals and components, I can only see Sucess Login: Original URL, no place where I can put a permit all setup.&lt;BR /&gt;&lt;BR /&gt;Is CWA chaining only works with MAB?&lt;BR /&gt;&lt;BR /&gt;Please reply if you have a solution.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2020 11:58:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-policy-set-of-cisco-ise-cwa-ise-2-4/m-p/4115265#M561580</guid>
      <dc:creator>pcno</dc:creator>
      <dc:date>2020-07-08T11:58:01Z</dc:date>
    </item>
    <item>
      <title>Re: Need policy set of Cisco ISE CWA ISE 2.4</title>
      <link>https://community.cisco.com/t5/network-access-control/need-policy-set-of-cisco-ise-cwa-ise-2-4/m-p/4115659#M561597</link>
      <description>You're not matching any of your authorization rules.&lt;BR /&gt;Have you tried to filter just using an ad group for example and  attach a permit to it. &lt;BR /&gt;This will work for sure</description>
      <pubDate>Thu, 09 Jul 2020 00:27:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-policy-set-of-cisco-ise-cwa-ise-2-4/m-p/4115659#M561597</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2020-07-09T00:27:26Z</dc:date>
    </item>
    <item>
      <title>Re: Need policy set of Cisco ISE CWA ISE 2.4</title>
      <link>https://community.cisco.com/t5/network-access-control/need-policy-set-of-cisco-ise-cwa-ise-2-4/m-p/4115762#M561605</link>
      <description>&lt;P&gt;Francesco, I did try by putting a simple policy like external group &amp;gt; corp users&amp;gt;permit all.&lt;BR /&gt;No hit for this policy as well, can you share me a screenshot of policy set just to make sure I am doing the same?&lt;BR /&gt;Till this day almost 20+ policies are tried but nothing gets any Hit after user enter username and password in CWA portal.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2020 06:33:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-policy-set-of-cisco-ise-cwa-ise-2-4/m-p/4115762#M561605</guid>
      <dc:creator>pcno</dc:creator>
      <dc:date>2020-07-09T06:33:21Z</dc:date>
    </item>
    <item>
      <title>Re: Need policy set of Cisco ISE CWA ISE 2.4</title>
      <link>https://community.cisco.com/t5/network-access-control/need-policy-set-of-cisco-ise-cwa-ise-2-4/m-p/4116324#M561614</link>
      <description>&lt;P&gt;We consider&amp;nbsp;&lt;STRONG&gt;CWA Chaining&lt;/STRONG&gt;&amp;nbsp;different from &lt;STRONG&gt;CWA&lt;/STRONG&gt;. I found you asked&amp;nbsp;&lt;A href="https://community.cisco.com/t5/network-access-control/cwa-chaining-with-intune/td-p/4110238" target="_self"&gt;CWA Chaining with Intune&lt;/A&gt;&amp;nbsp;earlier and&amp;nbsp;&lt;SPAN class=""&gt;&lt;A id="link_19" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://community.cisco.com/t5/user/viewprofilepage/user-id/388087" target="_self"&gt;Greg Gibbs&lt;/A&gt;&amp;nbsp;provided you the info.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;The condition example "&lt;SPAN&gt;CWA:CWA_ExternalGroups&lt;/SPAN&gt;&lt;SPAN&gt;= &lt;/SPAN&gt;&lt;SPAN&gt;Employee" works only with on-premise AD infrastructure at present. If your user already present there and in the proper AD group, then it's possible you are hitting a bug.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Jul 2020 23:09:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-policy-set-of-cisco-ise-cwa-ise-2-4/m-p/4116324#M561614</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2020-07-11T23:09:40Z</dc:date>
    </item>
    <item>
      <title>Re: Need policy set of Cisco ISE CWA ISE 2.4</title>
      <link>https://community.cisco.com/t5/network-access-control/need-policy-set-of-cisco-ise-cwa-ise-2-4/m-p/4117992#M561677</link>
      <description>&lt;P&gt;Ok let me share some screenshots.&lt;/P&gt;
&lt;P&gt;I will use a user called testcwa member of WiFi AD group.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;WLC SSID config&lt;/STRONG&gt;&lt;/U&gt;:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 696px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/78887iABFF3DAE91C591CE/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 676px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/78888i3318ED4FAB26D470/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 826px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/78889iCE5B387281860DD0/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 987px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/78890iF8EEEB830E627DDD/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;WLC ACL&lt;/STRONG&gt;&lt;/U&gt;:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 548px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/78891i894306184E1260BB/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/78894iE62E375A9B5C7082/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 934px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/78895i9E47E857E0852ACB/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Cisco ISE Authorization Profile Redirect&lt;/STRONG&gt;&lt;/U&gt;:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/78897iFAFA1029C0B9484E/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Cisco ISE Authorization Profile Permit&lt;/STRONG&gt;&lt;/U&gt;:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 833px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/78898iDB135C723FB27FC4/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a dedicate Policy-set,&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Cisco ISE Policy-Set&lt;/STRONG&gt;&lt;/U&gt;:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/78899i4702FF73B0DD9371/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/78900i369D3FC244A25E52/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now, I connect to this SSID, my user authenticates and get internet access.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Below results from ISE&lt;/U&gt;:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/78901iAEB283804342CA45/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 728px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/78902i0E03916E0601E4B0/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 717px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/78903i43650023EC62885E/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;Can you reproduce it in a very simple way like I did to make sure your Guest work and then you can start adding attributes to filter user authentication.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2020 21:57:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-policy-set-of-cisco-ise-cwa-ise-2-4/m-p/4117992#M561677</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2020-07-13T21:57:45Z</dc:date>
    </item>
    <item>
      <title>Re: Need policy set of Cisco ISE CWA ISE 2.4</title>
      <link>https://community.cisco.com/t5/network-access-control/need-policy-set-of-cisco-ise-cwa-ise-2-4/m-p/4118340#M561686</link>
      <description>&lt;P&gt;Thank you,&amp;nbsp;&lt;SPAN&gt;Francesco, I did try the same but it didn't give permit access, Today I installed a new ISE with Latest patch and tried the same and it worked looks like some bug. Anyway, Thank you so much for helping me with this. Closing this discussion now.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 10:46:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-policy-set-of-cisco-ise-cwa-ise-2-4/m-p/4118340#M561686</guid>
      <dc:creator>pcno</dc:creator>
      <dc:date>2020-07-14T10:46:29Z</dc:date>
    </item>
    <item>
      <title>Re: Need policy set of Cisco ISE CWA ISE 2.4</title>
      <link>https://community.cisco.com/t5/network-access-control/need-policy-set-of-cisco-ise-cwa-ise-2-4/m-p/4118855#M561705</link>
      <description>Glad it worked. Can't tell what you faced and TAC would have been able to help. Anyways you've installed a new ise and your issue is now solved</description>
      <pubDate>Wed, 15 Jul 2020 01:53:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-policy-set-of-cisco-ise-cwa-ise-2-4/m-p/4118855#M561705</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2020-07-15T01:53:42Z</dc:date>
    </item>
  </channel>
</rss>

