<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE Guest Flow  / Vlan Change after Authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-guest-flow-vlan-change-after-authentication/m-p/4310483#M566294</link>
    <description>&lt;P&gt;We have a traditional guest flow that redirects clients to a guest portal page in ISE, and after authentication, they are associated with an SSID configured for that WLAN on the WLC.&amp;nbsp; Is is possible to place specific clients based on the NAD(WLC) on a different vlan after authenticating?&amp;nbsp; We would not want this to apply to all guest clients, just clients that are connected to certain WLC's.&amp;nbsp; The vlan would be different for each WLC/site we would want to perform this at.&amp;nbsp; So, different WLC and VLAN.&amp;nbsp; How can this be easily achieved without extensive change to the authorization rule set in ISE?&lt;/P&gt;</description>
    <pubDate>Fri, 19 Mar 2021 15:13:03 GMT</pubDate>
    <dc:creator>awatson20</dc:creator>
    <dc:date>2021-03-19T15:13:03Z</dc:date>
    <item>
      <title>ISE Guest Flow  / Vlan Change after Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-flow-vlan-change-after-authentication/m-p/4310483#M566294</link>
      <description>&lt;P&gt;We have a traditional guest flow that redirects clients to a guest portal page in ISE, and after authentication, they are associated with an SSID configured for that WLAN on the WLC.&amp;nbsp; Is is possible to place specific clients based on the NAD(WLC) on a different vlan after authenticating?&amp;nbsp; We would not want this to apply to all guest clients, just clients that are connected to certain WLC's.&amp;nbsp; The vlan would be different for each WLC/site we would want to perform this at.&amp;nbsp; So, different WLC and VLAN.&amp;nbsp; How can this be easily achieved without extensive change to the authorization rule set in ISE?&lt;/P&gt;</description>
      <pubDate>Fri, 19 Mar 2021 15:13:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-flow-vlan-change-after-authentication/m-p/4310483#M566294</guid>
      <dc:creator>awatson20</dc:creator>
      <dc:date>2021-03-19T15:13:03Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest Flow  / Vlan Change after Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-flow-vlan-change-after-authentication/m-p/4310515#M566295</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/285906"&gt;@awatson20&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;please take a look at: &lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/216330-ise-self-registered-guest-portal-configu.html" target="_blank" rel="noopener"&gt;ISE Self Registered Guest Portal Configuration Example&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;"&lt;EM&gt;... There is a similar configuration for Accounting. It is also advised to configure the &lt;STRONG&gt;WLC&lt;/STRONG&gt; to send &lt;STRONG&gt;SSID&lt;/STRONG&gt; in the &lt;STRONG&gt;Called Station ID&lt;/STRONG&gt; attribute, which allows the &lt;STRONG&gt;ISE&lt;/STRONG&gt; to configure &lt;U&gt;flexible rules&lt;/U&gt; based on &lt;STRONG&gt;SSID&lt;/STRONG&gt;...&lt;/EM&gt;"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Fri, 19 Mar 2021 15:42:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-flow-vlan-change-after-authentication/m-p/4310515#M566295</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-03-19T15:42:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest Flow  / Vlan Change after Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-flow-vlan-change-after-authentication/m-p/4310914#M566320</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;&lt;A id="link_8" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://community.cisco.com/t5/user/viewprofilepage/user-id/285906" target="_self"&gt;awatson20&lt;/A&gt;, the sequence of events is not exactly what you described.&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN class=""&gt;A guest SSID/WLAN is configured for open/PSK but with MAC filtering to check against ISE and ISE has policies to redirect the endpoints to an ISE guest portal and to grant more access after guest logins.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN class=""&gt;An endpoint associates with the guest SSID/WLAN&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN class=""&gt;The user gets presented with the ISE guest portal, signs in, accept AUP, etc.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN class=""&gt;ISE triggers authorize-only CoA and WLC performs another auth against ISE and grant more access to the endpoint.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN class=""&gt;Thus, the endpoint does not move the SSID/WLAN after sign-in. Please note that each SSID/WLAN has a default VLAN, which can be different from WLC to WLC and this default VLAN is what the endpoints get unless overridden by ISE. Although it possible to have different subnets before and after the guest sign-in, it's not recommended before the endpoint is unlikely to automatically refresh its IP address and get a new assignment from the new subnet. If you have to do so, then consider to have either a short DHCP lease/refresh interval or the same IP subnet in pre-auth and post-auth VLANs.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 20 Mar 2021 19:59:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-flow-vlan-change-after-authentication/m-p/4310914#M566320</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2021-03-20T19:59:08Z</dc:date>
    </item>
  </channel>
</rss>

