<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Guest session is not being terminated in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/guest-session-is-not-being-terminated/m-p/4411722#M567658</link>
    <description>&lt;P&gt;Everything looks good to me with your RADIUS log.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Initial MAB defaults to Wifi_Redirect_to_Guest_Login.&lt;/LI&gt;
&lt;LI&gt;You login.&lt;/LI&gt;
&lt;LI&gt;After that, ISE recognizes the MAC address and puts you into Wifi_Guest_Access.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;That's how Guest_Flow works because it recognizes the endpoint MAC for the guest account duration (Daily, etc.). You will need to wait the entire account duration or manually &lt;EM&gt;purge&lt;/EM&gt; the endpoint info from ISE for it to be considered a new Guest Endpoint that gets redirected.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rad-log.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/121645iDB29B25B84C243B0/image-size/large?v=v2&amp;amp;px=999" role="button" title="rad-log.jpg" alt="rad-log.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 02 Jun 2021 00:21:56 GMT</pubDate>
    <dc:creator>thomas</dc:creator>
    <dc:date>2021-06-02T00:21:56Z</dc:date>
    <item>
      <title>Guest session is not being terminated</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-session-is-not-being-terminated/m-p/4411361#M567639</link>
      <description>&lt;P&gt;Version: 2.7.0.356&lt;/P&gt;&lt;P&gt;NAD: Non Cisco /Meraki&lt;BR /&gt;Steps:&lt;/P&gt;&lt;P&gt;1. Authenticate guest using CWA, there is no audit session-id attribute&lt;/P&gt;&lt;P&gt;2. Send radius session-timeout as 120 seconds in postauth radius accept packet&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. Send Radius Acct start after successful authentication ( post-auth mab ) with acct-session-id&lt;/P&gt;&lt;P&gt;4. After 120 seconds, NAD sends Radius acct-stop packet with same acct-session-id&lt;/P&gt;&lt;P&gt;5. Immediately trigger mac auth from NAD&lt;BR /&gt;&lt;BR /&gt;Expected:&amp;nbsp;&lt;BR /&gt;Redirect role from ISE since session is terminated&lt;BR /&gt;Reality:&lt;BR /&gt;Getting post auth role from ISE, Again after 120 seconds, when mab is triggered we get proper redirect role&lt;BR /&gt;&lt;BR /&gt;Seeing same issue even if mac-auth is triggered after 1 min of session expiry.&lt;BR /&gt;If mab is triggered after 2 minutes of session expiry, then getting redirect role properly.&lt;BR /&gt;&lt;BR /&gt;Note: If we don't send radius acct start and stop packet, the behavior is as expected. We get redirect role after session expiry.&lt;BR /&gt;Please help me to understand, if I am doing something wrong.&lt;BR /&gt;Attached screenshots and guest.log&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 11:13:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-session-is-not-being-terminated/m-p/4411361#M567639</guid>
      <dc:creator>AkshayJoshi34941</dc:creator>
      <dc:date>2021-06-01T11:13:40Z</dc:date>
    </item>
    <item>
      <title>Re: Guest session is not being terminated</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-session-is-not-being-terminated/m-p/4411722#M567658</link>
      <description>&lt;P&gt;Everything looks good to me with your RADIUS log.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Initial MAB defaults to Wifi_Redirect_to_Guest_Login.&lt;/LI&gt;
&lt;LI&gt;You login.&lt;/LI&gt;
&lt;LI&gt;After that, ISE recognizes the MAC address and puts you into Wifi_Guest_Access.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;That's how Guest_Flow works because it recognizes the endpoint MAC for the guest account duration (Daily, etc.). You will need to wait the entire account duration or manually &lt;EM&gt;purge&lt;/EM&gt; the endpoint info from ISE for it to be considered a new Guest Endpoint that gets redirected.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rad-log.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/121645iDB29B25B84C243B0/image-size/large?v=v2&amp;amp;px=999" role="button" title="rad-log.jpg" alt="rad-log.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 00:21:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-session-is-not-being-terminated/m-p/4411722#M567658</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2021-06-02T00:21:56Z</dc:date>
    </item>
    <item>
      <title>Re: Guest session is not being terminated</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-session-is-not-being-terminated/m-p/4412090#M567671</link>
      <description>&lt;P&gt;Auth policy is set to 'Guest Flow', It is not 'Identity Group equals Guest EndPoints'. In the latter case, it will recognise until endpoint is purged right ? My use case is to force re-login of guest client after 30 minutes. How can I achieve that ?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 16:46:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-session-is-not-being-terminated/m-p/4412090#M567671</guid>
      <dc:creator>AkshayJoshi34941</dc:creator>
      <dc:date>2021-06-02T16:46:03Z</dc:date>
    </item>
    <item>
      <title>Re: Guest session is not being terminated</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-session-is-not-being-terminated/m-p/4413724#M567720</link>
      <description>&lt;P&gt;Please use &lt;A href="https://community.cisco.com/t5/security-documents/ise-guest-access-prescriptive-deployment-guide/ta-p/3640475" target="_self"&gt;ISE Guest Access Prescriptive Deployment Guide&lt;/A&gt; as your reference.&lt;/P&gt;
&lt;P&gt;You have not specified what type of Guest portal you are trying to use: Hotspot, Self-Registered, or Sponsored. That changes your options. You said "Authenticate guest using CWA..." so I will assume &lt;STRONG&gt;Self-Registered&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;First, create a &lt;STRONG&gt;Guest Type&lt;/STRONG&gt; with your 30-minute guest limit. Go to &lt;STRONG&gt;☰ &amp;gt; Work Centers &amp;gt; Guest Access &amp;gt; Portals &amp;amp; Components &amp;gt; Guest Types&lt;/STRONG&gt;&amp;nbsp;and create a new &lt;STRONG&gt;30MinuteGuest&lt;/STRONG&gt; type with these values:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 686px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/121962iCE2AB170D3FE1A1D/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Then go to your Guest portal and assign your &lt;STRONG&gt;30MinuteGuest&lt;/STRONG&gt; Type:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/121961i1CD99F09C4C15A55/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Create a new Authorization Profile for your &lt;STRONG&gt;30MinuteGuest&lt;/STRONG&gt; . I am only showing the 1800 second timeout but you will need to apply whatever ACLs or segmentation you would want for your Guest to limit their access to your internal network if not using an anchor-controller guest architecture.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/121963i2CFCD5CD1F52F714/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;ISE has a built-in &lt;SPAN class="edited-span" contenteditable="true" data-id="policy-name-text-box"&gt;&lt;STRONG&gt;Wi-Fi_Guest_Access&lt;/STRONG&gt;&lt;/SPAN&gt; policy and&amp;nbsp;&lt;SPAN class="edited-span" contenteditable="true" data-id="policy-name-text-box"&gt;&lt;STRONG&gt;Wi-Fi_Redirect_to_Guest_Login&lt;/STRONG&gt;&lt;/SPAN&gt; (both disabled by default) in the &lt;STRONG&gt;Default Policy Set&lt;/STRONG&gt;. You may simply customize with your &lt;STRONG&gt;30MinuteGuest&lt;/STRONG&gt;&amp;nbsp;Authorization Profile&amp;nbsp; :&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/121964iCC424840E383DBA4/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 06 Jun 2021 21:25:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-session-is-not-being-terminated/m-p/4413724#M567720</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2021-06-06T21:25:21Z</dc:date>
    </item>
    <item>
      <title>Re: Guest session is not being terminated</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-session-is-not-being-terminated/m-p/4414666#M567743</link>
      <description>&lt;P&gt;&amp;gt;&amp;nbsp;&lt;SPAN&gt;If mab is triggered after 2 minutes of session expiry, then getting redirect role properly.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;In order to support 3rd-party NADs that do not support CoA reauth, ISE uses this timer to determine whether to continue with the sessions.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jun 2021 13:22:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-session-is-not-being-terminated/m-p/4414666#M567743</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2021-06-08T13:22:26Z</dc:date>
    </item>
  </channel>
</rss>

