<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Guest access using dual factor authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/guest-access-using-dual-factor-authentication/m-p/4511071#M571334</link>
    <description>&lt;P&gt;&lt;FONT face="tahoma,arial,helvetica,sans-serif"&gt;Is there anyway that the guest access can be configured using a dual factor authentication?&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- what is the use case here, Guest itself different user and it required different access to go to internet, guest do not have any Local resource access, but with SMS can be possible you need integrate with your Portal.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT face="tahoma,arial,helvetica,sans-serif"&gt;Or MAB based authentication using dual factor authentication?&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- what devices these are ?&amp;nbsp; smart phones ? or dumb devices can not be input any data like medical devices or industrial devices.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT face="tahoma,arial,helvetica,sans-serif"&gt;Is dual factor authentication possible using the base licenses?&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="tahoma,arial,helvetica,sans-serif"&gt;&amp;nbsp;-&amp;nbsp; Look at below what feature support each License : (ISE License Model and Features)&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="tahoma,arial,helvetica,sans-serif"&gt;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/identity-services-engine/guide-c07-656177.html#7Licensemanagement" target="_blank"&gt;https://www.cisco.com/c/en/us/products/collateral/security/identity-services-engine/guide-c07-656177.html#7Licensemanagement&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 01 Dec 2021 09:28:05 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2021-12-01T09:28:05Z</dc:date>
    <item>
      <title>Guest access using dual factor authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-access-using-dual-factor-authentication/m-p/4511028#M571333</link>
      <description>&lt;P&gt;&lt;FONT face="tahoma,arial,helvetica,sans-serif"&gt;Hi Experts,&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="tahoma,arial,helvetica,sans-serif"&gt;Is there anyway that the guest access can be configured using a dual factor authentication?&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="tahoma,arial,helvetica,sans-serif"&gt;Or MAB based authentication using dual factor authentication?&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="tahoma,arial,helvetica,sans-serif"&gt;Is dual factor authentication possible using the base licenses?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="tahoma,arial,helvetica,sans-serif"&gt;Any pointers appreciated.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Dec 2021 07:19:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-access-using-dual-factor-authentication/m-p/4511028#M571333</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2021-12-01T07:19:34Z</dc:date>
    </item>
    <item>
      <title>Re: Guest access using dual factor authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-access-using-dual-factor-authentication/m-p/4511071#M571334</link>
      <description>&lt;P&gt;&lt;FONT face="tahoma,arial,helvetica,sans-serif"&gt;Is there anyway that the guest access can be configured using a dual factor authentication?&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- what is the use case here, Guest itself different user and it required different access to go to internet, guest do not have any Local resource access, but with SMS can be possible you need integrate with your Portal.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT face="tahoma,arial,helvetica,sans-serif"&gt;Or MAB based authentication using dual factor authentication?&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- what devices these are ?&amp;nbsp; smart phones ? or dumb devices can not be input any data like medical devices or industrial devices.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT face="tahoma,arial,helvetica,sans-serif"&gt;Is dual factor authentication possible using the base licenses?&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="tahoma,arial,helvetica,sans-serif"&gt;&amp;nbsp;-&amp;nbsp; Look at below what feature support each License : (ISE License Model and Features)&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="tahoma,arial,helvetica,sans-serif"&gt;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/identity-services-engine/guide-c07-656177.html#7Licensemanagement" target="_blank"&gt;https://www.cisco.com/c/en/us/products/collateral/security/identity-services-engine/guide-c07-656177.html#7Licensemanagement&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Dec 2021 09:28:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-access-using-dual-factor-authentication/m-p/4511071#M571334</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-12-01T09:28:05Z</dc:date>
    </item>
    <item>
      <title>Re: Guest access using dual factor authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-access-using-dual-factor-authentication/m-p/4511104#M571336</link>
      <description>&lt;P&gt;&lt;SPAN&gt;- what is the use case here, Guest itself different user and it required different access to go to internet, guest do not have any Local resource access, but with SMS can be possible you need integrate with your Portal.&lt;BR /&gt;&lt;/SPAN&gt;&lt;FONT face="tahoma,arial,helvetica,sans-serif"&gt;A: These are some of the devices that the internal users or the corporate users bring and would need access to internal network.&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;- what devices these are ?&amp;nbsp; smart phones ? or dumb devices can not be input any data like medical devices or industrial devices.&lt;BR /&gt;&lt;FONT face="tahoma,arial,helvetica,sans-serif"&gt;A: Laptops, smart phones and tablets, connecting to the wireless network, where in the users use their own machines to work and access the company network and its resources. Kind of BYOD.&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;-&amp;nbsp; Look at below what feature support each License : (ISE License Model and Features&lt;BR /&gt;&lt;/SPAN&gt;&lt;FONT face="tahoma,arial,helvetica,sans-serif"&gt;A: Seems that there would be a need to upgrade the license for the feature that we are looking for.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Dec 2021 10:21:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-access-using-dual-factor-authentication/m-p/4511104#M571336</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2021-12-01T10:21:19Z</dc:date>
    </item>
    <item>
      <title>Re: Guest access using dual factor authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-access-using-dual-factor-authentication/m-p/4513193#M571440</link>
      <description>&lt;P&gt;You are not describing a &lt;STRONG&gt;Guest&lt;/STRONG&gt; scenario. "Guests" should &lt;EM&gt;never&lt;/EM&gt; be required to use MFA since that is too much effort for the guest and potential support overhead for you.&lt;/P&gt;
&lt;P&gt;Internal / corporate users bringing in devices for access to the internal corporate network is considered &lt;STRONG&gt;BYOD&lt;/STRONG&gt; and are generally managed with MDM software to ensure they are 1) secure and 2) provisioned with network access profiles (SSIDs, certificates, etc.) for secure connections. You don't do this for Guests with open/unsecured Guest networks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;See &lt;A href="https://cs.co/ise-licensing" target="_blank"&gt;https://cs.co/ise-licensing&lt;/A&gt; for ISE Licensing scenarios.&lt;/P&gt;
&lt;P&gt;Basic authentication with MFA uses an ISE Base or Essentials. MDM would be Apex/Premier licensing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 04 Dec 2021 20:26:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-access-using-dual-factor-authentication/m-p/4513193#M571440</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2021-12-04T20:26:20Z</dc:date>
    </item>
    <item>
      <title>Re: Guest access using dual factor authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-access-using-dual-factor-authentication/m-p/4513265#M571458</link>
      <description>&lt;P&gt;&lt;FONT face="tahoma,arial,helvetica,sans-serif"&gt;Here is the scenario, currently only base licenses are available for use and not in position to procure new ilcensing for the advance use cases.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="tahoma,arial,helvetica,sans-serif"&gt;The other thing is that the company has a policy of allowing users to allow access to network using devices of their choice, using the AD credentials.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="tahoma,arial,helvetica,sans-serif"&gt;Cannot using profiling or BYOD, because of the license upgrade involved. Or even cannot certificate authentication, as CA infrastructure is not available and setup will take quite a time.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="tahoma,arial,helvetica,sans-serif"&gt;Now, there have been incidents of password sharing, thus to curb this and allow only devices of the users to login thinking of MFA.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="tahoma,arial,helvetica,sans-serif"&gt;Or somehow use MAC address + user/password configuration.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="tahoma,arial,helvetica,sans-serif"&gt;I am pretty sure that such a configuration will not be feasible until Plus licenses are procured. Just want some more pointers for this kind of deployment scenario.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Dec 2021 05:22:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-access-using-dual-factor-authentication/m-p/4513265#M571458</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2021-12-05T05:22:21Z</dc:date>
    </item>
    <item>
      <title>Re: Guest access using dual factor authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-access-using-dual-factor-authentication/m-p/4516409#M571584</link>
      <description>&lt;P&gt;If users use the same username+password on multiple of their "devices of their choice", that is fine and MFA will not change anything.&lt;/P&gt;
&lt;P&gt;If users are sharing their corporate passwords with other corporate users or non-corporate users you have major security problems that go way beyond ISE. If they will share passwords, they will share MFA codes, too.&lt;/P&gt;
&lt;P&gt;The only solution to stop password sharing is to not use passwords at all and go with certificates on your devices.&lt;/P&gt;
&lt;P&gt;Since they do not want to buy ISE licenses for BYOD, they will need to buy MDM licenses to manage their users endpoints to ensure minimum levels of security and provision certificates for authentication.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Dec 2021 04:21:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-access-using-dual-factor-authentication/m-p/4516409#M571584</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2021-12-10T04:21:04Z</dc:date>
    </item>
    <item>
      <title>Re: Guest access using dual factor authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-access-using-dual-factor-authentication/m-p/4519126#M571678</link>
      <description>&lt;P&gt;&lt;FONT face="trebuchet ms,geneva"&gt;Yes, that does make sense and such a recommendation has already been provided.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="trebuchet ms,geneva"&gt;I was looking if such a scenario could have been deployed earlier and if there was any other workaround.&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="trebuchet ms,geneva"&gt;I think this resolves it then.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Dec 2021 06:53:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-access-using-dual-factor-authentication/m-p/4519126#M571678</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2021-12-15T06:53:29Z</dc:date>
    </item>
  </channel>
</rss>

