<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic bound guest user with mac address in cisco ise in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/bound-guest-user-with-mac-address-in-cisco-ise/m-p/4589407#M573992</link>
    <description>&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;i have question about how to bound guest users with their mac address as we have already more than 1000 guest user that already provisioned in "Workstation" identity group, also i create a new identity group named "Guest 2022".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;also we use ASA SSL VPN (Web VPN) instead of ISE Guest User Portal and it's difficult to force guest user to register their device again.&lt;/P&gt;&lt;P&gt;&amp;nbsp; Any HELP ?&lt;/P&gt;</description>
    <pubDate>Sat, 09 Apr 2022 02:54:56 GMT</pubDate>
    <dc:creator>Elbeshti1</dc:creator>
    <dc:date>2022-04-09T02:54:56Z</dc:date>
    <item>
      <title>bound guest user with mac address in cisco ise</title>
      <link>https://community.cisco.com/t5/network-access-control/bound-guest-user-with-mac-address-in-cisco-ise/m-p/4589407#M573992</link>
      <description>&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;i have question about how to bound guest users with their mac address as we have already more than 1000 guest user that already provisioned in "Workstation" identity group, also i create a new identity group named "Guest 2022".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;also we use ASA SSL VPN (Web VPN) instead of ISE Guest User Portal and it's difficult to force guest user to register their device again.&lt;/P&gt;&lt;P&gt;&amp;nbsp; Any HELP ?&lt;/P&gt;</description>
      <pubDate>Sat, 09 Apr 2022 02:54:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/bound-guest-user-with-mac-address-in-cisco-ise/m-p/4589407#M573992</guid>
      <dc:creator>Elbeshti1</dc:creator>
      <dc:date>2022-04-09T02:54:56Z</dc:date>
    </item>
    <item>
      <title>Re: bound guest user with mac address in cisco ise</title>
      <link>https://community.cisco.com/t5/network-access-control/bound-guest-user-with-mac-address-in-cisco-ise/m-p/4589869#M574023</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1089991"&gt;@Elbeshti1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not sure I follow your exact requirement, but are you saying that you want to perform MAB for a bunch of endpoints whose MAC addresses exist in a named Endpoint Identity Group.&amp;nbsp; If so, then of course this is just a simple Authentication check against the Internal Endpoints, and then a successful Authorization if the Endpoint is in that Endpoint Identity Group.&lt;/P&gt;
&lt;P&gt;You need to be more specific about your ISE Policy Set config. And, is this wired or wireless, etc.?&amp;nbsp; Has the NAD been configured for MAB already?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2022 04:22:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/bound-guest-user-with-mac-address-in-cisco-ise/m-p/4589869#M574023</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2022-04-11T04:22:44Z</dc:date>
    </item>
    <item>
      <title>Re: bound guest user with mac address in cisco ise</title>
      <link>https://community.cisco.com/t5/network-access-control/bound-guest-user-with-mac-address-in-cisco-ise/m-p/4593669#M574183</link>
      <description>&lt;P&gt;I agree with &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/82347"&gt;@Arne Bier&lt;/a&gt; , it is not clear what you are trying to do.&lt;/P&gt;
&lt;P&gt;I do not understand what a VPN has to do with guest access - these are completely different scenarios.&lt;/P&gt;
&lt;P&gt;MAC authentication is not the recommended way to do Guest authentication.&lt;/P&gt;
&lt;P&gt;Putting MAC addresses into endpoint identity groups is more appropriate for managed assets or IOT devices.&lt;/P&gt;
&lt;P&gt;Please be specific about the exact scenario you want to enable and if something is not working as expected, please share the necessary configurations from the components involved (endpoint, network device, ISE, etc.) as explained in &lt;LI-MESSAGE title="How to Ask The Community for Help" uid="3704356" url="https://community.cisco.com/t5/security-documents/how-to-ask-the-community-for-help/m-p/3704356#U3704356"&gt;&lt;/LI-MESSAGE&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Apr 2022 18:47:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/bound-guest-user-with-mac-address-in-cisco-ise/m-p/4593669#M574183</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2022-04-15T18:47:28Z</dc:date>
    </item>
    <item>
      <title>Re: bound guest user with mac address in cisco ise</title>
      <link>https://community.cisco.com/t5/network-access-control/bound-guest-user-with-mac-address-in-cisco-ise/m-p/4593761#M574196</link>
      <description>&lt;P&gt;&lt;SPAN&gt;hi&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;we use SSL AnyConnect With ISE Authentication&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;as showed in the link below:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.youtube.com/watch?v=499W8sHYn-I" target="_blank" rel="noopener"&gt;https://www.youtube.com/watch?v=499W8sHYn-I&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;instead&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;of using an internal user in policy set rule we use guest user&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;my question is how bind the mac address of each guest user with his username ??&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 15 Apr 2022 23:27:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/bound-guest-user-with-mac-address-in-cisco-ise/m-p/4593761#M574196</guid>
      <dc:creator>Elbeshti1</dc:creator>
      <dc:date>2022-04-15T23:27:38Z</dc:date>
    </item>
    <item>
      <title>Re: bound guest user with mac address in cisco ise</title>
      <link>https://community.cisco.com/t5/network-access-control/bound-guest-user-with-mac-address-in-cisco-ise/m-p/4593769#M574197</link>
      <description>&lt;P&gt;I do not understand why "guest users" are using VPN.&lt;/P&gt;
&lt;P&gt;&amp;gt; &lt;EM&gt;how bind the mac address of each guest user with his username??&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;If you want to bind a username to a MAC address, you would need to do that with an external identity store and compare the RADIUS Calling-Station-ID (user's MAC address) to an attribute of the user in the identity store.&lt;/P&gt;
&lt;P&gt;Alternatively, you could do it with ISE internal users and store the bound MAC address in the Internal User Custom Attributes ("GuestMAC" for example).&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 714px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/149076iCA1BDE63BCCF82FC/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;And the policy looks like this:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 762px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/149075iC7E5AA3F38E1085A/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Apr 2022 23:48:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/bound-guest-user-with-mac-address-in-cisco-ise/m-p/4593769#M574197</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2022-04-15T23:48:03Z</dc:date>
    </item>
    <item>
      <title>Re: bound guest user with mac address in cisco ise</title>
      <link>https://community.cisco.com/t5/network-access-control/bound-guest-user-with-mac-address-in-cisco-ise/m-p/4593827#M574200</link>
      <description>&lt;P&gt;When the user connects via SSL VPN, take a look at the Calling Station ID attribute that comes to ISE with the access request. That is the closest you’ll get to a MAC address.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Apr 2022 08:40:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/bound-guest-user-with-mac-address-in-cisco-ise/m-p/4593827#M574200</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2022-04-16T08:40:06Z</dc:date>
    </item>
    <item>
      <title>Re: bound guest user with mac address in cisco ise</title>
      <link>https://community.cisco.com/t5/network-access-control/bound-guest-user-with-mac-address-in-cisco-ise/m-p/4595804#M574252</link>
      <description>&lt;P&gt;For RA-VPN, the calling-station-ID is the public IP of the endpoint but NOT the mac address. If macOS or Windows endpoints using AnyConnect to connect to ASA or FTD head-ends, the VPN client module gathers the mac addresses and send them over to ISE via the head-ends so ISE may authorize the endpoints based on the endpoint attributes. Thus, I would suggest creating a custom attribute for the user owner, unless an exiting attribute has the info.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2022 00:31:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/bound-guest-user-with-mac-address-in-cisco-ise/m-p/4595804#M574252</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2022-04-20T00:31:37Z</dc:date>
    </item>
  </channel>
</rss>

