<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Where to configure public FQDN for Guest users. In Cisco ISE or WL in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/where-to-configure-public-fqdn-for-guest-users-in-cisco-ise-or/m-p/4869793#M582716</link>
    <description>&lt;P&gt;How many PSNs do you have? if more than one, then you would need to create an authorization profile and an authorization rule for each PSN to ensure the session is maintained on the same PSN that started it. In that case you would have multiple FQDNs for example guest1.mycompany.com and guest2.mycompany.com, each FQDN would be resolving to a specific PSN. A better way to do this would be to create an authorization profile without specifying the FQDN or the IP, and then creating a single authorization rule for redirection, and finally create IP aliases on the PSNs via CLI with the command "ip host &amp;lt; IP address &amp;gt; &amp;lt; FQDN &amp;gt;". Also, the DNS entries you created would need to be configured with ISE private IP addresses of the PSN unless you have a NAT device in the middle. That is the case even if you dedicate an interface on ISE for the guest portal.&lt;/P&gt;</description>
    <pubDate>Fri, 07 Jul 2023 14:21:26 GMT</pubDate>
    <dc:creator>Aref Alsouqi</dc:creator>
    <dc:date>2023-07-07T14:21:26Z</dc:date>
    <item>
      <title>Where to configure public FQDN for Guest users. In Cisco ISE or WLC?</title>
      <link>https://community.cisco.com/t5/network-access-control/where-to-configure-public-fqdn-for-guest-users-in-cisco-ise-or/m-p/4869630#M582705</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;BR /&gt;I have a doubt.&lt;BR /&gt;&lt;BR /&gt;I am using Cisco ISE guest portal to register Guest users.&lt;BR /&gt;I have configured a public FQDN to assign to guest portal, since Guest will not have access to internal DNS.&lt;BR /&gt;&lt;BR /&gt;My question is:&lt;BR /&gt;Where should I insert/configure this FQDN, in the WLC or in Cisco ISE?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2023 11:23:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/where-to-configure-public-fqdn-for-guest-users-in-cisco-ise-or/m-p/4869630#M582705</guid>
      <dc:creator>iran</dc:creator>
      <dc:date>2023-07-07T11:23:08Z</dc:date>
    </item>
    <item>
      <title>Re: Where to configure public FQDN for Guest users. In Cisco ISE or WL</title>
      <link>https://community.cisco.com/t5/network-access-control/where-to-configure-public-fqdn-for-guest-users-in-cisco-ise-or/m-p/4869638#M582706</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1051287"&gt;@iran &lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;You need to add it to your DNS server first as clients devices will&amp;nbsp; try to resolve your FQDN to IP in order to reach the Portal.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And you need to add it on ISE if you are going to use CWA or on the WLC if you are going to use LWA.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;CWA - Central web authentication - The ISE push the portal to cilents via RADIUS attributes.&lt;/P&gt;
&lt;P&gt;LWA - WLC handles the porta, and use ISE to validate the users database.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2023 11:30:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/where-to-configure-public-fqdn-for-guest-users-in-cisco-ise-or/m-p/4869638#M582706</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2023-07-07T11:30:31Z</dc:date>
    </item>
    <item>
      <title>Re: Where to configure public FQDN for Guest users. In Cisco ISE or WL</title>
      <link>https://community.cisco.com/t5/network-access-control/where-to-configure-public-fqdn-for-guest-users-in-cisco-ise-or/m-p/4869668#M582711</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;Thank you for your reply.&lt;BR /&gt;Yes, I already created the DNS record.&lt;BR /&gt;&lt;BR /&gt;I am using CWA.&lt;BR /&gt;Should I configure here the FQDN? And is the only place where should I add FQDN configurations?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="iran_0-1688733553388.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/189711i865ED443CCAA349E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="iran_0-1688733553388.png" alt="iran_0-1688733553388.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Please let me know if my understanding is correct.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2023 12:39:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/where-to-configure-public-fqdn-for-guest-users-in-cisco-ise-or/m-p/4869668#M582711</guid>
      <dc:creator>iran</dc:creator>
      <dc:date>2023-07-07T12:39:58Z</dc:date>
    </item>
    <item>
      <title>Re: Where to configure public FQDN for Guest users. In Cisco ISE or WL</title>
      <link>https://community.cisco.com/t5/network-access-control/where-to-configure-public-fqdn-for-guest-users-in-cisco-ise-or/m-p/4869670#M582712</link>
      <description>&lt;P&gt;Exactly!&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2023 12:47:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/where-to-configure-public-fqdn-for-guest-users-in-cisco-ise-or/m-p/4869670#M582712</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2023-07-07T12:47:04Z</dc:date>
    </item>
    <item>
      <title>Re: Where to configure public FQDN for Guest users. In Cisco ISE or WL</title>
      <link>https://community.cisco.com/t5/network-access-control/where-to-configure-public-fqdn-for-guest-users-in-cisco-ise-or/m-p/4869793#M582716</link>
      <description>&lt;P&gt;How many PSNs do you have? if more than one, then you would need to create an authorization profile and an authorization rule for each PSN to ensure the session is maintained on the same PSN that started it. In that case you would have multiple FQDNs for example guest1.mycompany.com and guest2.mycompany.com, each FQDN would be resolving to a specific PSN. A better way to do this would be to create an authorization profile without specifying the FQDN or the IP, and then creating a single authorization rule for redirection, and finally create IP aliases on the PSNs via CLI with the command "ip host &amp;lt; IP address &amp;gt; &amp;lt; FQDN &amp;gt;". Also, the DNS entries you created would need to be configured with ISE private IP addresses of the PSN unless you have a NAT device in the middle. That is the case even if you dedicate an interface on ISE for the guest portal.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2023 14:21:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/where-to-configure-public-fqdn-for-guest-users-in-cisco-ise-or/m-p/4869793#M582716</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2023-07-07T14:21:26Z</dc:date>
    </item>
    <item>
      <title>Re: Where to configure public FQDN for Guest users. In Cisco ISE or WL</title>
      <link>https://community.cisco.com/t5/network-access-control/where-to-configure-public-fqdn-for-guest-users-in-cisco-ise-or/m-p/4871130#M582755</link>
      <description>&lt;P&gt;Basically we have 5 PSN nodes.&lt;BR /&gt;Here are the the authorizations rules:&lt;BR /&gt;I have 6, one for Guest flow and 5 for redirect to the Guest portal&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="iran_0-1689000274622.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/190021i9C5734A1A0A1BFEE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="iran_0-1689000274622.png" alt="iran_0-1689000274622.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;And I have 5 Authorizations Profiles:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="iran_2-1689000447125.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/190024i5B84211D7C2C2D71/image-size/medium?v=v2&amp;amp;px=400" role="button" title="iran_2-1689000447125.png" alt="iran_2-1689000447125.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;My questions was, where should I put the FQDN? Is there right?&lt;BR /&gt;&lt;BR /&gt;I have 5 publics FQDNs, one per PSN.&lt;BR /&gt;&lt;BR /&gt;I sent the image as attached also, I dont know why my images lost quality.&lt;BR /&gt;&lt;BR /&gt;Please let me know if my approach makes sense&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 14:54:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/where-to-configure-public-fqdn-for-guest-users-in-cisco-ise-or/m-p/4871130#M582755</guid>
      <dc:creator>iran</dc:creator>
      <dc:date>2023-07-10T14:54:48Z</dc:date>
    </item>
    <item>
      <title>Re: Where to configure public FQDN for Guest users. In Cisco ISE or WL</title>
      <link>https://community.cisco.com/t5/network-access-control/where-to-configure-public-fqdn-for-guest-users-in-cisco-ise-or/m-p/4871166#M582759</link>
      <description>&lt;P&gt;The public FQDN for guest users can be configured in either Cisco ISE or the WLC. However, there are some pros and cons to each approach.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Cisco ISE:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Configuring the FQDN in ISE allows you to take advantage of ISE's centralized authentication and authorization capabilities. This can be helpful if you have a large number of guest users or if you need to enforce specific policies for guest access. However, configuring the FQDN in ISE can be more complex than configuring it in the WLC.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;WLC:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Configuring the FQDN in the WLC is simpler than configuring it in ISE. However, you will not be able to take advantage of ISE's centralized authentication and authorization capabilities.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;In general, if you need to take advantage of ISE's centralized authentication and authorization capabilities, then you should configure the FQDN in ISE. However, if you do not need these capabilities or if you need to simplify the configuration, then you can configure the FQDN in the WLC.&lt;/P&gt;&lt;P&gt;As an example, let's say you want to configure a &lt;A href="http://how%20to seal a smoker" target="_self"&gt;smoker&lt;/A&gt; so that it can only be accessed by guests who have been authenticated through Cisco ISE. In this case, you would need to configure the FQDN for the smoker in ISE. This would allow you to ensure that only authenticated guests can access the smoker, and it would also allow you to enforce specific policies for guest access, such as limiting the amount of time that guests can use the smoker.&lt;/P&gt;&lt;P&gt;On the other hand, if you did not need to take advantage of ISE's centralized authentication and authorization capabilities, then you could configure the FQDN for the smoker in the WLC. This would simplify the configuration, but it would also mean that you would not be able to enforce specific policies for guest access.&lt;/P&gt;&lt;P&gt;Ultimately, the best place to configure the public FQDN for guest users depends on your specific needs and requirements.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 15:37:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/where-to-configure-public-fqdn-for-guest-users-in-cisco-ise-or/m-p/4871166#M582759</guid>
      <dc:creator>halvespatwer</dc:creator>
      <dc:date>2023-07-10T15:37:38Z</dc:date>
    </item>
    <item>
      <title>Re: Where to configure public FQDN for Guest users. In Cisco ISE or WL</title>
      <link>https://community.cisco.com/t5/network-access-control/where-to-configure-public-fqdn-for-guest-users-in-cisco-ise-or/m-p/4871218#M582763</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check out our&amp;nbsp;&lt;A id="link_7" class="page-link lia-link-navigation lia-custom-event" href="https://community.cisco.com/t5/security-knowledge-base/ise-guest-access-prescriptive-deployment-guide/ta-p/3640475" target="_blank"&gt;ISE Guest Access Prescriptive Deployment Guide&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 17:43:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/where-to-configure-public-fqdn-for-guest-users-in-cisco-ise-or/m-p/4871218#M582763</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2023-07-10T17:43:56Z</dc:date>
    </item>
  </channel>
</rss>

