<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE BYOD Dual SSID with bot SSIDs closed in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-byod-dual-ssid-with-bot-ssids-closed/m-p/4952585#M584955</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I am interested if it is possible to configure BYOD with dual &lt;STRONG&gt;closed&lt;/STRONG&gt; SSIDs.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When user connects to first SSID it should be redirected to portal where he will enter AD username and password and if authentication is successful the process should continue. After onboarding and posture checks he will be redirected to second SSID.&lt;/P&gt;
&lt;P&gt;If it is possible, could you please provide documentation?&lt;/P&gt;</description>
    <pubDate>Thu, 02 Nov 2023 12:34:36 GMT</pubDate>
    <dc:creator>llomjaria</dc:creator>
    <dc:date>2023-11-02T12:34:36Z</dc:date>
    <item>
      <title>ISE BYOD Dual SSID with bot SSIDs closed</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-dual-ssid-with-bot-ssids-closed/m-p/4952585#M584955</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I am interested if it is possible to configure BYOD with dual &lt;STRONG&gt;closed&lt;/STRONG&gt; SSIDs.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When user connects to first SSID it should be redirected to portal where he will enter AD username and password and if authentication is successful the process should continue. After onboarding and posture checks he will be redirected to second SSID.&lt;/P&gt;
&lt;P&gt;If it is possible, could you please provide documentation?&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2023 12:34:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-dual-ssid-with-bot-ssids-closed/m-p/4952585#M584955</guid>
      <dc:creator>llomjaria</dc:creator>
      <dc:date>2023-11-02T12:34:36Z</dc:date>
    </item>
    <item>
      <title>Re: ISE BYOD Dual SSID with bot SSIDs closed</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-dual-ssid-with-bot-ssids-closed/m-p/4952877#M584961</link>
      <description>&lt;P&gt;While this could technically probably be done, I'm not sure I understand the point and it would be a poor user experience. In order to connect to the first secure SSID, the supplicant would prompt the user for their credentials (which would be PEAP-MSCHAPv2 authC in ISE). They would then be redirected to the portal and be forced to enter their credentials again for Central Web Auth, go through the BYOD enrolment process and be notified to manually change to the second SSID (Posture is not typically part of the BYOD flow).&lt;/P&gt;
&lt;P&gt;A smoother solution would be using the Single SSID flow described in the &lt;A href="https://community.cisco.com/t5/security-knowledge-base/cisco-ise-byod-prescriptive-deployment-guide/ta-p/3641867" target="_blank" rel="noopener"&gt;Cisco ISE BYOD Prescriptive Deployment Guide&lt;/A&gt;. If Posture is required, that flow would be better suited after the BYOD enrolment as a condition for authorization.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2023 21:21:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-dual-ssid-with-bot-ssids-closed/m-p/4952877#M584961</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2023-11-02T21:21:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE BYOD Dual SSID with bot SSIDs closed</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-dual-ssid-with-bot-ssids-closed/m-p/4954621#M585030</link>
      <description>&lt;P&gt;Posture is not typical for BYOD - once you do this it is basically a managed endpoint.&lt;/P&gt;
&lt;P&gt;If you are doing posture checks of your employee's personal devices, why not just use an MDM to enroll/provision them to a single SSID and then manage whatever security policies, applications, settings, WiFi profiles, etc. to minimize your risk concerns?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2023 00:12:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-dual-ssid-with-bot-ssids-closed/m-p/4954621#M585030</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2023-11-07T00:12:54Z</dc:date>
    </item>
  </channel>
</rss>

