<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Guest accounts stop working after 21 days in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-guest-accounts-stop-working-after-21-days/m-p/5079480#M589057</link>
    <description>&lt;P&gt;After some weeks of troubleshooting, apparently we finally found the issue.&amp;nbsp; We disabled the "Enable Session Timeout" on the WLC for this guest SSID and the non-working accounts are starting to work again.&amp;nbsp; Also new accounts after the 21 days.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.jpg" style="width: 437px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/216918iCA2FD69D17476DA6/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.jpg" alt="1.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I don´t understand the reason.&amp;nbsp; Meanwhile, we are monitoring if everything is working as expected. Thanks for your support.&lt;/P&gt;</description>
    <pubDate>Fri, 26 Apr 2024 13:00:32 GMT</pubDate>
    <dc:creator>Cliffer</dc:creator>
    <dc:date>2024-04-26T13:00:32Z</dc:date>
    <item>
      <title>ISE Guest accounts stop working after 21 days</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-accounts-stop-working-after-21-days/m-p/5036492#M587982</link>
      <description>&lt;P&gt;Hi team!&lt;/P&gt;
&lt;P&gt;We have been struggling with an issue after migrating our ISE deployment from 2.6 to 3.1 last year.&lt;BR /&gt;&lt;BR /&gt;We found out that accounts used for&amp;nbsp;Wifi guest solution stop working properly after 21 days of being created using the Sponsor portal.&amp;nbsp; The behaviour is that the user cannot navigate anymore and this is how it looks from Guest Accounting reports page:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cliffer_0-1709901869426.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/212064i7FDD28C853B8EB55/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Cliffer_0-1709901869426.png" alt="Cliffer_0-1709901869426.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;From a policy perspective, the attempt seems to get stucked at the CWA redirection and we couldn´t find anything relevant on the Live logs, except that compared to a working device, Step 15048 doesn´t appear for a non-working device.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cliffer_1-1709902238175.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/212065i8BD1317F4B5F3B87/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Cliffer_1-1709902238175.png" alt="Cliffer_1-1709902238175.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;This happens to any kind of device and once the account stops working, it doesn´t work anymore until we create it again.&amp;nbsp; On the Sponsor portal, the accounts are not locked or expired.&lt;BR /&gt;&lt;BR /&gt;We use AD for authentication and another strange behaviour is that some accounts are not able to creat guest accounts which work, even if they are on the same AD group.&lt;BR /&gt;&lt;BR /&gt;Any help or suggestion will be much appreciated.&amp;nbsp; I could provide more details but didn´t want to make it very extensive.&lt;BR /&gt;&lt;BR /&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2024 13:09:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-accounts-stop-working-after-21-days/m-p/5036492#M587982</guid>
      <dc:creator>Cliffer</dc:creator>
      <dc:date>2024-03-08T13:09:16Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest accounts stop working after 21 days</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-accounts-stop-working-after-21-days/m-p/5037499#M588004</link>
      <description>&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/how-to-ask-the-community-for-help/ta-p/3704356" target="_blank"&gt;https://community.cisco.com/t5/security-documents/how-to-ask-the-community-for-help/ta-p/3704356&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Endpoint purge rules?&amp;nbsp; Are you using Guest Flow in the policy?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2024 12:19:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-accounts-stop-working-after-21-days/m-p/5037499#M588004</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-03-11T12:19:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest accounts stop working after 21 days</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-accounts-stop-working-after-21-days/m-p/5038104#M588027</link>
      <description>&lt;P&gt;So, 2 things I can think of that we saw on ours.&lt;/P&gt;
&lt;P&gt;1) You may have your portal creating a 21 day account if that is all they are getting, check the portal settings.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-03-12 091947.jpg" style="width: 507px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/212270i7C09353E4778059E/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2024-03-12 091947.jpg" alt="Screenshot 2024-03-12 091947.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;There is also a second place to check and that is under guest type.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-03-12 092801.jpg" style="width: 404px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/212271i0E95ABA1F9475514/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2024-03-12 092801.jpg" alt="Screenshot 2024-03-12 092801.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The last thing we ran into is the endpoint purge. This was deleting registered guest endpoints. By default it is 30 days from registration, I had to change ours to 30 days inactive. You can find this under&amp;nbsp;Administration&amp;gt;&amp;gt;Identity Management&amp;gt;&amp;gt;Settings and will see endpoint purge on the left.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-03-12 092419.jpg" style="width: 769px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/212272iBAD49A04534938E9/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2024-03-12 092419.jpg" alt="Screenshot 2024-03-12 092419.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2024 14:32:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-accounts-stop-working-after-21-days/m-p/5038104#M588027</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2024-03-12T14:32:45Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest accounts stop working after 21 days</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-accounts-stop-working-after-21-days/m-p/5038287#M588031</link>
      <description>&lt;P&gt;Thanks for taking the time to answer.&amp;nbsp; The purge rules we have are the following, where the first two are not actually in use because those IdentityGroups are not referenced anywhere.&amp;nbsp; The third one is related, however the days doesn´t match.&amp;nbsp; We could try to disable it&amp;nbsp;&lt;SPAN&gt;though.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cliffer_0-1710269320744.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/212339iC1266FE6DCCFDE4A/image-size/large?v=v2&amp;amp;px=999" role="button" title="Cliffer_0-1710269320744.png" alt="Cliffer_0-1710269320744.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The other purge policy is the following, although we are able to see how a non-working account is not expired nor purged with this policy.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cliffer_1-1710269609807.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/212340i8A1425C7D50D61ED/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Cliffer_1-1710269609807.png" alt="Cliffer_1-1710269609807.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding the Guest Flow, yes, we use it and the weird thing is that it´s the same configuration as it was on previous deployment, version 2.6.&amp;nbsp; Now we have version 3.1, patch 7.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cliffer_3-1710269772830.jpeg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/212342iF1FCD852047D19AA/image-size/large?v=v2&amp;amp;px=999" role="button" title="Cliffer_3-1710269772830.jpeg" alt="Cliffer_3-1710269772830.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cliffer_4-1710269857248.jpeg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/212343iFBE041288424F07B/image-size/large?v=v2&amp;amp;px=999" role="button" title="Cliffer_4-1710269857248.jpeg" alt="Cliffer_4-1710269857248.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The CWA redirection policy result is the following:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cliffer_5-1710269997278.jpeg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/212344i151CCD9AD1B8D877/image-size/large?v=v2&amp;amp;px=999" role="button" title="Cliffer_5-1710269997278.jpeg" alt="Cliffer_5-1710269997278.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;One more thing we realized is that an account when stop working, it´s like it gets stucked on the CWA redirection policy according to the Live Logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2024 19:05:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-accounts-stop-working-after-21-days/m-p/5038287#M588031</guid>
      <dc:creator>Cliffer</dc:creator>
      <dc:date>2024-03-12T19:05:24Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest accounts stop working after 21 days</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-accounts-stop-working-after-21-days/m-p/5038309#M588032</link>
      <description>&lt;P&gt;Thanks Dustin for your reply.&lt;BR /&gt;&lt;BR /&gt;For point 1, the solution we have implemented is a Sponsored Guest Portal, not the Self-Registered, so there is no option specify the valid days for an account.&lt;/P&gt;
&lt;P&gt;For the second place, we have it just like your screenshot.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cliffer_1-1710272870237.jpeg" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/212346i774748971CA4A70A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Cliffer_1-1710272870237.jpeg" alt="Cliffer_1-1710272870237.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;In regards of the last thing you mentioned, we already have it like that &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cliffer_2-1710272966300.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/212347iEF9144F815ED1E2B/image-size/large?v=v2&amp;amp;px=999" role="button" title="Cliffer_2-1710272966300.png" alt="Cliffer_2-1710272966300.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2024 20:05:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-accounts-stop-working-after-21-days/m-p/5038309#M588032</guid>
      <dc:creator>Cliffer</dc:creator>
      <dc:date>2024-03-12T20:05:32Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest accounts stop working after 21 days</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-accounts-stop-working-after-21-days/m-p/5038338#M588035</link>
      <description>&lt;P&gt;Yeah, that is odd that you have it set at 90 days but getting removed. Have you verified a new register shows the expiration date is in 90 days? This would rule out anything with the portal and point to something with purging rules.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2024 20:58:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-accounts-stop-working-after-21-days/m-p/5038338#M588035</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2024-03-12T20:58:27Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest accounts stop working after 21 days</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-accounts-stop-working-after-21-days/m-p/5038767#M588056</link>
      <description>&lt;P&gt;Yes, we have verified that the expiration configured is the one being showed.&amp;nbsp; But I don´t think is related to purging rules, because when an account is not working anymore, it could be still present in the Identity group, however, we have disabled the purging for the Identity group related, for testing.&lt;BR /&gt;&lt;BR /&gt;Another behaviour we found is that some users belonging to the AD group that is authorized to create Sponsored accounts, are not able to create a working Sponsored account.&amp;nbsp; I mean, the account just created by these users, never works.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2024 13:31:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-accounts-stop-working-after-21-days/m-p/5038767#M588056</guid>
      <dc:creator>Cliffer</dc:creator>
      <dc:date>2024-03-13T13:31:32Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest accounts stop working after 21 days</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-accounts-stop-working-after-21-days/m-p/5038801#M588057</link>
      <description>&lt;P&gt;This just happened so I´m adding some screenshots in order to give you more details.&lt;/P&gt;
&lt;P&gt;An account created two months ago, that is still active and the MAC is present in the Guest Identity group is not working at the moment.&amp;nbsp; In the Live Logs we can see how is redirected to the proper auth policy and is showed as connected for a couple of minutes, until the connection drops.&amp;nbsp; In the Live Logs, is showing that goes back to the redirection policy and stays there.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cliffer_0-1710337245152.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/212418i51ABB305E64D9AA3/image-size/large?v=v2&amp;amp;px=999" role="button" title="Cliffer_0-1710337245152.png" alt="Cliffer_0-1710337245152.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cliffer_1-1710338696914.jpeg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/212419i11D9F688124133C5/image-size/large?v=v2&amp;amp;px=999" role="button" title="Cliffer_1-1710338696914.jpeg" alt="Cliffer_1-1710338696914.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Account details:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cliffer_2-1710338783144.jpeg" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/212420i3742203704D74DB7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Cliffer_2-1710338783144.jpeg" alt="Cliffer_2-1710338783144.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2024 14:07:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-accounts-stop-working-after-21-days/m-p/5038801#M588057</guid>
      <dc:creator>Cliffer</dc:creator>
      <dc:date>2024-03-13T14:07:43Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest accounts stop working after 21 days</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-accounts-stop-working-after-21-days/m-p/5038996#M588063</link>
      <description>&lt;P&gt;So, the only thing I see that is odd is when it works it's getting the guest username in the identity, but when it's not working it's presenting the mac of the phone. Does the system register the device at all as a guest endpoint? If so I wonder if you add to your or statement in the rule&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-03-13 151451.jpg" style="width: 508px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/212443iBB4A13E2A0D15DE7/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2024-03-13 151451.jpg" alt="Screenshot 2024-03-13 151451.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2024 20:15:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-accounts-stop-working-after-21-days/m-p/5038996#M588063</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2024-03-13T20:15:24Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest accounts stop working after 21 days</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-accounts-stop-working-after-21-days/m-p/5051659#M588445</link>
      <description>&lt;P&gt;Yes, the system registers the device as a guest endpoint, or whatever Indentity group you define in the Guest types.&amp;nbsp; The statement is added on the rule, we even tried without the Guest flow and the symptons are the same.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/214057i553E991E743626E3/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.jpg" alt="1.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 18:43:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-accounts-stop-working-after-21-days/m-p/5051659#M588445</guid>
      <dc:creator>Cliffer</dc:creator>
      <dc:date>2024-03-27T18:43:50Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest accounts stop working after 21 days</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-accounts-stop-working-after-21-days/m-p/5051693#M588449</link>
      <description>&lt;P&gt;With it not passing a user, you may not be hitting the guest type. You may want to try with the SSID contains Guest and the GuestEndpoints group.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 19:48:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-accounts-stop-working-after-21-days/m-p/5051693#M588449</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2024-03-27T19:48:16Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest accounts stop working after 21 days</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-accounts-stop-working-after-21-days/m-p/5057652#M588592</link>
      <description>&lt;P&gt;Hi Dustin,&lt;BR /&gt;&lt;BR /&gt;When we tried removing the guest type from the auth policy, that didn´t work either for new connections.&amp;nbsp; The attempts got stuck in the CWA redirection auth policy with the MAC as the username, as if the web redirection wasn´t working.&amp;nbsp; And the sponsor portal doesn´t appear on the device in order to authenticate.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/215003i48A40A4B08D30D55/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.jpg" alt="1.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;For a working account, this solution is still working, with the CWA redirection (until the three weeks pass)&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2024 19:01:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-accounts-stop-working-after-21-days/m-p/5057652#M588592</guid>
      <dc:creator>Cliffer</dc:creator>
      <dc:date>2024-04-05T19:01:05Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest accounts stop working after 21 days</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-accounts-stop-working-after-21-days/m-p/5060495#M588616</link>
      <description>&lt;P&gt;Not sure why your redirect isn't working. Here is what we use for guest without issue. when they are on the redirect, if they put in an IP address do they redirect? Something not on your network.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-04-08 081348.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/215296iF910571D241AF274/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2024-04-08 081348.jpg" alt="Screenshot 2024-04-08 081348.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 13:16:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-accounts-stop-working-after-21-days/m-p/5060495#M588616</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2024-04-08T13:16:46Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest accounts stop working after 21 days</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-accounts-stop-working-after-21-days/m-p/5079480#M589057</link>
      <description>&lt;P&gt;After some weeks of troubleshooting, apparently we finally found the issue.&amp;nbsp; We disabled the "Enable Session Timeout" on the WLC for this guest SSID and the non-working accounts are starting to work again.&amp;nbsp; Also new accounts after the 21 days.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.jpg" style="width: 437px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/216918iCA2FD69D17476DA6/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.jpg" alt="1.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I don´t understand the reason.&amp;nbsp; Meanwhile, we are monitoring if everything is working as expected. Thanks for your support.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2024 13:00:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-accounts-stop-working-after-21-days/m-p/5079480#M589057</guid>
      <dc:creator>Cliffer</dc:creator>
      <dc:date>2024-04-26T13:00:32Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest accounts stop working after 21 days</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-accounts-stop-working-after-21-days/m-p/5166603#M591437</link>
      <description>&lt;P&gt;I am also having the same issue. Has your fixed of disabling the "Enable Session Timeout" caused an issues or is everything working as expected?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 15:39:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-accounts-stop-working-after-21-days/m-p/5166603#M591437</guid>
      <dc:creator>lhernan455</dc:creator>
      <dc:date>2024-08-27T15:39:16Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest accounts stop working after 21 days</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-accounts-stop-working-after-21-days/m-p/5169055#M591584</link>
      <description>&lt;P&gt;Yes, we found out that after migrating the ISE, it was sending a timeout session very very big (a couple of millions), when that option wasn´t enabled on the ISE.&amp;nbsp; Forcing the timeout session on ISE or disabling that option on the WLC, solved the issue.&lt;/P&gt;</description>
      <pubDate>Sun, 01 Sep 2024 16:39:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-accounts-stop-working-after-21-days/m-p/5169055#M591584</guid>
      <dc:creator>Cliffer</dc:creator>
      <dc:date>2024-09-01T16:39:48Z</dc:date>
    </item>
  </channel>
</rss>

