<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE3.2- Self-registration users cannot be updated in GuestEndpoint in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise3-2-self-registration-users-cannot-be-updated-in/m-p/5272205#M595526</link>
    <description>&lt;P&gt;The problem description was clear from your first posting. But if you want assistance with finding the cause, then please supply us with some data to investigate. None of us here are clairvoyant.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Screenshots of your ISE Policy Set
&lt;UL&gt;
&lt;LI&gt;Authentication ... show the action for "If user not found" also)&lt;/LI&gt;
&lt;LI&gt;Authorization&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Screenshots of your Guest Type&lt;/LI&gt;
&lt;LI&gt;tcpdump of the RADIUS traffic before, during and after a user attempts to log into the portal (we want to see the Access-Request MAB to ISE, and the responses to the NAD (hopefully the URL redirect), and then any other RADIUS traffic thereafter)&lt;/LI&gt;
&lt;LI&gt;Live logs details of the MAB session&lt;/LI&gt;
&lt;LI&gt;Operations / Reports relating to Guest Portal - there are a few Reports to choose from - I can't remember which one&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 17 Mar 2025 20:58:05 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2025-03-17T20:58:05Z</dc:date>
    <item>
      <title>ISE3.2- Self-registration users cannot be updated in GuestEndpoints</title>
      <link>https://community.cisco.com/t5/network-access-control/ise3-2-self-registration-users-cannot-be-updated-in/m-p/5270250#M595437</link>
      <description>&lt;P&gt;Self-registration users cannot be updated in GuestEndpoints after users pass authentications. And CoA cannot be triggered.&lt;/P&gt;&lt;P&gt;I read this article:&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/216191-troubleshoot-common-cisco-ise-guest-acce.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/216191-troubleshoot-common-cisco-ise-guest-acce.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;It seems that CoA will be triggered automatically after self registration users passing authtentications.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did all the config according to this article:&lt;A href="https://community.cisco.com/t5/security-knowledge-base/how-to-cisco-ise-captive-portals-with-aruba-wireless/ta-p/4633904" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/how-to-cisco-ise-captive-portals-with-aruba-wireless/ta-p/4633904 &lt;/A&gt;&lt;/P&gt;&lt;P&gt;Can anyone explain the logic behind this and find out why this issue happens?&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Magret&lt;/P&gt;</description>
      <pubDate>Wed, 12 Mar 2025 08:20:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise3-2-self-registration-users-cannot-be-updated-in/m-p/5270250#M595437</guid>
      <dc:creator>Magret</dc:creator>
      <dc:date>2025-03-12T08:20:59Z</dc:date>
    </item>
    <item>
      <title>Re: ISE3.2- Self-registration users cannot be updated in GuestEndpoint</title>
      <link>https://community.cisco.com/t5/network-access-control/ise3-2-self-registration-users-cannot-be-updated-in/m-p/5270607#M595446</link>
      <description>&lt;P&gt;Your screenshots are not very helpful - without the details (i.e. we need more than seeing a red "failed" icon), it's impossible to tell what's gone wrong. Show us the details, and then also prove to us that the CoA was sent by ISE, and acknowledged by the Aruba AP. a tcpdump on ISE is a good place to start.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Mar 2025 23:02:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise3-2-self-registration-users-cannot-be-updated-in/m-p/5270607#M595446</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2025-03-12T23:02:08Z</dc:date>
    </item>
    <item>
      <title>Re: ISE3.2- Self-registration users cannot be updated in GuestEndpoint</title>
      <link>https://community.cisco.com/t5/network-access-control/ise3-2-self-registration-users-cannot-be-updated-in/m-p/5271933#M595507</link>
      <description>&lt;P&gt;Actually the current issue is that portal user cannot be put into GuestEndpoint, which then cannot trigger coa profile.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Magret_0-1742199378913.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/241846i7E997FACA7414032/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Magret_0-1742199378913.png" alt="Magret_0-1742199378913.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Mar 2025 08:16:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise3-2-self-registration-users-cannot-be-updated-in/m-p/5271933#M595507</guid>
      <dc:creator>Magret</dc:creator>
      <dc:date>2025-03-17T08:16:39Z</dc:date>
    </item>
    <item>
      <title>Re: ISE3.2- Self-registration users cannot be updated in GuestEndpoint</title>
      <link>https://community.cisco.com/t5/network-access-control/ise3-2-self-registration-users-cannot-be-updated-in/m-p/5272205#M595526</link>
      <description>&lt;P&gt;The problem description was clear from your first posting. But if you want assistance with finding the cause, then please supply us with some data to investigate. None of us here are clairvoyant.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Screenshots of your ISE Policy Set
&lt;UL&gt;
&lt;LI&gt;Authentication ... show the action for "If user not found" also)&lt;/LI&gt;
&lt;LI&gt;Authorization&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Screenshots of your Guest Type&lt;/LI&gt;
&lt;LI&gt;tcpdump of the RADIUS traffic before, during and after a user attempts to log into the portal (we want to see the Access-Request MAB to ISE, and the responses to the NAD (hopefully the URL redirect), and then any other RADIUS traffic thereafter)&lt;/LI&gt;
&lt;LI&gt;Live logs details of the MAB session&lt;/LI&gt;
&lt;LI&gt;Operations / Reports relating to Guest Portal - there are a few Reports to choose from - I can't remember which one&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Mar 2025 20:58:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise3-2-self-registration-users-cannot-be-updated-in/m-p/5272205#M595526</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2025-03-17T20:58:05Z</dc:date>
    </item>
    <item>
      <title>Re: ISE3.2- Self-registration users cannot be updated in GuestEndpoint</title>
      <link>https://community.cisco.com/t5/network-access-control/ise3-2-self-registration-users-cannot-be-updated-in/m-p/5277060#M595752</link>
      <description>&lt;P&gt;Thanks for the reminder.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The policy set details are as below:&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Magret_4-1743478370387.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/242721i5537DBC6C808B571/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Magret_4-1743478370387.png" alt="Magret_4-1743478370387.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Authentication:&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Magret_5-1743478391274.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/242722i1E549B4A69D15D6A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Magret_5-1743478391274.png" alt="Magret_5-1743478391274.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Authorization Policy:&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Magret_6-1743478413659.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/242723i47EC028ED0EC00AD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Magret_6-1743478413659.png" alt="Magret_6-1743478413659.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Guest Type:&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Magret_7-1743478443722.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/242724iA58B409FFA0A55F6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Magret_7-1743478443722.png" alt="Magret_7-1743478443722.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Session log：I also attached detailed info as pdf&lt;/LI&gt;&lt;/UL&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Magret_11-1743478688000.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/242728iAE0462C5C3620008/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Magret_11-1743478688000.png" alt="Magret_11-1743478688000.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;TCP dump: I start tcp dump first and then connect SSID, after device pops out login page, I registered a new accont and login, then I stopped the tcp dump. Strange thing is that I didn't see radius related packet capture in tcp dump. However, I can see radius request in NAS(aruba controller) packet capture.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Magret_8-1743478636453.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/242725iA1F6004F42670AFF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Magret_8-1743478636453.png" alt="Magret_8-1743478636453.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Magret_9-1743478667219.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/242726iE9553B8EC7AE5DAD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Magret_9-1743478667219.png" alt="Magret_9-1743478667219.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I attached Guest report as CSV type.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Apr 2025 03:42:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise3-2-self-registration-users-cannot-be-updated-in/m-p/5277060#M595752</guid>
      <dc:creator>Magret</dc:creator>
      <dc:date>2025-04-01T03:42:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISE3.2- Self-registration users cannot be updated in GuestEndpoint</title>
      <link>https://community.cisco.com/t5/network-access-control/ise3-2-self-registration-users-cannot-be-updated-in/m-p/5278764#M595849</link>
      <description>&lt;P&gt;In your ISE Guest Type definition, you show that you're using Identity Group 'GuestEndpoints' - which means that if a guest logs into the portal and provides the correct creds, then their MAC address gets added to GuestEnpoints. However, in the 'Session log - Guest auth.pdf' I see another Endpoint Identity Group mentioned - "GuestType_Guest-Daily" - since your Authorization Rule mentions 'GuestEndpoints' as the Group for which you want to grant access, you need to use this Group. Where does&amp;nbsp;"GuestType_Guest-Daily" fit into the picture?&lt;/P&gt;</description>
      <pubDate>Sun, 06 Apr 2025 21:02:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise3-2-self-registration-users-cannot-be-updated-in/m-p/5278764#M595849</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2025-04-06T21:02:11Z</dc:date>
    </item>
    <item>
      <title>Re: ISE3.2- Self-registration users cannot be updated in GuestEndpoint</title>
      <link>https://community.cisco.com/t5/network-access-control/ise3-2-self-registration-users-cannot-be-updated-in/m-p/5278782#M595850</link>
      <description>&lt;P&gt;Guest Type_Guest-Daily as below：&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Magret_0-1743989562639.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/243016i61C596954FF5655D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Magret_0-1743989562639.png" alt="Magret_0-1743989562639.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 01:33:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise3-2-self-registration-users-cannot-be-updated-in/m-p/5278782#M595850</guid>
      <dc:creator>Magret</dc:creator>
      <dc:date>2025-04-07T01:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: ISE3.2- Self-registration users cannot be updated in GuestEndpoint</title>
      <link>https://community.cisco.com/t5/network-access-control/ise3-2-self-registration-users-cannot-be-updated-in/m-p/5278791#M595851</link>
      <description>&lt;P&gt;Ok I see now - the confusion was because in the Live Logs details, a successful authentication shows the User Identity Group, which ISE creates for you internally - always has the prefix "GuestType_".&amp;nbsp; I thought I was looking at the Endpoint Identity Group.&amp;nbsp; Those are two different things. So your output looks ok.&lt;/P&gt;
&lt;P&gt;I can't tell what the issue might be.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 03:03:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise3-2-self-registration-users-cannot-be-updated-in/m-p/5278791#M595851</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2025-04-07T03:03:31Z</dc:date>
    </item>
  </channel>
</rss>

