<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Restrict GuestType to specific portal/SSID in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5321660#M597825</link>
    <description>&lt;P&gt;Hello!&lt;BR /&gt;For a customer, i'd like to configure two captive portals respectively tied to two SSID (different usage).&lt;/P&gt;
&lt;P&gt;However, i'd like Guest Type to be tied to one of the captive portal/SSID, basically :&amp;nbsp;&lt;BR /&gt;- GuestType "A" can only authenticate to GuestPortal/SSID "A"&lt;BR /&gt;- GuestType "B" can only authenticate to Guest Portal/SSID "B"&lt;BR /&gt;- GuesType "B" cannot login to Guest Portal/SSID "A" and vice-versa&lt;BR /&gt;&lt;BR /&gt;I there a way to perform this with ISE in 3.3 ?&lt;BR /&gt;Thanks a lot!&lt;/P&gt;</description>
    <pubDate>Mon, 18 Aug 2025 14:46:30 GMT</pubDate>
    <dc:creator>KevinMuller</dc:creator>
    <dc:date>2025-08-18T14:46:30Z</dc:date>
    <item>
      <title>Restrict GuestType to specific portal/SSID</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5321660#M597825</link>
      <description>&lt;P&gt;Hello!&lt;BR /&gt;For a customer, i'd like to configure two captive portals respectively tied to two SSID (different usage).&lt;/P&gt;
&lt;P&gt;However, i'd like Guest Type to be tied to one of the captive portal/SSID, basically :&amp;nbsp;&lt;BR /&gt;- GuestType "A" can only authenticate to GuestPortal/SSID "A"&lt;BR /&gt;- GuestType "B" can only authenticate to Guest Portal/SSID "B"&lt;BR /&gt;- GuesType "B" cannot login to Guest Portal/SSID "A" and vice-versa&lt;BR /&gt;&lt;BR /&gt;I there a way to perform this with ISE in 3.3 ?&lt;BR /&gt;Thanks a lot!&lt;/P&gt;</description>
      <pubDate>Mon, 18 Aug 2025 14:46:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5321660#M597825</guid>
      <dc:creator>KevinMuller</dc:creator>
      <dc:date>2025-08-18T14:46:30Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict GuestType to specific portal/SSID</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5321662#M597826</link>
      <description>&lt;P&gt;If I understand correctly, just assign different Endpoint ID Groups to each portal. In authz policies map those EIDs to SSIDs.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Aug 2025 14:48:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5321662#M597826</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2025-08-18T14:48:15Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict GuestType to specific portal/SSID</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5321666#M597829</link>
      <description>&lt;P&gt;Yes, this is something that^I've done already but it does not prevent you to have GuestType "A" authenticating on Guest Portal "B", and if the users does so, its MAC will be added to the Endpoint ID Group mapped to GuestType "A",&lt;/P&gt;</description>
      <pubDate>Mon, 18 Aug 2025 14:50:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5321666#M597829</guid>
      <dc:creator>KevinMuller</dc:creator>
      <dc:date>2025-08-18T14:50:11Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict GuestType to specific portal/SSID</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5321668#M597830</link>
      <description>&lt;P&gt;In wlc make sure you set calling ID to inlcude SSID&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then match SSID in authz&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 18 Aug 2025 14:51:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5321668#M597830</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-18T14:51:41Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict GuestType to specific portal/SSID</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5321673#M597831</link>
      <description>&lt;P&gt;Yes, that's already what I do for "classic" CWA, but in the Identity Source Sequence mapped to the Guest Portal, there is no way to set a specific "user groups", you can only define identity store.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Aug 2025 14:56:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5321673#M597831</guid>
      <dc:creator>KevinMuller</dc:creator>
      <dc:date>2025-08-18T14:56:01Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict GuestType to specific portal/SSID</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5321675#M597832</link>
      <description>&lt;P&gt;I think you can do two policy (not two authz policy) and match SSID in policy.&lt;/P&gt;
&lt;P&gt;So each policy have it authz policy abd it portal&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 18 Aug 2025 15:00:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5321675#M597832</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-18T15:00:32Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict GuestType to specific portal/SSID</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5321677#M597833</link>
      <description>&lt;P&gt;Just curious but why treat these two guest differently in the first place?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Aug 2025 15:01:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5321677#M597833</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2025-08-18T15:01:27Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict GuestType to specific portal/SSID</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5321776#M597836</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/299156"&gt;@KevinMuller&lt;/a&gt;&amp;nbsp;what is Type A/B exactly, and how would ISE discern (in a RADIUS Access-Request) which is which?&amp;nbsp; You can't rely on MAC addresses - so there is no unique client identifier that I know of, at the pre-auth stage (i.e. the stage where you want this MAC address to be steered to a particular Guest Portal).&lt;/P&gt;</description>
      <pubDate>Mon, 18 Aug 2025 20:58:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5321776#M597836</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2025-08-18T20:58:25Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict GuestType to specific portal/SSID</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5321887#M597843</link>
      <description>&lt;P&gt;Type A/B are GuestType (so basically the User ID Group to which Guest account belong).&lt;BR /&gt;Indeed, there is no actual way of filtering on the pre-auth as ISE only get the client's MAC, but I was thinking of restricting access to "A" portal to only guest that below to User ID Group mapped with GuestType "A" during the portal authentication. Hope it makes it clearer &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 08:58:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5321887#M597843</guid>
      <dc:creator>KevinMuller</dc:creator>
      <dc:date>2025-08-19T08:58:37Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict GuestType to specific portal/SSID</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5321892#M597844</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot (311).png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/250498iDCC20FB721F3890A/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot (311).png" alt="Screenshot (311).png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 09:11:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5321892#M597844</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-19T09:11:25Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict GuestType to specific portal/SSID</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5321900#M597846</link>
      <description>&lt;P&gt;You have One SSID or two ?&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have two use&amp;nbsp; one for each policy.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 09:36:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5321900#M597846</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-19T09:36:47Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict GuestType to specific portal/SSID</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5321914#M597847</link>
      <description>&lt;P&gt;I don’t understand why you’d want to do that. Notwithstanding the fact that it’s possible to direct a client to a specific portal based on MAC address identity - unless you had some bizarre 6th sense to know which MAC address needs which portal. The screenshot that MHM posted doesn’t solve the issue either. The portal selection can be done on ISE hostname, but that means the WLC is now the one with the 6th sense to know which PSN to target. What exact problem are you looking to solve? Is it that you want the self registering user to end up in a specific group, rather than the default (and one and only) Group for self registering guest flow?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 10:18:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5321914#M597847</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2025-08-19T10:18:32Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict GuestType to specific portal/SSID</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5321937#M597852</link>
      <description>&lt;P&gt;Challenge is quite simple : Sponsor can create account for group "A" or group "B". Depending on the SSID you are connected to, and the associated portal (Portal are different between SSID "A" and "B"), you only allow guest account from group "A" or group "B".&lt;BR /&gt;Let's say you have a Guest/Visitor SSID with its associated portal where Guest account are created and associated to User ID Group "Guest". We don't want them to use their account to associated to another CWA SSID named "Contractor" which is also authenticated via ISE. Even if the Guest Portal is different the Identity Store remains the same (Guest Users) and there is no way natively to limit to specific User ID Groups (Guest Type)&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 11:45:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5321937#M597852</guid>
      <dc:creator>KevinMuller</dc:creator>
      <dc:date>2025-08-19T11:45:01Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict GuestType to specific portal/SSID</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5322150#M597859</link>
      <description>&lt;P&gt;You should create two Guest Types - Contractor and GuestOnly - each Guest Type has its own Endpoint Identity Group and rules etc. The question you're asking is how to ensure that Contractor can't authenticated on 'GuestOnly' Portal and vice-versa.&lt;/P&gt;
&lt;P&gt;I think that would be possible in an Authorization Policy (each Guest Type that you create, also creates an internal user Identity Group that can be leveraged here)&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ArneBier_0-1755643077579.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/250528iB94B0AFEA3CA2798/image-size/large?v=v2&amp;amp;px=999" role="button" title="ArneBier_0-1755643077579.png" alt="ArneBier_0-1755643077579.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The Rules shown above do not include handling HA (multiple PSN's) - you should add the ISE hostname check to redirect to your secondary PSN (if you have one) - that just doubles the rules to 4 in total.&lt;/P&gt;
&lt;P&gt;The Rules that come after the redirection part will then simply check the Endpoint Identity Group and then return the Authorization Policies accordingly (Access-Accept with Session-Timeout etc.)&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 22:40:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5322150#M597859</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2025-08-19T22:40:35Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict GuestType to specific portal/SSID</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5322156#M597860</link>
      <description>&lt;P&gt;So what difference between my suggestion and your?&lt;/P&gt;
&lt;P&gt;Really don't get.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 23:10:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5322156#M597860</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-19T23:10:01Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict GuestType to specific portal/SSID</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5322166#M597861</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;- your screenshot shows the proven solution for doing ISE Portal HA, by checking which PSN is processing the request (hostname check) and then returning the appropriate URL to the endpoint. Noticed that the SSID is the same in both rules.&lt;/P&gt;
&lt;P&gt;What&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/299156"&gt;@KevinMuller&lt;/a&gt;&amp;nbsp;was asking for was to prevent Guests and Contractors from using the wrong portal - and that enforcement requires validation of the SSID AND the Internal User Group of the authenticating user.&lt;/P&gt;
&lt;P&gt;My comment at the end of my last post mentioned the HA aspect - which your slide covered. So it's a merging of both of our suggestions.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 23:56:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5322166#M597861</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2025-08-19T23:56:11Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict GuestType to specific portal/SSID</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5322168#M597862</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please check my all comments' I already mentioned many times he need two ssid.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 00:01:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5322168#M597862</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-20T00:01:11Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict GuestType to specific portal/SSID</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5322171#M597864</link>
      <description>&lt;P&gt;You're right about suggesting two SSID's - it was when&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/299156"&gt;@KevinMuller&lt;/a&gt;&amp;nbsp; explained his intention of restricting each guest type to a particular portal, that I added the AND rule logic to enforce that.&lt;/P&gt;
&lt;P&gt;Something worth trying and testing.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 00:05:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5322171#M597864</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2025-08-20T00:05:58Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict GuestType to specific portal/SSID</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5322322#M597865</link>
      <description>&lt;P&gt;You cannot checks on these conditions are for CWA you perform Host Lookup type of authentication. ISE performs the authentication process on the guest portal "internally", it doesn't go through the RADIUS Policy Sets for this. Only Endpoint ID Groups are correct conditions in the AuthZ Rules (unfortunatly ...).&lt;BR /&gt;I'll try enable external authentication in the ISS pointing to RADIUS Token Identity Store where the RADIUS Server is actually the same ISE to "loopback" the authentication.I've never tested that before. Anyhow, even if it works, I can only restrict one Portal not both.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 08:03:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5322322#M597865</guid>
      <dc:creator>KevinMuller</dc:creator>
      <dc:date>2025-08-20T08:03:14Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict GuestType to specific portal/SSID</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5322326#M597866</link>
      <description>&lt;P&gt;&lt;SPAN&gt;You cannot checks on these conditions are for CWA you perform Host Lookup type of authentication.&amp;nbsp; &amp;lt;&amp;lt;- I dont get what you meaning here&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;But&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Guest when it authc in ISE it &lt;STRONG&gt;CWA&lt;/STRONG&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;MHM&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 08:21:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-guesttype-to-specific-portal-ssid/m-p/5322326#M597866</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-20T08:21:42Z</dc:date>
    </item>
  </channel>
</rss>

