<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Wired Guest CWA with ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/wired-guest-cwa-with-ise/m-p/2653269#M74558</link>
    <description>&lt;P&gt;Having a heck of a time getting this to work.&lt;/P&gt;&lt;P&gt;First option is for the device to try and authenticate using Dot1X/EAP-TLS - for domain-connected devices only.&lt;/P&gt;&lt;P&gt;If that fails, they want the option to pop a CWA portal where they can enter either AD creds, or internal Guest user creds.&lt;/P&gt;&lt;P&gt;My challenge is the Policies and where to insert.&lt;/P&gt;&lt;P&gt;I'm using Policy Sets in ISE 1.2&lt;/P&gt;&lt;P&gt;Currently, I have these statements in the Default Policy Set:&lt;/P&gt;&lt;TABLE border="1" cellpadding="1" cellspacing="1" style="width: 500px;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Rule Name&lt;/TD&gt;&lt;TD&gt;Conditions&lt;/TD&gt;&lt;TD&gt;Permissions&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Wired Guest Portal Auth&lt;/TD&gt;&lt;TD&gt;if Net Access:UseCase EQUALS Guest Flow&lt;/TD&gt;&lt;TD&gt;Permit Access&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Wired Guest Redirect&lt;/TD&gt;&lt;TD&gt;if Wired_MAB&lt;/TD&gt;&lt;TD&gt;Wired CWA&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What i figured is if they fail the .1X, they'll drop down here to Wired MAB, and that will initiate a redirect and Guest Flow.&lt;/P&gt;&lt;P&gt;Couple problems:&lt;/P&gt;&lt;P&gt;First, it does seem to try; a show auth sess shows the proper redirect URL getting sent to the switchport.&lt;/P&gt;&lt;P&gt;Unfortunately, my browser pop gives me a certificate not recognized error, and if i try to continue anyways, it doesn't do anything. Wireless Guest, which I copied works fine.&lt;/P&gt;&lt;P&gt;Second challenge is that it forces the redirect whether i have the switch (NAD) in Monitor Mode or Low Impact Mode.&amp;nbsp; This is a problem because there are multiple sites, and we're cutting each over to Low Impact progressively.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone have any insight, or a document laying out in step by step terms implementing this?&lt;/P&gt;&lt;P&gt;thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 05:26:39 GMT</pubDate>
    <dc:creator>andrew.chappelle</dc:creator>
    <dc:date>2019-03-11T05:26:39Z</dc:date>
    <item>
      <title>Wired Guest CWA with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/wired-guest-cwa-with-ise/m-p/2653269#M74558</link>
      <description>&lt;P&gt;Having a heck of a time getting this to work.&lt;/P&gt;&lt;P&gt;First option is for the device to try and authenticate using Dot1X/EAP-TLS - for domain-connected devices only.&lt;/P&gt;&lt;P&gt;If that fails, they want the option to pop a CWA portal where they can enter either AD creds, or internal Guest user creds.&lt;/P&gt;&lt;P&gt;My challenge is the Policies and where to insert.&lt;/P&gt;&lt;P&gt;I'm using Policy Sets in ISE 1.2&lt;/P&gt;&lt;P&gt;Currently, I have these statements in the Default Policy Set:&lt;/P&gt;&lt;TABLE border="1" cellpadding="1" cellspacing="1" style="width: 500px;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Rule Name&lt;/TD&gt;&lt;TD&gt;Conditions&lt;/TD&gt;&lt;TD&gt;Permissions&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Wired Guest Portal Auth&lt;/TD&gt;&lt;TD&gt;if Net Access:UseCase EQUALS Guest Flow&lt;/TD&gt;&lt;TD&gt;Permit Access&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Wired Guest Redirect&lt;/TD&gt;&lt;TD&gt;if Wired_MAB&lt;/TD&gt;&lt;TD&gt;Wired CWA&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What i figured is if they fail the .1X, they'll drop down here to Wired MAB, and that will initiate a redirect and Guest Flow.&lt;/P&gt;&lt;P&gt;Couple problems:&lt;/P&gt;&lt;P&gt;First, it does seem to try; a show auth sess shows the proper redirect URL getting sent to the switchport.&lt;/P&gt;&lt;P&gt;Unfortunately, my browser pop gives me a certificate not recognized error, and if i try to continue anyways, it doesn't do anything. Wireless Guest, which I copied works fine.&lt;/P&gt;&lt;P&gt;Second challenge is that it forces the redirect whether i have the switch (NAD) in Monitor Mode or Low Impact Mode.&amp;nbsp; This is a problem because there are multiple sites, and we're cutting each over to Low Impact progressively.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone have any insight, or a document laying out in step by step terms implementing this?&lt;/P&gt;&lt;P&gt;thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:26:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wired-guest-cwa-with-ise/m-p/2653269#M74558</guid>
      <dc:creator>andrew.chappelle</dc:creator>
      <dc:date>2019-03-11T05:26:39Z</dc:date>
    </item>
    <item>
      <title>Update.  Looks like the</title>
      <link>https://community.cisco.com/t5/network-access-control/wired-guest-cwa-with-ise/m-p/2653270#M74559</link>
      <description>&lt;P&gt;Update.&amp;nbsp; Looks like the certificate issue is with Internet Explorer ?!?&amp;nbsp; Firefox redirects fine.&lt;/P&gt;&lt;P&gt;Still can't figure out why it does this even in Monitor Mode.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Feb 2015 19:16:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wired-guest-cwa-with-ise/m-p/2653270#M74559</guid>
      <dc:creator>andrew.chappelle</dc:creator>
      <dc:date>2015-02-11T19:16:40Z</dc:date>
    </item>
    <item>
      <title>Hello Andrew-Monitor mode</title>
      <link>https://community.cisco.com/t5/network-access-control/wired-guest-cwa-with-ise/m-p/2653271#M74560</link>
      <description>&lt;P&gt;Hello Andrew-&lt;/P&gt;&lt;P&gt;Monitor mode allows devices/users&amp;nbsp;to "proceed" even if they fail authentication. However, by proceed, I don't mean gaining access to the network. Instead, they are allowed to proceed from the &lt;STRONG&gt;authentication&lt;/STRONG&gt; step to the &lt;STRONG&gt;authorization&lt;/STRONG&gt;. Thus, you need to have a &lt;STRONG&gt;"catch_all"&lt;/STRONG&gt; rule in your &lt;STRONG&gt;authorization&lt;/STRONG&gt; section that is set to &lt;STRONG&gt;"Permit Access."&lt;/STRONG&gt; to any devices that were not authorized by one of your regular rules. For more info check out the following TrustSec guides:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/support/security/identity-services-engine/products-implementation-design-guides-list.html"&gt;http://www.cisco.com/c/en/us/support/security/identity-services-engine/products-implementation-design-guides-list.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM style="font-size: 14.3999996185303px; background-color: rgb(249, 249, 249);"&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Feb 2015 09:33:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wired-guest-cwa-with-ise/m-p/2653271#M74560</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2015-02-12T09:33:22Z</dc:date>
    </item>
    <item>
      <title>Thanks Neno,So to clarify;</title>
      <link>https://community.cisco.com/t5/network-access-control/wired-guest-cwa-with-ise/m-p/2653272#M74561</link>
      <description>&lt;P&gt;Thanks Neno,&lt;/P&gt;&lt;P&gt;So to clarify; even in Monitor Mode, AuthZ policies are still processed, and because my GuestFlow and Wired MAB rules are in AuthZ, they'll get used/processed no matter what?&lt;/P&gt;&lt;P&gt;How then do&amp;nbsp;I apply it only to the NADs&amp;nbsp;I want to progressively cut-over?&amp;nbsp;&amp;nbsp;Do I&amp;nbsp;have to add a condition that tests by Location and only match NADs in locations I'm cutting over?&lt;/P&gt;&lt;P&gt;I'm still not 100% sure I have the CWA AuthZ rules where&amp;nbsp;I should, and i think i need to move&amp;nbsp;them even further down the Default Policy set so that&amp;nbsp;they're after any Whitelists I have for phones, printers, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good news is that the web portal does pop!&amp;nbsp; IE still doesn't like it - or the cert at least.&lt;/P&gt;&lt;P&gt;Andrew&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Feb 2015 21:12:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wired-guest-cwa-with-ise/m-p/2653272#M74561</guid>
      <dc:creator>andrew.chappelle</dc:creator>
      <dc:date>2015-02-12T21:12:09Z</dc:date>
    </item>
    <item>
      <title>Hi Andrew! Yes, good job on</title>
      <link>https://community.cisco.com/t5/network-access-control/wired-guest-cwa-with-ise/m-p/2653273#M74562</link>
      <description>&lt;P&gt;Hi Andrew! Yes, good job on fixing the portal issue!&lt;/P&gt;&lt;P&gt;And yes, the &lt;STRONG&gt;authorization&lt;/STRONG&gt; rules are considered even in an open mode! And you are also correct that you will need to create different rules to account for NADs that are in production and for NADs that are in monitor mode. I have always liked using a separate &lt;STRONG&gt;Policy Set&lt;/STRONG&gt; for &lt;STRONG&gt;Monitor Mode&lt;/STRONG&gt; and a separate &lt;STRONG&gt;Policy Set&lt;/STRONG&gt; for &lt;STRONG&gt;Production&lt;/STRONG&gt; &lt;STRONG&gt;Mode&lt;/STRONG&gt;. Then I used device location to match against these conditions. For each location I have two sub-groups: One for &lt;STRONG&gt;Monitor&lt;/STRONG&gt;&amp;nbsp;and one for &lt;STRONG&gt;Production&lt;/STRONG&gt;. That way I can move a NAD from monitor mode to full production by simply changing its group.&lt;/P&gt;&lt;P&gt;Lastly, yes, your CWA rules should be at the bottom of your production authorization rules.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM style="font-size: 14.3999996185303px;"&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Feb 2015 01:56:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wired-guest-cwa-with-ise/m-p/2653273#M74562</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2015-02-13T01:56:27Z</dc:date>
    </item>
    <item>
      <title>Thanks Neno for all the</title>
      <link>https://community.cisco.com/t5/network-access-control/wired-guest-cwa-with-ise/m-p/2653274#M74563</link>
      <description>&lt;P&gt;Thanks Neno for all the advice and help!&lt;/P&gt;&lt;P&gt;Now&amp;nbsp;I think I've broken something, because for some reason the clients don't hit my policy any more. I tried adding the Stage as a Condition rather than Location for simplicity?&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/wired_1x.jpg" class="migrated-markup-image" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Feb 2015 20:25:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wired-guest-cwa-with-ise/m-p/2653274#M74563</guid>
      <dc:creator>andrew.chappelle</dc:creator>
      <dc:date>2015-02-13T20:25:28Z</dc:date>
    </item>
    <item>
      <title>I haven't used a custom NAD</title>
      <link>https://community.cisco.com/t5/network-access-control/wired-guest-cwa-with-ise/m-p/2653275#M74564</link>
      <description>&lt;P&gt;I haven't used a custom NAD group before but don't see any problems using one for simplicity. However, we need to figure out if this is the cause of your break/fix issue. So, in your authentication logs, can you confirm if you are at least hitting the correct "Policy Set" but then NOT hitting the correct rule within the set? Or are you not even hitting the correct "Policy Set" ? If so which one are you hitting.&amp;nbsp;&lt;/P&gt;&lt;P&gt;It would be helpful if you posted screenshots of:&lt;/P&gt;&lt;P&gt;- The live authentication screen&lt;/P&gt;&lt;P&gt;- The detailed authentication screen for the failed authentication&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM style="font-size: 14.3999996185303px;"&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Feb 2015 09:24:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wired-guest-cwa-with-ise/m-p/2653275#M74564</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2015-02-16T09:24:39Z</dc:date>
    </item>
    <item>
      <title>Hi Neno,Thanks a lot for the</title>
      <link>https://community.cisco.com/t5/network-access-control/wired-guest-cwa-with-ise/m-p/2653276#M74565</link>
      <description>&lt;P&gt;Hi Neno,&lt;/P&gt;&lt;P&gt;Thanks a lot for the repsonses, been a big help.&lt;/P&gt;&lt;P&gt;Well, the issue(s) have been resolved, and I've got everything working.&lt;/P&gt;&lt;P&gt;In the end the biggest issue was that the client supplicant (native windows) did not have a proper GPO - the &lt;STRONG&gt;Wired AutoConfig&lt;/STRONG&gt; wasn't set to start/auto.&amp;nbsp; That made a difference.&lt;/P&gt;&lt;P&gt;Plus I reordered a few rules, to get everything flowing proper.&lt;/P&gt;&lt;P&gt;All in all, things are looking good to cutover into LowImpact mode for production; my policy set condition matches on stage only, and so far it seems to work.&lt;/P&gt;&lt;P&gt;Thanks againn for the replies!&lt;/P&gt;&lt;P&gt;Andrew&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Feb 2015 19:35:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wired-guest-cwa-with-ise/m-p/2653276#M74565</guid>
      <dc:creator>andrew.chappelle</dc:creator>
      <dc:date>2015-02-16T19:35:05Z</dc:date>
    </item>
    <item>
      <title>Glad that you got your issues</title>
      <link>https://community.cisco.com/t5/network-access-control/wired-guest-cwa-with-ise/m-p/2653277#M74566</link>
      <description>&lt;P&gt;Glad that you got your issues resolved and that I was able to help! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Best regards,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Neno&lt;/P&gt;</description>
      <pubDate>Mon, 16 Feb 2015 19:43:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wired-guest-cwa-with-ise/m-p/2653277#M74566</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2015-02-16T19:43:43Z</dc:date>
    </item>
  </channel>
</rss>

