<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Guest flow is added after the in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/guest-web-authentication-issue/m-p/2512745#M89484</link>
    <description>&lt;P&gt;Guest flow is added after the CWA bit. By not adding the group it means you can't differentiate between different internal groups eg contractor vs guest.&lt;/P&gt;</description>
    <pubDate>Thu, 17 Jul 2014 03:06:16 GMT</pubDate>
    <dc:creator>Stephen McBride</dc:creator>
    <dc:date>2014-07-17T03:06:16Z</dc:date>
    <item>
      <title>Guest web authentication issue</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-web-authentication-issue/m-p/2512740#M89452</link>
      <description>&lt;P&gt;Hi Support team,&lt;/P&gt;&lt;P&gt;Issue with Guest CWA with ISE.&lt;/P&gt;&lt;P&gt;I can connect to guest SSID and redirection is happening to ISE guest portal page. Username and password (created by sponsor) is accepted in the guest portal. When i open a new browser it is again redirecting to guest portal rather moving to internet. Is it related to COA. Please advise. I am attaching the error what i am getting and the configuration also.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:52:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-web-authentication-issue/m-p/2512740#M89452</guid>
      <dc:creator>deepuvarghese1</dc:creator>
      <dc:date>2019-03-11T04:52:30Z</dc:date>
    </item>
    <item>
      <title>Hi Team, Please find the</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-web-authentication-issue/m-p/2512741#M89461</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please find the attached..&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jul 2014 08:56:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-web-authentication-issue/m-p/2512741#M89461</guid>
      <dc:creator>deepuvarghese1</dc:creator>
      <dc:date>2014-07-16T08:56:07Z</dc:date>
    </item>
    <item>
      <title>Hello-The issue is with your</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-web-authentication-issue/m-p/2512742#M89465</link>
      <description>&lt;P&gt;Hello-&lt;/P&gt;&lt;P&gt;The issue is with your authorization rules. You need to change the conditions for the "Wireless Guest Rule." Remove the current condition about the "guest flow" and add a new condition and instruct ISE to look at the ISE Identity Store group where the guest users are created. Typically, this is the "Guest" internal identity user group. Leave the second "condition" block blank.&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jul 2014 22:01:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-web-authentication-issue/m-p/2512742#M89465</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-07-16T22:01:21Z</dc:date>
    </item>
    <item>
      <title>Nothing wrong with your</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-web-authentication-issue/m-p/2512743#M89469</link>
      <description>&lt;P&gt;Nothing wrong with your authorization rules but Neno's suggestion would make security tighter in the long run. Your WLC configuration that is incorrect for CWA. Don't do layer 3 security- do layer 2 open auth with mac filtering and no layer 3 security.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2014 02:12:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-web-authentication-issue/m-p/2512743#M89469</guid>
      <dc:creator>Stephen McBride</dc:creator>
      <dc:date>2014-07-17T02:12:35Z</dc:date>
    </item>
    <item>
      <title>Ops, I did not see the second</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-web-authentication-issue/m-p/2512744#M89477</link>
      <description>&lt;P&gt;Ops, I did not see the second set of screen shots. Yes, you need to disable L3 security and only use L2 with mac filtering as suggested above. You will also need to enable "radius NAC" under the advanced tab. The link below should walk you through the whole setup:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/115732-central-web-auth-00.html"&gt;http://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/115732-central-web-auth-00.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On a side note, I still think that the current authorization rules are incorrect. If they are left alone, wouldn't the guest users be let on the network as soon as they enter the guest flow, thus never hitting the CWA rule? Or the "guest-flow" does not happen until after redirection has taken place and credentials are entered? I am not at home otherwise I would test it &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2014 02:26:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-web-authentication-issue/m-p/2512744#M89477</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-07-17T02:26:16Z</dc:date>
    </item>
    <item>
      <title>Guest flow is added after the</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-web-authentication-issue/m-p/2512745#M89484</link>
      <description>&lt;P&gt;Guest flow is added after the CWA bit. By not adding the group it means you can't differentiate between different internal groups eg contractor vs guest.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2014 03:06:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-web-authentication-issue/m-p/2512745#M89484</guid>
      <dc:creator>Stephen McBride</dc:creator>
      <dc:date>2014-07-17T03:06:16Z</dc:date>
    </item>
    <item>
      <title>Ah, so it is after the CWA.</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-web-authentication-issue/m-p/2512746#M89494</link>
      <description>&lt;P&gt;Ah, so it is after the CWA. Thanks for confirming. (+5 from me)&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2014 03:09:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-web-authentication-issue/m-p/2512746#M89494</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-07-17T03:09:15Z</dc:date>
    </item>
    <item>
      <title>Hi, Did u ever get this</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-web-authentication-issue/m-p/2512747#M89500</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did u ever get this solved? I rather have the same issue but the users are authenticated but redirected to the login page again. They do not get the "successfull" login screen but are authenticated anyway after the first time adding the credentials. Only after putting the credentials twice the successfull screen is shown.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jul 2014 11:57:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-web-authentication-issue/m-p/2512747#M89500</guid>
      <dc:creator>Ferdy RHN</dc:creator>
      <dc:date>2014-07-30T11:57:36Z</dc:date>
    </item>
    <item>
      <title>Have you modified Wireless</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-web-authentication-issue/m-p/2512748#M89503</link>
      <description>&lt;P&gt;Have you modified Wireless MAB authentication rule to Reject-Continue-Drop?&lt;/P&gt;&lt;P&gt;Select these values from the drop-down list:&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Identity Source: &lt;STRONG&gt;TestSequence&lt;/STRONG&gt; (this is the value created earlier)&lt;/LI&gt;&lt;LI&gt;If authentication failed: &lt;STRONG&gt;Reject&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="color:#40E0D0;"&gt;If user not found: &lt;STRONG&gt;Continue&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;If process failed: &lt;STRONG&gt;Drop&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/support/docs/wireless/5500-series-wireless-controllers/113606-byod-flexconnect-dg-000.html"&gt;http://www.cisco.com/c/en/us/support/docs/wireless/5500-series-wireless-controllers/113606-byod-flexconnect-dg-000.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jul 2014 19:06:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-web-authentication-issue/m-p/2512748#M89503</guid>
      <dc:creator>Peter Koltl</dc:creator>
      <dc:date>2014-07-30T19:06:15Z</dc:date>
    </item>
  </channel>
</rss>

