<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Guest users issue?? in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/guest-users-issue/m-p/1631404#M98166</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am expieriencing a weird behavior in the WLAN for guest users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can create tipical guest users and it redirects me to the sign in web page (there is no web auth server, it's done by the WLC itself) and it works normally. But I am having several domain users getting logged with their domain username and passwords eventhough they are not registered as guestusers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I avoid this situation?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
    <pubDate>Sun, 04 Jul 2021 02:38:02 GMT</pubDate>
    <dc:creator>rguzman.plannet</dc:creator>
    <dc:date>2021-07-04T02:38:02Z</dc:date>
    <item>
      <title>Guest users issue??</title>
      <link>https://community.cisco.com/t5/wireless/guest-users-issue/m-p/1631404#M98166</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am expieriencing a weird behavior in the WLAN for guest users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can create tipical guest users and it redirects me to the sign in web page (there is no web auth server, it's done by the WLC itself) and it works normally. But I am having several domain users getting logged with their domain username and passwords eventhough they are not registered as guestusers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I avoid this situation?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 02:38:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-users-issue/m-p/1631404#M98166</guid>
      <dc:creator>rguzman.plannet</dc:creator>
      <dc:date>2021-07-04T02:38:02Z</dc:date>
    </item>
    <item>
      <title>Re: Guest users issue??</title>
      <link>https://community.cisco.com/t5/wireless/guest-users-issue/m-p/1631405#M98167</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe we could quickly take a look at your configuration. Could you please attach the full text output of the command "show run-config" and confirm which WLAN you are using for web auth?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, we could in particular looking at the order defined for checking the web auth credentials: this can be found under the AAA Servers tab of the web auth WLAN.&lt;/P&gt;&lt;P&gt;If you'd like to check only users in the WLC's local database, only the local method should be present in the list.&lt;/P&gt;&lt;P&gt;Also, under the same tab, the Authentication Servers box should be unchecked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The WLC could have a Radius server configured, which can verify the user's credentials against an external AD/LDAP database.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fede&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jan 2011 17:49:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-users-issue/m-p/1631405#M98167</guid>
      <dc:creator>Federico Ziliotto</dc:creator>
      <dc:date>2011-01-06T17:49:39Z</dc:date>
    </item>
    <item>
      <title>Re: Guest users issue??</title>
      <link>https://community.cisco.com/t5/wireless/guest-users-issue/m-p/1631406#M98168</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Hi,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;The WLAN is "visitas"&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jan 2011 20:44:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-users-issue/m-p/1631406#M98168</guid>
      <dc:creator>rguzman.plannet</dc:creator>
      <dc:date>2011-01-06T20:44:24Z</dc:date>
    </item>
    <item>
      <title>Re: Guest users issue??</title>
      <link>https://community.cisco.com/t5/wireless/guest-users-issue/m-p/1631407#M98169</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We would please need the output of the command "show run-config" (not "show running-config", as this contains different info).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fede&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Jan 2011 07:51:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-users-issue/m-p/1631407#M98169</guid>
      <dc:creator>Federico Ziliotto</dc:creator>
      <dc:date>2011-01-07T07:51:40Z</dc:date>
    </item>
    <item>
      <title>Re: Guest users issue??</title>
      <link>https://community.cisco.com/t5/wireless/guest-users-issue/m-p/1631408#M98170</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry here it goes!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Jan 2011 14:32:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-users-issue/m-p/1631408#M98170</guid>
      <dc:creator>rguzman.plannet</dc:creator>
      <dc:date>2011-01-07T14:32:08Z</dc:date>
    </item>
    <item>
      <title>Re: Guest users issue??</title>
      <link>https://community.cisco.com/t5/wireless/guest-users-issue/m-p/1631409#M98171</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you are seeing may be due in fact to the WLAN's usage of the Radius servers from the global list, even if not directly specified under the WLAN's configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Radius Servers&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Authentication................................ Global Servers&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Accounting.................................... Global Servers&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;A very quick test to confirm this would be to uncheck the option "Network User" for all the Radius servers, under&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SECURITY &amp;gt; RADIUS &amp;gt; Authentication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WLC 4.2 was not yet allowing to select which method to use to authenticate web auth users (local, Radius, or LDAP).&lt;BR /&gt;Starting from later versions such as 6.0 we have further features that allow us to do that (see attached screenshot).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In your case, on the Radius server, you may want to filter Radius access-requests coming from users connecting through the SSID "visitas".&lt;BR /&gt;In ACS 4.2 for example, this can be done through NAPs:&lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/NAPs.html#wp1128143"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/NAPs.html#wp1128143&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the Radius access-request, the WLC is including the following attributes (among others):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Called-Station-Id: this should come in the form of "WLC mac:BSSID:SSID name)&lt;BR /&gt;Airespace-WLAN-Id: this is the index of the WLAN through which the user is connecting&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you could build a NAP in ACS that checks whether the Radius attribute Airespace-WLAN-Id has the same index as the "visitas" SSID (or the Called-Station-Id contains the string "visitas") and, if so, fail the authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fede&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Jan 2011 14:44:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-users-issue/m-p/1631409#M98171</guid>
      <dc:creator>Federico Ziliotto</dc:creator>
      <dc:date>2011-01-07T14:44:41Z</dc:date>
    </item>
  </channel>
</rss>

