cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
 
Register for the monthly ISE Webinars to learn about ISE configuration and deployment.
Choose one of the topics below to view our ISE Resources to help you on your journey with ISE

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

341
Views
1
Helpful
1
Replies
Highlighted
Enthusiast

device registration portal for internal endpoints that captures name phone etc

I am looking to capture BYOD end-user login information with ISE.

This project wants to track BYOD devices by user names that are not in Active Directory or local users on the ISE server.

They are looking to have a splash screen that will require the guest to enter valid:  Name, Email, Phone and have it mapped to the device and user information visible in live log.

I have questions on how they would validate information provided and I have not seen a AUP that will provide that service.

Can you assist with locating information or a resource I can talk this through with.

Thank you,

Everyone's tags (6)
1 ACCEPTED SOLUTION

Accepted Solutions
Cisco Employee

Re: BYOD - AUP login tracking

The only way to capture information with ise is through self registration guest flow

You can have a special SSID for them to connect and register their device as part of this flow, you would have to keep a guest account long enough for the employee and to purge these guests devices after X amount of time , you would authorize the device after registration in this guest endpoint flow

the problem here is you problem don't want it to work this way

Our my devices flow for byod (supplicant and certificate provisioning) doesn't capture this either

You would need to do the following

Create your own portal that captures needed info

This portal would capture the info and add it to ISE via API, the device Mac would be added to a group that is authorized access

This portal could be used before connecting the device to the network

If you want as part of the flow

Device connects and not part of endpoint group

Redirect to portal and register

Portal will register device and call a COA to change device access

Device would reconnect with proper access

View solution in original post

1 REPLY 1
Cisco Employee

Re: BYOD - AUP login tracking

The only way to capture information with ise is through self registration guest flow

You can have a special SSID for them to connect and register their device as part of this flow, you would have to keep a guest account long enough for the employee and to purge these guests devices after X amount of time , you would authorize the device after registration in this guest endpoint flow

the problem here is you problem don't want it to work this way

Our my devices flow for byod (supplicant and certificate provisioning) doesn't capture this either

You would need to do the following

Create your own portal that captures needed info

This portal would capture the info and add it to ISE via API, the device Mac would be added to a group that is authorized access

This portal could be used before connecting the device to the network

If you want as part of the flow

Device connects and not part of endpoint group

Redirect to portal and register

Portal will register device and call a COA to change device access

Device would reconnect with proper access

View solution in original post