11-26-2024 12:17 AM
We have configured a guest access policy as follows:
1. The first policy is a guest redirection policy. When a new user connects, they are redirected to a portal where they enter their username and password. During this process, their MAC address is supposed to be added automatically to the "GuestEndpoint" group.
2. After completing the portal authentication, the process moves to the second policy. This policy checks if the MAC address exists in the "GuestEndpoint" group. If it does, a CoA (Change of Authorization) is triggered, granting the user full access to the internet.
However, we are facing an issue where new users successfully authenticate through the portal, but their MAC addresses are not being added to the "GuestEndpoint" group. As a result, they fail to match the second policy, and the CoA is not triggered. This issue is affecting all new guest users. If we manually add their MAC addresses to the "GuestEndpoint" group, the process works as expected.
Has anyone encountered a similar issue? Could you provide guidance or suggestions to resolve this?
11-26-2024 12:38 AM
can I see policy set
MHM
11-26-2024 12:57 AM
First policy only for redirection for example if he hit in first policy portal redirection will happen and for second policy i have created a endpoint identity group as GuestEndpoints thats it straight forward guest policy configuration
11-26-2024 01:45 AM
I send you PM check it
thanks
MHM
11-26-2024 01:54 PM
Are you showing us the Policy Sets main page, or are you showing us the Authorization Rules of one of the Policy Sets (e.g. Wired/Wireless MAB) ? I would not have two separate Policy Sets - you should have one Policy Set, with MAB authentication (and, very important, if User Not Found, CONTINUE.
In the Authorization Policy, the First Rule should be the check in the Endpoint Identity Group, and then do what you need to do to authorize the user.
The next Authorization Rule should be one that redirects the endpoint, based on which ISE PSN is handling the MAB request (if you have two PSNs, then the redirection URLs will be different)
11-26-2024 05:16 PM
Yup we are following the same setup
11-26-2024 12:58 AM
@poornakumar is the group "GuestEndpoint" you are using in the AuthZ policy the same endpoint identity group as is configured under the guest portal.
What version of ISE are you using?
11-26-2024 01:03 AM
yes and also still now the policy working without any issue. we are currently in v3.2 p6
03-14-2025 04:31 AM
I am also facing the same issue, the issue is resolved ?
03-15-2025 01:45 AM
Hi Vishnu,
Yes we had solved the problem by context visibility reset in cli follow both the step 20 and 21. And follow the right process of context visibility reset in both primary and secondary node
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide