cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1617
Views
0
Helpful
6
Replies

Guest WiFi using Dot1x

evanspall
Level 1
Level 1

Hi all,

 

I have been using the Guest functionality in ISE 1.1.4 (and previous versions) for a long time now and I've always been frustrated with it. I am now in the process of setting up an alternate Guest network that uses dot1x to reference the Internal Users ID source (where all registered guests are stored) in ISE to authenticate clients.

 

It seems to work perfectly for any activated guests, but any newly created account gets the following...

RADIUS Status:
Authentication failed : 24206 User disabled

 

Is there any way to circumnavigate the activation through the use of the CWP and thus make it possible for newly registered guests authenticate using dot1x?

Will changing the Guest Portal Policy Configuration (Not Used/First Logon/Every Logon) or Authentication Type (Guest/CWA/Both) solve this? Weary of changing it on the fly in production environment.

 

Thanks

1 Accepted Solution

Accepted Solutions

Saurav Lodh
Level 7
Level 7

http://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-software/115802-radius-authentication-00.html

View solution in original post

6 Replies 6

mohanak
Cisco Employee
Cisco Employee
Message CodeMessage ClassMessage TextMessage DescriptionSeverity
24206Local-user-DBUser disabledUser marked disabled in Internal database.Info

 

 

Saurav Lodh
Level 7
Level 7

http://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-software/115802-radius-authentication-00.html

Ah perfect.

Thanks a lot.

jan.nielsen
Level 7
Level 7

Set the guests to be created in the activatedguests group instead of the regular "guests" group and they should be usable right after they are created

how exactly do you configure that?

Nevermind.

Answered in the article salodh linked