cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1776
Views
0
Helpful
15
Replies

ISE 1.4 Sponsor Portal Guests Accounts

James Davies
Level 1
Level 1

I have managed to create a working standalone ISE 1.4 for a customer. About 80% complete, but having a headache with the Sponsor Portal,

Where do I create the Guest Accounts locally? I only need 2, I can see the Manage Accounts under Guest Access, but I get a page not displayed as Im managing this remotely, Where is the URL for reception to access to create accounts?

Under Sponsor Groups there are 3 default groups (No idea how you can have 3 as default mind!)

I just want a URL, where someone can create guest accounts, really daft that you cant create them on the ISE itself...

2 Accepted Solutions

Accepted Solutions

Event 5418 Guest Authentication Failed
Failure Reason 22056 Subject not found in the applicable identity store(s)
Resolution Check whether the subject is present in any one of the chosen identity stores. Note that some identity stores may have been skipped due to identity resoultion settings or if they do not support the current authentication protocol.
Root cause Subject not found in the applicable identity store(s).

How can the subject not be found, if its been created by the ISE! is the store internal users? or guest users?

View solution in original post

Are you actually hitting the right authentication rule for Guest sequence.

Check the report and look for authentication rule hitting.

View solution in original post

15 Replies 15

Gagandeep Singh
Cisco Employee
Cisco Employee

You can use default sponsor portal where when you click on Portal test URL.

Get sponsor portal and can login with sponsor created on ISE for sponsor groups (All accounts, own accounts and Group Accounts). Also use AD users for sponsors.

Create Guest accounts accordingly.

URL that come up with Portal test URL can be used for sponsor portal access.

Regards

Gagan 

ps : rate if it helps!!!!

I tried just that, and it came up with the portal page, My tester couldnt create an account, this was because I hadnt added any sponsor groups from AD,

Now, he can log in and create a guest account, I am at the last hurdle! the guest he created could not log in though?

Thanks for replying, if I can get this last bit working, I will be a happy chap!

Logs say "Guest Status - AWAITING_INITIAL_LOGIN"

do these created guests need to be put somewhere?

You cannot check Guest accounts in ISE. The only way to check is to have sponsor login and check on sponsor portal.

Regards

Gagan

ps: rate if it helps!!!!

he tried to login as the newly created account, and it said authentication failed?

You mean, created guest account from sponsor portal doesn't work.

Did you get any error on ISE in reports.

correct, My sponsor, logged into the portal and created an account, no problem.

we then tested the account from another machine, but it gets authenticating failed... we have double checked the credentials..

no error on the ISE, cant even see anything attempting.. which is odd.

Check under Operations > Report > Guest.

You will find My devices Login and audit.

Check if you are able to see some record for it.

No record of the newly created username trying... most bizarre!

All seems to be fine now, one rule had a "reject reject" so I moved my guest rule above it, all seems to be great, thank you for your time and patience. I hope the new unit I am doingi tomorrow will be easier! its going to be a secondary node after all

Glad to hear that:).

Regards

Gagan

Event 5418 Guest Authentication Failed
Failure Reason 22056 Subject not found in the applicable identity store(s)
Resolution Check whether the subject is present in any one of the chosen identity stores. Note that some identity stores may have been skipped due to identity resoultion settings or if they do not support the current authentication protocol.
Root cause Subject not found in the applicable identity store(s).

How can the subject not be found, if its been created by the ISE! is the store internal users? or guest users?

Check the identity store sequence under

Administration > identity management > Identity store sequence.

Also in Authentication rule, which store is selected.

Regards

Gagan

I have used the default sequence:

Guest_Portal_Sequence - Internal Users, AD1, Guest Users. All_AD_Join_Points

Auth Rule, there are a few as I had to copy what I could from the old ISE 1.1.1

Please see screen shot:

Thanks so much for the assist...

Are you actually hitting the right authentication rule for Guest sequence.

Check the report and look for authentication rule hitting.