cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4408
Views
8
Helpful
10
Replies

ISE 2.1 Wired Guest Flow VLAN IP Release/Renew Issue

nadeekha
Level 1
Level 1

Hi Guys,

On a previous post I had a question about Wired Guest Flow scenario that required a VLAN switch and an IP renew on the new VLAN.

Jason Kunst had recommended many solutions to resolve the issue my customer was experiencing.

Now My customer wants to look at applying the below solution for the VLAN switch / DHCP IP renew scenario.

Jason:·"Have the user login with CWA and then Register the endpoints by redirecting to a hotspot portal that will disconnect them after registration and cause a new connection on the new VLAN coming through"

Unfortunately I am not sure exactly how to configure the above flow recommended by Jason. Please see attached screenshot of what I currently have. How do I introduce the Hotspot Portal to this Policy along with CWA?Screen Shot 2017-02-26 at 9.38.40 AM.png

Thanks in advance

Nadeem Khan

1 Accepted Solution

Accepted Solutions

Jason Kunst
Cisco Employee
Cisco Employee

Not exactly sure of the needed flow and types of users

Recommended disabling auto registration on the credentialed portal you are using

yes inject a rule between the initial redirect and then the final permission off endpoint group with the following

Create a guest type called VLANCHANGE and use for self-reg

Create an endpoint  group VLANCHANGE

if Guest_flow and guest_type VLANCHANGE equals X then redirect to hotspot portal that registers into endpoint group VLAN CHANGE, make sure Hotspot Portal is set to terminate not re-auth (ISE 2.1 patch 1 and higher)

The flow would be like this

1. User redirected to credentialed portal

2. after login, COA takes place and redirected to hotspot portal for device registration

3. After registration COA disconnect is sent

4. device comes back in using endpoint group authorization in new VLAN

View solution in original post

10 Replies 10