cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1336
Views
5
Helpful
3
Replies

ISE Authorization Profile to grant limited access to Wireless Guests

Mike Masalla
Level 1
Level 1

Hi,

I am after building sponsored guest access for wireless guests in ISE running on software release 1.3.

I wonder if there is a way to keep the guest on the initial vlan after successful authentication and grant him Internet-Only access. I mean to say, I do not want to assign him to different vlan and restrict his access by an ACL applied on Layer-3 Vlan Interface. 

I could have done it by dACL, if the guest is connecting through the wired network, but because Wireless Controller do not accepts dACLs, I am not aware of any way to do it without changing vlan   

 

Appreciate your idea.

 

Mike

 

 

1 Accepted Solution

Accepted Solutions

jan.nielsen
Level 7
Level 7

Sure, just create the ACL you wan't to use for your guests directly on your WLC, and then reference the name of that ACL in your authorization profile in the option called "Airespace ACL Name".

 

 

View solution in original post

3 Replies 3

jan.nielsen
Level 7
Level 7

Sure, just create the ACL you wan't to use for your guests directly on your WLC, and then reference the name of that ACL in your authorization profile in the option called "Airespace ACL Name".

 

 

Thanks Jan. Appreciate your pictorial answer.

Venkatesh Attuluri
Cisco Employee
Cisco Employee