cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2425
Views
10
Helpful
14
Replies

ISE + Selfregistering

andreas
Level 1
Level 1

Hi,

i have a wireless network with peap authentication and some VIP users on the network. Now i want to "pimp" that SSID with a self-service and want to make use of the My Devices Portal if this is possible.

1. User gets permission to access the wireless network by entering his AD credentials

2. User opens a webbrowser and gets redirected to a ISE portal

3. User logs in with his AD credentials

4. User adds the prefilled (!!!) MAC address to his device list

5. User accepts the AUP

6. User has access to internet

7. User can access the MyDevices Portal and is able to mark his previeously registered device as lost.

1st question: Is this possible?

2nd question: The portal under 2, is this the default guest portal or is this the MyDevices Portal?

3rd question: Under 4, it is really important that the mac address is prefilled. Is this possible?

Authentication and Authorization seems to work. But I don't know how to configure the authorization profile under Policy / Results and how to configure the portal.

So, question number 4: How to configure this :-)

Kind regards, Andreas

14 Replies 14

Marcin Latosiewicz
Cisco Employee
Cisco Employee

Andreas,

I've done something similar with a open SSID recently (ISE 1.1.1.245)

Before we start with details, some considerations:

- Device registration portal (DRW) WILL prefill mac address but not allow it to be managed from mydevices.

- Self provisioning flow within CWA might actually work for you since you're using a secure SSID. Might, I have not tested this myself but potentially you could push same profile.

- CWA + a separate redirection to supplicant proviosioning did allow it to work for me.

So, IMHO

1) Yes

2) That would be CWA portal not /mydevices (with customization as needed).

3) Check above for options.

Example authorization from my lab (open SSID!)

What I would suggest it to get in touch with your SE, ISE TMEs have most of examples like this covered and tested.

HTH,

M.

Hi Marcin,

thanks for your fast answer.

But how do i manage my devices and mark them as lost in your scenario if not possible via myDevices portal?

I don't want to do any client provisioning.

That's part of what I'm saying, you can do provisioning without actual provisioning. But you do have to use supplicant provisioning to have a device registered under your name and the MAC address pre-populated.

Confusing I know, we're trying to influence the business unit to change this into something more ... intuitive.

How dissapointing. I am far away from a solution now :-/ Supplicant Provisioning is, on my point of view, not very user friendly if you do not use TLS and if you want support a wide range of endpoints, espacially android or blackberry.

Thanks for your help.

Hi all,

I am trying to accomplish the same thing as Andreas. I want the user to register the device with a prefilled MAC, adding the MAC to the RegisteredDevices Group. Apparently this is only possible using "supplicant provisioning"?

Is it possible to skip the actual provisioning, and just allow access after device registration?? When trying to accomplish this, I cannot register the MAC...on the device registration page I get the message that no policy is configured or similar (in german).

Anybody have any idea on how I can do this? I simply want the guest to sign into the web portal (working), register the device with a prefilled MAC, and getting access straight afterwards. I do not want to push any policies/profiles etc. to the client.

Thanks in advance!

Did you allow flows which do not match provisioning rules?

"Native Supplicant Provisioning Policy Unavailable:"

Thanks, just stumbled upon that myself 

After several contacts and lab sessions with our partner i can tell you: It is  NOT possible (Tested with 1.1.4).

What you can do:

Login to the myDevice Portal

Register your Device manually with his MAC address

Connect to the (i.e. internet) SSID with your Device. If registered previously you have access to (i.e.) internet, if not...then not :-)

There is NO automatic AUP and NO prefilled MAC in this solution :-(

Provisioning is nice for your company devices but not if you want to grant internet access for a lot of 3rd party devices.

I am still trying to find a perfect solution, but what I have accomplished by now, is:

1. Sponsor creates guest account

2. Guest user connects to open Guest SSID

3. Guest user gets redirected to WebAuth portal, where he/she enters credentials

4. After login, Guest user gets redirected once again to device registration, where the MAC gets prepopulated, and the Guest can register his device.

5. After device registration, guest user gets internet access.

At the moment I am stuck at step 5, but I am sure its just an authorization policy issue.

Do you have an AUP in your process? When you have fixed step 5 please come back and report :-)

In Step 4, this is not the myDevices Portal where the MAC gets prepopulated, right?

Yes, AUP displayed at Step 3. At the moment I am using the internal AUP, but will be customizing later on. Will keep you posted on my progress. An no, its not the mydevices portal.

It looks to me as if the Device Registration Portal is not meant to be used in combination with Guest access. Once I register my device, the guest session seems to end, and I get prompted to reathuenticate.

Is there a way to automatically add a guest device to a specific endpoint group, when the guest logs in for the first time? This would help me a great deal!