05-06-2013 05:15 AM - edited 03-10-2019 08:23 PM
Hi,
i have a wireless network with peap authentication and some VIP users on the network. Now i want to "pimp" that SSID with a self-service and want to make use of the My Devices Portal if this is possible.
1. User gets permission to access the wireless network by entering his AD credentials
2. User opens a webbrowser and gets redirected to a ISE portal
3. User logs in with his AD credentials
4. User adds the prefilled (!!!) MAC address to his device list
5. User accepts the AUP
6. User has access to internet
7. User can access the MyDevices Portal and is able to mark his previeously registered device as lost.
1st question: Is this possible?
2nd question: The portal under 2, is this the default guest portal or is this the MyDevices Portal?
3rd question: Under 4, it is really important that the mac address is prefilled. Is this possible?
Authentication and Authorization seems to work. But I don't know how to configure the authorization profile under Policy / Results and how to configure the portal.
So, question number 4: How to configure this :-)
Kind regards, Andreas
05-06-2013 05:31 AM
Andreas,
I've done something similar with a open SSID recently (ISE 1.1.1.245)
Before we start with details, some considerations:
- Device registration portal (DRW) WILL prefill mac address but not allow it to be managed from mydevices.
- Self provisioning flow within CWA might actually work for you since you're using a secure SSID. Might, I have not tested this myself but potentially you could push same profile.
- CWA + a separate redirection to supplicant proviosioning did allow it to work for me.
So, IMHO
1) Yes
2) That would be CWA portal not /mydevices (with customization as needed).
3) Check above for options.
Example authorization from my lab (open SSID!)
What I would suggest it to get in touch with your SE, ISE TMEs have most of examples like this covered and tested.
HTH,
M.
05-06-2013 06:17 AM
Hi Marcin,
thanks for your fast answer.
But how do i manage my devices and mark them as lost in your scenario if not possible via myDevices portal?
I don't want to do any client provisioning.
05-06-2013 06:28 AM
That's part of what I'm saying, you can do provisioning without actual provisioning. But you do have to use supplicant provisioning to have a device registered under your name and the MAC address pre-populated.
Confusing I know, we're trying to influence the business unit to change this into something more ... intuitive.
05-06-2013 10:49 PM
How dissapointing. I am far away from a solution now :-/ Supplicant Provisioning is, on my point of view, not very user friendly if you do not use TLS and if you want support a wide range of endpoints, espacially android or blackberry.
Thanks for your help.
05-08-2013 04:44 AM
Following labminutes videos will surely help you out achieving your task-
http://www.youtube.com/watch?v=qfH9mvK29-I
http://www.youtube.com/watch?v=ZeS1Iu9daWo
http://www.youtube.com/watch?v=IO6gSzgtVvo
http://www.youtube.com/watch?v=9TD6UXodRVk
You can also refer BYOD design guide-
http://www.cisco.com/en/US/docs/solutions/Enterprise/Borderless_Networks/Unified_Access/byoddg.html
09-17-2013 01:00 AM
Hi all,
I am trying to accomplish the same thing as Andreas. I want the user to register the device with a prefilled MAC, adding the MAC to the RegisteredDevices Group. Apparently this is only possible using "supplicant provisioning"?
Is it possible to skip the actual provisioning, and just allow access after device registration?? When trying to accomplish this, I cannot register the MAC...on the device registration page I get the message that no policy is configured or similar (in german).
Anybody have any idea on how I can do this? I simply want the guest to sign into the web portal (working), register the device with a prefilled MAC, and getting access straight afterwards. I do not want to push any policies/profiles etc. to the client.
Thanks in advance!
09-17-2013 01:15 AM
Did you allow flows which do not match provisioning rules?
"Native Supplicant Provisioning Policy Unavailable:"
09-17-2013 01:17 AM
Thanks, just stumbled upon that myself
09-17-2013 01:16 AM
After several contacts and lab sessions with our partner i can tell you: It is NOT possible (Tested with 1.1.4).
What you can do:
Login to the myDevice Portal
Register your Device manually with his MAC address
Connect to the (i.e. internet) SSID with your Device. If registered previously you have access to (i.e.) internet, if not...then not :-)
There is NO automatic AUP and NO prefilled MAC in this solution :-(
Provisioning is nice for your company devices but not if you want to grant internet access for a lot of 3rd party devices.
09-17-2013 01:44 AM
I am still trying to find a perfect solution, but what I have accomplished by now, is:
1. Sponsor creates guest account
2. Guest user connects to open Guest SSID
3. Guest user gets redirected to WebAuth portal, where he/she enters credentials
4. After login, Guest user gets redirected once again to device registration, where the MAC gets prepopulated, and the Guest can register his device.
5. After device registration, guest user gets internet access.
At the moment I am stuck at step 5, but I am sure its just an authorization policy issue.
09-17-2013 02:08 AM
Do you have an AUP in your process? When you have fixed step 5 please come back and report :-)
In Step 4, this is not the myDevices Portal where the MAC gets prepopulated, right?
09-17-2013 02:17 AM
Yes, AUP displayed at Step 3. At the moment I am using the internal AUP, but will be customizing later on. Will keep you posted on my progress. An no, its not the mydevices portal.
09-17-2013 05:29 AM
It looks to me as if the Device Registration Portal is not meant to be used in combination with Guest access. Once I register my device, the guest session seems to end, and I get prompted to reathuenticate.
Is there a way to automatically add a guest device to a specific endpoint group, when the guest logs in for the first time? This would help me a great deal!
05-21-2013 03:27 AM
Kindly review the below link:
http://www.cisco.com/en/US/docs/solutions/Enterprise/Borderless_Networks/Unified_Access/byoddg.html
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide