06-29-2017 07:25 AM
Hello Experts,
After an extended discussion with one of our customers about guest access with ISE, and exploring a number of guest registration options, it seemed that self-registration with sponsor approval would be the way to go for them.
However, we would like to clarify one thing before going further.
My understanding is, ISE needs access to AD/LDAP on the network (to check sponsor e-mail credentials, this bit is obvious) before sending out the approval e-mail(s)… the question is, does the approver have to be on the corporate network (or VPN) to approve the request?
I believe so, as the link in the e-mail leads to the ISE node… is this correct? And if so, is there any way around this?
The customer would like to be able to approve or deny requests even when they are not on the corporate network/VPN.
Thank you very much in advance!
Kind Regards,
Matt
Solved! Go to Solution.
06-29-2017 08:01 AM
The approve/deny links are encoded with the sponsor's email address and a link to the sponsor portal matched by the Guest Portal. At the time the sponsor clicks the encoded approve/deny link a call is then made to the sponsor portal running on the PSN referenced in the URL.
Normally the sponsor link would be the FQDN of the PSN that was matched by the guest portal. You can override that by setting up the FQDNs for the sponsor portals. If those FQDNs are resolvable externally and the portal is accessible externally you could in theory allow approval from anywhere.
I am not saying I would do this but you could do something like this (theory crafting here):
It should work. I am sure Jason will correct me if this won't hehe
06-29-2017 08:01 AM
The approve/deny links are encoded with the sponsor's email address and a link to the sponsor portal matched by the Guest Portal. At the time the sponsor clicks the encoded approve/deny link a call is then made to the sponsor portal running on the PSN referenced in the URL.
Normally the sponsor link would be the FQDN of the PSN that was matched by the guest portal. You can override that by setting up the FQDNs for the sponsor portals. If those FQDNs are resolvable externally and the portal is accessible externally you could in theory allow approval from anywhere.
I am not saying I would do this but you could do something like this (theory crafting here):
It should work. I am sure Jason will correct me if this won't hehe
06-29-2017 08:08 AM
Nice help thanks Paul! The actual validation of the sponsor is done when the user self-registers. It will do the lookup then and if the sponsor email address doesn't match AD/LDAP then it will fail.
Yes you could expose your PSNs to the public internet if you like just have to buy well known certs for your guest and sponsor portal.
06-29-2017 08:11 AM
Brilliant, thank you both for your replies - helps out a lot.
Cheers,
Matt
07-06-2017 01:28 PM
Hello Guys,
am looking to enable this link ( if i understood correclty ) i cannot find where
My sponsor receive the email asking to approve or deny request but no link to the sponsor portal.
my email template is it french, maybe its missing. hard to try in English for now.
but i suspect that the link is not display or enable.
07-06-2017 01:31 PM
You need to add a link to the sponsor portal in the customization. The Approve/Deny link will be there but if you want to direct them to the sponsor portal add it in the customization.
Paul Haferman
Office- 920.996.3011
Cell- 920.284.9250
07-06-2017 02:18 PM
hey Paul,
i meant a link in the email received by the sponsor
i cannot even find the text of the email
07-06-2017 02:25 PM
Yes that is what I was referring to.
If you go into your Guest portal that is doing single click approval. Click on the Portal Page Customization tab. In the Notifications section you will see “Approval Request Email”. That is what you customize for the sponsor email. In there you can add a link (click the chain button) to your sponsor portal. You will need to use the long URL for the sponsor portal if you haven’t assigned an FQDN to it. If you have defined an FQDN use http://<FQDN<http://%3cFQDN>> do not use https://<FQDN<https://%3cFQDN>> or you will most likely get a cert error depending on how your certs are setup.
Paul Haferman
Office- 920.996.3011
Cell- 920.284.9250
07-06-2017 02:32 PM
wow!
i need a break! Thx!!! really appreciated
i was NOT able to find that... i gues a picture worth a thousand word
all good now
Thx again
07-09-2017 01:31 PM
Also Would rely on a global load balancer or intelligent DNS to resolve to nearest, most available, or simply pingable host. Also possible to return multiple entries and let client figure it out.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide