12-13-2024 05:40 AM - edited 12-13-2024 05:41 AM
We are using ISE 3.2 patch 7. We are encountering guest access issue for random users on our ISE sponsor portal based guest SSID. User device mac address is not getting added into GuestEndpoints while guest logging in with the guest credentials. After the COA from ISE, guest users are not matching the guest allow policy. it is skipping this policy as endpoint mac address is not in the GuestEndpoints and hitting the redirection policy again.
This issue occurs only for random users and not all the users.
When we remove the endpoint mac address from Context Visibility and test, its start working
We have 2 authorization policies,
1. If Endpoint Identity Group:GuestEndpoints ==> Allow
2. If MAB and from guest SSID ==> Redirect to Sponsor Portal URL
Let us know if anyone faced such issues and possible solution to fix this issue.
12-13-2024 06:11 AM
authz 1 (after sponsor) must include
1-wirless MAB
2- GuestEndpoints
authz 2 (before sponsor)
1- wireless MAB
2- optional you can match SSID
MHM
12-17-2024 05:46 AM
Hi @MHM Cisco World,
Thanks for your response.
We are currently having the authz policy likewise only. The thing is some users are getting added into GuestEndpoit group as expected, some of them are not. If we remove the endpoint Mac address from Context Visibility and try, user Mac address is getting added into GuestEndpoit group now.
Devendran Raju
12-17-2024 06:09 AM
are there any MAB (not guest) policy above this policy?
MHM
12-17-2024 06:12 AM
I would try to create a new endpoints group, associate it to the guest portal and see if that helps. If the issue should persist with the new endpoints group I would try to reset the MnT database. If this doesn't help neither I would raise it with TAC. To reset the MnT database you can issue the command "application configure ise" and select the fourth option if I remember correctly, it should be called reset MnT database or similar.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide