09-29-2020 08:54 AM
Hello
I have a use case where customer want to have several sponsor portals each tied to an SSID and they want to have several group of sponsors and Each sponsor group can only authenticate to her/his sponsor portal.
Ex:
Sponsor Group 1 / AD= group1 --> Sponsor Portal 1
Sponsor group 2 / AD= group2 --> Sponsor portal 2.
I have seen that we can tie a group of sponsor to a specific AD group, but how can i tie this sponsor group to a specific portal.
Many Thanks
Babacar
Solved! Go to Solution.
09-30-2020 03:57 PM
I'm not sure there is a way to do what you are asking unless you use completely different Identity Stores (e.g. AD for one, LDAP/Internal for the other; separate AD Join Points, etc) for the separate Sponsor Portals.
You restrict Sponsor logins using secondary attributes by pointing ISE back to itself as per this ISE Sponsor & My Devices Authorization on Secondary Attributes (LDAP) document, but I cannot see a way to differentiate between the different Sponsor Portals in the AuthZ Policy.
09-29-2020 09:12 AM
09-30-2020 03:06 AM
Hello Mohammed
Many Thanks for your feedback.
Please can you give more details on where you define this policy for the sponsor.
Best REgards,
Babacar
09-30-2020 03:57 PM
I'm not sure there is a way to do what you are asking unless you use completely different Identity Stores (e.g. AD for one, LDAP/Internal for the other; separate AD Join Points, etc) for the separate Sponsor Portals.
You restrict Sponsor logins using secondary attributes by pointing ISE back to itself as per this ISE Sponsor & My Devices Authorization on Secondary Attributes (LDAP) document, but I cannot see a way to differentiate between the different Sponsor Portals in the AuthZ Policy.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide