cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
813
Views
0
Helpful
7
Replies

ISE3.2- Self-registration users cannot be updated in GuestEndpoints

Magret
Level 1
Level 1

Self-registration users cannot be updated in GuestEndpoints after users pass authentications. And CoA cannot be triggered.

I read this article:https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/216191-troubleshoot-common-cisco-ise-guest-acce.html

It seems that CoA will be triggered automatically after self registration users passing authtentications. 

I did all the config according to this article:https://community.cisco.com/t5/security-knowledge-base/how-to-cisco-ise-captive-portals-with-aruba-wireless/ta-p/4633904

Can anyone explain the logic behind this and find out why this issue happens?

Best Regards

Magret

7 Replies 7

Arne Bier
VIP
VIP

Your screenshots are not very helpful - without the details (i.e. we need more than seeing a red "failed" icon), it's impossible to tell what's gone wrong. Show us the details, and then also prove to us that the CoA was sent by ISE, and acknowledged by the Aruba AP. a tcpdump on ISE is a good place to start.

Magret
Level 1
Level 1

Actually the current issue is that portal user cannot be put into GuestEndpoint, which then cannot trigger coa profile.

Magret_0-1742199378913.png

 

The problem description was clear from your first posting. But if you want assistance with finding the cause, then please supply us with some data to investigate. None of us here are clairvoyant.

  • Screenshots of your ISE Policy Set
    • Authentication ... show the action for "If user not found" also)
    • Authorization 
  • Screenshots of your Guest Type
  • tcpdump of the RADIUS traffic before, during and after a user attempts to log into the portal (we want to see the Access-Request MAB to ISE, and the responses to the NAD (hopefully the URL redirect), and then any other RADIUS traffic thereafter)
  • Live logs details of the MAB session
  • Operations / Reports relating to Guest Portal - there are a few Reports to choose from - I can't remember which one 

 

 

Magret
Level 1
Level 1

Thanks for the reminder.

  • The policy set details are as below:

Magret_4-1743478370387.png

 

  • Authentication:

Magret_5-1743478391274.png

 

  • Authorization Policy:

Magret_6-1743478413659.png

 

  • Guest Type:

Magret_7-1743478443722.png

  • Session log:I also attached detailed info as pdf
 

Magret_11-1743478688000.png

 

 

  • TCP dump: I start tcp dump first and then connect SSID, after device pops out login page, I registered a new accont and login, then I stopped the tcp dump. Strange thing is that I didn't see radius related packet capture in tcp dump. However, I can see radius request in NAS(aruba controller) packet capture.

Magret_8-1743478636453.pngMagret_9-1743478667219.png

 

I attached Guest report as CSV type.

 

 

 

 

In your ISE Guest Type definition, you show that you're using Identity Group 'GuestEndpoints' - which means that if a guest logs into the portal and provides the correct creds, then their MAC address gets added to GuestEnpoints. However, in the 'Session log - Guest auth.pdf' I see another Endpoint Identity Group mentioned - "GuestType_Guest-Daily" - since your Authorization Rule mentions 'GuestEndpoints' as the Group for which you want to grant access, you need to use this Group. Where does "GuestType_Guest-Daily" fit into the picture?

Guest Type_Guest-Daily as below:

Magret_0-1743989562639.png

 

Ok I see now - the confusion was because in the Live Logs details, a successful authentication shows the User Identity Group, which ISE creates for you internally - always has the prefix "GuestType_".  I thought I was looking at the Endpoint Identity Group.  Those are two different things. So your output looks ok.

I can't tell what the issue might be.