03-12-2025 01:20 AM
Self-registration users cannot be updated in GuestEndpoints after users pass authentications. And CoA cannot be triggered.
I read this article:https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/216191-troubleshoot-common-cisco-ise-guest-acce.html
It seems that CoA will be triggered automatically after self registration users passing authtentications.
I did all the config according to this article:https://community.cisco.com/t5/security-knowledge-base/how-to-cisco-ise-captive-portals-with-aruba-wireless/ta-p/4633904
Can anyone explain the logic behind this and find out why this issue happens?
Best Regards
Magret
03-12-2025 04:02 PM
Your screenshots are not very helpful - without the details (i.e. we need more than seeing a red "failed" icon), it's impossible to tell what's gone wrong. Show us the details, and then also prove to us that the CoA was sent by ISE, and acknowledged by the Aruba AP. a tcpdump on ISE is a good place to start.
03-17-2025 01:16 AM
Actually the current issue is that portal user cannot be put into GuestEndpoint, which then cannot trigger coa profile.
03-17-2025 01:58 PM
The problem description was clear from your first posting. But if you want assistance with finding the cause, then please supply us with some data to investigate. None of us here are clairvoyant.
03-31-2025 08:42 PM
Thanks for the reminder.
I attached Guest report as CSV type.
04-06-2025 02:02 PM
In your ISE Guest Type definition, you show that you're using Identity Group 'GuestEndpoints' - which means that if a guest logs into the portal and provides the correct creds, then their MAC address gets added to GuestEnpoints. However, in the 'Session log - Guest auth.pdf' I see another Endpoint Identity Group mentioned - "GuestType_Guest-Daily" - since your Authorization Rule mentions 'GuestEndpoints' as the Group for which you want to grant access, you need to use this Group. Where does "GuestType_Guest-Daily" fit into the picture?
04-06-2025 06:33 PM
Guest Type_Guest-Daily as below:
04-06-2025 08:03 PM
Ok I see now - the confusion was because in the Live Logs details, a successful authentication shows the User Identity Group, which ISE creates for you internally - always has the prefix "GuestType_". I thought I was looking at the Endpoint Identity Group. Those are two different things. So your output looks ok.
I can't tell what the issue might be.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide