cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1144
Views
0
Helpful
3
Replies

Using Guest Account for Device Policy Sets

Arie --
Level 1
Level 1

Hello,

Does anyone ever try below scenario before?

I'm using Cisco ISE 2.3 for Device Administration (TACACS). One thing I want to try is using Guest Account created from Sponsor Portal to be using in Device Policy Sets for Authentication and Authorization.

First, I created 2 Guest Type called: Monitor & Read Only

1a7182f9-99c3-4c25-b70a-3916a5003594.jpg

 

Second, I created an account from Sponsor Portal and assigned in Read_Only Guest Type:1a7182f9-99c3-4c25-b70a-3916a5003594.jpg

Third, I setup the Device Admin Policy Sets. Now, I focused on Authorization Policy since the Authentication Policy is work for me.

1a7182f9-99c3-4c25-b70a-3916a5003594.jpg

After I save the policy above, I tried to test AAA on a Cisco Switch. Unfortunately, it fails on Authorization and got default Deny Shell Profile. Below is the result:1a7182f9-99c3-4c25-b70a-3916a5003594.jpg

 

dbe6a4e6-f621-4768-9dda-a9fea61b856b.jpg

 

398d69cf-49ba-46d8-833c-fb5f054ca1b5.jpg

 

d2490031-2a9a-4f43-b4cd-36ab674a9109.jpg

 

 

I still don't know why the Authorization policy rule doesn't work for IdentityGroup. Does anyone here ever try this scenario before?

 

Thank you in advanced

Arie

 

1 Accepted Solution

Accepted Solutions

Arie --
Level 1
Level 1

Hi,

I would like to tell that there is a bug: 

CSCvh12508

 

It makes authorization rule can't read the guest database and that's why my authorization rule doesn't work with guest type identity group.

 

View solution in original post

3 Replies 3

Hi

Please paste all details from your shell profile "ReadOnly_Profile_Cisco"

/
David

Hi,

This is the detail of "ReadOnly_Profile_Cisco"1.PNG

 

2.PNG

 

 

 

Arie --
Level 1
Level 1

Hi,

I would like to tell that there is a bug: 

CSCvh12508

 

It makes authorization rule can't read the guest database and that's why my authorization rule doesn't work with guest type identity group.