02-02-2017 07:41 AM - edited 07-05-2021 06:29 AM
Hi Wireless Expert,
I got shocked only for guests SSID during roaming and registered to
Could you tell me, is it normal behavior or need some configuration adjustment to rectify this
I'll appreciate if someone can explain
Below is my reference how
https://supportforums.cisco.com/document/110031/central-web-authentication-cwa-guests-ise
Regards,
mM CisCo
02-02-2017 12:10 PM
I never use the "use case: Guest flow" myself, but create two wireless MAB authorization rules within ISE:
1. Guest - known:
1.1 Wireless MAB
1.2 Radius called station-id ends with "GuestSSID"
1.3 Endpoint Identity Group: "GuestEndpointIdentitygroup"
Result: Permit access
2. Guest - unknown
2.1 Wireless MAB
2.2 Radius called station-id ends with "GuestSSID"
Result: Redirect towards guest portal for registration
Make sure that the configured purging setting for the guest endpoint Identity Group is based on the duration of the guest account. This should be sufficient to have the same behavior across different controllers. Nevertheless I would advise you to review the WLC setup as well; you should keep access-points in the same building on the same controller.
Please rate useful posts... :-)
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide