cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
787
Views
1
Helpful
2
Replies

Audit trail for guest users

pangadi
Cisco Employee
Cisco Employee

Hi Team,

I have a customer who is adding his guest users into registered endpoints group as part of their CWA flow. Later on based on if the MACaddress is part of this registered endpoint group they are provided access.

Here are the authz rules :

1.png

When user authenticate via web portal, MAC address is remember and stored in RegisteredDevices identity group and later is used for authentication instead of username/password. But then we do not have full visibility which IP/MAC address is correlated to which user, and in WLC username is stored as MAC address:

image002 (1).jpg


On Cisco ISE if I go to Home > Guests > Guests type I will get this information, but it is not stored permanently:

image003.png

1.      When user logs in to guest wireless and authenticates using web portal, MAC address of his devices is registered. Where exactly correlation between Portal User and MAC address is stored?

image004.jpg

2.      After what time of user being idle (do not authenticate again using Portal User credentials) information about user (Portal User to device MAC address among other info) will be flushed?

3.      How to have full guest user visibility and audit trail in this scenario?


I looked at the Master Guest report but this doesn't give us full visibility of Portal user to MAC address/IP address binding.

Thanks

Priyanka

1 Accepted Solution

Accepted Solutions

Jason Kunst
Cisco Employee
Cisco Employee

Did you see my response on the internal

Post?

I shared a slide deck with 2 defects around guest MAC address remember me

This is for partners or cisco employees

https://communities.cisco.com/docs/DOC-63010

Look under attachments on the bottom for the guest PowerPoint

THis isna is a screenshot as I am on my phome

IMG_0786.PNG

View solution in original post

2 Replies 2

Jason Kunst
Cisco Employee
Cisco Employee

Did you see my response on the internal

Post?

I shared a slide deck with 2 defects around guest MAC address remember me

This is for partners or cisco employees

https://communities.cisco.com/docs/DOC-63010

Look under attachments on the bottom for the guest PowerPoint

THis isna is a screenshot as I am on my phome

IMG_0786.PNG

Hi Jason,

Thanks for sharing the BUGS. The customer was also curious about the portal user to MAC address mapping that we do see under context visibility >> Guest. Is there a specific time the portal user to MAC address shows up under context visibility ?

Thanks

Priyanka