cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
529
Views
0
Helpful
2
Replies

Mix hotspot with employee BYOD

blandrum
Cisco Employee
Cisco Employee

Scenario I'm trying to resolve -

User plugs in to an open network jack, ISE directs them to a portal page where they have two options - Click through for "guest" access (no registration or login required), or see a link for Employee access which would direct them to a login page where they would enter their AD credentials. 

Inbuilt pages in ISE 2.3 seem to either reflect one or the other, but not a mixture.

1 Accepted Solution

Accepted Solutions

Jason Kunst
Cisco Employee
Cisco Employee

Please look at the options on the community

http://cs.co/ise-community

guest web auth page

there is an option under special flows

View solution in original post

2 Replies 2

Jason Kunst
Cisco Employee
Cisco Employee

Please look at the options on the community

http://cs.co/ise-community

guest web auth page

there is an option under special flows

paul
Level 10
Level 10

Brad, just as an FYI I usually discourage customers from offering any type of guest access on wired.  I am assuming the customer has guest wireless so there should be no legitimate business reason to have wired guest access.  My default rule in ISE directs the user to a guest hotspot portal with no AUP that says "You have been denied access to the network.  Please contact help desk at (xxx) xxx-xxxx for further assistance.". 

You make sure your redirect ACL and DACL allows all traffic to and from the ISE PSNs so profiling still works.