cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
608
Views
0
Helpful
5
Replies

restrict AD group on guest self-reg portal with remember me option enabled

Paolo Bratti
Level 1
Level 1

Hi,
I want to restrict AD group (VIPUserMAB) on guest self-reg portal with remember me option enabled; how can i do this?

is it possible?

 

2018-12-19_093123.png

5 Replies 5

Surendra
Cisco Employee
Cisco Employee
Can you please explain the use case in detail ?

Timothy Abbott
Cisco Employee
Cisco Employee

The problem you are going to run into is that the authentication is for the endpoint and not the user since user credentials are not apart of the MAB process.  The way you currently have policy configured is to allow any MAC address in the VIPUserMAB endpoint identity group will receive the GuestPermit authorization result (if you were to enable it). There is no username component to the authorization rule and because the use case is wireless MAB, you won't receive a username.  Just the MAC address.

 

Regards,

-Tim

@Timothy Abbott is correct. there is no way to mix REMEMBER ME based of MAB endpoint group and Active directory group. 

There is a way to do it but its a little crude.

 

Check out special flows

http://cs.co/ise-guest


@Jason Kunst wrote:

@Timothy Abbott is correct. there is no way to mix REMEMBER ME based of MAB endpoint group and Active directory group. 

There is a way to do it but its a little crude.

 


which one?

Which one suits you. Did you look over the options?