Cisco ISE who created a ticket in sponsor portal

Hi I was wondering how to see who created a guest user ticket in Cisco ISE using the sponsor portal without checking the system logs that you have to download.
Is there any better way to do it?
kind regards

operations > reports >endpoints and users > guest sponsor summary
The Guest Sponsor Summary report displays all guest users created by each sponsor. Click on a sponsor name to display details about the guest users.

Similar Messages

  • ISE Sponsor Portal Questions!!!

    Hi Team,
    Few questions!!
    Can we integrate ISE with Safenet(Token) for VPN access using Inline Posture?
    2. When we create user account in Sponsor portal in ISE. By Default Where does the user gets created, In internal database of ISE  or in Active Directory?
    3. Advantages of Sponsor portal over NAC guest server?
    Cheers!!
    Minakshi

    Can we integrate ISE with Safenet(Token) for VPN access using Inline Posture?
    Yes you can
    2. When we create user account in Sponsor portal in ISE. By Default Where does the user gets created, In internal database of ISE  or in Active Directory?
    They are updated into Local ISE database
    3. Advantages of Sponsor portal over NAC guest server?
    Sponsor portal allows a person ( can be anyone assigned by Admin ) to manage Guest account.
    Refer http://www.cisco.com/c/en/us/td/docs/security/ise/1-0/sponsor_guide/ise10_sponsor_book/ise10_sponsor.html

  • Cisco ISE functionally and license

    HI. 
    I wanna configure the following on Cisco ISE 1.2.1.
    Self-registration portal for guests (SSID: guests)
    802.1x user certificate check (Cisco NAM supplicant) for employees (SSID: Corporate) (EAP-TLS)
    Self provisioning portal (to deploy BYOD certificate and give access for BYOD devices) for BYOD devices (SSID: Corporate) (PEAP, MSHAPv2)
    Can I configure these things with PLUS license or do I need Adv or Wireless? I am not sure if one of these requires profiling functionally.

    With plus license all the above items should work.
    Here is what plus license supports:
    Bring Your Own Device (BYOD)
    Profiling
    Endpoint Protection Service (EPS)
    TrustSec SGT
    For more info, refer ISE license section:
    http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_user_guide/ise_man_license.html#41012
    Regards,
    Jatin Katyal
    **Do rate helpful posts**

  • Cisco ISE Guest Sponsor Portal Isssue

    Dear all ,
    We have insatalled 5 ise 3315 boxes IOS 1.0.4 in our network where in two of them are admin node , two of policy services and one is mnt node. We are using guest sponsor portal for wirless guest user where in we have integrated WLC 5508 with ise and using weblogin for guest users.
    We have created open ssid in wlc and using external redirected url of ise for guest login page.
    But when we create any guest user in sponsor login for guest user we faced following issue
    1) When guest user gets conected to wirless and login in to guest portal with credential after putting credential  then its again redirect to same login page
    wihout successful login prompt.
    Can we pompt successful login after guest login to guest portal or redirect to any other link like google.com so guest user will gets to know he is able to access internet now
    2) We have creted time profile 8hours first login for guest user. When guest user gets connected while putting credential in to guest portal.
    But we face issue after approximately every 20 mins guest gets disconnected from internet and guest again gets login page of guest portal and if we put same credential then its working but after approx 20 min interval user get disconnected from internet.
    Can anyone help me to resolved above issue regading cisco ise guest sponsor portal
    Thanks & Regards
    Pranav Gade

    Pranav your answers are inline,
    1) When guest user gets conected to wirless and login in to guest  portal with credential after putting credential  then its again redirect  to same login page
    wihout successful login prompt. When you are using CWA (central web authentication) there is no way we can redirect users using the redirect-url because this will always redirect users for every time they initiate a web request. There is no other coa feature that will remove this condition since they have already been authenticated.  Here is a guide that explains the user experience when using central web auth -
    http://www.cisco.com/en/US/docs/security/ise/1.1.1/user_guide/ise_guest_pol.html#wp1296954
    Can  we pompt successful login after guest login to guest portal or redirect  to any other link like google.com so guest user will gets to know he is  able to access internet now No this is not possible, you can change the verbage and force the AUP to be displayed informing users that they can retry their web request after hitting the accept button.
    Here is the documented experience once users go through the guest process -
    http://www.cisco.com/en/US/products/ps11640/products_configuration_example09186a0080ba6514.shtml#final
    2)  We have creted time profile 8hours first login for guest user. When  guest user gets connected while putting credential in to guest portal.
    But  we face issue after approximately every 20 mins guest gets disconnected  from internet and guest again gets login page of guest portal and if we  put same credential then its working but after approx 20 min interval  user get disconnected from internet. Check the advanced timer on your SSID as you may be hitting the session timeout on the WLC. Please disable this option and let the COA feature in ISE expire user sessions on the controller.
    Thanks,
    Tarik Admani
    *Please rate helpful posts*

  • Is it possible to map a Sponsor Group in Cisco ISE to a user group in Active Directory, through a RADIUS server?

    Hi!!
    We are working on a mapping between a Sponsor Group in Cisco ISE and a user group in Active Directory....but the client wants the mapping to be through a RADIUS SERVER, for avoiding ISE querying directly the Active Directory.
    I know it is possible to use a RADIUS SERVER as an external identity source for ISE.....but, is it possible to use this RADIUS SERVER for this sponsor group handling?
    Thanks and regards!!

    Yes It is possible to map Sponser group to user group in AD and if you want to know how to do please open the below link and go to Mapping Active Directory Groups to Sponsor Groups heading.
    http://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_guest_pol.html#wp1096365

  • Using Rufus to create bootable USB Drives for Cisco ISE 3495 upgrade

    I will give a try in the lab but I just wanted to know if somebody else tried this option before.

    Firstable I have to said that I received a brand new 3495 Cisco ISE with version 1.3.0.876 already installed on it BUT my deployment is running 1.2.1.198 patch 3 so I had to downgrade that box.
    Hi Saurav, using Rufus did NOT work. I got an installation error so I found that using DAEMON TOOL Lite (trial version), I created a virtual DVD drive on my Win 7 Laptop which pointed to the ISO for version 1.2.1.198. Then I could make the downgrade with no issues. This is a Cisco Appliance not VM.
    I think the procedure indicated by cisco in the following link is INCOMPLETE:
    http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/installation_guide/ise_ig.pdf
    I will post some additional screenshots required on that link when you are using CIMC and upgrading/downgrading the ISE using External/Virtual DVD.
    Important to say that I found this mechanism using Virtual DVD the easiest one instead of the bootable flash drive.

  • ISE 1.1.1 Sponsor Portal - Unable to create First Names with "-"

    Hi!
    Regarding our international subsidiaries there are many names that contain the character "-" (i.e. Pierre-Pascal)
    When trying to create an new Guest Account the ISE refuses it because of an invalid character in the "First Name" field.
    In other formular fields i.e. Email Address - the character "-" is allowed.
    Is it possible to change the rule which checks the fields for illegal characters? (Is it a Bug?)

    ISE 1.1.3  Go to “Web portal mangment” -> Setting -> Username Policy
    You have a field “
    Username may   include the special characters
    Username Policy
    General
    Create   username from email address
    Create   username from first name and last name
    *   Minimum Username Length
    (Valid   Range 1 to 20)
    Random
    * Username may   include the alphabetic characters
    * Minimum   number to include
    (Valid   Range 0 to 20)
    * Username may   include the numeric characters
    (Should   contain only numeric characters)
    * Minimum   number to include
    (Valid   Range 0 to 20)
    * Username may   include the special characters
    * Minimum   number to include
    (Valid   Range 0 to 10)
    Bottom of Form
    This may help you.

  • Cisco ISE sponsor Portal email notification of guest account

    Is there anyway to not have the email button be displayed in the sponsor portal?  We don't have email or SMS enabled and sponsor users are complaining that the button is there but doesn't work, it woul be really good if you could just remove it.  I have looked at the sponsor language template configuration but it doesn't appear to be able to not display the button just rename it?
    any information would be much appreciated.
    Craig

    Martin,
              thank you very much for the information, I don't think I would ever have checked there for this configuration.  It is taking me awhile to get used to the ISE GUI, I don't find it particularly intuitive but hopefully I will get there.
    thanks
    Craig

  • Approve guest account in Cisco ISE 1.3

    Hello everybody,
          I can't approve guest account in the cisco ISE after I create them. when I want to approve an account I should write a sponsor email, but always I had the same problem: the values entered are incorrect. (Les valeurs saisies sont incorrectes.)
    PS:I don't have problem in mail server
    Best regards,
    ADDOULI Mohamed Ilias

    check if you have entered the sponsor email address here who is supposed to approved the guest

  • ISE 1.2 patch 3 - Sponsor Portal default timezone changed to non-existant ECT

    Hi everybody,
    We've applied patch3 to our ISE 1.2 cluster and after the upgrade all the sponsor accounts (externally autenticated on Active Directory) now have GMT +01:00 Europe/ECT as default Time Zone. Thus all the guest account created have the same time zone and guest authentication fails.
    This is the error from ise-console.log:
    guest:- com.cisco.cpm.guest.exceptions.PortalUserException: java.lang.IllegalArgumentException: The datetime zone id 'ECT' is not recognised
    guest:-        at com.cisco.cpm.guest.edf.GuestUserAdaptor.isAcctValid(GuestUserAdaptor.java:489)
    I checked the admin interface and the 1.2 documentation but could not find any default setting for sponsor users Time Zone
    Time zone for the 3315 is CET:
      clock timezone CET
    A workaround is to have each sponsor user update its Time Zone setting on the Sponsor Portal, but this is impratical.
    Did anybody experience the same issue?
    Regards,

    Hi Luigi Gangitano,
    From when are you experiencing this issue? I suspect this would have been an issue when the server timezones are changed from CEST timezone to CET timezone.
    To further figure out where exactly the issue is , 
    1.Can you please let us know what is the timezone in the UI on the top most right corner in the server information section is ?
    2.Similarly can you please check the timezone in the CLI of Primary ISE node.
    If the above two locations are displaying correct timezone then we have to suspect with the sponsor portal.

  • I want to integrate SMS gateway to Cisco ISE 1.2 and my question is SMS notifications are supported for Guest self−registration

    I want to integrate SMS gateway to Cisco ISE 1.2 and my question is 
    SMS notifications are supported for Guest self−registration Services ? or it should be done by Sponsor 

    I'm not sure I understand the question.  Do you want to log in to the Sponsor Portal using AD credentials?
    Create an Identity Source Sequence using AD as an Authentication Source.  Go to Administration > Identity Management > Identity Source Sequences.  Either Edit or +Add a Sequence and choose from the Authentication Sources shown.
    Then choose that Identity Source Sequence by going to Administration > Web Portal Management > Settings.  Double-click Sponsor from the Left Menu and click Authentication Source.  Choose the Identity Source Sequence.  Click Save.
    I hope this helps.
    Please Rate Helpful posts and mark this question as answered if, in fact, this does answer your question.  Otherwise, feel free to post follow-up questions.
    Charles Moreton

  • ISE 1.2 Sponsor Portal- Account Expiration Date Defaults to same time as Start Date

    We have a time profile setup for ISE Sponspr Portal with Start/End.  I understand this allows the sponsor to specifially set the start and end time for the guest account.  When creating an account, the Start/End time is the same time.  If a Sponsor forgets to set the end time, then the guest account will be created, but will expire not allowing the guest to login.  It would be nice to have the end time default to something other than the start time, like 8 hours default.  Is this possible?  Can the expiration time default to something like 8 hours, but still give the Sponsor the ability to adjust the start/end times if needed?  This is very simple, and I cannot believe this is not available.

    Beginning with Cisco ISE 1.2 time profiles are referred to as the account duration in the Sponsor portal.
    Cisco ISE 1.2 includes these default time profiles, which replace the profiles available previously:
    DefaultFirstLoginEight—the account is available for 8 hours starting when the guest user first successfully connects to the Guest portal. This replaces the DefaultFirstLogin time profile.
    DefaultEightHours—the account is available for 8 hours starting when sponsors first create the account. This replaces the DefaultOneHour time profile.
    DefaultStartEnd—sponsors can specify dates and times on which to start and stop network access.
    Upon expiration of their account per their assigned time profile, they will no longer be able to login or access the company network.
    If a guest were to return to the network, the sponsor can change the account duration via the sponsor portal to grant them access again and then require them to change their password if deemed necessary (depending on the settings). Changing account duration can be used for extending a guest users access longer than the original setup.
    If you upgrade to Cisco ISE 1.2, the older time profiles are still available, but you can delete them if you are not using them. If the older time profiles are assigned to a sponsor group, a message alerts you before deleting. If you perform a new installation of Cisco ISE 1.2, only the new time profiles display.

  • ISE 1.2 sponsor portal - disabling default languages

    Hi,
    We are implementing Cisco ISE 1.2 and have a question on the sponsor portal languages.
    The client company's official language is English and so we would like to disable all other languages from the sponsor portal. If we don't do it, the users might select their native language (on the sponsor settings and/or the guest notification language) meaning that we have to customize and maintain all 15 language templates.
    It has alread happened during the tests: a sponsor created a guest account and choose a notification language other than English - the SMS was not sent because the "Destination" on the "SMS text message notification" default value is "[email protected]".
    Thanks in advance.
    Regards,
    Telmo Oliveira

    Hi all,
    This reply to myself is done for documentation proposes, it can help someone with the same challenge.
    Today I was at an event at Cisco where ISE 1.3 beta was presented. This version will have already the option to choose between browser locale or static language template. Talking to the Cisco eng. responsible for the presentation, he told me that 1.2 had no way to do it.
    Cisco ISE 1.3 is now planned to be release end of 2014.
    Regards,
    Telmo Oliveira

  • Cisco ISE 1.2 - BYOD Guest Access Error with Certificate

    Hi all !
    I'm running on Cisco ISE 1.2. I'm trying to setup BYOD (dual SSID).
    Here's a walkthrough of what's happening:
    1. I connect to open SSID, enter username/password and register MAC 
    2. I download WinSPwizard, get trust root CA but WinSPwizard error
    This is spwprofilelog 
    [Wed Oct 01 11:27:17 2014] Installed [pvgas-DC-CA, hash: d0 ad c2 1e 19 b0 8b 61  8a 2d 81 88 da 8a a2 ca
    da d3 ab e8
    ] as rootCA
    [Wed Oct 01 11:27:17 2014] Warning - [HTTPConnection] InternetOpen() failed with code: [12038]
    [Wed Oct 01 11:27:17 2014] Warning - [HTTPConnection] Abort the HTTP connection due to invalid certificate CN
    [Wed Oct 01 11:27:17 2014] HttpWrapper::SendScepRequest - Retrying: [1] time, after: [4] secs , Error: [2]
    [Wed Oct 01 11:27:21 2014] Warning - [HTTPConnection] InternetOpen() failed with code: [12038]
    [Wed Oct 01 11:27:21 2014] Warning - [HTTPConnection] Abort the HTTP connection due to invalid certificate CN
    [Wed Oct 01 11:27:21 2014] HttpWrapper::SendScepRequest - Retrying: [2] time, after: [4] secs , Error: [2]
    [Wed Oct 01 11:27:25 2014] Warning - [HTTPConnection] InternetOpen() failed with code: [12038]
    [Wed Oct 01 11:27:25 2014] Warning - [HTTPConnection] Abort the HTTP connection due to invalid certificate CN
    [Wed Oct 01 11:27:25 2014] HttpWrapper::SendScepRequest - Retrying: [3] time, after: [4] secs , Error: [2]
    [Wed Oct 01 11:27:29 2014] Warning - [HTTPConnection] InternetOpen() failed with code: [12038]
    [Wed Oct 01 11:27:29 2014] Warning - [HTTPConnection] Abort the HTTP connection due to invalid certificate CN
    [Wed Oct 01 11:27:29 2014] Failed to get certificate from server - Error: [2]
    [Wed Oct 01 11:27:29 2014]  Failed to generate scep request. Error code:
    [Wed Oct 01 11:27:29 2014] ApplyCert - End...
    [Wed Oct 01 11:27:29 2014] Failed to configure the device.
    [Wed Oct 01 11:27:29 2014] ApplyProfile - End...
    [Wed Oct 01 11:27:32 2014] Cleaning up profile xml:  success 
    This is SCEP RA profiles
    Other Cert
    ACL On WLC
    and policy
    Please help me fix error.
    Thanks.

    you could create an ISE local user with a GUEST membership and provided you have your ISE password policy set so that it doesn't expire accounts, etc it would be a "permanent" guest account. we do something similiar. sponsors make temporary accounts while long-term or test guest accounts are created in the ise local identity store as guests and are processed the same way. you just have to ensure that the internal user store is part of your guest identity source sequence.

  • ISE Time Management for Sponsor Portal User

    Hi all,
    I'm currently using ISE version 1.2 and when I create a custom time management for each user, the rule applied to each user is only applied for a maximum 10 days eventhough I configured it for ex.30 days.
    want to check with all of you if anyone have the same issue?
    Firstly I think it's because the purge time is default set for 15 days, but even when I already changed it. The expiration time will still not get over than 10 days.
    Cheers
    Ryan

    Default Guest Time Profiles
    Time profiles provide a way to give different levels of time access to different guest accounts. Sponsors must assign a time profile to a guest when creating an account, but they cannot make changes to the time profiles. However, you can customize them and specify which time profiles can be used by particular sponsor groups. Beginning with Cisco ISE 1.2 time profiles are referred to as the account duration in the Sponsor portal.
    Cisco ISE 1.2 includes these default time profiles, which replace the profiles available previously:
    •DefaultFirstLoginEight—the account is available for 8 hours starting when the guest user first successfully connects to the Guest portal. This replaces the DefaultFirstLogin time profile.
    •DefaultEightHours—the account is available for 8 hours starting when sponsors first create the account. This replaces the DefaultOneHour time profile.
    •DefaultStartEnd—sponsors can specify dates and times on which to start and stop network access.
    If you upgrade to Cisco ISE 1.2, the older time profiles are still available, but you can delete them if you are not using them. If the older time profiles are assigned to a sponsor group, a message alerts you before deleting. If you perform a new installation of Cisco ISE 1.2, only the new time profiles display.

Maybe you are looking for

  • Returns.

    Hi, How to handle Sales returns in SD if customer want Replacement of goods not Credit memo. ie. OR> DEL->INVOICE> RETURN ORDER> RETURN DELIVERY> DELIVERY OF MATERIAL How to map above process? Free goods is the solution for the same? Regards, Amol

  • Advanced mapping from IDOC to SOAP with reversed 3 level context change

    Hi everyone. I am having a though time mapping the HRMD_A01 IDOC into a SOAP message. The reason is that the reciever expects an xml structure where the root node is cost center instead of employee which is the case in the IDOC. Mapping from: IDOC (1

  • Java files question

    Hi I recently downloaded and installed the sql developer version 1.5. I am very happy that i can now see the java classes that have been loaded into the database. I want to know if there is a way i could change the way the files are listed, as in the

  • I need to provide red color to the texbox control in list tile

    Hi, I need to provide red color to the texbox control in list tile, please reply if any one knows how to do it. Thanks, Vijay.

  • Subwoofer not utilized...

    Hi, I have an XFI Titanium card, connected (via the discrete outputs) to my Denon AVR-603, which is connected to my fi've speakers, and the pre-out to my subwoofer. Playing Bioshock earlier, on Game mode, the sub was working fine, but I fired up Fall