Lobby Ambassador - Selecting Profile

We have a WCS version 5.2.130 and WLC version 4.2.130.0
Not very familiar with it. The issue here is although the WLC is reachable from WCS, I can't seems to select a profile when we want to create guest users from lobby ambassador. The WLC has been configured with 2 wlans - wlanguest and wlan01 but I can't select this profile to assign the user to.
Hope someone can shed some light.

For guest users and lobby admins, the WLAN profiles that can be selected from the WLC are only those that are using WEB-AUTH as security policy.
Make sure the WLAN profile for guest user is using web-auth on your WLC, that will address your issue.

Similar Messages

  • PI 1.3 Lobby Ambassador Defaults where Building stays None?

    When creating local Lobby Ambassador user, the Lobby Ambassador Defaults profile needs to be set.  At the Lobby Ambassador Default page, the Building dropdown stays at "None" with no other selections, although the building has been created in the corresponding Campus.
    PI1.3 won't create the Lobby Ambassador user when Building selection is NONE.
    Any one runs into this problem?

    When creating local Lobby Ambassador user, the Lobby Ambassador Defaults profile needs to be set.  At the Lobby Ambassador Default page, the Building dropdown stays at "None" with no other selections, although the building has been created in the corresponding Campus.
    PI1.3 won't create the Lobby Ambassador user when Building selection is NONE.
    Any one runs into this problem?

  • Lobby Ambassador Profiles in ACS 5.3

    We've set our WCS up to do AAA through our ACS 5.3 which works great. So in order to log into the WCS for Administration or as a Lobby Ambassador (to create guest users etc) the AAA is all done by the ACS, GREAT!
    I have assigned a set of users the Lobby Ambassador role as passed that back through TACACS to the WCS, so those users have their role setup as Lobby Ambassador and are limited from doing anything else, as expected.
    What I want to know is: With normal local AAA on the WCS, when you created a Lobby Ambassador account, you could give the account a set of defaults for any guests accounts created by that Lobby Ambassador account, which was good, so Lobby Ambassadors couldn't set up unlimited time accounts and stuff like that.
    What I want to know now is that since I'm now doing all the AAA on the ACS, is there an attribute I can pass to the WCS in the Shell Profile, along with the roles etc telling the WCS what the guest user creation defaults for the Lobby Ambassador account is, so that we can continue to limit the defaults of any guest account that the Lobby Ambassador accounts create, as it used to be? We'd really like different lobby ambassadors to be able to do different things as well. i.e., Lobby Ambassador X can only create accounts for one region. Lobby Ambassador Y can create Unlimited time accounts where the others can not. We used to do this by assigning different guest user creation defaults to different lobby ambassador accounts on the WCS.
    Help appreciated        

    Hi,
    at the moment the only solution for your requirement is to create local NCS/WCS accounts with exactly the same username as existing in your ACS, no matter what password. Authentication will happen via TACACS+ while the defaults will be taken from the local user account. Please be aware that this mechanism is case sensitive.
    Regards
    Stefan

  • Profile for Lobby Ambassador Account

    How do you configure the Lobby Ambass. Profiles. This is so I can set the defaults for users that the Lobby Ambass configures.

    This is under the WLC not WCS. For WCS, look at this doc:
    http://www.cisco.com/en/US/docs/wireless/wcs/5.1/configuration/guide/wcsmanag.html#wp1077061

  • Restricted Lobby Ambassador

    Hi,
    Does anyone know if there is a way to limit a lobby admin user (on WLC or PI) to a specific AP group or WLAN?
    I would like to have o lobby admin who can add guest users just for specific WLANs configured on the WLC.
    I know that the lobby admin can map just one WLAN (vs. Any WLAN) to a guest user when creating his account, but I want to restrict the WLANs that the lobby admin can choose from.
    Thank you,
    Sebastian

    I found that it is possible from PI.
    You can select one SSID under lobby ambassador defaults TAB from Profiles drop down.
    Thank you,
    Sebastian

  • NCS - lobby ambassador controller list

    Under NCS --> Administration --> Users we have created a specific user to enable guest user access. However, when tinkering with the defaults you can select a controller list. The problem is we only see 5 of our controllers (we have 8).
    Is this a limitation on lobby ambassador? Or is there a way to add additional controllers here?

    When you create the lobby ambassador you specify the defaults.
    You specify the WLAN profile ,user role ...etc.
    If you choose a WLAN profile, then only WLCs that have that WLAN profile will appear.
    Same manner, if you specify user role, only WLCs that has that QoS role configured will appear on the list.
    If you configured both, intersection of both (WLCs that have both the profile and the role) will appear.
    If you choose the default user role and use any profile then you should see all the WLCs on the list.
    HTH
    Amjad

  • Lobby Ambassador - WCS Logging of Guest Account Creation

    Hello all,
    If I am user "admin-ken" and I setup an guest user account "guestuser1" via the WCS controller templates > Guest User (which takes me into lobby ambassador), is there a log file that indicates that "admin-ken" had setup "guestuser1" guest account?
    Many thx indeed,
    Kind regards,
    Ken

    HiKen,
    Hope all is well :)
    Maybe this is what you are looking for;
    Logging the Lobby Ambassador Activities
    The following activities are logged for each lobby ambassador account:
    •Lobby ambassador login: WCS logs the authentication operation results for all users.
    •Guest user creation: When a lobby ambassador creates a guest user account, WCS logs the guest user name.
    •Guest user deletion: When a lobby ambassador deletes the guest user account, WCS logs the deleted guest user name.
    •Account updates: WCS logs the details of any updates made to the guest user account. For example, increasing the life time.
    Follow these steps to view the lobby ambassador activities.
    Note You must have superuser status to open this window.
    Step 1 Log into the Navigator or WCS user interface as an administrator.
    Step 2 Click Administration > AAA, then click Groups in the left sidebar menu to display the All Groups window.
    Step 3 On the All Groups windows, click the Audit Trail icon for the lobby ambassador account you want to view. The Audit Trail window for the lobby ambassador displays.
    This window enables you to view a list of lobby ambassador activities over time.
    •User: User login name
    •Operation: Type of operation audited
    •Time: Time operation was audited
    •Status: Success or failure
    Step 4 To clear the audit trail, choose Clear Audit Trail from the Select a command drop-down menu and click GO.
    http://www.cisco.com/en/US/docs/wireless/wcs/4.2/configuration/guide/wcsmanag.html#wp1076868
    http://www.cisco.com/en/US/docs/wireless/technology/guest_access/technical/reference/4.1/GAccess_41.html#wp1001609
    Hope this helps!
    Rob

  • WCS setup RADIUS users Lobby Ambassador Defaults

    Hi
    I'm using RADIUS so my users can use their active directory credentials to login WCS and generate guest users accounts...
    But I would like to setup some Lobby Ambassador Defaults, I can easily do ths for local users on the WCS system, but how to setup defaults for RADIUS users?
    Best Regards,
    Steffen.

    Hi Scott
    Tanks for your reply.
    I've allready read the article, but I can't see that it says anything about setting up Defaults for the users, only which task the should be able to do...
    I would like to setup defaults for the radius users, so when they are authenticated as lobby abassadors the do not need to select which SSID the a generating a guest user account for and so on...
    This is possible for local WCS users, but i need to setup these defaults for my RADIUS authenticated users.
    Best Reards
    Steffen
    And btw.. this dicussion was started by me.. https://supportforums.cisco.com/thread/2115616

  • Lobby Ambassador TACACS denied to create Guest Users

    Hi,
    I read some threads but I found no answer.
    I use WCS 7.0.172.0 an ACS 5.2
    I configured in ACS a Shell Profile for Lobby Ambassador Accs like I did for Admins.
    If I login as such lobby ambassador, I see just what i have to see. But if i'm going to create a guest user I got the message:
    Permission Denied
    You do not have privileges for the requested  operation.
    After Forum reading I created a local user with exact the same name, differnt pw, with no success.
    The shell profile:
    role0 | mandtory | LobbyAmbassador
    task0 | mandtory | Configure Guest Users
    task1 | mandtory | Lobby Ambassador User Preferences
    Thx 4 reading!
    btw: I just can authenticate with tacas+/pap, if I configure chap I've got a failure. chap is allowed in ACS...

    OK I fixed it.
    I had to add:
    virtual-domain0 | mandatory | root
    to the top of the shell profile, like described in:
    http://www.cisco.com/en/US/docs/wireless/wcs/7.0/configuration/guide/7_0admin.html
    now it works...
    The WCS "Task List" output of the group hasn't list it...
    But the CHAP probleme still wasn't fixed. Anyone who use TACACS/CHAP auth?

  • WCS Lobby Ambassador Accounts

    Unable to manage Guest accounts created by different WCS Lobby Ambassador user Accounts.
    I have setup three Lobby Ambassador accounts in WCS. Three staff members have been given seperate usernames and passwords to WCS with Lobby Ambassador profiles to allow them to create and manage the Guest Wireless Accounts.
    It was expected that they would be able to view and manange all Guest accounts, but they can only manage accounts they created. If I login as WCS admin I can then see all accounts created by each user.
    We require that all three can view and manage each others accounts using their own WCS login. Is this possible as docs do not mention??

    Hi Stuart,
    Just to add a note to the great tips from Leo;
    CSCsw42942 Bug Details
    SuperUser cannot see guest users created by admin users
    Symptom:
    If a WCS admin user creates a guest user through controller template, a Superuser will not be able to see the guest user created.
    Conditions:
    wcs 5.2.110
    Workaround:
    the root user can see everything
    Further Problem Description: Status
    Fixed
    Severity
    3 - moderate
    Last Modified
    In Last 3 Days
    Product
    Cisco Wireless Control System
    Technology
    1st Found-In
    5.2(110.0)
    Fixed-In
    5.2(122.0)
    6.0(23.0)
    Have a look at this good recent thread;
    http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&forum=Wireless%20-%20Mobility&topic=Security%20and%20Network%20Management&topicID=.ee6e8c0&fromOutline=&CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cc2cc01
    And this good thread;
    http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&forum=Wireless%20-%20Mobility&topic=Security%20and%20Network%20Management&topicID=.ee6e8c0&fromOutline=&CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cc3077f
    Hope this helps!
    Rob

  • Customize Lobby Ambassador View

    Hi all,
    I have a problem with the following situation:
    - Cisco Prime Infrastructure 2.0 (2.0.0.0.294)
    - Cisco ACS 5.4 (5.4.0.46.0a)
    - 2x Cisco WLAN Controller 5508 in SSO mode
    - x APs 2600 Series
    All devices are configured properly, I can see the WLC on Prime, etc.
    Prime and WLC are added to ACS for TACACS+ Authentication.
    Admin users are able to login to Prime with full feature set (root permission).
    Lobby Ambassadors can also login to Prime for Guest User creation.
    Therefore I have created two Shell Profiles on ACS.
    Now I want to create WLAN Guest User with Lobby Ambassador Account (TACACS-authenticated!).
    I want to customize the Default Guest User Creation page with a company logo and some default settings (WLAN Profile, Apply to Controller List, set "generate password" to fixed, etc.) to fixed values.
    Only thing what Lobby Ambassador can change should be setting the password period (with hours or using calender), guest user name and description.
    If I configure a local user on Prime, I can customize the page.
    However if I use TACACS user, I am not able to use the customized page.
    Can anybody help me with this issue?
    THANKS a lot!!!!
    edit: problem solved by workaround...
    https://supportforums.cisco.com/thread/2201703
    BR, Stefan

    You will not be able to unless you build a back-end that does it and sends the commands to the WLC. Other than that, you can't customize the lobby ambassador page.
    Sent from Cisco Technical Support iPhone App

  • Lobby Ambassador Managment of Users that have expired.

    Hi there all :)
    When you set users up on LA and you set a user to a "controller list", the entry on the listing always shows the account as active from the front menu even if the time has expired.
    You then go into the account and you can see the date has expired, and if you test the account, yes, you cant login.
    Is this a bug?
    I am running WCS version 4.2.62.11.
    Also, I would like a function on LA to allow me to delete all expired users in one go. Is this possible?
    As the above indicates that the users is not expired but active, at the moment, you have to go into every account, check the expiry date and then delete the account one by one.
    Painful?
    Many thx indeed,
    Ken

    Hey Ken,
    Is it time for a beer yet??
    In answer to your first question, I think you are seeing this bug;
    CSCsk17497 Bug Details
    D3WCS:lobby ambassador-guest user account expiry not shown clearly
    Symptom:
    After successful scheduling the Guest account, the detail page for the created account doesn't show the expiry time details.
    Conditions:
    This condition arrives only when the browsed account is the scheduled account.
    Workaround:
    The detail page has the 'start' and 'end' time selection, which can be used for the expiry detail.
    Further Problem Description:
    Status
    Fixed
    Severity
    3 - moderate
    Last Modified
    Any Time
    Product
    Cisco Wireless Control System
    Technology
    1st Found-In
    4.2(47.0)
    Fixed-In
    5.0(28.0)
    Hope this helps bud!
    Rob

  • How to use the selection profile and status profile for production order?

    Hi expert,
       I want to know how to use the selection profile and status profile for production order. what's the usage for these two selection profile and status profile ?
      Please help me.
      thanks in advance.
      george.shi

    Hi George,
    There are are two types of statuses.One is system status and second one is user status.These statuses will tell us current situation of an order.
    We can't change system statuses.But we can create our own statuses through status profile.With this profile we can control user statuses.
    In this status profile,
    1.We define the sequence in which user statuses can be activated,
    2.We define initial statuses
    3. Allow or prohibit certain business transactions.
    Selection profiles are used to select the objects (say production orders) with different status combinations.We assign status profiles to selection profiles in BS42 T-Code.
    Regards,
    Raja.
    Edited by: Rajarao on Oct 30, 2008 6:21 AM
    Edited by: Rajarao on Oct 30, 2008 6:22 AM

  • WCS Lobby Ambassador audit report for a specific period of time

    Hi all,
    I know there is an WCS audit report for each lobby ambassador activities. But the problem is that I see only activities from Nov 9 to the present. I don't know what the reason is, whether somebody erased that information before Nov 9 or something else happened.
    Is there any option to manually configure a specific period of time, for example obtain all activities for last 3 months?
    Thanks for any hint.
    Jozef

    Hi Koti,
    What error did you meet when you used audit report from Oct 16 to Oct 31?
    Please check the log file to find more information about this issue. The path of the log file is: C:\Program Files\Common Files\microsoft shared\Web Server Extensions\15\LOGS. You can check the log file whose modified date is from Oct 16 to Oct 31.
    In addition, please deactivate and reactivate Reporting feature at site collection level.
    A similar post for your reference:
    http://sharepointknowledgebase.blogspot.com/2012/07/unexpected-error-when-trying-to-view.html#.VG2cFouUeog
    About audit log report, please take a look at:
    https://support.office.com/en-us/article/Configure-audit-settings-for-a-site-collection-a9920c97-38c0-44f2-8bcb-4cf1e2ae22d2?ui=en-US&rs=en-US&ad=US
    Best Regards,
    Wendy
    Wendy Li
    TechNet Community Support

  • Table for process order &Selection profile status  details -reg

    Hi ,
    From which tabel we can get the link between the process order and selection status profile (like SAP001 etc..
    When we input the process orders we should get the selection status profiel linked to it
    Regards,
    Madhu Kiran

    Hi,
    The tables JEST and JSTO  are related to status profile .
    What i need is of Selection Profile
    You can see this field in COOIS or COOISPI  just above the Sys Status field
    We need this urgently
    Can any one help ?
    Madhu Kiran

Maybe you are looking for

  • How to get Flashlite2.1 on Samsung

    I wish to post my earlier Q here since the more specific category involving Samsung doesn't seem to get much attention as yet. ...so I bought this beefed up phone, the Samsung SGH ZX20 with the 1Gg microSD card and USB transfer cable and see I may be

  • BPM process query integrating with EP

    Hello,    Our present finance process  where in we are using lotus notes for approvals workflow. --> user login to lotus notes fill the form and clicks submit and this triggers approval workflow's in lotusnotes and after approvals it generates a form

  • Creating portal DB provider: Can be schema on what instances?

    When I look at the Database Objects through the Navigator, the Database Schemas all seem to reside on the instance that supports 9iAS. Is it possible to get at a schema in another instance? John [email protected]

  • SYSTEM 9.2 PLANNING ERROR when trying to connect through web client

    <p>Hi ,</p><p> I have created a Planning application on system 9.2version. Whwn i try to access it it gives an error and comesout.However i am able to log into application and refresh databaseusing planning desktop. I do not want to use externalauthe

  • Active data guard 11gr2

    hi, I want to setup Active Data Guard Oracle 11gr2. This is my first time. Is there any good guide or cookbook for setting up active data guard 11g. I want to setup on linux. I'll be thankful. thanx