New to Cisco Lobby Ambassador

I want to be able to tie the registering users into the visitor registration section of a segregated guest network. I want to have a link that would appear in the front end after you register a visitor which would direct you to this program which is the lobby ambassador. Any non guest user could be able to register a guest and be provided a temp logon for the guest for a period of time.
Anyone has an idea of how I can achieve this using a Cisco lobby ambassador

You should be able to expand it to something bigger.  On the controller go to Security, AAA, General.  Increase this number, it will require a reboot.  I'm not sure the maximum you can increase it to (could be controller dependent).

Similar Messages

  • WCS Lobby Ambassador with AAA Authentication

    We are using WCS 7.0.164.0. I configured a user as local lobby ambassador with special defaults and also with a special guest login logo. If I use this user to create guest accounts everything is alright. Now I want to change the authentication to radius, so I export the cisco lobby ambassador attributes to the radius server and extend these network policies. Now I can login as user, authenticated from the radius server and I create guest accounts in the same way as before with local login, BUT !!! Our special guest login logo isn't shown and there is now way to upload or configure this special logo. Is there a way to configure these options for users authenticated with AAA ? Thanks for any Help  Bernhard

    Hi Bernhard,
    I used following doc-link: http://www.cisco.com/en/US/customer/tech/tk722/tk809/technologies_tech_note09186a0080851f7c.shtml
    The trick I used is to configure same username on tacacs+ and local, but different passwords.
    local-user: configure your special attributes like logo
    tacacs+: configure the authentication and group
    local-user password is not the same like tacacs+ password.
    I configured Authentication in WCS section: Administration > AAA > AAA Mode Settings
    Enable fallback to local == on auth failure or no server response
    Maybe if you deselect Enable fallback to local you can only authenticate to tacacs+. But now I can authenticate with local user/password and tacacs+ user/password.
    Attributes for tacacs+ or radius server can be exported in WCS section: Administration > AAA > All Groups; Export Task List
    Attributes for tacacs+ server:
    virtual-domain0=root
    role0=LobbyAmbassador
    task0=Configure Guest Users
    task1=Lobby Ambassador User Preferences
    Attributes for Radius (I never tried radius):
    Wireless-WCS:role0=LobbyAmbassador
    Wireless-WCS:task0=Configure Guest Users
    Wireless-WCS:task1=Lobby Ambassador User Preferences
    ==> I think also virtual-domain can be set.

  • Cisco Prime UTC/GMT Lobby Ambassador Issue

    After creating guest user credentials via Cisco Prime Lobby Ambassador, you receive a summary page(attached) that list the start time and end time.  The issue is that the times show up in UTC instead of GMT, does anyone know how to change this?  Thanks.

    I am not  sure ,if this BUG is applicable to P1 2.1 or not , hopefully not .but you can contact TAC  to confirm the behavior.
    If  anyone have a different view ,kindly share it with us.
    Thanks-
    Afroz
    ***Ratings Encourages Contributors ***

  • Cisco Prime UTC/GMT Lobby Ambassador

    After creating guest user credentials via Cisco Prime Lobby Ambassador, you receive a summary page(attached) that list the start time and end time.  The issue is that the times show up in UTC instead of GMT, does anyone know how to change this?  PI v 2.1  Thanks.

    Please refer: https://supportforums.cisco.com/discussion/11821441/cisco-prime-infra-13-how-change-time-zone
    Hope that helps.

  • Lobby ambassador can't see controller

    have added a new WLC to the WCS which has the same setup like others
    But when the lobby ambassador wants to add a guest user - he can't find this controller in the choice box
    what is missing?

    Please check if tha tWLC has the GUEST WLAN configured?? if not it will not come is wat i beleive.. on top of that..
    http://www.cisco.com/en/US/partner/docs/wireless/wcs/release/notes/WCS_RN7_0_220.html#wp68364
    7.0.172 WCS does not support 7.0.220 WLC..
    Regards
    Surendra

  • WCS Lobby Ambassador and Monitor User

    I'm running our WCS authentication through ACS with TACACS and it's working fine.  However, I currently have my Help Desk setup with a monitor user so they can login and view WCS, but this does not give them the Lobby Ambassador of course.  How can I get a user to have both WCS and Lobby access with having to login with seperate user identities?

    It's either admin either lobby account, you can not have both, the http pages are completly different and dont intermix.
    Your solution is to have 2 users on your TACACS where one is the admin and one the lobby.
    Here are the step by step config lines:
    http://www.cisco.com/en/US/docs/wireless/wcs/6.0/configuration/guide/6_0admin.html#wpmkr1064288

  • Lobby Ambassador can't email guest user accounts via WCS

    WCS is configured with SMTP server under Administration-Settings-Mail Server Configuration and test is successful and it sends e-mail alerts out no problem. However, when Lobby Ambassador creates a new guest account and clicks on the e-mail link to email it out, this message pops-up: 'Email Server is not configured.Contact Network Administrator'.
    Any ideas?

    by poking around I've found an answer. Even though we have a single email server, right after I've added the same server as a secondary email server, notifications started working. Seems to be a WCS bug.

  • Lobby Ambassador - WCS Logging of Guest Account Creation

    Hello all,
    If I am user "admin-ken" and I setup an guest user account "guestuser1" via the WCS controller templates > Guest User (which takes me into lobby ambassador), is there a log file that indicates that "admin-ken" had setup "guestuser1" guest account?
    Many thx indeed,
    Kind regards,
    Ken

    HiKen,
    Hope all is well :)
    Maybe this is what you are looking for;
    Logging the Lobby Ambassador Activities
    The following activities are logged for each lobby ambassador account:
    •Lobby ambassador login: WCS logs the authentication operation results for all users.
    •Guest user creation: When a lobby ambassador creates a guest user account, WCS logs the guest user name.
    •Guest user deletion: When a lobby ambassador deletes the guest user account, WCS logs the deleted guest user name.
    •Account updates: WCS logs the details of any updates made to the guest user account. For example, increasing the life time.
    Follow these steps to view the lobby ambassador activities.
    Note You must have superuser status to open this window.
    Step 1 Log into the Navigator or WCS user interface as an administrator.
    Step 2 Click Administration > AAA, then click Groups in the left sidebar menu to display the All Groups window.
    Step 3 On the All Groups windows, click the Audit Trail icon for the lobby ambassador account you want to view. The Audit Trail window for the lobby ambassador displays.
    This window enables you to view a list of lobby ambassador activities over time.
    •User: User login name
    •Operation: Type of operation audited
    •Time: Time operation was audited
    •Status: Success or failure
    Step 4 To clear the audit trail, choose Clear Audit Trail from the Select a command drop-down menu and click GO.
    http://www.cisco.com/en/US/docs/wireless/wcs/4.2/configuration/guide/wcsmanag.html#wp1076868
    http://www.cisco.com/en/US/docs/wireless/technology/guest_access/technical/reference/4.1/GAccess_41.html#wp1001609
    Hope this helps!
    Rob

  • Lobby Ambassador- Guest User Creation

    Hi all,
    I am currently implementing the use of the lobby ambassador for guest account creation, however I am looking to see if some features exist. I would like to be able to tie into AD to create lobby ambassador's to have further control of who can and cannot create guest accounts. I am also looking if there is a way to put restrictions on the time frame a guest account can remain active for when created by the lobby ambassador. An example of what I am trying to do is to not have a guest account created by an ambassador to go over a day for it's time frame.
    Thanks in advance,
    Chris

    Yes and yes. From WCS you can pull the role for lobby admin and use that to create the group with the proper attributes.
    Then on the WCS you build the template you want them to use. There you can create the restrictions of how long.
    Steve
    Sent from Cisco Technical Support iPhone App

  • WCS setup RADIUS users Lobby Ambassador Defaults

    Hi
    I'm using RADIUS so my users can use their active directory credentials to login WCS and generate guest users accounts...
    But I would like to setup some Lobby Ambassador Defaults, I can easily do ths for local users on the WCS system, but how to setup defaults for RADIUS users?
    Best Regards,
    Steffen.

    Hi Scott
    Tanks for your reply.
    I've allready read the article, but I can't see that it says anything about setting up Defaults for the users, only which task the should be able to do...
    I would like to setup defaults for the radius users, so when they are authenticated as lobby abassadors the do not need to select which SSID the a generating a guest user account for and so on...
    This is possible for local WCS users, but i need to setup these defaults for my RADIUS authenticated users.
    Best Reards
    Steffen
    And btw.. this dicussion was started by me.. https://supportforums.cisco.com/thread/2115616

  • Lobby Ambassador TACACS denied to create Guest Users

    Hi,
    I read some threads but I found no answer.
    I use WCS 7.0.172.0 an ACS 5.2
    I configured in ACS a Shell Profile for Lobby Ambassador Accs like I did for Admins.
    If I login as such lobby ambassador, I see just what i have to see. But if i'm going to create a guest user I got the message:
    Permission Denied
    You do not have privileges for the requested  operation.
    After Forum reading I created a local user with exact the same name, differnt pw, with no success.
    The shell profile:
    role0 | mandtory | LobbyAmbassador
    task0 | mandtory | Configure Guest Users
    task1 | mandtory | Lobby Ambassador User Preferences
    Thx 4 reading!
    btw: I just can authenticate with tacas+/pap, if I configure chap I've got a failure. chap is allowed in ACS...

    OK I fixed it.
    I had to add:
    virtual-domain0 | mandatory | root
    to the top of the shell profile, like described in:
    http://www.cisco.com/en/US/docs/wireless/wcs/7.0/configuration/guide/7_0admin.html
    now it works...
    The WCS "Task List" output of the group hasn't list it...
    But the CHAP probleme still wasn't fixed. Anyone who use TACACS/CHAP auth?

  • Lobby Ambassador - Automatic deletion from WCS after Expiry or Account

    Hi Guys,
    When I create a guest account and the account time expires, the account still remains on the WCS (but not on the controller).
    Is this a feature of the WCS or a bug?
    If so, can I ask the WCS to automatically remove all guest users accounts from the WCS lobby ambassador either directly after expiry, or say at 00:00 hours every day?
    Many thx
    Ken

    Hi there,
    Many thx.
    The way I understand it, is that yes the user expires, but you still have to clear down the username off the WCS periodically.
    Just thought the WCS may be able to do this as the timer expires but had a chat with a few guys at Cisco and is not possible currently.
    Cheers
    Ken

  • WCS Lobby Ambassador Accounts

    Unable to manage Guest accounts created by different WCS Lobby Ambassador user Accounts.
    I have setup three Lobby Ambassador accounts in WCS. Three staff members have been given seperate usernames and passwords to WCS with Lobby Ambassador profiles to allow them to create and manage the Guest Wireless Accounts.
    It was expected that they would be able to view and manange all Guest accounts, but they can only manage accounts they created. If I login as WCS admin I can then see all accounts created by each user.
    We require that all three can view and manage each others accounts using their own WCS login. Is this possible as docs do not mention??

    Hi Stuart,
    Just to add a note to the great tips from Leo;
    CSCsw42942 Bug Details
    SuperUser cannot see guest users created by admin users
    Symptom:
    If a WCS admin user creates a guest user through controller template, a Superuser will not be able to see the guest user created.
    Conditions:
    wcs 5.2.110
    Workaround:
    the root user can see everything
    Further Problem Description: Status
    Fixed
    Severity
    3 - moderate
    Last Modified
    In Last 3 Days
    Product
    Cisco Wireless Control System
    Technology
    1st Found-In
    5.2(110.0)
    Fixed-In
    5.2(122.0)
    6.0(23.0)
    Have a look at this good recent thread;
    http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&forum=Wireless%20-%20Mobility&topic=Security%20and%20Network%20Management&topicID=.ee6e8c0&fromOutline=&CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cc2cc01
    And this good thread;
    http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&forum=Wireless%20-%20Mobility&topic=Security%20and%20Network%20Management&topicID=.ee6e8c0&fromOutline=&CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cc3077f
    Hope this helps!
    Rob

  • 2504 WLC Question - Lobby Ambassador Available?

    I was wondering if the 2504 has the lobby ambassador feature available. Customer requires temp username/passwords for guests managed through web gui. I couldn't find conclusive documentation it was included so I figured I'd check here before calling Cisco.
    Thanks in advance!
    - Mike

    There should be the ability to configure that yes.  Go into the Management and add a user.  In the drop down for the role, there should be Lobby Ambasador/Admin listed there.
    Steve

  • Customize Lobby Ambassador View

    Hi all,
    I have a problem with the following situation:
    - Cisco Prime Infrastructure 2.0 (2.0.0.0.294)
    - Cisco ACS 5.4 (5.4.0.46.0a)
    - 2x Cisco WLAN Controller 5508 in SSO mode
    - x APs 2600 Series
    All devices are configured properly, I can see the WLC on Prime, etc.
    Prime and WLC are added to ACS for TACACS+ Authentication.
    Admin users are able to login to Prime with full feature set (root permission).
    Lobby Ambassadors can also login to Prime for Guest User creation.
    Therefore I have created two Shell Profiles on ACS.
    Now I want to create WLAN Guest User with Lobby Ambassador Account (TACACS-authenticated!).
    I want to customize the Default Guest User Creation page with a company logo and some default settings (WLAN Profile, Apply to Controller List, set "generate password" to fixed, etc.) to fixed values.
    Only thing what Lobby Ambassador can change should be setting the password period (with hours or using calender), guest user name and description.
    If I configure a local user on Prime, I can customize the page.
    However if I use TACACS user, I am not able to use the customized page.
    Can anybody help me with this issue?
    THANKS a lot!!!!
    edit: problem solved by workaround...
    https://supportforums.cisco.com/thread/2201703
    BR, Stefan

    You will not be able to unless you build a back-end that does it and sends the commands to the WLC. Other than that, you can't customize the lobby ambassador page.
    Sent from Cisco Technical Support iPhone App

Maybe you are looking for