Prime Lobby Ambassador defaults

I can't figure out if it's possible to standardize the configuration for Guest User creation for users who are authenticated using RADIUS and assigned to the Lobby Ambassador group.
Any help?
Thanks!

I went through this nightmare before as well if memory serves.  Unfortunately, it doesn't appear it's possible.  
If I'm incorrect, someone please pipe up as I don't believe I was ever able to find a way either.

Similar Messages

  • Prime Lobby Ambassador defaults scheduling guest users

    Hi.
    I'm actually testing Prime Infrastructure and one important thing there for me is the Lobby Ambassador feature.
    I want to give our colleagues from other sites the possibility to create guest accounts on their own, but with some defaults already set. They should only be able to create accounts with a lifetime of 14 days ( not editable ), but with the possibility to schedule the accounts.
    If I now set the defaults of the Lobby Ambassador to 14 days lifetime and make them not editable, the Lobby Ambassador can’t schedule the guest user. If they choose “Schedule Guest User” from dropdown, they get the message “The creation will be scheduled 5 minutes after the current server time.”
    Is there a way to get that working?
    Best would be to have the defaults partially not editable, so that you can make some things default ( e.g. lifetime, generate password, controller config group ) and some things editable ( e.g. description, disclaimer, scheduling ).
    Regards,
    Sven Lindeke

    I went through this nightmare before as well if memory serves.  Unfortunately, it doesn't appear it's possible.  
    If I'm incorrect, someone please pipe up as I don't believe I was ever able to find a way either.

  • WCS setup RADIUS users Lobby Ambassador Defaults

    Hi
    I'm using RADIUS so my users can use their active directory credentials to login WCS and generate guest users accounts...
    But I would like to setup some Lobby Ambassador Defaults, I can easily do ths for local users on the WCS system, but how to setup defaults for RADIUS users?
    Best Regards,
    Steffen.

    Hi Scott
    Tanks for your reply.
    I've allready read the article, but I can't see that it says anything about setting up Defaults for the users, only which task the should be able to do...
    I would like to setup defaults for the radius users, so when they are authenticated as lobby abassadors the do not need to select which SSID the a generating a guest user account for and so on...
    This is possible for local WCS users, but i need to setup these defaults for my RADIUS authenticated users.
    Best Reards
    Steffen
    And btw.. this dicussion was started by me.. https://supportforums.cisco.com/thread/2115616

  • PI 1.3 Lobby Ambassador Defaults where Building stays None?

    When creating local Lobby Ambassador user, the Lobby Ambassador Defaults profile needs to be set.  At the Lobby Ambassador Default page, the Building dropdown stays at "None" with no other selections, although the building has been created in the corresponding Campus.
    PI1.3 won't create the Lobby Ambassador user when Building selection is NONE.
    Any one runs into this problem?

    When creating local Lobby Ambassador user, the Lobby Ambassador Defaults profile needs to be set.  At the Lobby Ambassador Default page, the Building dropdown stays at "None" with no other selections, although the building has been created in the corresponding Campus.
    PI1.3 won't create the Lobby Ambassador user when Building selection is NONE.
    Any one runs into this problem?

  • Cisco Prime UTC/GMT Lobby Ambassador Issue

    After creating guest user credentials via Cisco Prime Lobby Ambassador, you receive a summary page(attached) that list the start time and end time.  The issue is that the times show up in UTC instead of GMT, does anyone know how to change this?  Thanks.

    I am not  sure ,if this BUG is applicable to P1 2.1 or not , hopefully not .but you can contact TAC  to confirm the behavior.
    If  anyone have a different view ,kindly share it with us.
    Thanks-
    Afroz
    ***Ratings Encourages Contributors ***

  • Cisco Prime UTC/GMT Lobby Ambassador

    After creating guest user credentials via Cisco Prime Lobby Ambassador, you receive a summary page(attached) that list the start time and end time.  The issue is that the times show up in UTC instead of GMT, does anyone know how to change this?  PI v 2.1  Thanks.

    Please refer: https://supportforums.cisco.com/discussion/11821441/cisco-prime-infra-13-how-change-time-zone
    Hope that helps.

  • Lobby ambassador guest acounts

    When creating a guest user account using lobby ambassador on wcs 4.2 the guest account defaults to 8 hours. I would like to change the default time to 1 day. Does anyone know how i can do this?
    Thanks!

    Great. Also, I noticed that when using ACS to authenticate the user that creates guest accounts the lobby ambassador default settings don't apply to this user. Any ideas on how to correct this? Any estimated date when 5.1 will be released?
    Thanks!

  • Restricted Lobby Ambassador

    Hi,
    Does anyone know if there is a way to limit a lobby admin user (on WLC or PI) to a specific AP group or WLAN?
    I would like to have o lobby admin who can add guest users just for specific WLANs configured on the WLC.
    I know that the lobby admin can map just one WLAN (vs. Any WLAN) to a guest user when creating his account, but I want to restrict the WLANs that the lobby admin can choose from.
    Thank you,
    Sebastian

    I found that it is possible from PI.
    You can select one SSID under lobby ambassador defaults TAB from Profiles drop down.
    Thank you,
    Sebastian

  • Customize Lobby Ambassador View

    Hi all,
    I have a problem with the following situation:
    - Cisco Prime Infrastructure 2.0 (2.0.0.0.294)
    - Cisco ACS 5.4 (5.4.0.46.0a)
    - 2x Cisco WLAN Controller 5508 in SSO mode
    - x APs 2600 Series
    All devices are configured properly, I can see the WLC on Prime, etc.
    Prime and WLC are added to ACS for TACACS+ Authentication.
    Admin users are able to login to Prime with full feature set (root permission).
    Lobby Ambassadors can also login to Prime for Guest User creation.
    Therefore I have created two Shell Profiles on ACS.
    Now I want to create WLAN Guest User with Lobby Ambassador Account (TACACS-authenticated!).
    I want to customize the Default Guest User Creation page with a company logo and some default settings (WLAN Profile, Apply to Controller List, set "generate password" to fixed, etc.) to fixed values.
    Only thing what Lobby Ambassador can change should be setting the password period (with hours or using calender), guest user name and description.
    If I configure a local user on Prime, I can customize the page.
    However if I use TACACS user, I am not able to use the customized page.
    Can anybody help me with this issue?
    THANKS a lot!!!!
    edit: problem solved by workaround...
    https://supportforums.cisco.com/thread/2201703
    BR, Stefan

    You will not be able to unless you build a back-end that does it and sends the commands to the WLC. Other than that, you can't customize the lobby ambassador page.
    Sent from Cisco Technical Support iPhone App

  • WCS Lobby Ambassador with AAA Authentication

    We are using WCS 7.0.164.0. I configured a user as local lobby ambassador with special defaults and also with a special guest login logo. If I use this user to create guest accounts everything is alright. Now I want to change the authentication to radius, so I export the cisco lobby ambassador attributes to the radius server and extend these network policies. Now I can login as user, authenticated from the radius server and I create guest accounts in the same way as before with local login, BUT !!! Our special guest login logo isn't shown and there is now way to upload or configure this special logo. Is there a way to configure these options for users authenticated with AAA ? Thanks for any Help  Bernhard

    Hi Bernhard,
    I used following doc-link: http://www.cisco.com/en/US/customer/tech/tk722/tk809/technologies_tech_note09186a0080851f7c.shtml
    The trick I used is to configure same username on tacacs+ and local, but different passwords.
    local-user: configure your special attributes like logo
    tacacs+: configure the authentication and group
    local-user password is not the same like tacacs+ password.
    I configured Authentication in WCS section: Administration > AAA > AAA Mode Settings
    Enable fallback to local == on auth failure or no server response
    Maybe if you deselect Enable fallback to local you can only authenticate to tacacs+. But now I can authenticate with local user/password and tacacs+ user/password.
    Attributes for tacacs+ or radius server can be exported in WCS section: Administration > AAA > All Groups; Export Task List
    Attributes for tacacs+ server:
    virtual-domain0=root
    role0=LobbyAmbassador
    task0=Configure Guest Users
    task1=Lobby Ambassador User Preferences
    Attributes for Radius (I never tried radius):
    Wireless-WCS:role0=LobbyAmbassador
    Wireless-WCS:task0=Configure Guest Users
    Wireless-WCS:task1=Lobby Ambassador User Preferences
    ==> I think also virtual-domain can be set.

  • WCS Lobby Ambassador

    Hello all,
    In WCS by default the lobby ambassador has option to generate manual or auto (random) password for guest user account.
    Is there any way that we can restrict lobby ambassador to generate manual password for guest user ?
    Regards,
    Anis

    No not exactly ,
    We dont want lobby admin's to create manuall passwords for there guest. Loby admin should have option to generate the random passwords only.
    Regards,
    Anis

  • Lobby Ambassador Profiles in ACS 5.3

    We've set our WCS up to do AAA through our ACS 5.3 which works great. So in order to log into the WCS for Administration or as a Lobby Ambassador (to create guest users etc) the AAA is all done by the ACS, GREAT!
    I have assigned a set of users the Lobby Ambassador role as passed that back through TACACS to the WCS, so those users have their role setup as Lobby Ambassador and are limited from doing anything else, as expected.
    What I want to know is: With normal local AAA on the WCS, when you created a Lobby Ambassador account, you could give the account a set of defaults for any guests accounts created by that Lobby Ambassador account, which was good, so Lobby Ambassadors couldn't set up unlimited time accounts and stuff like that.
    What I want to know now is that since I'm now doing all the AAA on the ACS, is there an attribute I can pass to the WCS in the Shell Profile, along with the roles etc telling the WCS what the guest user creation defaults for the Lobby Ambassador account is, so that we can continue to limit the defaults of any guest account that the Lobby Ambassador accounts create, as it used to be? We'd really like different lobby ambassadors to be able to do different things as well. i.e., Lobby Ambassador X can only create accounts for one region. Lobby Ambassador Y can create Unlimited time accounts where the others can not. We used to do this by assigning different guest user creation defaults to different lobby ambassador accounts on the WCS.
    Help appreciated        

    Hi,
    at the moment the only solution for your requirement is to create local NCS/WCS accounts with exactly the same username as existing in your ACS, no matter what password. Authentication will happen via TACACS+ while the defaults will be taken from the local user account. Please be aware that this mechanism is case sensitive.
    Regards
    Stefan

  • NCS - lobby ambassador controller list

    Under NCS --> Administration --> Users we have created a specific user to enable guest user access. However, when tinkering with the defaults you can select a controller list. The problem is we only see 5 of our controllers (we have 8).
    Is this a limitation on lobby ambassador? Or is there a way to add additional controllers here?

    When you create the lobby ambassador you specify the defaults.
    You specify the WLAN profile ,user role ...etc.
    If you choose a WLAN profile, then only WLCs that have that WLAN profile will appear.
    Same manner, if you specify user role, only WLCs that has that QoS role configured will appear on the list.
    If you configured both, intersection of both (WLCs that have both the profile and the role) will appear.
    If you choose the default user role and use any profile then you should see all the WLCs on the list.
    HTH
    Amjad

  • WCS Lobby Ambassador audit report for a specific period of time

    Hi all,
    I know there is an WCS audit report for each lobby ambassador activities. But the problem is that I see only activities from Nov 9 to the present. I don't know what the reason is, whether somebody erased that information before Nov 9 or something else happened.
    Is there any option to manually configure a specific period of time, for example obtain all activities for last 3 months?
    Thanks for any hint.
    Jozef

    Hi Koti,
    What error did you meet when you used audit report from Oct 16 to Oct 31?
    Please check the log file to find more information about this issue. The path of the log file is: C:\Program Files\Common Files\microsoft shared\Web Server Extensions\15\LOGS. You can check the log file whose modified date is from Oct 16 to Oct 31.
    In addition, please deactivate and reactivate Reporting feature at site collection level.
    A similar post for your reference:
    http://sharepointknowledgebase.blogspot.com/2012/07/unexpected-error-when-trying-to-view.html#.VG2cFouUeog
    About audit log report, please take a look at:
    https://support.office.com/en-us/article/Configure-audit-settings-for-a-site-collection-a9920c97-38c0-44f2-8bcb-4cf1e2ae22d2?ui=en-US&rs=en-US&ad=US
    Best Regards,
    Wendy
    Wendy Li
    TechNet Community Support

  • WCS Lobby Ambassador and Monitor User

    I'm running our WCS authentication through ACS with TACACS and it's working fine.  However, I currently have my Help Desk setup with a monitor user so they can login and view WCS, but this does not give them the Lobby Ambassador of course.  How can I get a user to have both WCS and Lobby access with having to login with seperate user identities?

    It's either admin either lobby account, you can not have both, the http pages are completly different and dont intermix.
    Your solution is to have 2 users on your TACACS where one is the admin and one the lobby.
    Here are the step by step config lines:
    http://www.cisco.com/en/US/docs/wireless/wcs/6.0/configuration/guide/6_0admin.html#wpmkr1064288

Maybe you are looking for