03-29-2017 11:59 AM
Wondering if there is anyway to adjust a Captive Portal Users role after they were created in the Guest Provisioning Portal and still allow them to be seen in that portal by the user that created it? I did an import without issue of some users but wanted to modify the Role of the account I selected that from the drop down in the Internal DB but once I did that it disappeared from the user who created once I changed it back to the default Role and it the appeared back in their Portal to manage is there anyway that this can be done?
04-11-2017 06:23 AM
Was looking at attaching a different role to apply different access controls such as App Access and Bandwidth Controls but the general staff would manage everything else via the GPP such as setup an account, manage credentials and expiration date.
05-01-2017 09:33 PM
From a guest network perspective, you would apply same set of access policies/bandwidth control for each user.
if yes, the role mapped in the captive profile could be changed to the role which will contain the required policies.
05-02-2017 06:23 AM
Downfall that I saw was once I defined that policy change by leveraging a Role Attribute to Set the new Role within the Server Group and then selecting that Role within the account it removed the user from view within the GPP for the Tech Staff to manage the account from expiration date, password or removing the account. Only way they see it is if it is set to Guest Role which is the default role. Are there any other options to do this type of control as ar as the role or is this one of those areas that has exceeded the basic function on the controller and Clear Pass is required?
05-03-2017 01:32 AM
The user will only disappear from the GPP page if you will modify the role assigned to the user by navigating to internal database of the controller.
You can map the required role (with controllers access) to the captive portal profile.
The user will get this role post authenticating on the CP page.
In this case, we do not have to make any changes to the user in the internal database.
The role mapped to captive portal profile should override the role listed in the internal database automatically.
In order to check the config that you have, please share the following outputs:
1. show local-userdb | include <name of guest user>
2. show aaa authentication captive-portal <name of profile>
In the captive portal profile, you will see a server group mapped to it.
I need the following output as well:
show aaa server-group <name of the group mapped in CP profile>