{"id":97567,"date":"2020-10-19T14:42:54","date_gmt":"2020-10-19T12:42:54","guid":{"rendered":"https:\/\/prohoster.info\/blog\/administrirovanie\/cisco-ise-nastrojka-gostevogo-dostupa-na-fortiap-chast-3"},"modified":"2020-10-19T14:42:54","modified_gmt":"2020-10-19T12:42:54","slug":"cisco-ise-nastrojka-gostevogo-dostupa-na-fortiap-chast-3","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/cisco-ise-nastrojka-gostevogo-dostupa-na-fortiap-chast-3","title":{"rendered":"Cisco ISE: Configuring Guest Access on FortiAP. Part 3","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"Cisco ISE: Configuring Guest Access on FortiAP. Part 3\" src=\"\/wp-content\/uploads\/2020\/10\/8e74c6fa08917bece4999beb5cfbeff8.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>Welcome to the third publication in the series of articles dedicated to Cisco ISE. Links to all articles in the series are provided below:<\/p>\n<ol>\n<li>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/519616\/\">Cisco ISE: Introduction, Requirements, Installation. Part 1<\/a><\/noindex><\/p>\n<\/li>\n<li>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/520222\/\">Cisco ISE: Creating Users, Adding LDAP Servers, Integrating with AD. Part 2<\/a><\/noindex><\/p>\n<\/li>\n<li>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/publication\/edit\/523778\/\">Cisco ISE: Configuring Guest Access on FortiAP. Part 3<\/a><\/noindex><\/p>\n<\/li>\n<\/ol>\n<p>This publication takes you into guest access, as well as a step-by-step guide to integrating Cisco ISE and FortiGate for setting up FortiAP \u2014 access points from Fortinet (in general, any device that supports <strong>RADIUS CoA <\/strong>\u2014 Change of Authorization).<\/p>\n<p>Additionally, I am attaching our articles <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/495556\/\">Fortinet \u2014 a collection of useful materials<\/a><\/noindex>.<\/p>\n<p><strong><em>Note<\/em><\/strong>: Check Point SMB devices do not support RADIUS CoA.<\/p>\n<p>The wonderful <noindex><a rel=\"nofollow\" href=\"https:\/\/community.cisco.com\/t5\/security-documents\/ise-guest-access-prescriptive-deployment-guide\/ta-p\/3640475#toc-hId--611508106\">guide<\/a><\/noindex> in English describes how to create guest access using Cisco ISE on Cisco WLC (Wireless Controller). Let's figure it out!<\/p>\n<h2>1. Introduction<\/h2>\n<p>Guest access (portal) allows providing Internet or internal resource access for guests and users whom you do not want to let into your local network. There are 3 pre-installed types of guest portals (Guest portal):<\/p>\n<ol>\n<li>\n<p>Hotspot Guest portal \u2014 network access is provided to guests without login credentials. Generally, users are required to accept the company\u2019s \u201cTerms of Use and Privacy Policy\u201d before gaining access to the network.<\/p>\n<\/li>\n<li>\n<p>Sponsored-Guest portal \u2014 network access and login information must be issued by the sponsor \u2014 the user responsible for creating guest accounts on Cisco ISE.<\/p>\n<\/li>\n<li>\n<p>Self-Registered Guest portal \u2014 in this case, guests use existing login information, or they can create an account with login data themselves, although sponsor confirmation is required for network access.<\/p>\n<\/li>\n<\/ol>\n<p>Multiple portals can be deployed on Cisco ISE simultaneously. By default, on the guest portal, users will see the Cisco logo and standard common phrases. This can all be customized and even involve mandatory advertisement viewing before gaining access.<\/p>\n<p>The setup of guest access can be broken down into 4 main stages: configuring FortiAP, establishing connectivity between Cisco ISE and FortiAP, creating the guest portal, and setting up access policies.<\/p>\n<h2>2. Configuring FortiAP on FortiGate<\/h2>\n<p>FortiGate serves as the access point controller, and all configurations are made on it. FortiAP access points support PoE, so once you connect it to the network via Ethernet, you can start the configuration.<\/p>\n<p>1) On FortiGate, go to the tab <em>WiFi &amp; Switch Controller &gt; Managed FortiAPs &gt; Create New &gt; Managed AP<\/em>Using the unique serial number of the access point, which is indicated on the access point itself, add it as an object. Alternatively, it may be discovered automatically and then click <em>Authorize <\/em>using the right mouse button.<\/p>\n<p><img decoding=\"async\" alt=\"Cisco ISE: Configuring Guest Access on FortiAP. Part 3\" src=\"\/wp-content\/uploads\/2020\/10\/a63d4528b96a3ec4ab4f8f1e78f3b68d.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>2) The FortiAP settings may be default; for example, leave them as shown in the screenshot. I highly recommend enabling the 5 GHz mode, as some devices do not support 2.4 GHz.<\/p>\n<p>3) Then, go to the tab <em>WiFi &amp; Switch Controller &gt; FortiAP Profiles &gt; Create New <\/em>to create a configuration profile for the access point (protocol version 802.11, SSID mode, channel frequency, and their quantity).<\/p>\n<p>Example FortiAP settings<img decoding=\"async\" alt=\"Cisco ISE: Configuring Guest Access on FortiAP. Part 3\" src=\"\/wp-content\/uploads\/2020\/10\/af458341562b9771cee070c1af340385.jpeg\" style=\"display:block;margin: 0 auto;\" \/><img decoding=\"async\" alt=\"Cisco ISE: Configuring Guest Access on FortiAP. Part 3\" src=\"\/wp-content\/uploads\/2020\/10\/01fde83461472c04eb978ce4cdd052ef.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<\/p>\n<p>4) The next step \u2014 creating the SSID. Navigate to the tab <em>WiFi &amp; Switch Controller &gt; SSIDs &gt; Create New &gt; SSID. <\/em>Here, it is important to configure:<\/p>\n<ul>\n<li>\n<p>address space for guest WLAN \u2014 IP\/Netmask<\/p>\n<\/li>\n<li>\n<p>RADIUS Accounting and Secure Fabric Connection in the Administrative Access field<\/p>\n<\/li>\n<li>\n<p>Device Detection option<\/p>\n<\/li>\n<li>\n<p>SSID and Broadcast SSID option<\/p>\n<\/li>\n<li>\n<p>Security Mode Settings &gt; Captive Portal&nbsp;<\/p>\n<\/li>\n<li>\n<p>Authentication Portal \u2014 External and insert the link to the created guest portal from Cisco ISE from point 20<\/p>\n<\/li>\n<li>\n<p>User Group \u2014 Guest Group \u2014 External \u2014 add RADIUS on Cisco ISE (p. 6 and beyond)<\/p>\n<\/li>\n<\/ul>\n<p>Example SSID configuration<img decoding=\"async\" alt=\"Cisco ISE: Configuring Guest Access on FortiAP. Part 3\" src=\"\/wp-content\/uploads\/2020\/10\/2153cb0a4c38c8f66fc99195b1be46f9.jpeg\" style=\"display:block;margin: 0 auto;\" \/><img decoding=\"async\" alt=\"Cisco ISE: Configuring Guest Access on FortiAP. Part 3\" src=\"\/wp-content\/uploads\/2020\/10\/788c52b1b6a6663bedb6fdf1e354a147.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>5) Next, you need to create rules in the access policy on FortiGate. Go to the tab <em>Policy &amp; Objects &gt; Firewall Policy <\/em>and create a rule of the following type:<\/p>\n<p><img decoding=\"async\" alt=\"Cisco ISE: Configuring Guest Access on FortiAP. Part 3\" src=\"\/wp-content\/uploads\/2020\/10\/ce3bcfbf5902ef621eabed1d236d7f93.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<h2>3. RADIUS configuration<\/h2>\n<p>6) Go to the web interface of Cisco ISE, then to the tab <em>Policy &gt; Policy Elements &gt; Dictionaries &gt; System &gt; Radius &gt; RADIUS Vendors &gt; Add. <\/em>In this tab, we will add Fortinet-supported RADIUS protocols to the list, as almost every vendor has its own specific attributes \u2014 VSA (Vendor-Specific Attributes).<\/p>\n<p>The list of RADIUS attributes for Fortinet can be found <noindex><a rel=\"nofollow\" href=\"https:\/\/kb.fortinet.com\/kb\/viewContent.do?externalId=FD36919&amp;sliceId=1\">here<\/a><\/noindex>. VSA differ by their unique Vendor ID number. For Fortinet, this ID = <strong>12356<\/strong>. The complete <noindex><a rel=\"nofollow\" href=\"https:\/\/www.iana.org\/assignments\/enterprise-numbers\/enterprise-numbers\">list <\/a><\/noindex>of VSA was published by IANA.<\/p>\n<p>7) Assign a name to the dictionary, specify <em>Vendor ID<\/em> (12356) and click <em>Submit.<\/em><\/p>\n<p>8) Next, go to <em>Administration &gt; Network Device Profiles &gt; Add <\/em>and create a new device profile. In the RADIUS Dictionaries field, select the previously created Fortinet RADIUS dictionary and select CoA methods to use them later in the ISE policy. I chose RFC 5176 and Port Bounce (shutdown\/no shutdown of the network interface) and corresponding VSA:&nbsp;<\/p>\n<p><strong><em>Fortinet-Access-Profile = read-write<\/em><\/strong><\/p>\n<p><strong><em>Fortinet-Group-Name = fmg_faz_admins<\/em><\/strong><\/p>\n<p>9) Next, add FortiGate for connectivity with ISE. For this, go to the tab <em>Administration &gt; Network Resources &gt; Network Device Profiles &gt; Add. <\/em>Modify the fields <em>Name, Vendor, RADIUS Dictionaries <\/em>(IP Address uses FortiGate, not FortiAP).<\/p>\n<p>Example configuration of RADIUS from the ISE side<img decoding=\"async\" alt=\"Cisco ISE: Configuring Guest Access on FortiAP. Part 3\" src=\"\/wp-content\/uploads\/2020\/10\/25d983fca26e9d2e436494fc3db374a3.jpeg\" style=\"display:block;margin: 0 auto;\" \/><img decoding=\"async\" alt=\"Cisco ISE: Configuring Guest Access on FortiAP. Part 3\" src=\"\/wp-content\/uploads\/2020\/10\/4eab2e69c05d9366f2d082891f1d4b32.jpeg\" style=\"display:block;margin: 0 auto;\" \/><img decoding=\"async\" alt=\"Cisco ISE: Configuring Guest Access on FortiAP. Part 3\" src=\"\/wp-content\/uploads\/2020\/10\/317c5eb8d2838d793f68ac4140d231f6.jpeg\" style=\"display:block;margin: 0 auto;\" \/><img decoding=\"async\" alt=\"Cisco ISE: Configuring Guest Access on FortiAP. Part 3\" src=\"\/wp-content\/uploads\/2020\/10\/523539547ce89a40bfb4e0d77e434a25.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>10) Next, configure RADIUS on the FortiGate side. In the FortiGate web interface, go to <em>User &amp; Authentication &gt; RADIUS Servers &gt; Create New<\/em>. Specify the name, IP address, and Shared secret (password) from the previous step. Then click <strong>Test User Credentials<\/strong> and enter any credentials that can be retrieved via RADIUS (for example, a local user on Cisco ISE).<\/p>\n<p><img decoding=\"async\" alt=\"Cisco ISE: Configuring Guest Access on FortiAP. Part 3\" src=\"\/wp-content\/uploads\/2020\/10\/bb996caa79f1d6bcdf8b218243ed0b9b.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>11) Add the RADIUS server to the Guest-Group (if it doesn\u2019t exist, create it), as well as external user sources.<\/p>\n<p><img decoding=\"async\" alt=\"Cisco ISE: Configuring Guest Access on FortiAP. Part 3\" src=\"\/wp-content\/uploads\/2020\/10\/81f4a97ef64c4ccc470ade4767cc67b3.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>12) Don't forget to add the Guest-Group to the SSID that we created earlier in step 4.<\/p>\n<h2>4. User authentication configuration<\/h2>\n<p>13) Optionally, you can import a certificate to the guest portal ISE or create a self-signed certificate in the tab <em>Work Centers &gt; Guest Access &gt; Administration &gt; Certification &gt; System Certificates<\/em>.<\/p>\n<p><img decoding=\"async\" alt=\"Cisco ISE: Configuring Guest Access on FortiAP. Part 3\" src=\"\/wp-content\/uploads\/2020\/10\/1f0a1448ce28332d295b76df4553976f.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>14) After that, in the tab <em>Work Centers &gt; Guest Access &gt; Identity Groups &gt; User Identity Groups &gt; Add <\/em>create a new user group for guest access, or use the default ones.<\/p>\n<p><img decoding=\"async\" alt=\"Cisco ISE: Configuring Guest Access on FortiAP. Part 3\" src=\"\/wp-content\/uploads\/2020\/10\/a96bbbc41a82299e4628b5d26bfee614.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>15) Next, in the tab <em>Administration &gt; Identities <\/em>create guest users and add them to the groups from the previous step. If you wish to use external accounts, skip this step.<\/p>\n<p><img decoding=\"async\" alt=\"Cisco ISE: Configuring Guest Access on FortiAP. Part 3\" src=\"\/wp-content\/uploads\/2020\/10\/51708ff1595b507c5b5d0bd12ec94d2e.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>16) Then we go to the settings <em>Work Centers &gt; Guest Access &gt; Identities &gt;<\/em> <em>Identity Source Sequence &gt; Guest Portal Sequence \u2014 <\/em>this is the preconfigured authentication sequence for guest users. In the field <em>Authentication Search List <\/em>select the order of user authentication.<\/p>\n<p><img decoding=\"async\" alt=\"Cisco ISE: Configuring Guest Access on FortiAP. Part 3\" src=\"\/wp-content\/uploads\/2020\/10\/04b5e2042e7735d32f5fbfba5d576337.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>17) For notifying guests with a one-time password, SMS providers or an SMTP server can be configured for this purpose. Go to the tab <em>Work Centers &gt; Guest Access &gt; Administration &gt; SMTP Server <\/em>or <em>SMS Gateway Providers <\/em>for these settings. In the case of an SMTP server, you need to create an account for ISE and enter the details in this tab.<\/p>\n<p>18) For SMS notifications, use the corresponding tab. There are preconfigured profiles for popular SMS providers in ISE, but it's better to create your own. Use these profiles as a sample configuration <em>SMS Email Gateway<\/em>or <em>SMS HTTP API<\/em>.<\/p>\n<p>Example configuration of an SMTP server and SMS gateway for a one-time password<img decoding=\"async\" alt=\"Cisco ISE: Configuring Guest Access on FortiAP. Part 3\" src=\"\/wp-content\/uploads\/2020\/10\/c7e7d5d50961efc0aa30c27a3dd80b9b.jpeg\" style=\"display:block;margin: 0 auto;\" \/><img decoding=\"async\" alt=\"Cisco ISE: Configuring Guest Access on FortiAP. Part 3\" src=\"\/wp-content\/uploads\/2020\/10\/7e682a3fb9ae65b9b9e59a12856adebf.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<\/p>\n<h2>5. Guest portal configuration<\/h2>\n<p>19) As mentioned at the beginning, there are 3 types of pre-installed guest portals: Hotspot, Sponsored, Self-Registered. I suggest selecting the third option, as it is the most frequently encountered. In any case, the settings are largely identical. Therefore, we move to the tab <em>Work Centers &gt; Guest Access &gt; Portals &amp; Components &gt; Guest Portals &gt; Self-Registered Guest Portal (default).&nbsp;<\/em><\/p>\n<p>20) Next, in the Portal Page Customization tab, select <em>\u201cView in Russian \u2014 \u0420\u0443\u0441\u0441\u043a\u0438\u0439\u201d <\/em>so that the portal will display in Russian. You can modify the text of any tab, add your logo, and much more. On the right corner, there is a preview of the guest portal for easier visualization.<\/p>\n<p>Example of setting up a self-registered guest portal<img decoding=\"async\" alt=\"Cisco ISE: Configuring Guest Access on FortiAP. Part 3\" src=\"\/wp-content\/uploads\/2020\/10\/9500a0b96d4c11b400c8450e3ec384bf.jpeg\" style=\"display:block;margin: 0 auto;\" \/><img decoding=\"async\" alt=\"Cisco ISE: Configuring Guest Access on FortiAP. Part 3\" src=\"\/wp-content\/uploads\/2020\/10\/30c950ecc50e2ecd3125c38a3b973a14.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>21) Click on the phrase<em> <\/em><strong><em>\u201cPortal test URL\u201d<\/em><\/strong> and copy the portal URL to the SSID on FortiGate in step 4. The URL will look something like this <noindex><a rel=\"nofollow\" href=\"https:\/\/10.10.30.38:8433\/portal\/PortalSetup.action?portal=deaaa863-1df0-4198-baf1-8d5b690d4361\"><u>https:\/\/10.10.30.38:8433\/portal\/PortalSetup.action?portal=deaaa863-1df0-4198-baf1-8d5b690d4361<\/u><\/a><\/noindex><\/p>\n<p>To display your domain, you need to upload a certificate to the guest portal, see step 13.<\/p>\n<p><img decoding=\"async\" alt=\"Cisco ISE: Configuring Guest Access on FortiAP. Part 3\" src=\"\/wp-content\/uploads\/2020\/10\/f04bda68e296ef0945b239790cb4e099.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>22) Go to the tab <em>Work Centers &gt; Guest Access &gt; Policy Elements &gt; Results &gt; Authorization Profiles &gt; Add <\/em>to create an authorization profile for the previously created <em>Network Device Profile.<\/em><\/p>\n<p><img decoding=\"async\" alt=\"Cisco ISE: Configuring Guest Access on FortiAP. Part 3\" src=\"\/wp-content\/uploads\/2020\/10\/4607e547f69817e67c744c31efa9f045.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>23) In the tab <em>Work Centers &gt; Guest Access &gt; Policy Sets <\/em>edit the access policy for WiFi users.<\/p>\n<p><img decoding=\"async\" alt=\"Cisco ISE: Configuring Guest Access on FortiAP. Part 3\" src=\"\/wp-content\/uploads\/2020\/10\/17a9da8de1aed13c132d36ed90d9fec8.jpeg\" style=\"display:block;margin: 0 auto;\" \/><img decoding=\"async\" alt=\"Cisco ISE: Configuring Guest Access on FortiAP. Part 3\" src=\"\/wp-content\/uploads\/2020\/10\/af568493da78a97f634ec8343b0df9a5.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>24) Let's try to connect to the guest SSID. I am immediately redirected to the login page. Here, you can log in with the guest account created locally on ISE or register as a guest user.<\/p>\n<p><img decoding=\"async\" alt=\"Cisco ISE: Configuring Guest Access on FortiAP. Part 3\" src=\"\/wp-content\/uploads\/2020\/10\/25bc5b264f19ee030b6445ba273979dc.jpeg\" style=\"display:block;margin: 0 auto;\" \/><img decoding=\"async\" alt=\"Cisco ISE: Configuring Guest Access on FortiAP. Part 3\" src=\"\/wp-content\/uploads\/2020\/10\/81313ffda4c99b3e77f0c942986e508f.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>25) If you chose the self-registration option, the one-time login details can be sent via email, SMS, or printed out.<\/p>\n<p><img decoding=\"async\" alt=\"Cisco ISE: Configuring Guest Access on FortiAP. Part 3\" src=\"\/wp-content\/uploads\/2020\/10\/57f51d73009fa95a35b28193f7dec6e2.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>26) In the RADIUS &gt; Live Logs tab on Cisco ISE, you will see the corresponding login logs.<\/p>\n<p><img decoding=\"async\" alt=\"Cisco ISE: Configuring Guest Access on FortiAP. Part 3\" src=\"\/wp-content\/uploads\/2020\/10\/d81cd278b635acb68efa19d7a1a168c3.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<h3>6. Conclusion<\/h3>\n<p>In this lengthy article, we successfully set up guest access on Cisco ISE, where FortiGate acts as the access point controller and FortiAP as the access point. This resulted in a non-trivial integration, which once again proves the wide applicability of ISE.<\/p>\n<p>For testing Cisco ISE, please contact <noindex><a rel=\"nofollow\" href=\"https:\/\/tssolution.ru\/katalog\/cisco\/ise\"><u>this link<\/u><\/a><\/noindex>, and also follow our updates on our channels (<noindex><a rel=\"nofollow\" href=\"https:\/\/t.me\/tssolution\"><u>Telegram<\/u><\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.facebook.com\/groups\/tssolution.info\/\"><u>Facebook<\/u><\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/vk.com\/ts_solution\"><u>VK<\/u><\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/tssolution.ru\/blog\"><u>TS Solution Blog<\/u><\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/zen.yandex.ru\/id\/5c7d2162fa818600ae386a52\"><u>Yandex.Zen<\/u><\/a><\/noindex>).<\/p>\n<p>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/523778\/\">habr.com<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041f\u0440\u0438\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u044e \u0432 \u0442\u0440\u0435\u0442\u044c\u0435\u0439 \u043f\u0443\u0431\u043b\u0438\u043a\u0430\u0446\u0438\u0438 \u0446\u0438\u043a\u043b\u0430 \u0441\u0442\u0430\u0442\u0435\u0439, \u043f\u043e\u0441\u0432\u044f\u0449\u0435\u043d\u043d\u043e\u043c\u0443 Cisco ISE. \u0421\u0441\u044b\u043b\u043a\u0438 \u043d\u0430 \u0432\u0441\u0435 \u0441\u0442\u0430\u0442\u044c\u0438 \u0432 \u0446\u0438\u043a\u043b\u0435 \u043f\u0440\u0438\u0432\u0435\u0434\u0435\u043d\u044b \u043d\u0438\u0436\u0435: Cisco ISE: \u0412\u0432\u0435\u0434\u0435\u043d\u0438\u0435, \u0442\u0440\u0435\u0431\u043e\u0432\u0430\u043d\u0438\u044f, \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430. \u0427\u0430\u0441\u0442\u044c 1 Cisco ISE: \u0421\u043e\u0437\u0434\u0430\u043d\u0438\u0435 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439, \u0434\u043e\u0431\u0430\u0432\u043b\u0435\u043d\u0438\u0435 LDAP \u0441\u0435\u0440\u0432\u0435\u0440\u043e\u0432, \u0438\u043d\u0442\u0435\u0433\u0440\u0430\u0446\u0438\u044f \u0441 AD. \u0427\u0430\u0441\u0442\u044c 2 Cisco ISE: \u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 \u0433\u043e\u0441\u0442\u0435\u0432\u043e\u0433\u043e \u0434\u043e\u0441\u0442\u0443\u043f\u0430 \u043d\u0430 FortiAP. \u0427\u0430\u0441\u0442\u044c 3 \u0412 \u0434\u0430\u043d\u043d\u043e\u0439 \u043f\u0443\u0431\u043b\u0438\u043a\u0430\u0446\u0438\u0438 \u0432\u0430\u0441 \u0436\u0434\u0435\u0442 \u043f\u043e\u0433\u0440\u0443\u0436\u0435\u043d\u0438\u0435 \u0432 \u0433\u043e\u0441\u0442\u0435\u0432\u043e\u0439 \u0434\u043e\u0441\u0442\u0443\u043f, \u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":97568,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-97567","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/cisco-ise-nastrojka-gostevogo-dostupa-na-fortiap-chast-3\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47Cisco ISE: \u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 \u0433\u043e\u0441\u0442\u0435\u0432\u043e\u0433\u043e \u0434\u043e\u0441\u0442\u0443\u043f\u0430 \u043d\u0430 FortiAP. \u0427\u0430\u0441\u0442\u044c 3 | ProHoster\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/cisco-ise-nastrojka-gostevogo-dostupa-na-fortiap-chast-3\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-10-19T12:42:54+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-10-19T12:42:54+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Cisco ISE: Configuring guest access on FortiAP. Part 3 | ProHoster","description":"","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/cisco-ise-nastrojka-gostevogo-dostupa-na-fortiap-chast-3","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47Cisco ISE: \u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 \u0433\u043e\u0441\u0442\u0435\u0432\u043e\u0433\u043e \u0434\u043e\u0441\u0442\u0443\u043f\u0430 \u043d\u0430 FortiAP. \u0427\u0430\u0441\u0442\u044c 3 | ProHoster","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/cisco-ise-nastrojka-gostevogo-dostupa-na-fortiap-chast-3","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-10-19T12:42:54+00:00","article:modified_time":"2020-10-19T12:42:54+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"97567","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 10:17:23","updated":"2022-09-29 01:39:28","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/97567","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=97567"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/97567\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/97568"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=97567"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=97567"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=97567"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}