<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE - CWA Redirection in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-cwa-redirection/m-p/2209791#M127008</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The redirection URL is correct. If i copy the redirect URL from the switch and paste it in to my browser, I come to the Guest Portal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks to me that the switch does not inform the client about the redirection...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my setup all the devices is in the same VLAN. Client, ISE, switch, AD servers all have IP in the same IP range.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 18 Sep 2013 14:22:41 GMT</pubDate>
    <dc:creator>hermodfinjord</dc:creator>
    <dc:date>2013-09-18T14:22:41Z</dc:date>
    <item>
      <title>ISE - CWA Redirection</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cwa-redirection/m-p/2209783#M127000</link>
      <description>&lt;P&gt;HI&lt;/P&gt;&lt;P&gt;i am trying to implement guest portal and i have configure the ISE and switch to redirect guests and i see the whole process goes will when i issue &lt;/P&gt;&lt;P&gt;show authentication session interface GigabitEthernet1/0/11&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface:&amp;nbsp; GigabitEthernet1/0/11&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MAC Address:&amp;nbsp; 1078.d2fc.698c&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP Address:&amp;nbsp; 192.168.0.59&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; User-Name:&amp;nbsp; 10-78-D2-FC-69-8C&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Status:&amp;nbsp; Authz Success&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Domain:&amp;nbsp; DATA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper host mode:&amp;nbsp; multi-domain&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper control dir:&amp;nbsp; both&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Authorized By:&amp;nbsp; Authentication Server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Vlan Policy:&amp;nbsp; 81&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ACS ACL:&amp;nbsp; xACSACLx-IP-TEST-WEBAUTH-DACL-519b76ec&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; URL Redirect ACL:&amp;nbsp; ACL-WEBAUTH-REDIRECT&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; URL Redirect:&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://HDOFFISEP01.mycompany.com:8443/guestportal/gateway?sessionId=0A0A6518000000010006F2B5&amp;amp;action=cwa" target="_blank"&gt;https://HDOFFISEP01.mycompany.com:8443/guestportal/gateway?sessionId=0A0A6518000000010006F2B5&amp;amp;action=cwa&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Session timeout:&amp;nbsp; N/A&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Idle timeout:&amp;nbsp; N/A&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Common Session ID:&amp;nbsp; 0A0A6518000000010006F2B5&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Acct Session ID:&amp;nbsp; 0x00000003&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Handle:&amp;nbsp; 0x0D000001&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Runnable methods list:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&amp;nbsp;&amp;nbsp; State&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; mab&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Authc Success&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dot1x&amp;nbsp;&amp;nbsp;&amp;nbsp; Not run&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my problem that the web browser does NOT direct automtically to the portal but it does manually when i copy the URL from the switch, any idea ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;switch configuration &lt;/P&gt;&lt;P&gt;!!!!!!!!!!!!!!!!!!!!!!!!!!!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;boot-start-marker&lt;/P&gt;&lt;P&gt;boot-end-marker&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;logging monitor informational&lt;/P&gt;&lt;P&gt;enable secret 5 $1$PO2h$G1BUFwkbkA8ywc89FhBso/&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;username cisco privilege 15 password 0 cisco&lt;/P&gt;&lt;P&gt;username ise-rad-alive password 0 CICSOISEalive123&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login local local&lt;/P&gt;&lt;P&gt;aaa authentication dot1x default group radius&lt;/P&gt;&lt;P&gt;aaa authorization network default group radius &lt;/P&gt;&lt;P&gt;aaa authorization auth-proxy default group radius &lt;/P&gt;&lt;P&gt;aaa accounting auth-proxy default start-stop group radius&lt;/P&gt;&lt;P&gt;aaa accounting dot1x default start-stop group radius&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa server radius dynamic-author&lt;/P&gt;&lt;P&gt; client 10.10.20.13 server-key myshared&lt;/P&gt;&lt;P&gt; client 10.10.20.14 server-key myshared&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;switch 1 provision ws-c2960s-24ps-l&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip dhcp snooping vlan 1-2000&lt;/P&gt;&lt;P&gt;no ip dhcp snooping information option&lt;/P&gt;&lt;P&gt;ip dhcp snooping&lt;/P&gt;&lt;P&gt;ip domain-name mycompany.com&lt;/P&gt;&lt;P&gt;ip name-server 192.168.10.40&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip device tracking probe use-svi&lt;/P&gt;&lt;P&gt;ip device tracking&lt;/P&gt;&lt;P&gt;ip admission name Webauth proxy http inactivity-time 60&lt;/P&gt;&lt;P&gt;vtp mode transparent&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;epm logging&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dot1x system-auth-control&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;fallback profile Webauth&lt;/P&gt;&lt;P&gt; ip access-group ACL-WEBAUTH-REDIRECT in&lt;/P&gt;&lt;P&gt; ip admission Webauth&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;spanning-tree mode pvst&lt;/P&gt;&lt;P&gt;spanning-tree extend system-id&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0/11&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; switchport voice vlan 93&lt;/P&gt;&lt;P&gt; ip access-group ACL-ALLOW in&lt;/P&gt;&lt;P&gt; authentication event fail action next-method&lt;/P&gt;&lt;P&gt; authentication event server dead action reinitialize vlan 777&lt;/P&gt;&lt;P&gt; authentication event server dead action authorize voice&lt;/P&gt;&lt;P&gt; authentication host-mode multi-domain&lt;/P&gt;&lt;P&gt; authentication order mab dot1x&lt;/P&gt;&lt;P&gt; authentication priority dot1x mab&lt;/P&gt;&lt;P&gt; authentication port-control auto&lt;/P&gt;&lt;P&gt; mab&lt;/P&gt;&lt;P&gt; dot1x pae authenticator&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan80&lt;/P&gt;&lt;P&gt; ip address 10.10.101.24 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip default-gateway 10.10.101.1&lt;/P&gt;&lt;P&gt;ip http server&lt;/P&gt;&lt;P&gt;ip http secure-server&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip access-list extended ACL-AGENT-REDIRECT&lt;/P&gt;&lt;P&gt; remark explicitly prevent DNS from being redirected to address a bug&lt;/P&gt;&lt;P&gt; deny&amp;nbsp;&amp;nbsp; udp any any eq domain&lt;/P&gt;&lt;P&gt; remark redirect HTTP traffic only&lt;/P&gt;&lt;P&gt; permit tcp any any eq www&lt;/P&gt;&lt;P&gt; remark all other traffic will be implicitly denied from the redirection&lt;/P&gt;&lt;P&gt;ip access-list extended ACL-ALLOW&lt;/P&gt;&lt;P&gt; permit ip any any&lt;/P&gt;&lt;P&gt;ip access-list extended ACL-DEFAULT&lt;/P&gt;&lt;P&gt; remark DHCP&lt;/P&gt;&lt;P&gt; permit udp any eq bootpc any eq bootps&lt;/P&gt;&lt;P&gt; remark DNS&lt;/P&gt;&lt;P&gt; permit udp any any eq domain&lt;/P&gt;&lt;P&gt; remark Ping&lt;/P&gt;&lt;P&gt; permit icmp any any&lt;/P&gt;&lt;P&gt; remark PXE / TFTP&lt;/P&gt;&lt;P&gt; permit udp any any eq tftp&lt;/P&gt;&lt;P&gt; remark Drop all the rest&lt;/P&gt;&lt;P&gt; deny&amp;nbsp;&amp;nbsp; ip any any log&lt;/P&gt;&lt;P&gt;ip access-list extended ACL-WEBAUTH-REDIRECT&lt;/P&gt;&lt;P&gt; deny&amp;nbsp;&amp;nbsp; ip any host 10.10.20.13&lt;/P&gt;&lt;P&gt; deny&amp;nbsp;&amp;nbsp; ip any host 10.10.20.14&lt;/P&gt;&lt;P&gt; deny&amp;nbsp;&amp;nbsp; ip any host 192.168.10.43&lt;/P&gt;&lt;P&gt; deny&amp;nbsp;&amp;nbsp; ip any host 192.168.10.40&lt;/P&gt;&lt;P&gt; deny&amp;nbsp;&amp;nbsp; ip any host 192.168.10.41&lt;/P&gt;&lt;P&gt; deny&amp;nbsp;&amp;nbsp; ip any host 192.168.10.42&lt;/P&gt;&lt;P&gt; remark explicitly prevent DNS from being redirected to accommodate certain switches&lt;/P&gt;&lt;P&gt; deny&amp;nbsp;&amp;nbsp; udp any any eq domain&lt;/P&gt;&lt;P&gt; remark redirect all applicable traffic to the ISE Server&lt;/P&gt;&lt;P&gt; permit tcp any any eq www&lt;/P&gt;&lt;P&gt; permit tcp any any eq 443&lt;/P&gt;&lt;P&gt;ip radius source-interface Vlan80 &lt;/P&gt;&lt;P&gt;logging origin-id ip&lt;/P&gt;&lt;P&gt;logging source-interface Vlan80&lt;/P&gt;&lt;P&gt;logging host 10.10.20.11 transport udp port 20514&lt;/P&gt;&lt;P&gt;logging host 10.10.20.12 transport udp port 20514&lt;/P&gt;&lt;P&gt;radius-server attribute 6 on-for-login-auth&lt;/P&gt;&lt;P&gt;radius-server attribute 6 support-multiple&lt;/P&gt;&lt;P&gt;radius-server attribute 8 include-in-access-req&lt;/P&gt;&lt;P&gt;radius-server attribute 25 access-request include&lt;/P&gt;&lt;P&gt;radius-server dead-criteria time 5 tries 3&lt;/P&gt;&lt;P&gt;radius-server host 10.10.20.13 auth-port 1812 acct-port 1813 key myshared&lt;/P&gt;&lt;P&gt;radius-server host 10.10.20.14 auth-port 1812 acct-port 1813 key myshared&lt;/P&gt;&lt;P&gt;radius-server vsa send accounting&lt;/P&gt;&lt;P&gt;radius-server vsa send authentication&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:27:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cwa-redirection/m-p/2209783#M127000</guid>
      <dc:creator>eng.malak</dc:creator>
      <dc:date>2019-03-11T03:27:14Z</dc:date>
    </item>
    <item>
      <title>ISE - CWA Redirection</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cwa-redirection/m-p/2209784#M127001</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does DNS work correctly? Do you have any proxy servers in the way? Can you post the content of the DACL please?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 May 2013 21:23:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cwa-redirection/m-p/2209784#M127001</guid>
      <dc:creator>Richard Atkin</dc:creator>
      <dc:date>2013-05-28T21:23:04Z</dc:date>
    </item>
    <item>
      <title>ISE - CWA Redirection</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cwa-redirection/m-p/2209785#M127002</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;DNS works perfectly , you can ping &lt;A href="https://HDOFFISEP01.mycompany.com:8443/guestportal/gateway?sessionId=0A0A6518000000010006F2B5&amp;amp;action=cwa" rel="nofollow"&gt;HDOFFISEP01.mycompany.com&lt;/A&gt; from the PC and switch&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NO proxy configured on PC&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS ACL: permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;URL Redirect ACL&lt;/P&gt;&lt;P&gt;deny ip any host "ISE server"&lt;/P&gt;&lt;P&gt;deny udp an an eq 53&lt;/P&gt;&lt;P&gt;permit tcp an an eq 80&lt;/P&gt;&lt;P&gt;permit tcp an an eq 443&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 May 2013 21:37:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cwa-redirection/m-p/2209785#M127002</guid>
      <dc:creator>eng.malak</dc:creator>
      <dc:date>2013-05-28T21:37:07Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - CWA Redirection</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cwa-redirection/m-p/2209786#M127003</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When the switch sends a redirect, it has to do it from a configured SVI, in your case vlan 80, even though it spoofs the original destination IP. If your switch tried to route from its vlan 80 interface to your clients on vlan 81, where would it go? Does it have to go off through a firewall?&lt;BR /&gt;If it does, the firewall may be breaking the redirect process.&lt;BR /&gt;Is this the case?&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jun 2013 00:09:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cwa-redirection/m-p/2209786#M127003</guid>
      <dc:creator>bikespace</dc:creator>
      <dc:date>2013-06-06T00:09:58Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - CWA Redirection</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cwa-redirection/m-p/2209787#M127004</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just to help you,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps11640/products_configuration_example09186a0080ba6514.shtml"&gt;http://www.cisco.com/en/US/products/ps11640/products_configuration_example09186a0080ba6514.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jun 2013 02:08:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cwa-redirection/m-p/2209787#M127004</guid>
      <dc:creator>Saurav Lodh</dc:creator>
      <dc:date>2013-06-06T02:08:55Z</dc:date>
    </item>
    <item>
      <title>ISE - CWA Redirection</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cwa-redirection/m-p/2209788#M127005</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Did you find the reason for this error? I have the same problem using a 2960G-8TC-L switch with IOS version &lt;/P&gt;&lt;P&gt;15.0(2)SE4.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No traffic is redirected to the ISE. I have used the same ACL as you have, but with my own ISE ip &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Sep 2013 10:33:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cwa-redirection/m-p/2209788#M127005</guid>
      <dc:creator>hermodfinjord</dc:creator>
      <dc:date>2013-09-18T10:33:34Z</dc:date>
    </item>
    <item>
      <title>ISE - CWA Redirection</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cwa-redirection/m-p/2209789#M127006</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV id="__tbSetup"&gt; &lt;/DIV&gt;&lt;P&gt;Verify that the redirection URL specified in Cisco ISE via Cisco-av pair "URL Redirect" is correct&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;CWA Redirection URL: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://ip:8443/guestportal/gateway?sessionId=SessionIdValue&amp;amp;action=cwa"&gt;https://ip:8443/guestportal/gateway?sessionId=SessionIdValue&amp;amp;action=cwa&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;A name="wp192734"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt; 802.1X Redirection URL: url-redirect=&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://ip:8443/guestportal/gateway?sessionId=SessionIdValue&amp;amp;action=cpp"&gt;https://ip:8443/guestportal/gateway?sessionId=SessionIdValue&amp;amp;action=cpp&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Sep 2013 14:12:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cwa-redirection/m-p/2209789#M127006</guid>
      <dc:creator>Venkatesh Attuluri</dc:creator>
      <dc:date>2013-09-18T14:12:08Z</dc:date>
    </item>
    <item>
      <title>ISE - CWA Redirection</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cwa-redirection/m-p/2209790#M127007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The redirection URL is correct. If i copy the redirect URL from the switch and paste it in to my browser, I come to the Guest Portal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks to me that the switch does not inform the client about the redirection...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my setup all the devices is in the same VLAN. Client, ISE, switch, AD servers all have IP in the same IP range.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Sep 2013 14:20:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cwa-redirection/m-p/2209790#M127007</guid>
      <dc:creator>hermodfinjord</dc:creator>
      <dc:date>2013-09-18T14:20:22Z</dc:date>
    </item>
    <item>
      <title>ISE - CWA Redirection</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cwa-redirection/m-p/2209791#M127008</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The redirection URL is correct. If i copy the redirect URL from the switch and paste it in to my browser, I come to the Guest Portal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks to me that the switch does not inform the client about the redirection...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my setup all the devices is in the same VLAN. Client, ISE, switch, AD servers all have IP in the same IP range.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Sep 2013 14:22:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cwa-redirection/m-p/2209791#M127008</guid>
      <dc:creator>hermodfinjord</dc:creator>
      <dc:date>2013-09-18T14:22:41Z</dc:date>
    </item>
    <item>
      <title>BRO FINALLY YOU RESOLVED THE</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cwa-redirection/m-p/2209792#M127009</link>
      <description>&lt;P&gt;BRO FINALLY YOU RESOLVED THE ISSUE? I HAVE SAME PROBLEM, COPY PASTE MANUAL LINK AND WORK!!&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2014 19:31:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cwa-redirection/m-p/2209792#M127009</guid>
      <dc:creator>claudioparker</dc:creator>
      <dc:date>2014-06-26T19:31:17Z</dc:date>
    </item>
    <item>
      <title>Bro i have same problem,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cwa-redirection/m-p/2209793#M127010</link>
      <description>&lt;P&gt;Bro i have same problem, finally you resolved the issue?&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2014 19:36:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cwa-redirection/m-p/2209793#M127010</guid>
      <dc:creator>claudioparker</dc:creator>
      <dc:date>2014-06-26T19:36:27Z</dc:date>
    </item>
  </channel>
</rss>

