<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Wired guest portal redirect even after authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-wired-guest-portal-redirect-even-after-authentication/m-p/2193190#M177226</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mohannad,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually the as per the configuration it should work, I'm still trying to find out what is what has gone wrong with this configuration. Infact I have tested with 3560 switch with the same config and it worked. only difference here is we used 2960S switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We need to find out why the next Auth policy is not hitting once user is authenticated. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the port configuration and the authen status of the port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ABQT-3FLR-ACC-01#sh running-config interface gig4/0/19&lt;/P&gt;&lt;P&gt;Building configuration...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Current configuration : 427 bytes&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet4/0/19&lt;/P&gt;&lt;P&gt; switchport access vlan 103&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; switchport voice vlan 135&lt;/P&gt;&lt;P&gt; authentication event fail action next-method&lt;/P&gt;&lt;P&gt; authentication host-mode multi-auth&lt;/P&gt;&lt;P&gt; authentication order dot1x mab&lt;/P&gt;&lt;P&gt; authentication priority dot1x mab webauth&lt;/P&gt;&lt;P&gt; authentication port-control auto&lt;/P&gt;&lt;P&gt; authentication violation restrict&lt;/P&gt;&lt;P&gt; mab&lt;/P&gt;&lt;P&gt; dot1x pae authenticator&lt;/P&gt;&lt;P&gt; dot1x timeout tx-period 10&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ABQT-3FLR-ACC-01#&lt;/P&gt;&lt;P&gt;Mar 31 12:32:14.127: %AAA-3-BADSERVERTYPEERROR: Cannot process accounting server type tacacs+ (UNKNOWN)&lt;/P&gt;&lt;P&gt;ABQT-3FLR-ACC-01#&lt;/P&gt;&lt;P&gt;ABQT-3FLR-ACC-01#sh atuh&lt;/P&gt;&lt;P&gt;ABQT-3FLR-ACC-01#sh atu &lt;/P&gt;&lt;P&gt;ABQT-3FLR-ACC-01#sh authe&lt;/P&gt;&lt;P&gt;ABQT-3FLR-ACC-01#sh authentication se&lt;/P&gt;&lt;P&gt;ABQT-3FLR-ACC-01#sh authentication sessions in&lt;/P&gt;&lt;P&gt;ABQT-3FLR-ACC-01#sh authentication sessions interface gi&lt;/P&gt;&lt;P&gt;ABQT-3FLR-ACC-01#sh authentication sessions interface gigabitEthernet 4/0/19&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface:&amp;nbsp; GigabitEthernet4/0/19&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MAC Address:&amp;nbsp; 0015.c5b4.fd4a&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP Address:&amp;nbsp; 10.1.3.23&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; User-Name:&amp;nbsp; 00-15-C5-B4-FD-4A&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Status:&amp;nbsp; Authz Success&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Domain:&amp;nbsp; DATA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper host mode:&amp;nbsp; multi-auth&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper control dir:&amp;nbsp; both&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Authorized By:&amp;nbsp; Authentication Server&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Vlan Policy:&amp;nbsp; N/A&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; URL Redirect ACL:&amp;nbsp; ACL-WEBAUTH-REDIRECT&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; URL Redirect:&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://ABQ-TW-ISE-2.abq.gov.qa:8443/guestportal/gateway?sessionId=AC14011F0000018A32B4D906&amp;amp;action=cwa"&gt;https://ABQ-TW-ISE-2.abq.gov.qa:8443/guestportal/gateway?sessionId=AC14011F0000018A32B4D906&amp;amp;action=cwa&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Session timeout:&amp;nbsp; N/A&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Idle timeout:&amp;nbsp; N/A&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Common Session ID:&amp;nbsp; AC14011F0000018A32B4D906&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Acct Session ID:&amp;nbsp; 0x00000394&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Handle:&amp;nbsp; 0x3E00018B&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Runnable methods list:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&amp;nbsp;&amp;nbsp; State&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dot1x&amp;nbsp;&amp;nbsp;&amp;nbsp; Failed over&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; mab&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Authc Success&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 31 Mar 2013 09:37:50 GMT</pubDate>
    <dc:creator>pemasirid</dc:creator>
    <dc:date>2013-03-31T09:37:50Z</dc:date>
    <item>
      <title>ISE Wired guest portal redirect even after authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wired-guest-portal-redirect-even-after-authentication/m-p/2193184#M176794</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured both Wired and Wireless guest authentication via guest portal. Wireless is working fine, however the when trying with Wired, the redireciton page is keep getting even after user authenticated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not seen the redirection authorization policy in my logs however I can see only the user authentication logs (successful). Attached is my configuration and logging output. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is what I see on the interface&lt;/P&gt;&lt;P&gt;ABQT-3FLR-ACC-01#sh authentication sessions interface gigabitEthernet 4/0/19&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface:&amp;nbsp; GigabitEthernet4/0/19&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MAC Address:&amp;nbsp; a0b3.ccca.2ab1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP Address:&amp;nbsp; 10.1.3.16&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; User-Name:&amp;nbsp; A0-B3-CC-CA-2A-B1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Status:&amp;nbsp; Authz Success&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Domain:&amp;nbsp; DATA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper host mode:&amp;nbsp; multi-auth&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper control dir:&amp;nbsp; both&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Authorized By:&amp;nbsp; Authentication Server&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Vlan Policy:&amp;nbsp; N/A&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; URL Redirect ACL:&amp;nbsp; ACL-WEBAUTH-REDIRECT&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; URL Redirect:&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://xxxx-TW-ISE-2.xxx.xxx.qa:8443/guestportal/gateway?sessionId=AC14011F000001571E52779F&amp;amp;action=cwa" target="_blank"&gt;https://xxxx-TW-ISE-2.xxx.xxx.qa:8443/guestportal/gateway?sessionId=AC14011F000001571E52779F&amp;amp;action=cwa&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Session timeout:&amp;nbsp; N/A&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Idle timeout:&amp;nbsp; N/A&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Common Session ID:&amp;nbsp; AC14011F000001571E52779F&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Acct Session ID:&amp;nbsp; 0x00000309&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Handle:&amp;nbsp; 0xE6000158&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Runnable methods list:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&amp;nbsp;&amp;nbsp; State&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dot1x&amp;nbsp;&amp;nbsp;&amp;nbsp; Failed over&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; mab&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Authc Success&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the ACL&lt;/P&gt;&lt;P&gt;Extended IP access list ACL-WEBAUTH-REDIRECT&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10 deny udp any any eq domain (1344 matches)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 20 deny ip any host 172.20.5.12 (8122 matches)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 30 deny ip any host 172.20.5.14&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 40 permit tcp any any eq www (3124 matches)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 50 permit tcp any any eq 443 (202927 matches)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 60 permit tcp any any eq 8080 (114 matches)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 70 permit ip any any (8056 matches)&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:14:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wired-guest-portal-redirect-even-after-authentication/m-p/2193184#M176794</guid>
      <dc:creator>pemasirid</dc:creator>
      <dc:date>2019-03-11T03:14:28Z</dc:date>
    </item>
    <item>
      <title>ISE Wired guest portal redirect even after authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wired-guest-portal-redirect-even-after-authentication/m-p/2193185#M176852</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you please tell us what is your switch model, also the configratoin on the interface ... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Mar 2013 07:40:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wired-guest-portal-redirect-even-after-authentication/m-p/2193185#M176852</guid>
      <dc:creator>r.mohannad</dc:creator>
      <dc:date>2013-03-28T07:40:23Z</dc:date>
    </item>
    <item>
      <title>ISE Wired guest portal redirect even after authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wired-guest-portal-redirect-even-after-authentication/m-p/2193186#M176911</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, I missed to write the swtich/software details.. here it is:&lt;/P&gt;&lt;P&gt;WS-C2960S-48FPD-L&amp;nbsp; IOS version: 15.0(2)SE1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Mar 2013 12:47:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wired-guest-portal-redirect-even-after-authentication/m-p/2193186#M176911</guid>
      <dc:creator>pemasirid</dc:creator>
      <dc:date>2013-03-28T12:47:43Z</dc:date>
    </item>
    <item>
      <title>ISE Wired guest portal redirect even after authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wired-guest-portal-redirect-even-after-authentication/m-p/2193187#M176961</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try to &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;remove the last policy "Guest Wired Redirect" &lt;/P&gt;&lt;P&gt;change "Wired MAB" policy to be :&lt;/P&gt;&lt;P&gt; "NetworkAccess:UseCase=Hostlookup" and "Session:Posture Status=Unknown" conditions&lt;/P&gt;&lt;P&gt;without Wired_MAB condition &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remove the first two policices and add new one at the top "GUEST" policy:&lt;/P&gt;&lt;P&gt;GUEST if Network Access:UseCase EQUALS Guest Flow then PermitAccess&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;let me know if this works &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Mar 2013 12:45:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wired-guest-portal-redirect-even-after-authentication/m-p/2193187#M176961</guid>
      <dc:creator>r.mohannad</dc:creator>
      <dc:date>2013-03-29T12:45:27Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Wired guest portal redirect even after authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wired-guest-portal-redirect-even-after-authentication/m-p/2193188#M177044</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mohannad,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried with the above changes, but now it seems it does not hit those policies as I see I'm getting default Deny Access authorization policy. Then I enabled previosuly created Wired_MAB and got the login portal and after giving the username/passwords it again redirecting the same login portal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attached is my Authorization policy and logging screen shots. We need to the reason for "Dynamic Authentication Failed" error we see after username/password accepted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Screen shots are attached as stated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 31 Mar 2013 07:39:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wired-guest-portal-redirect-even-after-authentication/m-p/2193188#M177044</guid>
      <dc:creator>pemasirid</dc:creator>
      <dc:date>2013-03-31T07:39:14Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Wired guest portal redirect even after authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wired-guest-portal-redirect-even-after-authentication/m-p/2193189#M177152</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The changes should work. Can you past the interface configration of the switch, please make sure the MAB is enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, make sure in the authentication in the ISE continue if the user was not found as shown in the bellow figure &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/image/gif/paws/113362/web-auth-ise-03.gif"&gt;http://www.cisco.com/image/gif/paws/113362/web-auth-ise-03.gif&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 31 Mar 2013 09:31:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wired-guest-portal-redirect-even-after-authentication/m-p/2193189#M177152</guid>
      <dc:creator>r.mohannad</dc:creator>
      <dc:date>2013-03-31T09:31:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Wired guest portal redirect even after authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wired-guest-portal-redirect-even-after-authentication/m-p/2193190#M177226</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mohannad,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually the as per the configuration it should work, I'm still trying to find out what is what has gone wrong with this configuration. Infact I have tested with 3560 switch with the same config and it worked. only difference here is we used 2960S switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We need to find out why the next Auth policy is not hitting once user is authenticated. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the port configuration and the authen status of the port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ABQT-3FLR-ACC-01#sh running-config interface gig4/0/19&lt;/P&gt;&lt;P&gt;Building configuration...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Current configuration : 427 bytes&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet4/0/19&lt;/P&gt;&lt;P&gt; switchport access vlan 103&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; switchport voice vlan 135&lt;/P&gt;&lt;P&gt; authentication event fail action next-method&lt;/P&gt;&lt;P&gt; authentication host-mode multi-auth&lt;/P&gt;&lt;P&gt; authentication order dot1x mab&lt;/P&gt;&lt;P&gt; authentication priority dot1x mab webauth&lt;/P&gt;&lt;P&gt; authentication port-control auto&lt;/P&gt;&lt;P&gt; authentication violation restrict&lt;/P&gt;&lt;P&gt; mab&lt;/P&gt;&lt;P&gt; dot1x pae authenticator&lt;/P&gt;&lt;P&gt; dot1x timeout tx-period 10&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ABQT-3FLR-ACC-01#&lt;/P&gt;&lt;P&gt;Mar 31 12:32:14.127: %AAA-3-BADSERVERTYPEERROR: Cannot process accounting server type tacacs+ (UNKNOWN)&lt;/P&gt;&lt;P&gt;ABQT-3FLR-ACC-01#&lt;/P&gt;&lt;P&gt;ABQT-3FLR-ACC-01#sh atuh&lt;/P&gt;&lt;P&gt;ABQT-3FLR-ACC-01#sh atu &lt;/P&gt;&lt;P&gt;ABQT-3FLR-ACC-01#sh authe&lt;/P&gt;&lt;P&gt;ABQT-3FLR-ACC-01#sh authentication se&lt;/P&gt;&lt;P&gt;ABQT-3FLR-ACC-01#sh authentication sessions in&lt;/P&gt;&lt;P&gt;ABQT-3FLR-ACC-01#sh authentication sessions interface gi&lt;/P&gt;&lt;P&gt;ABQT-3FLR-ACC-01#sh authentication sessions interface gigabitEthernet 4/0/19&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface:&amp;nbsp; GigabitEthernet4/0/19&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MAC Address:&amp;nbsp; 0015.c5b4.fd4a&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP Address:&amp;nbsp; 10.1.3.23&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; User-Name:&amp;nbsp; 00-15-C5-B4-FD-4A&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Status:&amp;nbsp; Authz Success&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Domain:&amp;nbsp; DATA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper host mode:&amp;nbsp; multi-auth&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper control dir:&amp;nbsp; both&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Authorized By:&amp;nbsp; Authentication Server&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Vlan Policy:&amp;nbsp; N/A&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; URL Redirect ACL:&amp;nbsp; ACL-WEBAUTH-REDIRECT&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; URL Redirect:&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://ABQ-TW-ISE-2.abq.gov.qa:8443/guestportal/gateway?sessionId=AC14011F0000018A32B4D906&amp;amp;action=cwa"&gt;https://ABQ-TW-ISE-2.abq.gov.qa:8443/guestportal/gateway?sessionId=AC14011F0000018A32B4D906&amp;amp;action=cwa&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Session timeout:&amp;nbsp; N/A&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Idle timeout:&amp;nbsp; N/A&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Common Session ID:&amp;nbsp; AC14011F0000018A32B4D906&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Acct Session ID:&amp;nbsp; 0x00000394&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Handle:&amp;nbsp; 0x3E00018B&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Runnable methods list:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&amp;nbsp;&amp;nbsp; State&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dot1x&amp;nbsp;&amp;nbsp;&amp;nbsp; Failed over&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; mab&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Authc Success&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 31 Mar 2013 09:37:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wired-guest-portal-redirect-even-after-authentication/m-p/2193190#M177226</guid>
      <dc:creator>pemasirid</dc:creator>
      <dc:date>2013-03-31T09:37:50Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Wired guest portal redirect even after authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wired-guest-portal-redirect-even-after-authentication/m-p/2193191#M177279</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mohannad,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I found the issue and fixed it and its working perfectly now. &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The issue was on radius dynamic-author key, so I re-configured the key and started working&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa server radius dynamic-author&lt;/P&gt;&lt;P&gt; client X.X.X.X server-key xxxxx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks a lot for all your responses.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 31 Mar 2013 09:52:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wired-guest-portal-redirect-even-after-authentication/m-p/2193191#M177279</guid>
      <dc:creator>pemasirid</dc:creator>
      <dc:date>2013-03-31T09:52:42Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Wired guest portal redirect even after authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wired-guest-portal-redirect-even-after-authentication/m-p/2193192#M177338</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good News pemasirid &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Apr 2013 06:28:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wired-guest-portal-redirect-even-after-authentication/m-p/2193192#M177338</guid>
      <dc:creator>r.mohannad</dc:creator>
      <dc:date>2013-04-01T06:28:27Z</dc:date>
    </item>
  </channel>
</rss>

