<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE posture redirect not working in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-posture-redirect-not-working/m-p/1968719#M187685</link>
    <description>&lt;P&gt;ISE v1.1.0.665, 3395 h/w.&lt;/P&gt;&lt;P&gt;Single Admin/Monitor/Policy node.&lt;/P&gt;&lt;P&gt;WS-C3560-48TS&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 12.2(55)SE5&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; C3560-IPBASEK9-M&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For Client Provisioning I created an authorisation policy as follows:&lt;/P&gt;&lt;P&gt;download acl "ACL-POSTURE-REMEDIATION"&lt;/P&gt;&lt;P&gt;apply url redirect "ACL-POSTURE-REDIRECT".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Debug radius" shows all this is downloaded to the switch but:&lt;/P&gt;&lt;P&gt;- Redirect does not work.&lt;/P&gt;&lt;P&gt;- dACL is not applied if the URL redirect is also configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wireshark on the client shows no direct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attached file shows "debug radius" for various combinations of authorisation policy i.e. dACL only, Redirect only, dACL + Redirect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've also attached screen shots of these policies and wireshark.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 02:13:34 GMT</pubDate>
    <dc:creator>grant.maynard</dc:creator>
    <dc:date>2019-03-11T02:13:34Z</dc:date>
    <item>
      <title>ISE posture redirect not working</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-redirect-not-working/m-p/1968719#M187685</link>
      <description>&lt;P&gt;ISE v1.1.0.665, 3395 h/w.&lt;/P&gt;&lt;P&gt;Single Admin/Monitor/Policy node.&lt;/P&gt;&lt;P&gt;WS-C3560-48TS&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 12.2(55)SE5&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; C3560-IPBASEK9-M&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For Client Provisioning I created an authorisation policy as follows:&lt;/P&gt;&lt;P&gt;download acl "ACL-POSTURE-REMEDIATION"&lt;/P&gt;&lt;P&gt;apply url redirect "ACL-POSTURE-REDIRECT".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Debug radius" shows all this is downloaded to the switch but:&lt;/P&gt;&lt;P&gt;- Redirect does not work.&lt;/P&gt;&lt;P&gt;- dACL is not applied if the URL redirect is also configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wireshark on the client shows no direct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attached file shows "debug radius" for various combinations of authorisation policy i.e. dACL only, Redirect only, dACL + Redirect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've also attached screen shots of these policies and wireshark.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:13:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-redirect-not-working/m-p/1968719#M187685</guid>
      <dc:creator>grant.maynard</dc:creator>
      <dc:date>2019-03-11T02:13:34Z</dc:date>
    </item>
    <item>
      <title>ISE posture redirect not working</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-redirect-not-working/m-p/1968720#M187687</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Grant,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks like you are changing the vlan after your client gets an ip address, it seems like the client gets an ip address of &lt;/P&gt;&lt;P&gt;192.168.16.164 and you are changing the vlan over to 516. I wanted to know if that is there isnt an ip to vlan mismatch before you move forward. If 516 is quarantine vlan you may want to start all clients on that vlan and use dynamic vlan assignment through change of authorization once a client becomes compliant. The reason is is that you can use the web portal, or the nac agent to change the ip address once the vlan is changed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik Admani&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Jun 2012 03:51:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-redirect-not-working/m-p/1968720#M187687</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-06-24T03:51:48Z</dc:date>
    </item>
  </channel>
</rss>

