<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE - Central Webauthentication // Guest accouts in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-central-webauthentication-guest-accouts/m-p/1938958#M211902</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okay, I just tried some different things, and after adding these two commands, the redirection works!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip dhcp snooping&lt;/P&gt;&lt;P&gt;ip device tracking&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 09 May 2012 12:19:13 GMT</pubDate>
    <dc:creator>marczacho</dc:creator>
    <dc:date>2012-05-09T12:19:13Z</dc:date>
    <item>
      <title>ISE - Central Webauthentication // Guest accouts</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-central-webauthentication-guest-accouts/m-p/1938954#M211898</link>
      <description>&lt;P&gt;Hi, I'm working with the Cisco ISE as a school project, but I have some problems with the central web authentication. I have followed &lt;A href="https://community.cisco.com/document/71786/configuration-example-central-web-authentication-switch-and-identity-service-engine" target="_blank"&gt;this guide&lt;/A&gt;, and at the moment I have the following two problems:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The redirection does not work, but it seems like the ISE tells the switch to redirect, but nothing happens at the client. (See buttom of the post)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can access the guest webportal by entering the direct url-address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried to trigger the redirect both by a DNS name and by an ip-address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My second problem is my guest users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I create a guest account from the sponsorportal, I can't see the password only stars (****), and I can't figure out if this is a security feature or a bug. Right now I'm working in an offline environment so I don't have access to a SMTP server, so I can't try the email function to get the guest account information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried to create a guest account in the adminportal, but I can't login with it. If I go the authentication logs, I just get an "86020 unknown error".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I run everything in VMware, and I have to go through two switches with a trunk connection, before I can reach the switch I'm working on, therefore I have a bit unusually configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have attached the switch configuration, and a screenshot to show my setup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;sw03#sh auth sess int fa0/5&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface:&amp;nbsp; FastEthernet0/5&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MAC Address:&amp;nbsp; 000c.29ff.28f7&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP Address:&amp;nbsp; Unknown&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; User-Name:&amp;nbsp; 00-0C-29-FF-28-F7&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Status:&amp;nbsp; Authz Success&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Domain:&amp;nbsp; DATA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Security Policy:&amp;nbsp; Should Secure&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Security Status:&amp;nbsp; Unsecure&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper host mode:&amp;nbsp; single-host&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper control dir:&amp;nbsp; both&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Authorized By:&amp;nbsp; Authentication Server&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Vlan Group:&amp;nbsp; N/A&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; URL Redirect ACL:&amp;nbsp; redirect&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; URL Redirect:&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://mz-ise.mz:8443/guestportal/gateway?sessionId=C0A80A020000000C047D8E21&amp;amp;action=cwa" target="_blank"&gt;https://mz-ise.mz:8443/guestportal/gateway?sessionId=C0A80A020000000C047D8E21&amp;amp;action=cwa&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Session timeout:&amp;nbsp; N/A&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Idle timeout:&amp;nbsp; N/A&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Common Session ID:&amp;nbsp; C0A80A020000000C047D8E21&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Acct Session ID:&amp;nbsp; 0x00000014&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Handle:&amp;nbsp; 0x7F00000C&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Runnable methods list:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&amp;nbsp; State&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; mab&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Authc Success&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:04:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-central-webauthentication-guest-accouts/m-p/1938954#M211898</guid>
      <dc:creator>marczacho</dc:creator>
      <dc:date>2019-03-11T02:04:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - Central Webauthentication // Guest accouts</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-central-webauthentication-guest-accouts/m-p/1938955#M211899</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;An ACL could be blocking the redirect if the management interface of the switch and the device are on two separate VLANs.  If the switch is layer three, temporarily create routing on it between the two and see of it works.&lt;/P&gt;&lt;P&gt;Second, a proxy will also mess with URL redirection if it is on a different port than port 80.  on a WLAN controller a proxy should work fine with URL redirection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2012 01:49:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-central-webauthentication-guest-accouts/m-p/1938955#M211899</guid>
      <dc:creator>Alex Pfeil</dc:creator>
      <dc:date>2012-05-09T01:49:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - Central Webauthentication // Guest accouts</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-central-webauthentication-guest-accouts/m-p/1938956#M211900</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also redirect ACLs are the opposite of regular ACLs so can you post the redirect ACL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2012 01:52:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-central-webauthentication-guest-accouts/m-p/1938956#M211900</guid>
      <dc:creator>Alex Pfeil</dc:creator>
      <dc:date>2012-05-09T01:52:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - Central Webauthentication // Guest accouts</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-central-webauthentication-guest-accouts/m-p/1938957#M211901</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Regarding the guest password/login problem, the problem is solved.&lt;BR /&gt;I updated to ISE v1.1, and now that part is working, but I still have the problem with redirect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is my redirect ACL:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip access-list extended redirect&lt;/P&gt;&lt;P&gt; deny&amp;nbsp;&amp;nbsp; ip any host 192.168.10.5 (my ISE ip)&lt;/P&gt;&lt;P&gt; permit tcp any any eq www&lt;/P&gt;&lt;P&gt; permit tcp any any eq 443&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2012 11:12:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-central-webauthentication-guest-accouts/m-p/1938957#M211901</guid>
      <dc:creator>marczacho</dc:creator>
      <dc:date>2012-05-09T11:12:05Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - Central Webauthentication // Guest accouts</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-central-webauthentication-guest-accouts/m-p/1938958#M211902</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okay, I just tried some different things, and after adding these two commands, the redirection works!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip dhcp snooping&lt;/P&gt;&lt;P&gt;ip device tracking&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2012 12:19:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-central-webauthentication-guest-accouts/m-p/1938958#M211902</guid>
      <dc:creator>marczacho</dc:creator>
      <dc:date>2012-05-09T12:19:13Z</dc:date>
    </item>
  </channel>
</rss>

