<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: catalyst 3750 authentication session not showing URL Redirect ACL for MAB with ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/catalyst-3750-authentication-session-not-showing-url-redirect/m-p/3398711#M23354</link>
    <description>&lt;P&gt;did you ever get this fixed? I have same issue on 2960S - the correct authorization policy is matched, but dACL and redirect URLs are not getting to user interface.&lt;/P&gt;</description>
    <pubDate>Wed, 13 Jun 2018 11:32:57 GMT</pubDate>
    <dc:creator>trimmy</dc:creator>
    <dc:date>2018-06-13T11:32:57Z</dc:date>
    <item>
      <title>catalyst 3750 authentication session not showing URL Redirect ACL for MAB with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/catalyst-3750-authentication-session-not-showing-url-redirect/m-p/3039246#M23352</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;
&lt;P&gt;I've strange problem on catalyst 3750 I don't know if connected to the IOS or some missing on the configuration.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I'd like to authenticate some users with MAB-wired, from ISE radius log everithings seems look good, but on the "show authentication sessions" are missing some parameters that usually should appear:&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;EM&gt;SW-3750#sh authentication sessions interface fa1/0/11&lt;/EM&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface:&amp;nbsp; FastEthernet1/0/11&lt;/EM&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MAC Address:&amp;nbsp; 0021.ccd9.37be&lt;/EM&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP Address:&amp;nbsp; 10.40.40.199&lt;/EM&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; User-Name:&amp;nbsp; 00-21-CC-D9-37-BE&lt;/EM&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Status:&amp;nbsp; Authz Success&lt;/EM&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Domain:&amp;nbsp; DATA&lt;/EM&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper host mode:&amp;nbsp; single-host&lt;/EM&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper control dir:&amp;nbsp; both&lt;/EM&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Authorized By:&amp;nbsp; Authentication Server&lt;/EM&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Vlan Policy:&amp;nbsp; N/A&lt;/EM&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Session timeout:&amp;nbsp; N/A&lt;/EM&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Idle timeout:&amp;nbsp; N/A&lt;/EM&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Common Session ID:&amp;nbsp; 0A0A0AFC000000010017381D&lt;/EM&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Acct Session ID:&amp;nbsp; 0x00000002&lt;/EM&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Handle:&amp;nbsp; 0xFD000001&lt;/EM&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;EM&gt;Runnable methods list:&lt;/EM&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&amp;nbsp;&amp;nbsp; State&lt;/EM&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; mab&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Authc Success&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;As you can see, part from URL redirect and URL redirect ACL are not showing!?&lt;/P&gt;
&lt;P&gt;I was thinking some radius and vsa part missing, but on the switch I've:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN style="font-size: 8pt;"&gt;aaa authentication dot1x default group radius&lt;/SPAN&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;EM&gt;aaa server radius dynamic-author&lt;/EM&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;EM&gt;&amp;nbsp;client 10.20.20.200 server-key estremo&lt;/EM&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;EM&gt;&amp;nbsp;auth-type all&lt;/EM&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;EM&gt;&lt;SPAN style="font-size: 8pt;"&gt;radius-server host 10.20.20.200 auth-port 1645 acct-port 1646&lt;/SPAN&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;SPAN style="font-size: 8pt;"&gt;radius-server key xxxxxx&lt;/SPAN&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;SPAN style="font-size: 8pt;"&gt;radius-server vsa send accounting&lt;/SPAN&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;SPAN style="font-size: 8pt;"&gt;radius-server vsa send authentication&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN style="font-size: 8pt;"&gt;interface FastEthernet1/0/11&lt;BR /&gt;&amp;nbsp;description GUEST&lt;BR /&gt;&amp;nbsp;switchport access vlan 40&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;authentication order mab&lt;BR /&gt;&amp;nbsp;authentication priority mab&lt;BR /&gt;&amp;nbsp;authentication port-control auto&lt;BR /&gt;&amp;nbsp;authentication periodic&lt;BR /&gt;&amp;nbsp;authentication timer reauthenticate server&lt;BR /&gt;&amp;nbsp;mab&lt;BR /&gt;&amp;nbsp;dot1x pae authenticator&lt;BR /&gt;&amp;nbsp;dot1x max-req 10&lt;BR /&gt;&amp;nbsp;dot1x max-reauth-req 10&lt;BR /&gt;&amp;nbsp;spanning-tree portfast&lt;BR /&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN style="font-size: 8pt;"&gt;SW-3750#sh aaa servers&lt;BR /&gt;&lt;BR /&gt;RADIUS: id 1, priority 1, host 10.20.20.200, auth-port 1645, acct-port 1646&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; State: current UP, duration 3192s, previous duration 0s&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Dead: total time 0s, count 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Quarantined: No&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Authen: request 1, timeouts 0&lt;BR /&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN style="font-size: 8pt;"&gt;dot1x system-auth-control&lt;BR /&gt;dot1x critical eapol&lt;BR /&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN style="font-size: 8pt;"&gt;ip device tracking&lt;BR /&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN style="font-size: 8pt;"&gt;ip http server&lt;BR /&gt;ip http secure-server&lt;BR /&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;BR /&gt;ip access-list extended ACL_WEBAUTH_REDIRECT&lt;BR /&gt;&amp;nbsp;deny&amp;nbsp;&amp;nbsp; ip any host 10.20.20.200&lt;BR /&gt;&amp;nbsp;deny&amp;nbsp;&amp;nbsp; udp any any eq domain&lt;BR /&gt;&amp;nbsp;permit tcp any any eq www&lt;BR /&gt;&amp;nbsp;permit tcp any any eq 443&lt;BR /&gt;&amp;nbsp;permit tcp any any eq 8443&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;On the ISE monitoring, auth seems send the correct AV parameters:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3 class="title"&gt;Result&lt;/H3&gt;
&lt;TABLE class="content_table" style="table-layout: fixed;" border="0"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="31%"&gt;User-Name&lt;/TD&gt;
&lt;TD id="eapKey" style="word-wrap: break-word;" width="69%"&gt;00-21-CC-D9-37-BE&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="31%"&gt;State&lt;/TD&gt;
&lt;TD id="eapKey" style="word-wrap: break-word;" width="69%"&gt;ReauthSession:0A0A0AFC000000010017381D&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="31%"&gt;Class&lt;/TD&gt;
&lt;TD id="eapKey" style="word-wrap: break-word;" width="69%"&gt;CACS:0A0A0AFC000000010017381D:ise1/280058218/272&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="31%"&gt;cisco-av-pair&lt;/TD&gt;
&lt;TD id="eapKey" style="word-wrap: break-word;" width="69%"&gt;url-redirect-acl=ACL_WEBAUTH_REDIRECT&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="31%"&gt;cisco-av-pair&lt;/TD&gt;
&lt;TD id="eapKey" style="word-wrap: break-word;" width="69%"&gt;url-redirect=&lt;A href="https://ise1.estremo.local:8443/portal/gateway?sessionId=0A0A0AFC000000010017381D&amp;amp;portal=a692c530-2230-11e6-99ab-005056bf55e0&amp;amp;action=cwa&amp;amp;token=e5afe6a346055cbaca8dab304e3541af" target="_blank"&gt;https://ise1.estremo.local:8443/portal/gateway?sessionId=0A0A0AFC000000010017381D&amp;amp;portal=a692c530-2230-11e6-99ab-005056bf55e0&amp;amp;action=cwa&amp;amp;token=e5afe6a346055cbaca8dab304e3541af&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="31%"&gt;cisco-av-pair&lt;/TD&gt;
&lt;TD id="eapKey" style="word-wrap: break-word;" width="69%"&gt;ACS:CiscoSecure-Defined-ACL=#ACSACL#-IP-pre-webauth-ACL-58da9681&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="31%"&gt;cisco-av-pair&lt;/TD&gt;
&lt;TD id="eapKey" style="word-wrap: break-word;" width="69%"&gt;profile-name=Unknown&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="31%"&gt;LicenseTypes&lt;/TD&gt;
&lt;TD id="eapKey" style="word-wrap: break-word;" width="69%"&gt;Base license consumed&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN style="font-size: 12pt;"&gt;A&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN style="font-size: 12pt;"&gt;nd Policy auth auth are configured in attachement&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;EM&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN style="font-size: 12pt;"&gt;Do you have some ideas?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN style="font-size: 12pt;"&gt;regards&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:34:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/catalyst-3750-authentication-session-not-showing-url-redirect/m-p/3039246#M23352</guid>
      <dc:creator>teatrodelsogno</dc:creator>
      <dc:date>2019-03-11T07:34:47Z</dc:date>
    </item>
    <item>
      <title>Anybody? :-)</title>
      <link>https://community.cisco.com/t5/network-access-control/catalyst-3750-authentication-session-not-showing-url-redirect/m-p/3039247#M23353</link>
      <description>&lt;P&gt;Anybody? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 21:01:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/catalyst-3750-authentication-session-not-showing-url-redirect/m-p/3039247#M23353</guid>
      <dc:creator>teatrodelsogno</dc:creator>
      <dc:date>2017-03-29T21:01:13Z</dc:date>
    </item>
    <item>
      <title>Re: catalyst 3750 authentication session not showing URL Redirect ACL for MAB with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/catalyst-3750-authentication-session-not-showing-url-redirect/m-p/3398711#M23354</link>
      <description>&lt;P&gt;did you ever get this fixed? I have same issue on 2960S - the correct authorization policy is matched, but dACL and redirect URLs are not getting to user interface.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jun 2018 11:32:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/catalyst-3750-authentication-session-not-showing-url-redirect/m-p/3398711#M23354</guid>
      <dc:creator>trimmy</dc:creator>
      <dc:date>2018-06-13T11:32:57Z</dc:date>
    </item>
    <item>
      <title>Re: catalyst 3750 authentication session not showing URL Redirect ACL for MAB with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/catalyst-3750-authentication-session-not-showing-url-redirect/m-p/3398745#M23355</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/290377"&gt;@trimmy&lt;/a&gt; post your configuration please. This is an old thread but from the output provided it looks like the "aaa authorization...." commands are missing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jun 2018 12:21:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/catalyst-3750-authentication-session-not-showing-url-redirect/m-p/3398745#M23355</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-06-13T12:21:00Z</dc:date>
    </item>
  </channel>
</rss>

