<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.4 CWA Guest portal redirection on distributed deployment in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-4-cwa-guest-portal-redirection-on-distributed-deployment/m-p/3744392#M25090</link>
    <description>&lt;P&gt;In previous version I used only ONE ise and this setup that I am trying to configure CWA is a distributed deployment so there is difference.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 12 Nov 2018 12:27:18 GMT</pubDate>
    <dc:creator>walwar</dc:creator>
    <dc:date>2018-11-12T12:27:18Z</dc:date>
    <item>
      <title>ISE 2.4 CWA Guest portal redirection on distributed deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-cwa-guest-portal-redirection-on-distributed-deployment/m-p/3743893#M25079</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We're using two ISE Prim/Seco and I am trying to configure wired guest portal on eth1 (I know if I use port eth0 ISE will choose its hostname i.e ise1.example.com/ise2.example.com) the redirection works as long as it's not using any fqdn. I tried to configure to use static ip/fqdn in authorization profile but that didn't work. so I tried the ip host as following and this didn't work either. In both cases the client doesn't redirect but when I change the fqdn to ip in the browser it works just fine.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;ip host 10.1.1.190 guests guests.exammple.com
ip host 10.1.1.191 guests guests.exammple.com&lt;/PRE&gt;
&lt;P&gt;&lt;BR /&gt;In my previous setup (2.3) with one ISE it worked fine to use a static&amp;nbsp;fqdn in the authorization profile and client were redirected correctly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help or hint would be very much appreciated!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 08:51:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-cwa-guest-portal-redirection-on-distributed-deployment/m-p/3743893#M25079</guid>
      <dc:creator>walwar</dc:creator>
      <dc:date>2019-03-11T08:51:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 CWA Guest portal redirection on distributed deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-cwa-guest-portal-redirection-on-distributed-deployment/m-p/3744316#M25085</link>
      <description>&lt;P&gt;If this is something working in a previous release then should be working through tac&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV dir="ltr"&gt;Did you use this?&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/117620-configure-ISE-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/117620-configure-ISE-00.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;why can’t you use dynamic redirection&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Nov 2018 12:28:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-cwa-guest-portal-redirection-on-distributed-deployment/m-p/3744316#M25085</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-11-12T12:28:57Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 CWA Guest portal redirection on distributed deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-cwa-guest-portal-redirection-on-distributed-deployment/m-p/3744392#M25090</link>
      <description>&lt;P&gt;In previous version I used only ONE ise and this setup that I am trying to configure CWA is a distributed deployment so there is difference.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Nov 2018 12:27:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-cwa-guest-portal-redirection-on-distributed-deployment/m-p/3744392#M25090</guid>
      <dc:creator>walwar</dc:creator>
      <dc:date>2018-11-12T12:27:18Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 CWA Guest portal redirection on distributed deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-cwa-guest-portal-redirection-on-distributed-deployment/m-p/3745655#M25095</link>
      <description>&lt;P&gt;Did you mean the IP address in URL of Gig1 or Gig0 works?&amp;nbsp; In your portal config did you put a tick against Gig1 interface?&amp;nbsp; Stupid question - just checking ..&lt;/P&gt;
&lt;P&gt;Could it be that the client is somehow not resolving the DNS entry for that FQDN?&amp;nbsp; e.g. I had cases where I was testing something specific and I had to hard code my etc\hosts file for a while.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Other than that I can't think why this wouldn't work. Does adding an IP host command require application restart (or reboot)?&lt;/P&gt;</description>
      <pubDate>Tue, 13 Nov 2018 10:24:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-cwa-guest-portal-redirection-on-distributed-deployment/m-p/3745655#M25095</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2018-11-13T10:24:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 CWA Guest portal redirection on distributed deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-cwa-guest-portal-redirection-on-distributed-deployment/m-p/3746364#M25100</link>
      <description>&lt;P&gt;Jason, the link you provided worked like a dream, and happy it solved my problem, though when those authorizations rules are active all clients are hitting the guest rule and all are redirected to guest portal even the domain pc which they shouldn't but that is another problem and nothing have to do with this thread, therefore I'll mark it as solved.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;, yes, the gig 1 interface is ticked otherwise the traffic will go through gig 0 which we do not want to. Unfortunately the ip host restarts the application. It feels like I am doing something wrong but not sure what... I guess that is a learning curve as well. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Nov 2018 09:18:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-cwa-guest-portal-redirection-on-distributed-deployment/m-p/3746364#M25100</guid>
      <dc:creator>walwar</dc:creator>
      <dc:date>2018-11-14T09:18:07Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 CWA Guest portal redirection on distributed deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-cwa-guest-portal-redirection-on-distributed-deployment/m-p/3746599#M25103</link>
      <description>Glad to here perhaps you can match your GUEST SSID or WLAN ID as well in those authorization rules. Like in this article &lt;A href="https://www.network-node.com/blog/2017/10/7/ise-23-new-policy-sets" target="_blank"&gt;https://www.network-node.com/blog/2017/10/7/ise-23-new-policy-sets&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 14 Nov 2018 15:07:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-cwa-guest-portal-redirection-on-distributed-deployment/m-p/3746599#M25103</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-11-14T15:07:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 CWA Guest portal redirection on distributed deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-cwa-guest-portal-redirection-on-distributed-deployment/m-p/3747180#M25107</link>
      <description>&lt;P&gt;It's for my wired guests not wireless.&lt;/P&gt;
&lt;P&gt;Well my VLAN ID was already in the authorization rules I created for both of my ISE and honestly I think that was what made all users, PC, etc to be redirected to the urls. And now I can't test as those are in production now. I will definitely test it the next&amp;nbsp;maintenance window and update here.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks though for taking the time and helping out, much appreciated!&lt;/P&gt;</description>
      <pubDate>Thu, 15 Nov 2018 08:13:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-cwa-guest-portal-redirection-on-distributed-deployment/m-p/3747180#M25107</guid>
      <dc:creator>walwar</dc:creator>
      <dc:date>2018-11-15T08:13:29Z</dc:date>
    </item>
  </channel>
</rss>

