<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Urgent - NAC+ACS+Web-Auth in Wired environment - https redirection - Certificate Issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/urgent-nac-acs-web-auth-in-wired-environment-https-redirection/m-p/1660128#M256391</link>
    <description>&lt;P&gt;Hi everyone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm seting up an environment which uses Web-Auth for my wired and wireless networks. I have followed the exact same steps in this Cisco page to get it working:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/prod/collateral/iosswrel/ps6537/ps6586/ps6638/app_note_c27-577490.html" target="_blank"&gt;http://www.cisco.com/en/US/prod/collateral/iosswrel/ps6537/ps6586/ps6638/app_note_c27-577490.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm only testing the wired environment right now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I plug a PC to a port, and I try to get access to a randon internet page (for example &lt;A href="https://community.cisco.com/www.cisco.com)" target="_blank"&gt;www.cisco.com)&lt;/A&gt; . It is automatically redirected to authentication page. I type the username and password, but, when authentication passes, it goes automatically to https version of the page, which brings me to the problem. I have to add an exception (continue on this webpage option on IE) to that page in order to continue with the authentication and get the access to the internet. I'm attaching the steps I have to perform:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/1/5/4/52451-1.png" alt="1.png" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/2/5/4/52452-2.png" alt="2.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/3/5/4/52453-3.png" alt="3.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think it is related to Certificate, but I'm not quite sure which or where. I'd like to have some advices from you to avoid this problem. I'm not planning to buy any certificates, so if I could skip the https would be great.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a bunch for your help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Victor Alves&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 01:13:02 GMT</pubDate>
    <dc:creator>vialves</dc:creator>
    <dc:date>2019-03-11T01:13:02Z</dc:date>
    <item>
      <title>Urgent - NAC+ACS+Web-Auth in Wired environment - https redirection - Certificate Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/urgent-nac-acs-web-auth-in-wired-environment-https-redirection/m-p/1660128#M256391</link>
      <description>&lt;P&gt;Hi everyone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm seting up an environment which uses Web-Auth for my wired and wireless networks. I have followed the exact same steps in this Cisco page to get it working:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/prod/collateral/iosswrel/ps6537/ps6586/ps6638/app_note_c27-577490.html" target="_blank"&gt;http://www.cisco.com/en/US/prod/collateral/iosswrel/ps6537/ps6586/ps6638/app_note_c27-577490.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm only testing the wired environment right now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I plug a PC to a port, and I try to get access to a randon internet page (for example &lt;A href="https://community.cisco.com/www.cisco.com)" target="_blank"&gt;www.cisco.com)&lt;/A&gt; . It is automatically redirected to authentication page. I type the username and password, but, when authentication passes, it goes automatically to https version of the page, which brings me to the problem. I have to add an exception (continue on this webpage option on IE) to that page in order to continue with the authentication and get the access to the internet. I'm attaching the steps I have to perform:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/1/5/4/52451-1.png" alt="1.png" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/2/5/4/52452-2.png" alt="2.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/3/5/4/52453-3.png" alt="3.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think it is related to Certificate, but I'm not quite sure which or where. I'd like to have some advices from you to avoid this problem. I'm not planning to buy any certificates, so if I could skip the https would be great.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a bunch for your help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Victor Alves&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:13:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/urgent-nac-acs-web-auth-in-wired-environment-https-redirection/m-p/1660128#M256391</guid>
      <dc:creator>vialves</dc:creator>
      <dc:date>2019-03-11T01:13:02Z</dc:date>
    </item>
    <item>
      <title>Urgent - NAC+ACS+Web-Auth in Wired environment - https redirecti</title>
      <link>https://community.cisco.com/t5/network-access-control/urgent-nac-acs-web-auth-in-wired-environment-https-redirection/m-p/1660129#M256431</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if you don't want an official cert you need to go for http only. But this means that people paswords will transit in clear on the network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's been long time since I tried this but isnt removing "ip http secure-server" doing the trick ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Jul 2011 18:09:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/urgent-nac-acs-web-auth-in-wired-environment-https-redirection/m-p/1660129#M256431</guid>
      <dc:creator>Nicolas Darchis</dc:creator>
      <dc:date>2011-07-11T18:09:57Z</dc:date>
    </item>
    <item>
      <title>Urgent - NAC+ACS+Web-Auth in Wired environment - https redirecti</title>
      <link>https://community.cisco.com/t5/network-access-control/urgent-nac-acs-web-auth-in-wired-environment-https-redirection/m-p/1660130#M256506</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You simply nailed it! Just removed ip http secure-server command and everything is working as a charm!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another question: To get it working with https, I should have a certificate to each access switch I have? A self signed certificate would work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot for your help! A+++&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Jul 2011 18:20:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/urgent-nac-acs-web-auth-in-wired-environment-https-redirection/m-p/1660130#M256506</guid>
      <dc:creator>vialves</dc:creator>
      <dc:date>2011-07-11T18:20:24Z</dc:date>
    </item>
    <item>
      <title>Urgent - NAC+ACS+Web-Auth in Wired environment - https redirecti</title>
      <link>https://community.cisco.com/t5/network-access-control/urgent-nac-acs-web-auth-in-wired-environment-https-redirection/m-p/1660131#M256527</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need a certificate that your client will trust.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Easy way is to buy one from an official source. All PC browsers have a list of the major cert vendors so that's automatically trusted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could issue the certificate yourself also, for free :&lt;/P&gt;&lt;P&gt;-Self signed : the signing authority is the switch ... That means you need all your PCs to trust all your switches. Manual operation ...&lt;/P&gt;&lt;P&gt;-You create an enterprise CA and create a certificate for all your switches : you just need your clients to trust your enterprise CA so that's still a manual task but a simpler one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When laptops are integrated in a domain, it's usually easier to create your CA on windows server and push the certificates to the clients automatically&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jul 2011 06:08:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/urgent-nac-acs-web-auth-in-wired-environment-https-redirection/m-p/1660131#M256527</guid>
      <dc:creator>Nicolas Darchis</dc:creator>
      <dc:date>2011-07-12T06:08:50Z</dc:date>
    </item>
  </channel>
</rss>

