<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CWA redirect failure in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cwa-redirect-failure/m-p/2013450#M290066</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tarik,&lt;/P&gt;&lt;P&gt;Thanks for the suggestion,&lt;/P&gt;&lt;P&gt;I did initially have it set to this, as that was initially logical to me, but when I had that in place you get a session has expired window after the logon has completed, so I thought I would try a couple of other redirects to see if they would work, but thats where I ended up at the initial redirect url that I posted.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 03 Sep 2012 11:06:12 GMT</pubDate>
    <dc:creator>martyn.rees</dc:creator>
    <dc:date>2012-09-03T11:06:12Z</dc:date>
    <item>
      <title>CWA redirect failure</title>
      <link>https://community.cisco.com/t5/network-access-control/cwa-redirect-failure/m-p/2013448#M290019</link>
      <description>&lt;P&gt;I have a situation where DNS cannot be used for redirecting on CWA, so I have had to create a auth profile that has manual entries in it that redirects the guest to the IP address of the guest portal, rather than the DNS name.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The attribute is configured with the following:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;cisco-av-pair = url-redirect=&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://x.x.x.x:8443/guestportal/Login.action" rel="nofollow" target="_blank"&gt;https://x.x.x.x:8443/guestportal/Login.action&lt;/A&gt;&lt;/P&gt;&lt;P&gt;cisco-av-pair = url-redirect-acl=cwa&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The redirection works, and the guest is prompted with a login screen, but as soon as they are authenticated they receive a error page stating that the resource is not found, with the resource being /guestportal. &lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The URL that it is trying to reach is &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://x.x.x.x:8443/guestportal/guest/redir.html" rel="nofollow" target="_blank"&gt;https://x.x.x.x:8443/guestportal/guest/redir.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone managed to configure CWA to use the IP address rather than the DNS name, and go around this issue?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:29:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cwa-redirect-failure/m-p/2013448#M290019</guid>
      <dc:creator>martyn.rees</dc:creator>
      <dc:date>2019-03-11T02:29:25Z</dc:date>
    </item>
    <item>
      <title>Re: CWA redirect failure</title>
      <link>https://community.cisco.com/t5/network-access-control/cwa-redirect-failure/m-p/2013449#M290036</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Martyn,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you try this av-pair instead (substitue only the x.x.x.x and leave the other variables ISE should populate them with the correct session id). Keep in mind DNS is critical but lets see how if the following changes your luck, usually the redirection afterwards is a page that tells the user to retry their original request.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; url-redirect=&lt;A class="jive-link-external-small" href="https://x.x.x.x:8443/guestportal/gateway?sessionId=SessionIdValue&amp;amp;action=cwa" rel="nofollow"&gt;https://x.x.x.x:8443/guestportal/gateway?sessionId=SessionIdValue&amp;amp;action=cwa&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;url-redirect-acl=cwa&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Sep 2012 07:36:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cwa-redirect-failure/m-p/2013449#M290036</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-09-03T07:36:33Z</dc:date>
    </item>
    <item>
      <title>CWA redirect failure</title>
      <link>https://community.cisco.com/t5/network-access-control/cwa-redirect-failure/m-p/2013450#M290066</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tarik,&lt;/P&gt;&lt;P&gt;Thanks for the suggestion,&lt;/P&gt;&lt;P&gt;I did initially have it set to this, as that was initially logical to me, but when I had that in place you get a session has expired window after the logon has completed, so I thought I would try a couple of other redirects to see if they would work, but thats where I ended up at the initial redirect url that I posted.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Sep 2012 11:06:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cwa-redirect-failure/m-p/2013450#M290066</guid>
      <dc:creator>martyn.rees</dc:creator>
      <dc:date>2012-09-03T11:06:12Z</dc:date>
    </item>
    <item>
      <title>CWA redirect failure</title>
      <link>https://community.cisco.com/t5/network-access-control/cwa-redirect-failure/m-p/2013451#M290104</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I understand, you can try opening a TAC case but DNS is the main issue, also do you see two authenticate requests or just the authenticate request to the portal? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Sep 2012 00:40:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cwa-redirect-failure/m-p/2013451#M290104</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-09-05T00:40:26Z</dc:date>
    </item>
    <item>
      <title>Re: CWA redirect failure</title>
      <link>https://community.cisco.com/t5/network-access-control/cwa-redirect-failure/m-p/2013452#M290138</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I see the initial success upon connection and can see the redirect being applied, but then once it is authenticated it shows another entry with a failure and you get the session expired page.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Sep 2012 00:56:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cwa-redirect-failure/m-p/2013452#M290138</guid>
      <dc:creator>martyn.rees</dc:creator>
      <dc:date>2012-09-05T00:56:26Z</dc:date>
    </item>
    <item>
      <title>Re: CWA redirect failure</title>
      <link>https://community.cisco.com/t5/network-access-control/cwa-redirect-failure/m-p/2013453#M290175</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can see that if I allow ISE to populate the redirect URL then a session ID is generated. If I manually specify the radius attribute then a session ID is not generated.&lt;/P&gt;&lt;P&gt;Is there a way then to change the URL that the guest is redirected to so that it isn't the host name?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Sep 2012 01:51:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cwa-redirect-failure/m-p/2013453#M290175</guid>
      <dc:creator>martyn.rees</dc:creator>
      <dc:date>2012-09-05T01:51:46Z</dc:date>
    </item>
    <item>
      <title>Re: CWA redirect failure</title>
      <link>https://community.cisco.com/t5/network-access-control/cwa-redirect-failure/m-p/2013454#M290219</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;I've followed this up with TAC and have confirmation that at the moment&amp;nbsp; you cannot change the DNS name that the user is re-directed to.&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Also in ISE 1.1 you could manually specify the radius attrbute with the IP address and as I was doing and it will give you unique session ID, but in 1.1.1 you cannot do this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Sep 2012 04:19:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cwa-redirect-failure/m-p/2013454#M290219</guid>
      <dc:creator>martyn.rees</dc:creator>
      <dc:date>2012-09-05T04:19:30Z</dc:date>
    </item>
    <item>
      <title>Re: CWA redirect failure</title>
      <link>https://community.cisco.com/t5/network-access-control/cwa-redirect-failure/m-p/2013455#M290261</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Martin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is ths a bug on why this won't work in ISE?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Sep 2012 04:48:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cwa-redirect-failure/m-p/2013455#M290261</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-09-05T04:48:17Z</dc:date>
    </item>
    <item>
      <title>Re: CWA redirect failure</title>
      <link>https://community.cisco.com/t5/network-access-control/cwa-redirect-failure/m-p/2013456#M290294</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The bug for not being able to change the DNS name that the guest is redirected to is here:&lt;/P&gt;&lt;P&gt;&lt;A href="http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCub97631"&gt;http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCub97631&lt;/A&gt;&lt;/P&gt;&lt;P&gt;It's not currently viewable, but should be in the next couple of days apparently.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to find out if the method of manually specifying the radius attribute was deliberatley removed in 1.1.1 or if it is a bug.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Sep 2012 04:51:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cwa-redirect-failure/m-p/2013456#M290294</guid>
      <dc:creator>martyn.rees</dc:creator>
      <dc:date>2012-09-05T04:51:39Z</dc:date>
    </item>
    <item>
      <title>Re: CWA redirect failure</title>
      <link>https://community.cisco.com/t5/network-access-control/cwa-redirect-failure/m-p/2013457#M290329</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any news on this ?, i am having the same issue, the sessionIdValue field is not getting filled out with a session id, when i attempt to manually define the redirect url in the cwa authz result, so ISE does not know the session id when you then log into the guest portal &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Oct 2012 22:43:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cwa-redirect-failure/m-p/2013457#M290329</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2012-10-04T22:43:59Z</dc:date>
    </item>
    <item>
      <title>Re: CWA redirect failure</title>
      <link>https://community.cisco.com/t5/network-access-control/cwa-redirect-failure/m-p/2013458#M290356</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just to share:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I saw a good document on CWA&amp;nbsp; with ISE:&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/docs/DOC-26442"&gt;https://supportforums.cisco.com/docs/DOC-26442&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Sep 2013 09:32:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cwa-redirect-failure/m-p/2013458#M290356</guid>
      <dc:creator>Naveen Kumar</dc:creator>
      <dc:date>2013-09-12T09:32:06Z</dc:date>
    </item>
    <item>
      <title>Re: CWA redirect failure</title>
      <link>https://community.cisco.com/t5/network-access-control/cwa-redirect-failure/m-p/2013459#M290391</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt; text-align: justify; line-height: normal;"&gt;You can configure custom portal to perform Client Provisioning and Posture. If you select this option, the guest login flow performs a CWA and the guest portal will be redirected to Client Provisioning after performing AUP and change password checks. In this case, the posture subsystem performs a CoA to the NAD to re-authenticate the client connection once the posture has been assessed.&lt;/P&gt;&lt;P style="margin-bottom: .0001pt; text-align: justify; line-height: normal;"&gt;If &lt;STRONG&gt;Vlan Dhcp Release &lt;/STRONG&gt;is selected under Multi-Portal Configurations, posture will perform the client side IP release and renew operation. Check the &lt;STRONG&gt;Vlan Dhcp Release &lt;/STRONG&gt;option to refresh Windows clients IP address after VLAN change in both wired or wireless environments for Guest with posture.&lt;/P&gt;&lt;P style="margin-bottom: .0001pt; text-align: justify; line-height: normal;"&gt;This affects the CWA user login flow when the network access during the final authorization switches the guest VLAN to a new VLAN. In this case, the old IP of the guest needs to be released before the VLAN change and a new guest IP needs to be requested through DHCP once the new VLAN access is in place. The Cisco ISE server redirects the guest browser to download an applet to perform the IP release renew operation.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Sep 2013 06:42:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cwa-redirect-failure/m-p/2013459#M290391</guid>
      <dc:creator>Muhammad Munir</dc:creator>
      <dc:date>2013-09-13T06:42:41Z</dc:date>
    </item>
  </channel>
</rss>

