<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic It somehow seemed to be a in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-posture-pending/m-p/2973610#M37441</link>
    <description>&lt;P&gt;It somehow seemed to be a routing issue. The customer is doing routing for all VLANs on the core switch but not the one we were testing with. The setup is like this - access switch----&amp;gt;core switch. The default gw of the access switch is the core switch. The core switch has SVIs for all of the other VLANs but not the one we were testing with. Routing for that VLAN is done on the firewall. So I moved the user to another VLAN on the access switch and got the redirection page &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Thanks for your assistance.&lt;/P&gt;</description>
    <pubDate>Sun, 04 Dec 2016 00:53:18 GMT</pubDate>
    <dc:creator>Wesoley</dc:creator>
    <dc:date>2016-12-04T00:53:18Z</dc:date>
    <item>
      <title>ISE Posture Pending</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-pending/m-p/2973605#M37427</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I am newly configuring and testing&amp;nbsp; Posturing/Client Provisioning on ISE.&amp;nbsp; I configured Client_Provisioning Policy with a Posture_Policy.&lt;/P&gt;
&lt;P&gt;The redirection is being pushed to the switch but when the client opens a webpage they are not redirected to the ISE page.&lt;/P&gt;
&lt;P&gt;See configs below&lt;/P&gt;
&lt;P&gt;SW#show authentication sessions interface g1/0/44&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface:&amp;nbsp; GigabitEthernet1/0/44&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MAC Address:&amp;nbsp; 00b5.6d00.6fc3&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP Address:&amp;nbsp; 10.128.32.58&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; User-Name:&amp;nbsp;&amp;nbsp;username&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Status:&amp;nbsp; Authz Success&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Domain:&amp;nbsp; DATA&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper host mode:&amp;nbsp; multi-auth&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper control dir:&amp;nbsp; both&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Authorized By:&amp;nbsp; Authentication Server&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Vlan Policy:&amp;nbsp; N/A&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ACS ACL:&amp;nbsp; xACSACLx-IP-PERMIT_ALL_TRAFFIC-5484c0cc&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; URL Redirect ACL:&amp;nbsp; TAC-Redirect&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; URL Redirect:&amp;nbsp; &lt;A href="https://10.128.1.20:8443/portal/gateway?sessionId=0A80041C00000A053AFFCBAC&amp;amp;portal=a2eef740-7e54-11e4-9ebe-005056bf01c7&amp;amp;action=cpp&amp;amp;token=4d8ad888c678873e7f8455b036b804c5" target="_blank"&gt;https://10.128.1.20:8443/portal/gateway?sessionId=0A80041C00000A053AFFCBAC&amp;amp;portal=a2eef740-7e54-11e4-9ebe-005056bf01c7&amp;amp;action=cpp&amp;amp;token=4d8ad888c678873e7f8455b036b804c5&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Session timeout:&amp;nbsp; N/A&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Idle timeout:&amp;nbsp; N/A&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Common Session ID:&amp;nbsp; 0A80041C00000A053AFFCBAC&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Acct Session ID:&amp;nbsp; 0x00000AF8&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Handle:&amp;nbsp; 0x9F000A06&lt;/P&gt;
&lt;P&gt;Runnable methods list:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&amp;nbsp;&amp;nbsp; State&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dot1x&amp;nbsp;&amp;nbsp;&amp;nbsp; Authc Success&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; mab&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Not run&lt;/P&gt;
&lt;P&gt;Extended IP access list TAC-Redirect&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10 deny udp any eq bootpc any eq bootps&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 20 deny udp any any eq domain&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 30 deny ip any host 10.128.1.20&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 40 deny ip any host 10.129.1.20&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 50 permit tcp any any eq www&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 60 permit tcp any any eq 443&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 70 permit tcp any any eq 8443&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The dynamic ACL xACSACLx-IP-PERMIT_ALL_TRAFFIC-5484c0cc is a permit ip any any&lt;/P&gt;
&lt;P&gt;Any help would be greatly appreciated.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:15:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-pending/m-p/2973605#M37427</guid>
      <dc:creator>Wesoley</dc:creator>
      <dc:date>2019-03-11T07:15:43Z</dc:date>
    </item>
    <item>
      <title>hello ,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-pending/m-p/2973606#M37431</link>
      <description>&lt;P&gt;hello ,&lt;/P&gt;
&lt;P&gt;kindly access any local server web on your LAN . Most probably you will be redirected .&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2016 09:52:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-pending/m-p/2973606#M37431</guid>
      <dc:creator>saifnetzone</dc:creator>
      <dc:date>2016-12-01T09:52:32Z</dc:date>
    </item>
    <item>
      <title>Saifnetzone,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-pending/m-p/2973607#M37435</link>
      <description>&lt;P&gt;Saifnetzone,&lt;/P&gt;
&lt;P&gt;I will try that this morning. I have always been trying to access a public url. However, I was doing a debug yesterday and look at what I was getting.&lt;/P&gt;
&lt;P&gt;http://pastebin.com/4b5gGjR4&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2016 10:52:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-pending/m-p/2973607#M37435</guid>
      <dc:creator>Wesoley</dc:creator>
      <dc:date>2016-12-01T10:52:46Z</dc:date>
    </item>
    <item>
      <title>USE this ACL</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-pending/m-p/2973608#M37439</link>
      <description>&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;ISE Version 2.1&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2016 13:21:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-pending/m-p/2973608#M37439</guid>
      <dc:creator>saifnetzone</dc:creator>
      <dc:date>2016-12-01T13:21:05Z</dc:date>
    </item>
    <item>
      <title>I will try it and let you</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-pending/m-p/2973609#M37440</link>
      <description>&lt;P&gt;I will try it and let you know. What version of ISE are you running?&lt;/P&gt;
&lt;P&gt;What ACL do you have for your DACL?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2016 13:21:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-pending/m-p/2973609#M37440</guid>
      <dc:creator>Wesoley</dc:creator>
      <dc:date>2016-12-01T13:21:06Z</dc:date>
    </item>
    <item>
      <title>It somehow seemed to be a</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-pending/m-p/2973610#M37441</link>
      <description>&lt;P&gt;It somehow seemed to be a routing issue. The customer is doing routing for all VLANs on the core switch but not the one we were testing with. The setup is like this - access switch----&amp;gt;core switch. The default gw of the access switch is the core switch. The core switch has SVIs for all of the other VLANs but not the one we were testing with. Routing for that VLAN is done on the firewall. So I moved the user to another VLAN on the access switch and got the redirection page &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Thanks for your assistance.&lt;/P&gt;</description>
      <pubDate>Sun, 04 Dec 2016 00:53:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-pending/m-p/2973610#M37441</guid>
      <dc:creator>Wesoley</dc:creator>
      <dc:date>2016-12-04T00:53:18Z</dc:date>
    </item>
  </channel>
</rss>

