<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic It looks like your servers in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/redirect-posture-cisco-ise/m-p/2828474#M41042</link>
    <description>&lt;P&gt;It looks like your servers are bouncing...perhaps you are losing connectivity between the switches and the ISE servers. Also, one of your server's IP is 1.1.1.166? Is that correct?&lt;/P&gt;
&lt;P&gt;Also, in your config I see that you have defined your ISE servers:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;&lt;SPAN&gt;aaa group server radius ISE&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;server name ISE1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;server name ISE2&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN&gt;But I don't see any configurations with regards to what ISE1 and ISE2 actually are. You should have something like this:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;radius server &lt;B&gt;ISE_server_1_name&lt;/B&gt;&lt;/P&gt;
&lt;P style="margin: 0in; margin-left: .375in; font-family: Calibri; font-size: 11.0pt;"&gt;address ipv4 &lt;B&gt;ISE_server_1_ip&lt;/B&gt; auth-port 1812 acct-port 1813&lt;/P&gt;
&lt;P style="margin: 0in; margin-left: .375in; font-family: Calibri; font-size: 11.0pt;"&gt;automate-tester username ise-test idle-time 10&lt;/P&gt;
&lt;P style="margin: 0in; margin-left: .375in; font-family: Calibri; font-size: 11.0pt;"&gt;key &lt;B&gt;Aaa_shared_key&lt;/B&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;radius server &lt;B&gt;ISE_server_2_name&lt;/B&gt;&lt;/P&gt;
&lt;P style="margin: 0in; margin-left: .375in; font-family: Calibri; font-size: 11.0pt;"&gt;address &lt;B&gt;ipv4 ISE_server_2_ip&lt;/B&gt;&amp;nbsp; auth-port 1812 acct-port 1813&lt;/P&gt;
&lt;P style="margin: 0in; margin-left: .375in; font-family: Calibri; font-size: 11.0pt;"&gt;automate-tester username ise-test idle-time 10&lt;/P&gt;
&lt;P style="margin: 0in; margin-left: .375in; font-family: Calibri; font-size: 11.0pt;"&gt;key &lt;B&gt;Aaa_shared_key&lt;/B&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 14 Jan 2016 23:59:59 GMT</pubDate>
    <dc:creator>nspasov</dc:creator>
    <dc:date>2016-01-14T23:59:59Z</dc:date>
    <item>
      <title>Redirect Posture Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/redirect-posture-cisco-ise/m-p/2828469#M41037</link>
      <description>&lt;P&gt;Cisco ISE 1.3.&lt;/P&gt;
&lt;P&gt;Problem:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Some workstations are not doing posture, after observation noticed that the switches are to redirect to the ISE standalone (Secondary), but&amp;nbsp;the primary be active.&lt;/P&gt;
&lt;P&gt;At this time turn off&amp;nbsp;the secundary to return to normal operation.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Does anyone have any idea of this problem ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Port configuration&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;interface GigabitEthernet X/0/60&lt;BR /&gt; switchport access vlan&amp;nbsp;111&lt;BR /&gt; switchport mode access&lt;BR /&gt; switchport voice vlan&amp;nbsp;222&lt;BR /&gt; power inline auto max 15400&lt;BR /&gt; authentication event fail action next-method&lt;BR /&gt; authentication event server dead action authorize&lt;BR /&gt; authentication event server alive action reinitialize&lt;BR /&gt; authentication host-mode multi-auth&lt;BR /&gt; authentication order dot1x mab&lt;BR /&gt; authentication priority dot1x mab&lt;BR /&gt; authentication port-control auto&lt;BR /&gt; authentication violation restrict&lt;BR /&gt; mab&lt;BR /&gt; dot1x pae authenticator&lt;BR /&gt; dot1x timeout tx-period 10&lt;BR /&gt; spanning-tree portfast&lt;BR /&gt; spanning-tree bpduguard enable&lt;BR /&gt;!&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;See attached.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:23:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/redirect-posture-cisco-ise/m-p/2828469#M41037</guid>
      <dc:creator>Emerson Oliveira</dc:creator>
      <dc:date>2019-03-11T06:23:09Z</dc:date>
    </item>
    <item>
      <title>Can you post your aaa and</title>
      <link>https://community.cisco.com/t5/network-access-control/redirect-posture-cisco-ise/m-p/2828470#M41038</link>
      <description>&lt;P&gt;Can you post your&amp;nbsp;&lt;STRONG&gt;aaa&amp;nbsp;&lt;/STRONG&gt;and&amp;nbsp;&lt;STRONG&gt;radius&amp;nbsp;&lt;/STRONG&gt;configs and also post the&amp;nbsp;&lt;STRONG&gt;posture ACL&amp;nbsp;&lt;/STRONG&gt;config.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jan 2016 21:37:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/redirect-posture-cisco-ise/m-p/2828470#M41038</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2016-01-12T21:37:28Z</dc:date>
    </item>
    <item>
      <title>Switch Radius</title>
      <link>https://community.cisco.com/t5/network-access-control/redirect-posture-cisco-ise/m-p/2828471#M41039</link>
      <description>&lt;P&gt;Switch Radius&lt;/P&gt;
&lt;P&gt;aaa group server radius ISE&lt;BR /&gt;&amp;nbsp;server name ISE1&lt;BR /&gt;&amp;nbsp;server name ISE2&lt;BR /&gt;!&lt;BR /&gt;aaa authentication dot1x default group ISE&lt;BR /&gt;aaa authorization network default group ISE&lt;BR /&gt;aaa authorization network auth-list group ISE&lt;BR /&gt;aaa authorization auth-proxy default group ISE&lt;BR /&gt;aaa accounting update periodic 5&lt;BR /&gt;aaa accounting auth-proxy default start-stop group ISE&lt;BR /&gt;aaa accounting dot1x default start-stop group ISE&lt;BR /&gt;aaa accounting network default start-stop group ISE&lt;BR /&gt;!&lt;BR /&gt;aaa server radius dynamic-author&lt;BR /&gt;&amp;nbsp;client 1.1.1.166 server-key 7 143x012E3x3B953Agt32763&lt;BR /&gt;&amp;nbsp;client 10.0.0.4 server-key 7 0726x2697Dx6002Bgt45&lt;BR /&gt;!&lt;BR /&gt;aaa session-id common&lt;BR /&gt;clock timezone&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Switch RACL&lt;/P&gt;
&lt;P&gt;ip access-list extended RACL-POSTURE&lt;BR /&gt;&amp;nbsp;deny&amp;nbsp;&amp;nbsp; icmp any any&lt;BR /&gt;&amp;nbsp;deny&amp;nbsp;&amp;nbsp; udp any any eq domain&lt;BR /&gt;&amp;nbsp;deny&amp;nbsp;&amp;nbsp; udp any eq bootpc any eq bootps&lt;BR /&gt;&amp;nbsp;deny&amp;nbsp;&amp;nbsp; tcp any eq 3389 any&lt;BR /&gt;&amp;nbsp;deny&amp;nbsp;&amp;nbsp; tcp any eq 6129 any&lt;BR /&gt;&amp;nbsp;remark ISE&lt;BR /&gt;&amp;nbsp;deny&amp;nbsp;&amp;nbsp; ip any host 1.1.1.166&lt;BR /&gt;&amp;nbsp;deny&amp;nbsp;&amp;nbsp; ip any host 10.0.0.4&lt;BR /&gt;&amp;nbsp;ip access-list extended RACL-WEBAUTH&lt;BR /&gt;&amp;nbsp;remark DHCP e DNS&lt;BR /&gt;&amp;nbsp;deny&amp;nbsp;&amp;nbsp; udp any any eq domain&lt;BR /&gt;&amp;nbsp;deny&amp;nbsp;&amp;nbsp; udp any eq bootpc any eq bootps&lt;BR /&gt;&amp;nbsp;remark Cisco ISE&lt;BR /&gt;&amp;nbsp;deny&amp;nbsp;&amp;nbsp; ip any host 1.1.1.166&lt;BR /&gt;&amp;nbsp;deny&amp;nbsp;&amp;nbsp; ip any host 10.0.0.4&lt;BR /&gt;&amp;nbsp;permit ip any any&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;In cisco ISE I have "Downloadable ACL"&lt;/P&gt;
&lt;P&gt;permit ip any any&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2016 11:21:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/redirect-posture-cisco-ise/m-p/2828471#M41039</guid>
      <dc:creator>Emerson Oliveira</dc:creator>
      <dc:date>2016-01-13T11:21:26Z</dc:date>
    </item>
    <item>
      <title>Can you also post some screen</title>
      <link>https://community.cisco.com/t5/network-access-control/redirect-posture-cisco-ise/m-p/2828472#M41040</link>
      <description>&lt;P&gt;Can you also post some screen shots of your authorization profiles?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Also, which ACL do you use for the posture redirection?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2016 19:27:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/redirect-posture-cisco-ise/m-p/2828472#M41040</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2016-01-14T19:27:17Z</dc:date>
    </item>
    <item>
      <title>I used 802.1x and checked</title>
      <link>https://community.cisco.com/t5/network-access-control/redirect-posture-cisco-ise/m-p/2828473#M41041</link>
      <description>&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 10pt;"&gt;I used 802.1x and checked some switches with radius problem.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 10pt;"&gt;Jan 14 11:39:58.343 BRV: %RADIUS-4-RADIUS_DEAD: RADIUS server 1.1.1.166:1812,1813 is not responding.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 10pt;"&gt;Jan 14 11:40:03.843 BRV: %RADIUS-4-RADIUS_DEAD: RADIUS server 10.0.0.4:1812,1813 is not responding.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 10pt;"&gt;Jan 14 11:40:07.545 BRV: %RADIUS-4-RADIUS_ALIVE: RADIUS server 1.1.1.166:1812,1813 is being marked alive.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: 'Calibri','sans-serif'; font-size: 12pt;"&gt;Jan 14 12:10:03.930 BRV: %RADIUS-4-RADIUS_ALIVE: RADIUS server 10.0.0.4:1812,1813 is being marked alive.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2016 20:39:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/redirect-posture-cisco-ise/m-p/2828473#M41041</guid>
      <dc:creator>Emerson Oliveira</dc:creator>
      <dc:date>2016-01-14T20:39:05Z</dc:date>
    </item>
    <item>
      <title>It looks like your servers</title>
      <link>https://community.cisco.com/t5/network-access-control/redirect-posture-cisco-ise/m-p/2828474#M41042</link>
      <description>&lt;P&gt;It looks like your servers are bouncing...perhaps you are losing connectivity between the switches and the ISE servers. Also, one of your server's IP is 1.1.1.166? Is that correct?&lt;/P&gt;
&lt;P&gt;Also, in your config I see that you have defined your ISE servers:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;&lt;SPAN&gt;aaa group server radius ISE&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;server name ISE1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;server name ISE2&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN&gt;But I don't see any configurations with regards to what ISE1 and ISE2 actually are. You should have something like this:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;radius server &lt;B&gt;ISE_server_1_name&lt;/B&gt;&lt;/P&gt;
&lt;P style="margin: 0in; margin-left: .375in; font-family: Calibri; font-size: 11.0pt;"&gt;address ipv4 &lt;B&gt;ISE_server_1_ip&lt;/B&gt; auth-port 1812 acct-port 1813&lt;/P&gt;
&lt;P style="margin: 0in; margin-left: .375in; font-family: Calibri; font-size: 11.0pt;"&gt;automate-tester username ise-test idle-time 10&lt;/P&gt;
&lt;P style="margin: 0in; margin-left: .375in; font-family: Calibri; font-size: 11.0pt;"&gt;key &lt;B&gt;Aaa_shared_key&lt;/B&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;radius server &lt;B&gt;ISE_server_2_name&lt;/B&gt;&lt;/P&gt;
&lt;P style="margin: 0in; margin-left: .375in; font-family: Calibri; font-size: 11.0pt;"&gt;address &lt;B&gt;ipv4 ISE_server_2_ip&lt;/B&gt;&amp;nbsp; auth-port 1812 acct-port 1813&lt;/P&gt;
&lt;P style="margin: 0in; margin-left: .375in; font-family: Calibri; font-size: 11.0pt;"&gt;automate-tester username ise-test idle-time 10&lt;/P&gt;
&lt;P style="margin: 0in; margin-left: .375in; font-family: Calibri; font-size: 11.0pt;"&gt;key &lt;B&gt;Aaa_shared_key&lt;/B&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2016 23:59:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/redirect-posture-cisco-ise/m-p/2828474#M41042</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2016-01-14T23:59:59Z</dc:date>
    </item>
    <item>
      <title>IP Example:1.1.1.166 (Fake IP</title>
      <link>https://community.cisco.com/t5/network-access-control/redirect-posture-cisco-ise/m-p/2828475#M41043</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;IP Example:1.1.1.166 (Fake IP)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Show run in my Switch &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;aaa group server radius ISE&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;server name ISE1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;server name ISE2&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;aaa authentication dot1x default group ISE&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;aaa authorization network default group ISE &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;aaa authorization network auth-list group ISE &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;aaa authorization auth-proxy default group ISE &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;aaa accounting update periodic 5&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;aaa accounting auth-proxy default start-stop group ISE&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;aaa accounting dot1x default start-stop group ISE&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;aaa accounting network default start-stop group ISE&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;aaa server radius dynamic-author&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;client 1.1.1.166 server-key 7 XXXXXXXXXXXXXXXXXXXXXXXX&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;client 10.0.0.4 server-key 7 XXXXXXXXXXXXXXXXXXXXXXXXXX&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;aaa session-id common&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;interface GigabitEthernet X/0/X&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;switchport access vlan 111&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;switchport mode access&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;switchport voice vlan 222&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;authentication event fail action next-method&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;authentication event server dead action authorize &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;authentication event server alive action reinitialize &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;authentication host-mode multi-auth&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;authentication order dot1x mab&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;authentication priority dot1x mab&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;authentication port-control auto&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;authentication violation restrict&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;mab&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;dot1x pae authenticator&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;dot1x timeout tx-period 10&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;spanning-tree portfast&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;spanning-tree bpduguard enable&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;ip access-list extended RACL-POSTURE&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;deny&amp;nbsp;&amp;nbsp; icmp any any&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;deny&amp;nbsp;&amp;nbsp; udp any any eq domain&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;deny&amp;nbsp;&amp;nbsp; udp any eq bootpc any eq bootps&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;deny&amp;nbsp;&amp;nbsp; tcp any eq 3389 any&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;deny&amp;nbsp;&amp;nbsp; tcp any eq 6129 any&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;remark ISE&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;deny&amp;nbsp;&amp;nbsp; ip any host 1.1.1.166&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;deny&amp;nbsp;&amp;nbsp; ip any host 10.0.0.4&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;permit ip any any&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;ip access-list extended RACL-WEBAUTH&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;remark DHCP e DNS&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;deny&amp;nbsp;&amp;nbsp; udp any any eq domain&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;deny&amp;nbsp;&amp;nbsp; udp any eq bootpc any eq bootps&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;remark Cisco ISE&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;deny&amp;nbsp;&amp;nbsp; ip any host 1.1.1.166&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;deny&amp;nbsp;&amp;nbsp; ip any host 10.0.0.4&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;permit ip any any&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;logging trap warnings&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;logging origin-id ip&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;logging source-interface Vlan465&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;logging host 1.1.1.166 transport udp port 20514&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;logging host 10.0.0.4 transport udp port 20514&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;radius-server attribute 6 on-for-login-auth&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;radius-server attribute 6 support-multiple&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;radius-server attribute 8 include-in-access-req&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;radius-server attribute 25 access-request include&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;radius-server dead-criteria time 5 tries 3&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;radius-server deadtime 30&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;radius server ISE1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;address ipv4 1.1.1.166 auth-port 1812 acct-port 1813&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;key 7 XXXXXXXXXXXXXXXXXXXXXXXXXX&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;radius server ISE2&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;address ipv4 10.0.0.4 auth-port 1812 acct-port 1813&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;key 7 1XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2016 16:37:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/redirect-posture-cisco-ise/m-p/2828475#M41043</guid>
      <dc:creator>Emerson Oliveira</dc:creator>
      <dc:date>2016-01-15T16:37:31Z</dc:date>
    </item>
  </channel>
</rss>

