<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Redirection is not working  (IOL) in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/redirection-is-not-working-iol/m-p/3814414#M484605</link>
    <description>&lt;P&gt;Hey, thanks for your reply, but that did not work unfortunately. It's the same issue.&lt;/P&gt;</description>
    <pubDate>Tue, 05 Mar 2019 17:28:44 GMT</pubDate>
    <dc:creator>abhisheks</dc:creator>
    <dc:date>2019-03-05T17:28:44Z</dc:date>
    <item>
      <title>Redirection is not working  (IOL)</title>
      <link>https://community.cisco.com/t5/network-access-control/redirection-is-not-working-iol/m-p/3813755#M484600</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am using IOL image -&amp;nbsp;Version 15.2(CML_NIGHTLY_20180510) as a L2 switch, and I really cannot understand why the redirection to the sponsored guest portal is not working.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The endpoint is failing DOT1X as expected and is falling over to MAB. The correct REDIRECT ACL is being applied, as intended, and I can even see hits on the REDIRECT ACL when I browse from the client, however, that's about it, when I browse, the actual webpage opens up without being redirected, and on the REDIRECT ACL, I see the corresponding hits.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I browse to the URL that is applied by ISE on the switchport, I'm able to load the guest portal as intended. However, the switch just refuses to redirect to that URL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here are some configurations:&lt;/P&gt;&lt;P&gt;ip http server&lt;BR /&gt;ip http active-session-modules none&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;S1#show authentication session int ethernet 1/1 policy&lt;BR /&gt;Interface: Ethernet1/1&lt;BR /&gt;MAC Address: 5000.0008.0000&lt;BR /&gt;IPv6 Address: Unknown&lt;BR /&gt;IPv4 Address: 10.10.10.22&lt;BR /&gt;User-Name: 50-00-00-08-00-00&lt;BR /&gt;Status: Authorized&lt;BR /&gt;Domain: DATA&lt;BR /&gt;Oper host mode: multi-auth&lt;BR /&gt;Oper control dir: both&lt;BR /&gt;Session timeout: N/A&lt;BR /&gt;Restart timeout: N/A&lt;BR /&gt;Periodic Acct timeout: 86400s (local), Remaining: 85492s&lt;BR /&gt;Session Uptime: 953s&lt;BR /&gt;Common Session ID: 0A0A0A0A0000001500837926&lt;BR /&gt;Acct Session ID: 0x0000000A&lt;BR /&gt;Handle: 0xF6000009&lt;BR /&gt;Current Policy: POLICY_Et1/1&lt;/P&gt;&lt;P&gt;Local Policies:&lt;BR /&gt;Service Template: DEFAULT_LINKSEC_POLICY_SHOULD_SECURE (priority 150)&lt;BR /&gt;Security Policy: Should Secure&lt;BR /&gt;Security Status: Link Unsecure&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Server Policies:&lt;BR /&gt;URL Redirect: &lt;A href="https://ise.mylab.com:8544/portal/gateway?sessionId=0A0A0A0A0000001500837926&amp;amp;portal=e0591220-3e6a-11e9-815c-5000000e0001&amp;amp;action=cwa&amp;amp;token=d6169cfaf69d133a875c68b6b439c85c" target="_blank" rel="noopener"&gt;https://ise.mylab.com:8544/portal/gateway?sessionId=0A0A0A0A0000001500837926&amp;amp;portal=e0591220-3e6a-11e9-815c-5000000e0001&amp;amp;action=cwa&amp;amp;token=d6169cfaf69d133a875c68b6b439c85c&lt;/A&gt;&lt;BR /&gt;URL Redirect ACL: ACL-WEBAUTH-REDIRECT&lt;/P&gt;&lt;P&gt;Resultant Policies:&lt;BR /&gt;Security Policy: Should Secure&lt;BR /&gt;Security Status: Link Unsecure&lt;BR /&gt;URL Redirect: &lt;A href="https://ise.mylab.com:8544/portal/gateway?sessionId=0A0A0A0A0000001500837926&amp;amp;portal=e0591220-3e6a-11e9-815c-5000000e0001&amp;amp;action=cwa&amp;amp;token=d6169cfaf69d133a875c68b6b439c85c" target="_blank" rel="noopener"&gt;https://ise.mylab.com:8544/portal/gateway?sessionId=0A0A0A0A0000001500837926&amp;amp;portal=e0591220-3e6a-11e9-815c-5000000e0001&amp;amp;action=cwa&amp;amp;token=d6169cfaf69d133a875c68b6b439c85c&lt;/A&gt;&lt;BR /&gt;URL Redirect ACL: ACL-WEBAUTH-REDIRECT&lt;/P&gt;&lt;P&gt;Method status list:&lt;BR /&gt;Method State&lt;/P&gt;&lt;P&gt;dot1x Stopped&lt;BR /&gt;mab Authc Success&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Extended IP access list ACL-WEBAUTH-REDIRECT&lt;BR /&gt;10 deny udp any any eq domain (225 matches)&lt;BR /&gt;20 permit tcp any any eq www (11330 matches)&lt;BR /&gt;30 permit tcp any any eq 443 (21898 matches)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, despite hitting the right ACEs, the switch doesn't re-direct the traffic, and the endpoint simply loads up the webpage.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help please? Thank you &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Full config is also attached if interested!&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2019 18:54:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/redirection-is-not-working-iol/m-p/3813755#M484600</guid>
      <dc:creator>abhisheks</dc:creator>
      <dc:date>2019-03-04T18:54:59Z</dc:date>
    </item>
    <item>
      <title>Re: Redirection is not working  (IOL)</title>
      <link>https://community.cisco.com/t5/network-access-control/redirection-is-not-working-iol/m-p/3813911#M484603</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you try denying the ISE IP address in your redirect URL and give a try?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Use below ACE as a first entry on your&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;ACL-WEBAUTH-REDIRECT ACL&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;deny ip any host &amp;lt; ISE IP address&amp;gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2019 00:04:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/redirection-is-not-working-iol/m-p/3813911#M484603</guid>
      <dc:creator>mnagired</dc:creator>
      <dc:date>2019-03-05T00:04:44Z</dc:date>
    </item>
    <item>
      <title>Re: Redirection is not working  (IOL)</title>
      <link>https://community.cisco.com/t5/network-access-control/redirection-is-not-working-iol/m-p/3814414#M484605</link>
      <description>&lt;P&gt;Hey, thanks for your reply, but that did not work unfortunately. It's the same issue.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2019 17:28:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/redirection-is-not-working-iol/m-p/3814414#M484605</guid>
      <dc:creator>abhisheks</dc:creator>
      <dc:date>2019-03-05T17:28:44Z</dc:date>
    </item>
    <item>
      <title>Re: Redirection is not working  (IOL)</title>
      <link>https://community.cisco.com/t5/network-access-control/redirection-is-not-working-iol/m-p/3814421#M484607</link>
      <description>Are you configuring FQDN in portal settings? If so, do you have a dns entry for it? Also, please test this:&lt;BR /&gt;Please try modifying the authz profile to use static IP instead of fqdn.</description>
      <pubDate>Tue, 05 Mar 2019 17:41:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/redirection-is-not-working-iol/m-p/3814421#M484607</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2019-03-05T17:41:34Z</dc:date>
    </item>
    <item>
      <title>Re: Redirection is not working  (IOL)</title>
      <link>https://community.cisco.com/t5/network-access-control/redirection-is-not-working-iol/m-p/3814757#M484608</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did you configure in the Authentication on ISE that if the mab fails to continue the process ?&lt;/P&gt;
&lt;P&gt;enable also https on the switch&lt;/P&gt;
&lt;P&gt;and add it to the redirect-acl.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also add in the ACL permit to your DNS servers additional to the DHCP server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;maybe it is IOS-L issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Normally you should be redirected to the ise hostname FQDN by default.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;also make sure you have a DNS entry that can resolve this FQDN on the endpoint side.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope this helps&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2019 08:33:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/redirection-is-not-working-iol/m-p/3814757#M484608</guid>
      <dc:creator>bern81</dc:creator>
      <dc:date>2019-03-06T08:33:46Z</dc:date>
    </item>
  </channel>
</rss>

