<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE web redirect not working in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3812509#M484674</link>
    <description>&lt;P&gt;Ok. Check the ACL on the WLC and ensure the case is the same as defined on ISE and spelling.&lt;/P&gt;
&lt;P&gt;Check &lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/115732-central-web-auth-00.html" target="_self"&gt;this page&lt;/A&gt; and double check the configuration of the WLC configuration.&lt;/P&gt;</description>
    <pubDate>Fri, 01 Mar 2019 13:35:40 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2019-03-01T13:35:40Z</dc:date>
    <item>
      <title>Cisco ISE web redirect not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3812425#M484668</link>
      <description>&lt;P&gt;Can anyone help with this. I have an open SSID doing MAC filtering to ISE with the following auth rules;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/31163i5F01D5FD2BE238C8/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My devices is hitting correct rule for the unknown MAC but it is not redirecting me to the guest portal &amp;amp; is allowing me access in the associated VLAN assigned to the WebAuth policy.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture1.PNG" style="width: 529px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/31164iF0D7559EF3F50CCC/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture1.PNG" alt="Capture1.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture2.PNG" style="width: 715px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/31165iDF62FBB47A414BCE/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture2.PNG" alt="Capture2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2019 10:41:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3812425#M484668</guid>
      <dc:creator>Jason Weids</dc:creator>
      <dc:date>2019-03-01T10:41:30Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE web redirect not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3812432#M484669</link>
      <description>&lt;P&gt;Just to add, I can browse to the redirect link from the device.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2019 10:54:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3812432#M484669</guid>
      <dc:creator>Jason Weids</dc:creator>
      <dc:date>2019-03-01T10:54:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE web redirect not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3812444#M484670</link>
      <description>Hi,&lt;BR /&gt;When you access the link from the device is it via FQDN or IP address?....can the device resolve the dns hostname of the ISE PSN?&lt;BR /&gt;&lt;BR /&gt;Can you confirm the redirect ACL been applied to the interface?...what is the output of "show authentication session interface Gi x" ?&lt;BR /&gt;&lt;BR /&gt;What is the configuration of your called ACL_WEBAUTH_REDIRECT?&lt;BR /&gt;</description>
      <pubDate>Fri, 01 Mar 2019 11:19:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3812444#M484670</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-03-01T11:19:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE web redirect not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3812486#M484671</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Accessing the link works using the FQDN &amp;amp; the client can resolve this.&lt;/P&gt;
&lt;P&gt;What interface would the ACL be applied to being this a wireless connection?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Below show the attribute of the Cisco_WebAuth profile but where to I find the configuration of the ACL_WEBAUTH_REDIRECT.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture3.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/31172i6243F5326D8B07BC/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture3.PNG" alt="Capture3.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is also a "!" withe the following note;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture4.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/31174i7266516F6B8756D1/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture4.PNG" alt="Capture4.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2019 12:52:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3812486#M484671</guid>
      <dc:creator>Jason Weids</dc:creator>
      <dc:date>2019-03-01T12:52:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE web redirect not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3812492#M484672</link>
      <description>Sorry I mis-read the original post and assumed it was wired. Can you confirm the configuration of the ACL_WEBAUTH_REDIRECT ACL defined on the WLC? Can you check the WLC for the client session and confirm the redirect ACL is applied.</description>
      <pubDate>Fri, 01 Mar 2019 13:02:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3812492#M484672</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-03-01T13:02:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE web redirect not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3812508#M484673</link>
      <description>&lt;P&gt;It doesn't look like it is applying the ACL. Do I need to create the ACL on the WLC as well?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture5.PNG" style="width: 520px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/31176iDA98535F9C5E4C43/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture5.PNG" alt="Capture5.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2019 13:33:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3812508#M484673</guid>
      <dc:creator>Jason Weids</dc:creator>
      <dc:date>2019-03-01T13:33:36Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE web redirect not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3812509#M484674</link>
      <description>&lt;P&gt;Ok. Check the ACL on the WLC and ensure the case is the same as defined on ISE and spelling.&lt;/P&gt;
&lt;P&gt;Check &lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/115732-central-web-auth-00.html" target="_self"&gt;this page&lt;/A&gt; and double check the configuration of the WLC configuration.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2019 13:35:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3812509#M484674</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-03-01T13:35:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE web redirect not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3812533#M484675</link>
      <description>&lt;P&gt;Awesome thank you. It works. Wish I had this guide before.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've another question now.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A guest theoretically could enter any details they like on the registration page to get access. Is there a way to verify them by email or any other methods? We sometimes have minors on site &amp;amp; they might need a different level of access or URL filtering, either way, for compliance we would have to be able to identify the users.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2019 14:17:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3812533#M484675</guid>
      <dc:creator>Jason Weids</dc:creator>
      <dc:date>2019-03-01T14:17:22Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE web redirect not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3812569#M484676</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Glad to hear it's working now. I haven't used Guest for a log time, but does &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_01111.html#SelfRegAcctApprovConcept" target="_self"&gt;this link&lt;/A&gt; do what you want? This is to configure approval request email to a sponsor.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2019 15:16:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3812569#M484676</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-03-01T15:16:18Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE web redirect not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3812668#M484677</link>
      <description>&lt;P&gt;Only issue is the web page only seems to work with IE or edge. Is there support for other browsers &amp;amp; mobile devices?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2019 17:41:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3812668#M484677</guid>
      <dc:creator>Jason Weids</dc:creator>
      <dc:date>2019-03-01T17:41:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE web redirect not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3812762#M484678</link>
      <description>Do you get a certificate on the non MS browsers? If you are using an Internal CA then the IE/Edge browsers would automatically trust those certificates and not present a certificate error. Firefox/Chrome and a mobile browser would not trust the Internal CA unless specifically configured to do.&lt;BR /&gt;&lt;BR /&gt;HTH</description>
      <pubDate>Fri, 01 Mar 2019 20:23:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3812762#M484678</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-03-01T20:23:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE web redirect not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3813530#M484679</link>
      <description>&lt;P&gt;We have imported the full certificate chain that has been signed by a CA authority &amp;amp; bound the original cert request. It has being used by the default portal certificate group and we can confirm in the browser when redirected that is is using this certificate but it is still saying it is not trusted.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cert error1.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/31255iFE852CE603834438/image-size/large?v=v2&amp;amp;px=999" role="button" title="Cert error1.PNG" alt="Cert error1.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cert error.PNG" style="width: 484px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/31254iB2F333FDB702455F/image-size/large?v=v2&amp;amp;px=999" role="button" title="cert error.PNG" alt="cert error.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2019 14:09:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3813530#M484679</guid>
      <dc:creator>Jason Weids</dc:creator>
      <dc:date>2019-03-04T14:09:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE web redirect not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3813584#M484680</link>
      <description>Does your client computer have the QuoVadis EV SSL ICA G3 certificate in it's machine store?</description>
      <pubDate>Mon, 04 Mar 2019 15:16:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3813584#M484680</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-03-04T15:16:31Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE web redirect not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3813671#M484681</link>
      <description>&lt;P&gt;No it doesn't&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2019 16:59:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3813671#M484681</guid>
      <dc:creator>Jason Weids</dc:creator>
      <dc:date>2019-03-04T16:59:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE web redirect not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3813676#M484682</link>
      <description>That QuoVadis certificate needs to be imported to the computer trusted certificate store, otherwise the web browser will consider it untrusted and error.</description>
      <pubDate>Mon, 04 Mar 2019 17:03:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3813676#M484682</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-03-04T17:03:44Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE web redirect not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3814042#M484683</link>
      <description>&lt;P&gt;How is this meant to work for guests then?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have now imported the certificate to the machine &amp;amp; it is now trusted &amp;amp; all browsers working. I'm confused how this is going to work for guests on their own devices though.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2019 09:02:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3814042#M484683</guid>
      <dc:creator>Jason Weids</dc:creator>
      <dc:date>2019-03-05T09:02:48Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE web redirect not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3814111#M484684</link>
      <description>That QuoVadis CA certificate is possibly not, as default installed onto a computer compared to Comodo, Entrust, Verisign etc which are. Possibly use one of these other CAs which should ensure trust for most devices (hopefully).&lt;BR /&gt;&lt;BR /&gt;HTH</description>
      <pubDate>Tue, 05 Mar 2019 09:55:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3814111#M484684</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-03-05T09:55:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE web redirect not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3814141#M484685</link>
      <description>&lt;P&gt;So do I need to use one of the trusted certificates in ISE for the guest portal, like the verisign class 3 public certification authority?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How do I apply this to the guest portal?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2019 10:57:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3814141#M484685</guid>
      <dc:creator>Jason Weids</dc:creator>
      <dc:date>2019-03-05T10:57:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE web redirect not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3814760#M484686</link>
      <description>you can use self-signing portal with sponsor approval.&lt;BR /&gt;like this when the guest get the redirect page, he has to create a user and who he is visiting.&lt;BR /&gt;the request goes to a sponsor account email that approve the guest and define the duration for the connection.&lt;BR /&gt;the guest received an email with his passwd and can access internet.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 06 Mar 2019 08:41:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3814760#M484686</guid>
      <dc:creator>bern81</dc:creator>
      <dc:date>2019-03-06T08:41:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE web redirect not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3815445#M484687</link>
      <description>&lt;P&gt;After applying the cert to the admin role &amp;amp; restarting ISE all portals on all browsers are now accepting the certificate. Seems strange that they didn't when we applied it to the portal role because that doesn't require a restart.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2019 08:18:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-web-redirect-not-working/m-p/3815445#M484687</guid>
      <dc:creator>Jason Weids</dc:creator>
      <dc:date>2019-03-07T08:18:15Z</dc:date>
    </item>
  </channel>
</rss>

