<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CWA redirection not working in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cwa-redirection-not-working/m-p/3811684#M484715</link>
    <description>&lt;P&gt;Hi , i have same problems with my 5508 ,and i downgrade the code because withe latest code noone from guest take ip address ,there was not even authentication log in ISE and in WLC the client was with ip address 0.0.0.0&amp;nbsp;&amp;nbsp; . Witch version of code you use ? And again this was only for guest network all other networks like corporate WPA2 etc working as expected . I resolve with downgrade the code but there was 1 more way to add PSK for guest it will allow you clients to take ip address .&lt;/P&gt;</description>
    <pubDate>Thu, 28 Feb 2019 12:30:40 GMT</pubDate>
    <dc:creator>ognyan.totev</dc:creator>
    <dc:date>2019-02-28T12:30:40Z</dc:date>
    <item>
      <title>CWA redirection not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cwa-redirection-not-working/m-p/3811543#M484713</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope you all are doing good&lt;/P&gt;
&lt;P&gt;I am working on wireless guest access ( Sponsor Base ).&lt;/P&gt;
&lt;P&gt;I have WLC 5508, 3560 SW, 1702i AP, ISE 2.4&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Problem Description : Earlier i was getting connect on Guest SSID but redirection was not happening, Now i am not able to connect on Guest SSID&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When i checked on ISE there is no logs/hits on live logs&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On WLC i checked and found that device is not getting the IP addr so what i did i amanually put the IP addr but it also didn't work, i meant no connectivity.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Attaching screen shots for reference.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please help me on this, Appreciate prompt response.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2019 09:27:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cwa-redirection-not-working/m-p/3811543#M484713</guid>
      <dc:creator>sajid231088</dc:creator>
      <dc:date>2019-02-28T09:27:32Z</dc:date>
    </item>
    <item>
      <title>Re: CWA redirection not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cwa-redirection-not-working/m-p/3811684#M484715</link>
      <description>&lt;P&gt;Hi , i have same problems with my 5508 ,and i downgrade the code because withe latest code noone from guest take ip address ,there was not even authentication log in ISE and in WLC the client was with ip address 0.0.0.0&amp;nbsp;&amp;nbsp; . Witch version of code you use ? And again this was only for guest network all other networks like corporate WPA2 etc working as expected . I resolve with downgrade the code but there was 1 more way to add PSK for guest it will allow you clients to take ip address .&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2019 12:30:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cwa-redirection-not-working/m-p/3811684#M484715</guid>
      <dc:creator>ognyan.totev</dc:creator>
      <dc:date>2019-02-28T12:30:40Z</dc:date>
    </item>
    <item>
      <title>Re: CWA redirection not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cwa-redirection-not-working/m-p/3811742#M484717</link>
      <description>You ACL should look something along these lines:&lt;BR /&gt;&lt;BR /&gt;Extended IP access list ACL_WEBAUTH_REDIRECT&lt;BR /&gt;10 deny ip any host &amp;lt;ISE SERVER&amp;gt; log&lt;BR /&gt;20 deny ip any host &amp;lt;ISE SERVER&amp;gt; log&lt;BR /&gt;30 permit tcp any any eq www log&lt;BR /&gt;40 permit tcp any any eq 443 log&lt;BR /&gt;50 permit tcp any any eq 8443 log&lt;BR /&gt;60 deny udp any any eq domain log&lt;BR /&gt;70 deny udp any eq bootpc any eq bootps log&lt;BR /&gt;&lt;BR /&gt;Based on my experience with posture assessment &amp;amp; guest portal redirects the logic is backwards. For example:&lt;BR /&gt;10 deny ip any host &amp;lt;ISE SERVER&amp;gt; log -- This is actually allowing connectivity to your ISE server.&lt;BR /&gt;&lt;BR /&gt;I recommend testing this out. Prior to doing so ensure that routing is in place for your WLC/user endpoint to reach whatever nic you are using on ISE for your portal.&lt;BR /&gt;&lt;BR /&gt;HTH!&lt;BR /&gt;</description>
      <pubDate>Thu, 28 Feb 2019 13:41:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cwa-redirection-not-working/m-p/3811742#M484717</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2019-02-28T13:41:52Z</dc:date>
    </item>
  </channel>
</rss>

