<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Guest redirection using a non Cisco Switch in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/guest-redirection-using-a-non-cisco-switch/m-p/3760527#M487462</link>
    <description>&lt;P&gt;It turns out that Juniper does not support CWA on 4200EX series of switches.&lt;/P&gt;
&lt;P&gt;The tested switch from Cisco is 3200 series.&lt;/P&gt;
&lt;P&gt;The&amp;nbsp;list is&amp;nbsp;provided below in the document from Juniper:&amp;nbsp;&lt;A href="https://apps.juniper.net/feature-explorer/feature-info.html?fKey=7084&amp;amp;fn=Central%20Web%20authentication " target="_self"&gt;here&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 10 Dec 2018 13:03:10 GMT</pubDate>
    <dc:creator>dgaikwad</dc:creator>
    <dc:date>2018-12-10T13:03:10Z</dc:date>
    <item>
      <title>Guest redirection using a non Cisco Switch</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-redirection-using-a-non-cisco-switch/m-p/3758779#M487445</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;
&lt;P&gt;We are using&amp;nbsp;a third party NADs (Juniper 4200EX) in our environment and want to work with wired guest redirection on these NADs.&lt;/P&gt;
&lt;P&gt;Using the third party NAD profile provided by the community, I am able to get the following use cases working:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;dot1x&lt;/LI&gt;
&lt;LI&gt;posture&lt;/LI&gt;
&lt;LI&gt;VLAN change and assignment&lt;/LI&gt;
&lt;LI&gt;dACL assignment&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;I see that its not supported with the Juniper switch NAD profile and asking for to configure authentication VLAN for the same.&lt;/P&gt;
&lt;P&gt;There are some queries with the this configuration:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Only one NAD profile could be used per NAD, then is there a way to keep the dot1x and guest redirection separate?&lt;/LI&gt;
&lt;LI&gt;Would I need to make this change for the other NADs as well, which are working fine on a third party AND profiles from &lt;A href="https://community.cisco.com/t5/security-documents/ise-third-party-nad-profiles-and-configs/ta-p/3648719" target="_self"&gt;here&lt;/A&gt;?&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 06 Dec 2018 08:09:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-redirection-using-a-non-cisco-switch/m-p/3758779#M487445</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-12-06T08:09:19Z</dc:date>
    </item>
    <item>
      <title>Re: Guest redirection using a non Cisco Switch</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-redirection-using-a-non-cisco-switch/m-p/3759770#M487447</link>
      <description>May i know what you meant when you said "I see that its not supported with the Juniper switch NAD profile and asking for to configure authentication VLAN for the same." ?&lt;BR /&gt;&lt;BR /&gt;It looks like Juniper does support redirect-URLs and you can combine with firewall filter to restrict access just like Cisco switches use redirect url, redirect ACLs/dACLs.&lt;BR /&gt;&lt;BR /&gt;Apparently you can use the JNPR_RSVD_FILTER_CWA filter, sent using the standard RADIUS Filter-ID attribute to limit the access and use Juniper-CWA-Redirect-URL VSA and set the value as the redirect URL.&lt;BR /&gt;&lt;BR /&gt;More info here:&lt;BR /&gt;&lt;A href="https://www.juniper.net/documentation/en_US/release-independent/nce/topics/concept/nce160-aruba-guest-access-technical-overview.html" target="_blank"&gt;https://www.juniper.net/documentation/en_US/release-independent/nce/topics/concept/nce160-aruba-guest-access-technical-overview.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;I personally have never tried this and this is me just trying to help.</description>
      <pubDate>Fri, 07 Dec 2018 19:32:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-redirection-using-a-non-cisco-switch/m-p/3759770#M487447</guid>
      <dc:creator>Surendra</dc:creator>
      <dc:date>2018-12-07T19:32:54Z</dc:date>
    </item>
    <item>
      <title>Re: Guest redirection using a non Cisco Switch</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-redirection-using-a-non-cisco-switch/m-p/3759773#M487450</link>
      <description>I would recommend working through the TAC as well. I am not sure of the issue exactly and need more detail. If the Juniper doesn’t support redirection you can look at the authentication VLAN feature.&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_01001.html#concept_CDD87F6FE3A54351B27FF35316A23DA3" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_01001.html#concept_CDD87F6FE3A54351B27FF35316A23DA3&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;The 3300 was tested to work, other comparable platforms should then work.&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/compatibility/b_ise_sdt_24.html#thirdpartyaccessswitches" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/compatibility/b_ise_sdt_24.html#thirdpartyaccessswitches&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;when I google ise juniper guest found a lot of information, one that stood out is this one&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/identity-services-engine-ise/integrating-a-juniper-switch-with-ise-2-3/td-p/3685582" target="_blank"&gt;https://community.cisco.com/t5/identity-services-engine-ise/integrating-a-juniper-switch-with-ise-2-3/td-p/3685582&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 07 Dec 2018 19:47:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-redirection-using-a-non-cisco-switch/m-p/3759773#M487450</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-12-07T19:47:31Z</dc:date>
    </item>
    <item>
      <title>Re: Guest redirection using a non Cisco Switch</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-redirection-using-a-non-cisco-switch/m-p/3760527#M487462</link>
      <description>&lt;P&gt;It turns out that Juniper does not support CWA on 4200EX series of switches.&lt;/P&gt;
&lt;P&gt;The tested switch from Cisco is 3200 series.&lt;/P&gt;
&lt;P&gt;The&amp;nbsp;list is&amp;nbsp;provided below in the document from Juniper:&amp;nbsp;&lt;A href="https://apps.juniper.net/feature-explorer/feature-info.html?fKey=7084&amp;amp;fn=Central%20Web%20authentication " target="_self"&gt;here&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Dec 2018 13:03:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-redirection-using-a-non-cisco-switch/m-p/3760527#M487462</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-12-10T13:03:10Z</dc:date>
    </item>
  </channel>
</rss>

