<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Redirection to an internal web server in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/redirection-to-an-internal-web-server/m-p/3750994#M487892</link>
    <description>&lt;P&gt;Jorgen,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I do notice a &lt;STRONG&gt;dACL - &lt;FONT size="2" face="arial,helvetica,sans-serif"&gt;ACS ACL: xACSACLx-IP-LimitedAccessDACL-5bec09c6&lt;/FONT&gt;&lt;/STRONG&gt; which is part of auth policy.. Can you share the content of the dACL and i hope dACL isnt denying http/https access.&lt;/P&gt;</description>
    <pubDate>Wed, 21 Nov 2018 19:29:31 GMT</pubDate>
    <dc:creator>mnagired</dc:creator>
    <dc:date>2018-11-21T19:29:31Z</dc:date>
    <item>
      <title>Redirection to an internal web server</title>
      <link>https://community.cisco.com/t5/network-access-control/redirection-to-an-internal-web-server/m-p/3750718#M487884</link>
      <description>&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;I am trying to get ISE (2.4) to redirect clients to an internal web server. The redirection is part of an authorization policy used for quarantine clients, but I am a bit stuck getting this to work properly. I can get the redirection to work without any issues if I am using the web redirection option and point it directly to a portal page on the ISE server itself, but my customer wants to use an&amp;nbsp;internal MS web server. I used the advanced&amp;nbsp;attribute settings in the authorization policy and used the cisco-av-pair. The config looks like this:&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;cisco-av-pair = url-redirect-acl=CWA-URL-REDIRECT-ACL&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;cisco-av-pair = url-redirect=&lt;A href="http://10.159.9.29:80/pxgrid/unquaran.html" target="_blank"&gt;http://10.159.9.29:80/pxgrid/unquaran.html&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;When looking at the switch, I can see the redirection&amp;nbsp;url and the address is correct. If I just copy/paste the url, the client have no problem to reach the page, but no redirection is happening.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;Here is the output from the switch:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;SW01-FIPWR-SBOX#show authentication sessions interface gigabitEthernet1/0/1 details&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Server Policies:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt; Security Policy: None&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt; Security Status: Link Unsecured&lt;/FONT&gt;&lt;BR /&gt; &lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;URL Redirect ACL: CWA-URL-REDIRECT-ACL&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt; URL Redirect: &lt;A href="https://10.159.9.29/pxgrid/unquaran.html" target="_blank"&gt;https://10.159.9.29/pxgrid/unquaran.html&lt;/A&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt; ACS ACL: xACSACLx-IP-LimitedAccessDACL-5bec09c6&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;Any suggestion how to get this to work?&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;Thanks&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;/Jorgen&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Nov 2018 13:03:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/redirection-to-an-internal-web-server/m-p/3750718#M487884</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2018-11-21T13:03:09Z</dc:date>
    </item>
    <item>
      <title>Re: Redirection to an internal web server</title>
      <link>https://community.cisco.com/t5/network-access-control/redirection-to-an-internal-web-server/m-p/3750874#M487886</link>
      <description>&lt;P&gt;Could you answer following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1&amp;gt; Do you have &lt;FONT size="2" face="arial,helvetica,sans-serif"&gt;CWA-URL-REDIRECT-ACL&lt;/FONT&gt; ACL configured on switch?&lt;/P&gt;
&lt;P&gt;2&amp;gt; Does the ACL &lt;FONT size="2" face="arial,helvetica,sans-serif"&gt;CWA-URL-REDIRECT-ACL&lt;/FONT&gt; have 10.159.9.29 in deny statement?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In authorization policy you have &lt;A href="https://10.159.9.29" target="_blank"&gt;http&lt;/A&gt;://10.159.9.29 but on switch you have &lt;A href="https://10.159.9.29" target="_blank"&gt;https://10.159.9.29&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Nov 2018 16:20:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/redirection-to-an-internal-web-server/m-p/3750874#M487886</guid>
      <dc:creator>pan</dc:creator>
      <dc:date>2018-11-21T16:20:09Z</dc:date>
    </item>
    <item>
      <title>Re: Redirection to an internal web server</title>
      <link>https://community.cisco.com/t5/network-access-control/redirection-to-an-internal-web-server/m-p/3750888#M487889</link>
      <description>&lt;P&gt;I have tested it works:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3750#show access-lists redirect-test&lt;BR /&gt;Extended IP access list redirect-test&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10 deny ip any host 10.127.196.230&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 20 permit tcp any any eq www (20 matches)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 30 permit tcp any any eq 443&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3750#show authentication sessions int g2/0/1&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface:&amp;nbsp; GigabitEthernet2/0/1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MAC Address:&amp;nbsp; b496.9126.dec0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP Address:&amp;nbsp; 10.106.37.240&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; User-Name:&amp;nbsp; panadmin&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Status:&amp;nbsp; Authz Success&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Domain:&amp;nbsp; DATA&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Security Policy:&amp;nbsp; Should Secure&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Security Status:&amp;nbsp; Unsecure&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper host mode:&amp;nbsp; single-host&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper control dir:&amp;nbsp; both&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Authorized By:&amp;nbsp; Authentication Server&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Vlan Policy:&amp;nbsp; N/A&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; URL Redirect ACL:&amp;nbsp; redirect-test&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; URL Redirect:&amp;nbsp; &lt;A href="https://10.127.196.230" target="_blank"&gt;https://10.127.196.230&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Session timeout:&amp;nbsp; N/A&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Idle timeout:&amp;nbsp; N/A&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Common Session ID:&amp;nbsp; 0A6A25DE000031FF914E75EE&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Acct Session ID:&amp;nbsp; 0x0000385A&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Handle:&amp;nbsp; 0x420001E1&lt;BR /&gt;&lt;BR /&gt;Runnable methods list:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&amp;nbsp;&amp;nbsp; State&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dot1x&amp;nbsp;&amp;nbsp;&amp;nbsp; Authc Success&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="redirect.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/24550i617B1CEA11577B4C/image-size/large?v=v2&amp;amp;px=999" role="button" title="redirect.png" alt="redirect.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I have tried to open some http website and it automatically redirected me to redirect url&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="redirect2.png" style="width: 794px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/24551iC15680E85F42701A/image-size/large?v=v2&amp;amp;px=999" role="button" title="redirect2.png" alt="redirect2.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Nov 2018 16:32:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/redirection-to-an-internal-web-server/m-p/3750888#M487889</guid>
      <dc:creator>pan</dc:creator>
      <dc:date>2018-11-21T16:32:36Z</dc:date>
    </item>
    <item>
      <title>Re: Redirection to an internal web server</title>
      <link>https://community.cisco.com/t5/network-access-control/redirection-to-an-internal-web-server/m-p/3750948#M487891</link>
      <description>&lt;P&gt;Thank you for the suggestions, We do have the CWA-URL-REDIRECT-ACL ACL on the switch and&lt;BR /&gt;it is including deny ip any 10.159.9.29.&lt;/P&gt;
&lt;P&gt;I will not be able to test this until monday next week, but I will have a look at your config and compare it to what we have.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;BR /&gt;/Jorgen&lt;/P&gt;</description>
      <pubDate>Wed, 21 Nov 2018 18:17:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/redirection-to-an-internal-web-server/m-p/3750948#M487891</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2018-11-21T18:17:27Z</dc:date>
    </item>
    <item>
      <title>Re: Redirection to an internal web server</title>
      <link>https://community.cisco.com/t5/network-access-control/redirection-to-an-internal-web-server/m-p/3750994#M487892</link>
      <description>&lt;P&gt;Jorgen,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I do notice a &lt;STRONG&gt;dACL - &lt;FONT size="2" face="arial,helvetica,sans-serif"&gt;ACS ACL: xACSACLx-IP-LimitedAccessDACL-5bec09c6&lt;/FONT&gt;&lt;/STRONG&gt; which is part of auth policy.. Can you share the content of the dACL and i hope dACL isnt denying http/https access.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Nov 2018 19:29:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/redirection-to-an-internal-web-server/m-p/3750994#M487892</guid>
      <dc:creator>mnagired</dc:creator>
      <dc:date>2018-11-21T19:29:31Z</dc:date>
    </item>
    <item>
      <title>Re: Redirection to an internal web server</title>
      <link>https://community.cisco.com/t5/network-access-control/redirection-to-an-internal-web-server/m-p/3751204#M487894</link>
      <description>&lt;P&gt;&lt;FONT size="2"&gt;The&amp;nbsp;&lt;STRONG&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;ACL&lt;/FONT&gt;&lt;STRONG&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;: xACSACLx-IP-LimitedAccessDACL-5bec09c6 &lt;/FONT&gt;&lt;/STRONG&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;is permitting http and https traffic to the web server and also domain traffic. Reaching the url directly from the client works without any issues,&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;Thanks&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="arial,helvetica,sans-serif" size="2"&gt;/Jorgen&amp;nbsp;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Nov 2018 06:17:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/redirection-to-an-internal-web-server/m-p/3751204#M487894</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2018-11-22T06:17:40Z</dc:date>
    </item>
  </channel>
</rss>

