<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Restrict DNS traffic during web redirection pre-auth phase in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/restrict-dns-traffic-during-web-redirection-pre-auth-phase/m-p/3724597#M495217</link>
    <description>Are you asking how to restrict what sites someone can get to? With the WLC did you look into the DNS based ACLs?&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/7-6/configuration-guide/b_cg76/b_cg76_chapter_0110101.html#concept_AEEDD6D25578413784092B48A4636163" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/7-6/configuration-guide/b_cg76/b_cg76_chapter_0110101.html#concept_AEEDD6D25578413784092B48A4636163&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;This is shown in the ISE how to byod guide as an example&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-documents/cisco-ise-byod-deployment-guide/ta-p/3641867" target="_blank"&gt;https://community.cisco.com/t5/security-documents/cisco-ise-byod-deployment-guide/ta-p/3641867&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Fri, 12 Oct 2018 21:18:00 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2018-10-12T21:18:00Z</dc:date>
    <item>
      <title>Restrict DNS traffic during web redirection pre-auth phase</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-dns-traffic-during-web-redirection-pre-auth-phase/m-p/3724587#M495216</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Its my understanding that the redirection URL only dictates what URL traffic has to be exempted.&lt;/P&gt;
&lt;P&gt;It will not restrict DNS traffic to certain IPs (only internal and external DNS).&lt;/P&gt;
&lt;P&gt;Is my understanding correct for WLC as well ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What are various ways we can restrict DNS traffic on WLC during pre-auth phase for guest since&amp;nbsp;WLC does not support DACL&lt;/P&gt;</description>
      <pubDate>Fri, 12 Oct 2018 21:01:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-dns-traffic-during-web-redirection-pre-auth-phase/m-p/3724587#M495216</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2018-10-12T21:01:08Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict DNS traffic during web redirection pre-auth phase</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-dns-traffic-during-web-redirection-pre-auth-phase/m-p/3724597#M495217</link>
      <description>Are you asking how to restrict what sites someone can get to? With the WLC did you look into the DNS based ACLs?&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/7-6/configuration-guide/b_cg76/b_cg76_chapter_0110101.html#concept_AEEDD6D25578413784092B48A4636163" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/7-6/configuration-guide/b_cg76/b_cg76_chapter_0110101.html#concept_AEEDD6D25578413784092B48A4636163&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;This is shown in the ISE how to byod guide as an example&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-documents/cisco-ise-byod-deployment-guide/ta-p/3641867" target="_blank"&gt;https://community.cisco.com/t5/security-documents/cisco-ise-byod-deployment-guide/ta-p/3641867&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 12 Oct 2018 21:18:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-dns-traffic-during-web-redirection-pre-auth-phase/m-p/3724597#M495217</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-10-12T21:18:00Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict DNS traffic during web redirection pre-auth phase</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-dns-traffic-during-web-redirection-pre-auth-phase/m-p/3725633#M495218</link>
      <description>&lt;P&gt;Thanks Jason.&lt;/P&gt;
&lt;P&gt;I just had one clarification and I think the below link talks about it.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/wireless-mobility-documents/central-web-authentication-cwa-for-guests-with-ise/ta-p/3121101" target="_blank"&gt;https://community.cisco.com/t5/wireless-mobility-documents/central-web-authentication-cwa-for-guests-with-ise/ta-p/3121101&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"&lt;SPAN&gt;This ACL will be referenced in the access-accept of the ISE and will define what traffic should be redirected (denied by ACL), and what traffic shouldn't (permitted by the ACL"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The above statement does not mention that the ACL will also act as a pre-auth ACL.&lt;/P&gt;
&lt;P&gt;I guess the customer was expecting the ACL to also block traffic and this was brought up in their pen testing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;They had only their internal DNS server permitted in the ACL and the pen tester was able to query public DNS server.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Oct 2018 15:08:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-dns-traffic-during-web-redirection-pre-auth-phase/m-p/3725633#M495218</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2018-10-15T15:08:50Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict DNS traffic during web redirection pre-auth phase</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-dns-traffic-during-web-redirection-pre-auth-phase/m-p/3725649#M495219</link>
      <description>&lt;P&gt;The ACL will block if written correctly.&amp;nbsp; If you write the ACL as:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;permit DNS to desired DNS servers&lt;/P&gt;
&lt;P&gt;permit traffic to ISE PSNs&lt;/P&gt;
&lt;P&gt;deny all other traffic&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Nothing else should get through.&amp;nbsp; Is that not what you are seeing?&amp;nbsp; Can you send a screen shot of your redirect ACL?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Oct 2018 15:26:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-dns-traffic-during-web-redirection-pre-auth-phase/m-p/3725649#M495219</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-10-15T15:26:12Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict DNS traffic during web redirection pre-auth phase</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-dns-traffic-during-web-redirection-pre-auth-phase/m-p/3725664#M495220</link>
      <description>&lt;P&gt;Attached is the screenshot.&lt;/P&gt;
&lt;P&gt;I have redacted IPs to and from their DNS server.&lt;/P&gt;
&lt;P&gt;They are able to perform nslookup against 8.8.8.8.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Oct 2018 15:47:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-dns-traffic-during-web-redirection-pre-auth-phase/m-p/3725664#M495220</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2018-10-15T15:47:47Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict DNS traffic during web redirection pre-auth phase</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-dns-traffic-during-web-redirection-pre-auth-phase/m-p/3725668#M495221</link>
      <description>&lt;P&gt;In addition to explicitly allowing your DNS servers, you also need another ACL near the bottom to deny any other DNS traffic.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Oct 2018 15:45:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-dns-traffic-during-web-redirection-pre-auth-phase/m-p/3725668#M495221</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2018-10-15T15:45:04Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict DNS traffic during web redirection pre-auth phase</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-dns-traffic-during-web-redirection-pre-auth-phase/m-p/3725675#M495222</link>
      <description>&lt;P&gt;There should be an implicit deny all at the end, but maybe the WLCs don't do that for redirect ACLs.&amp;nbsp; I always put a deny all at the end of the redirect ACL.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Umahar, also you can clean up that ACL a bit.&amp;nbsp; You don't need to put both directions in the ACL if you make your first line:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;permit any any direction outbound&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We don't care about the outbound direction (network-&amp;gt;client).&amp;nbsp; We only care about inbound.&amp;nbsp; I always cringe when I see both directions in the ACL.&amp;nbsp; Makes it a bit tougher to read and doubles your chance to make a typo.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Oct 2018 15:50:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-dns-traffic-during-web-redirection-pre-auth-phase/m-p/3725675#M495222</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-10-15T15:50:27Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict DNS traffic during web redirection pre-auth phase</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-dns-traffic-during-web-redirection-pre-auth-phase/m-p/3725680#M495223</link>
      <description>&lt;P&gt;Just to give you an example here is my standard redirect ACL with subnet erased.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.JPG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/20430i5BA7D822720BF913/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.JPG" alt="Capture.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Oct 2018 15:55:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-dns-traffic-during-web-redirection-pre-auth-phase/m-p/3725680#M495223</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-10-15T15:55:41Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict DNS traffic during web redirection pre-auth phase</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-dns-traffic-during-web-redirection-pre-auth-phase/m-p/3725705#M495224</link>
      <description>&lt;P&gt;When endpoint is in WebAuth state the pre-auth ACL allows DNS traffic even with implicit deny. So you need to specify deny statement at the end to deny DNS to other untrusted DNS servers. Either deny any or deny DNS works.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Oct 2018 16:45:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-dns-traffic-during-web-redirection-pre-auth-phase/m-p/3725705#M495224</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2018-10-15T16:45:12Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict DNS traffic during web redirection pre-auth phase</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-dns-traffic-during-web-redirection-pre-auth-phase/m-p/3725709#M495225</link>
      <description>&lt;P&gt;Thanks Hosuk and Paul.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just tried in my lab and I was able to block adding a Deny.&lt;/P&gt;
&lt;P&gt;The only reason I went thinking into this direction because the Wireless expert mentioned earlier that no implicit deny is required and I ruled that out.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Oct 2018 16:55:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-dns-traffic-during-web-redirection-pre-auth-phase/m-p/3725709#M495225</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2018-10-15T16:55:37Z</dc:date>
    </item>
  </channel>
</rss>

