<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Guest Portal Settings - HTTPS Port Range in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-guest-portal-settings-https-port-range/m-p/3953466#M496309</link>
    <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/199790"&gt;@Jason Kunst&lt;/a&gt;&amp;nbsp;, will do!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/397746"&gt;@rdediana&lt;/a&gt;&amp;nbsp;I have configured nginx proxy and I do redirect from here to custom ise port (8443):&lt;BR /&gt;&lt;BR /&gt;server {&lt;BR /&gt;server_name ise-reverse-proxy-on-nginx.company-name.com;&lt;BR /&gt;return 308 &lt;A href="https://ise.company-name.com:8443/portal/g?p=abcdefgh" target="_blank"&gt;https://ise.company-name.com:8443/portal/g?p=abcdefgh&lt;/A&gt;;&lt;BR /&gt;}&lt;/P&gt;</description>
    <pubDate>Tue, 05 Nov 2019 16:20:03 GMT</pubDate>
    <dc:creator>EvaldasOu</dc:creator>
    <dc:date>2019-11-05T16:20:03Z</dc:date>
    <item>
      <title>ISE Guest Portal Settings - HTTPS Port Range</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-portal-settings-https-port-range/m-p/3526592#M496305</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;SPAN style="font-size: 11pt;"&gt;Hello team. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;SPAN style="font-size: 11pt;"&gt;Looking for some insight regarding the port range available for the ISE Guest portal.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;SPAN style="font-size: 11pt;"&gt;Today, using the portal setting UI in ISE the available port domain is 8000-8999.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-size: 11pt; background-color: yellow;"&gt;What is the reasoning behind this limitation?&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-size: 11pt; font-family: Calibri, sans-serif;"&gt;Or, asked a differently. &lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-size: 11pt; background-color: yellow;"&gt;Why are we not able to uniquely bind the Guest portal to port 443; on a unique interface, or any interface?&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;SPAN style="font-size: 11pt;"&gt;Considering that for portal configuration illustrated below, the interface (Gigabit Ethernet 2) is exclusively reserved for Guest Portal / CWA workflow. Nothing else would be expected on that socket (IP:PORT combination).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;SPAN style="font-size: 11pt;"&gt;I have a situation where a client-side policy is configured on end-user devices which prevents access to port 8443.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;IMG __jive_id="118553" alt="ise_8443.png" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/118553_ise_8443.png" style="height: 317px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri, sans-serif; font-size: 14.6667px;"&gt;Any guidance or insight that could be shared with the customer would be greatly appreciated.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;SPAN style="font-size: 11pt;"&gt;Regan&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Jul 2018 21:44:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-portal-settings-https-port-range/m-p/3526592#M496305</guid>
      <dc:creator>rdediana</dc:creator>
      <dc:date>2018-07-10T21:44:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest Portal Settings - HTTPS Port Range</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-portal-settings-https-port-range/m-p/3526593#M496306</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Specific implementation logic/decisions can't be discussed in a public community thread. Please contact your Cisco support team to get the specifics. Those can only be shared on an NDA with the customer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Krish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jul 2018 14:52:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-portal-settings-https-port-range/m-p/3526593#M496306</guid>
      <dc:creator>kvenkata1</dc:creator>
      <dc:date>2018-07-11T14:52:28Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest Portal Settings - HTTPS Port Range</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-portal-settings-https-port-range/m-p/3953437#M496307</link>
      <description>&lt;P&gt;This is funny actually... To discuss why ISE Guest portal runs on port 8443 instead 443 we need to sign NDA &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp; ...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Guess I will do reverse proxy here... we need to use "duck tape" workarounds for "duck tape" designs.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2019 15:41:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-portal-settings-https-port-range/m-p/3953437#M496307</guid>
      <dc:creator>EvaldasOu</dc:creator>
      <dc:date>2019-11-05T15:41:30Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest Portal Settings - HTTPS Port Range</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-portal-settings-https-port-range/m-p/3953457#M496308</link>
      <description>&lt;P&gt;I recommend providing &lt;A href="http://cs.co/ise-feedback" target="_blank" rel="noopener"&gt;http://cs.co/ise-feedback&lt;/A&gt; if there is a way we can do something better in the future. This goes directly to our Product managers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can change the portal you're using under portal settings&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_011100.html#reference_1F6EF09DE16E480096C2619625C256C5" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_011100.html#reference_1F6EF09DE16E480096C2619625C256C5&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2019 16:20:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-portal-settings-https-port-range/m-p/3953457#M496308</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-11-05T16:20:02Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest Portal Settings - HTTPS Port Range</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-portal-settings-https-port-range/m-p/3953466#M496309</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/199790"&gt;@Jason Kunst&lt;/a&gt;&amp;nbsp;, will do!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/397746"&gt;@rdediana&lt;/a&gt;&amp;nbsp;I have configured nginx proxy and I do redirect from here to custom ise port (8443):&lt;BR /&gt;&lt;BR /&gt;server {&lt;BR /&gt;server_name ise-reverse-proxy-on-nginx.company-name.com;&lt;BR /&gt;return 308 &lt;A href="https://ise.company-name.com:8443/portal/g?p=abcdefgh" target="_blank"&gt;https://ise.company-name.com:8443/portal/g?p=abcdefgh&lt;/A&gt;;&lt;BR /&gt;}&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2019 16:20:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-portal-settings-https-port-range/m-p/3953466#M496309</guid>
      <dc:creator>EvaldasOu</dc:creator>
      <dc:date>2019-11-05T16:20:03Z</dc:date>
    </item>
  </channel>
</rss>

