<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Redirection URL missing in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514024#M496669</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I could see where 2 different switches are running and svi for same vlan perhaps and traffic is being proxied perhaps by another switch?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 28 Jun 2018 11:18:39 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2018-06-28T11:18:39Z</dc:date>
    <item>
      <title>Redirection URL missing</title>
      <link>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514013#M496658</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: 'book antiqua', palatino;"&gt;Hi Experts,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'book antiqua', palatino;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'book antiqua', palatino;"&gt;While configuring for wired guest redirection using the sponsor guest portal, I have seen something &lt;SPAN style="font-size: 13.3333px;"&gt;weird&lt;/SPAN&gt; that is happening here.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'book antiqua', palatino;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'book antiqua', palatino;"&gt;When I have the user redirect from a test switch to the Test ISE server, the redirection URL is working and can be seen on switch as well as the Test endpoint browser.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'book antiqua', palatino;"&gt;Then I, make the same to same configuration on our Production server, but there is no redirection URL!!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'book antiqua', palatino;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'book antiqua', palatino;"&gt;I have the same guest redirect ACL in test and production ISE instances.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'book antiqua', palatino;"&gt;Also, the AuthZ profiles and Policy and conditions are same as well.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'book antiqua', palatino;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'book antiqua', palatino;"&gt;Not sure what is going on?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'book antiqua', palatino;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'book antiqua', palatino;"&gt;Could any shed some light on this issue, and what are the things that could be missing out?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'book antiqua', palatino;"&gt;Any pointers are really helpful.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2018 11:40:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514013#M496658</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-06-27T11:40:55Z</dc:date>
    </item>
    <item>
      <title>Re: Redirection URL missing</title>
      <link>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514014#M496659</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Firewall between deployment switch and ISE ??&lt;/P&gt;&lt;P&gt;Blocked port 1812,1813 ,1645,1646&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2018 12:06:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514014#M496659</guid>
      <dc:creator>ognyan.totev</dc:creator>
      <dc:date>2018-06-27T12:06:03Z</dc:date>
    </item>
    <item>
      <title>Re: Redirection URL missing</title>
      <link>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514015#M496660</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Would suggest trying a new portal on your production&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Use the tac to debug&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2018 12:14:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514015#M496660</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-06-27T12:14:33Z</dc:date>
    </item>
    <item>
      <title>Re: Redirection URL missing</title>
      <link>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514016#M496661</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also try different browser&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2018 12:16:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514016#M496661</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-06-27T12:16:57Z</dc:date>
    </item>
    <item>
      <title>Re: Redirection URL missing</title>
      <link>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514017#M496662</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;UL&gt;&lt;LI&gt;Make sure hitting the right policy rule and authorization profile -- check live log entry -- should see URL redirect.&lt;/LI&gt;&lt;LI&gt;Make sure URL redirect ACL configured on production switch.&amp;nbsp; For wireless, only need redirect ACL.&amp;nbsp; For wired, need to include the dACL as well.&amp;nbsp; Redirect ACL logic is different between wired and wireless in terms of what is denied and permitted.&lt;/LI&gt;&lt;LI&gt;Make sure client has IP address, else cannot redirect.&amp;nbsp; For wired, dACL cannot be instantiated on port.&lt;/LI&gt;&lt;LI&gt;Make sure host/subnet entries are correct for production.&lt;/LI&gt;&lt;/UL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2018 12:47:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514017#M496662</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-06-27T12:47:48Z</dc:date>
    </item>
    <item>
      <title>Re: Redirection URL missing</title>
      <link>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514018#M496663</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have rechecked the configuration and all the things are in the right place.&lt;/P&gt;&lt;P&gt;There is a redirect ACL on the switch, and as off now I have only included only one PSN in the ACL.&lt;/P&gt;&lt;P&gt;I can see that the its hitting the right policy and condition, but even then I am not able to see any redirection URL on the switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The user is then presented with the guest login page, he enters the credentials, but then authentication fails and there is no access..&lt;/P&gt;&lt;P&gt;This is happening even when the user is present...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2018 06:25:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514018#M496663</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-06-28T06:25:50Z</dc:date>
    </item>
    <item>
      <title>Re: Redirection URL missing</title>
      <link>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514019#M496664</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, these ports are open and I can see that the request is hitting the right policy and condition on ISE server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2018 06:26:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514019#M496664</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-06-28T06:26:35Z</dc:date>
    </item>
    <item>
      <title>Re: Redirection URL missing</title>
      <link>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514020#M496665</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tried with a completely new portal, yet I don't see the redirect URL on the switch where as on ISE I can see that its hitting the right policy and condition.&lt;/P&gt;&lt;P&gt;Also, the user is able to see the guest login page on his endpoint, but his authentication fails, even when the user is present in the guest users...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2018 06:28:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514020#M496665</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-06-28T06:28:26Z</dc:date>
    </item>
    <item>
      <title>Re: Redirection URL missing</title>
      <link>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514021#M496666</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;While further troubleshooting found that the redirection URL was being sent. but it was being sent by another switch.&lt;/P&gt;&lt;P&gt;User was able to authenticate and was able to gain access normally it would do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the question is that, if this switch is in open mode, in that case...&lt;/P&gt;&lt;P&gt;if the port 1812 and 1813 are not open between ISE and switch, will another switch that has ports open between ISE process the request?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this something strange or has been faced earlier as well?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2018 10:09:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514021#M496666</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-06-28T10:09:00Z</dc:date>
    </item>
    <item>
      <title>Re: Redirection URL missing</title>
      <link>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514022#M496667</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not clear what is meant by "sent by another switch".&amp;nbsp;&amp;nbsp; The redirection is originated by ISE, not the switch.&amp;nbsp; Once redirect authorization applied to the access device, the user is redirected by the wireless controller or wired switch to which it is connected.&amp;nbsp; The only way I see that happening is if you are hanging additional hubs/switches off an authenticating switch port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will see in RADIUS Live Logs the switch IP (Device IP and NAS-IP-Address) of the authenticating network access device.&amp;nbsp; Authorization will be sent to that switch only.&amp;nbsp; The URL redirect should be seen on connected switchport using the "sh auth session interface &amp;lt;x&amp;gt; detail" command (or similar command depending on model/version).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2018 10:19:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514022#M496667</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-06-28T10:19:10Z</dc:date>
    </item>
    <item>
      <title>Re: Redirection URL missing</title>
      <link>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514023#M496668</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think the answer is NO ,endpoint is connected to the 1 switch no mater if there are any other switches ,the request will be send exact form this switch and the answer must be on same switch on same port that endpoint is . Give us some configuration on the switch my opinion is NO.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2018 10:19:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514023#M496668</guid>
      <dc:creator>ognyan.totev</dc:creator>
      <dc:date>2018-06-28T10:19:54Z</dc:date>
    </item>
    <item>
      <title>Re: Redirection URL missing</title>
      <link>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514024#M496669</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I could see where 2 different switches are running and svi for same vlan perhaps and traffic is being proxied perhaps by another switch?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2018 11:18:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514024#M496669</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-06-28T11:18:39Z</dc:date>
    </item>
    <item>
      <title>Re: Redirection URL missing</title>
      <link>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514025#M496670</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is the snippet of the configuration on the switch:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;aaa new-model&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;aaa group server radius POC_ISE&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt; server &amp;lt;Test ISE Server&amp;gt; auth-port 1812 acct-port 1813&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;aaa group server radius PROD_ISE&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt; server &amp;lt;Prod PSN Server&amp;gt; auth-port 1812 acct-port 1813&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;aaa authentication login default local&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;aaa authentication dot1x default group PROD_ISE&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;aaa authorization exec default local&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;aaa authorization commands 15 default local&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;aaa authorization network default group PROD_ISE&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;aaa accounting dot1x default start-stop group PROD_ISE&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;aaa server radius dynamic-author&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt; client &amp;lt;Test ISE Server&amp;gt; server-key 7 01100F175804575D72&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt; client &amp;lt;Prod PSN Server&amp;gt; server-key 7 0802455D0A1625464058&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;interface FastEthernet1/0/3&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt; switchport access vlan 230&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt; switchport mode access&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt; switchport voice vlan 260&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt; authentication event server dead action authorize vlan 231&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt; authentication event server dead action authorize voice&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt; authentication event server alive action reinitialize&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt; authentication host-mode multi-domain&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt; authentication open&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt; authentication order mab dot1x&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt; authentication priority dot1x mab&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt; authentication port-control auto&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt; mab&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt; dot1x pae authenticator&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt; dot1x timeout tx-period 10&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt; spanning-tree portfast&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;ip access-list extended GUEST_REDIRECT&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt; deny&amp;nbsp;&amp;nbsp; udp any any eq domain&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt; deny&amp;nbsp;&amp;nbsp; udp any eq bootps any eq bootpc&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt; deny&amp;nbsp;&amp;nbsp; udp any eq bootpc any eq bootps&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt; deny&amp;nbsp;&amp;nbsp; ip any host &amp;lt;Prod PSN Server&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt; permit tcp any any eq www&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt; permit tcp any any eq 443&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt; radius-server attribute 6 on-for-login-auth&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;radius-server attribute 8 include-in-access-req&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;radius-server attribute 25 access-request include&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;radius-server dead-criteria time 5 tries 2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;radius-server host &amp;lt;Test ISE Server&amp;gt; auth-port 1812 acct-port 1813 key 7 1511021F07257A767B&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;radius-server host &amp;lt;Prod PSNr&amp;gt; auth-port 1812 acct-port 1813 key 7 062506324F4129485744&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;radius-server deadtime 10&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;radius-server vsa send accounting&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;radius-server vsa send authentication&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;Output when the switch is pointed to the production PSN:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;NAC-3750v1#show authentication sessions interface fastEthernet 1/0/3&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface:&amp;nbsp; FastEthernet1/0/3&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MAC Address:&amp;nbsp; 54e1.ad5d.194a&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP Address:&amp;nbsp; 10.226.242.13&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; User-Name:&amp;nbsp; 54e1ad5d194a&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Status:&amp;nbsp; Authz Success&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Domain:&amp;nbsp; DATA&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Security Policy:&amp;nbsp; Should Secure&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Security Status:&amp;nbsp; Unsecure&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper host mode:&amp;nbsp; multi-host&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper control dir:&amp;nbsp; both&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Authorized By:&amp;nbsp; Critical Auth&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Vlan Policy:&amp;nbsp; 231&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Session timeout:&amp;nbsp; N/A&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Idle timeout:&amp;nbsp; N/A&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Common Session ID:&amp;nbsp; 0AE2E8190000008A0E9F12A9&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Acct Session ID:&amp;nbsp; 0x000000A4&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Handle:&amp;nbsp; 0x3D00008A&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;Runnable methods list:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&amp;nbsp;&amp;nbsp; State&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; mab&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Authc Failed&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dot1x&amp;nbsp;&amp;nbsp;&amp;nbsp; Not run&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;Critical Authorization is in effect for domain(s) DATA and VOICE&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;Let me what else is needed.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2018 11:24:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514025#M496670</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-06-28T11:24:08Z</dc:date>
    </item>
    <item>
      <title>Re: Redirection URL missing</title>
      <link>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514026#M496671</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok lets say same SVI interface but this interface must have different IP address . 1 switch 1 ip address&lt;/P&gt;&lt;P&gt;and other 2 ip address on svi&lt;/P&gt;&lt;P&gt;In mine deployment&amp;nbsp; most of&amp;nbsp; switches are on same SVI example interface VLan 570&amp;nbsp; but all are have different&lt;/P&gt;&lt;P&gt;but all of them different IP address. And i never face this. ANd according to netowrok i dont think it is possible &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2018 11:26:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514026#M496671</guid>
      <dc:creator>ognyan.totev</dc:creator>
      <dc:date>2018-06-28T11:26:00Z</dc:date>
    </item>
    <item>
      <title>Re: Redirection URL missing</title>
      <link>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514027#M496672</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;show authentication sessions interface fastEthernet 1/0/3 details please&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;And screen shot from radius live logs&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2018 11:37:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514027#M496672</guid>
      <dc:creator>ognyan.totev</dc:creator>
      <dc:date>2018-06-28T11:37:37Z</dc:date>
    </item>
    <item>
      <title>Re: Redirection URL missing</title>
      <link>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514028#M496673</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is the output for Auth sessions:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;NAC-3750v1#sh auth sess int fa1/0/3&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface:&amp;nbsp; FastEthernet1/0/3&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MAC Address:&amp;nbsp; 54e1.ad5d.194a&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP Address:&amp;nbsp; 10.226.242.13&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; User-Name:&amp;nbsp; 54e1ad5d194a&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Status:&amp;nbsp; Authz Success&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Domain:&amp;nbsp; DATA&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Security Policy:&amp;nbsp; Should Secure&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Security Status:&amp;nbsp; Unsecure&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper host mode:&amp;nbsp; multi-host&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper control dir:&amp;nbsp; both&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Authorized By:&amp;nbsp; Critical Auth&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Vlan Policy:&amp;nbsp; 231&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Session timeout:&amp;nbsp; N/A&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Idle timeout:&amp;nbsp; N/A&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Common Session ID:&amp;nbsp; 0AE2E8190000008B0F0373F3&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Acct Session ID:&amp;nbsp; 0x000000A6&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Handle:&amp;nbsp; 0x1400008B&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;Runnable methods list:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&amp;nbsp;&amp;nbsp; State&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; mab&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Authc Failed&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dot1x&amp;nbsp;&amp;nbsp;&amp;nbsp; Not run&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;Critical Authorization is in effect for domain(s) DATA and VOICE&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;Live logs:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;What exactly is needed from ilve logs?&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2018 11:58:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514028#M496673</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-06-28T11:58:20Z</dc:date>
    </item>
    <item>
      <title>Re: Redirection URL missing</title>
      <link>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514029#M496674</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to get past failed AAA auth/server...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;Runnable methods list:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&amp;nbsp;&amp;nbsp; State&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;mab&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Authc Failed&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dot1x&amp;nbsp;&amp;nbsp;&amp;nbsp; Not run&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;STRONG&gt;Critical Authorization is in effect for domain(s) DATA and VOICE&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2018 13:49:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514029#M496674</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-06-28T13:49:35Z</dc:date>
    </item>
    <item>
      <title>Re: Redirection URL missing</title>
      <link>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514030#M496675</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am seeing this failed auth server when I am pointing it to the Prod ISE, not when I point it to test ISE server...&lt;/P&gt;&lt;P&gt;Is this due to two servers specified&lt;SPAN style="font-size: 10pt;"&gt;in the dynamic author command?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2018 14:13:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514030#M496675</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-06-28T14:13:18Z</dc:date>
    </item>
    <item>
      <title>Re: Redirection URL missing</title>
      <link>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514031#M496676</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Authorized By:  Critical Auth&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Critical Auth kicks in when the switch can’t communicate to the radius server.  It’s probably a firewall issue.  As far as the redirect being on another switch, it’s possible that happens if you have a switch upstream that is doing multi-auth on the downlink port…then than switch could possibly be sending an authc request to ISE for the same endpoint via MAB.  I don’t recommend this design if you have it configured that way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;George&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2018 16:25:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514031#M496676</guid>
      <dc:creator>gbekmezi-DD</dc:creator>
      <dc:date>2018-06-28T16:25:37Z</dc:date>
    </item>
    <item>
      <title>Re: Redirection URL missing</title>
      <link>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514032#M496677</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the end it turned out that, the guy who had configured the policies and ACL for the prod has also created a specific dACL for the closed mode.&lt;/P&gt;&lt;P&gt;After applying the dACL for closed mode on the AuthZ profile, was to see the redirect URL on the switch as well.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Jul 2018 08:03:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/redirection-url-missing/m-p/3514032#M496677</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-07-02T08:03:08Z</dc:date>
    </item>
  </channel>
</rss>

