<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Guest CWA - portal not redirecting in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/guest-cwa-portal-not-redirecting/m-p/3597110#M504301</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes I did follow that guide and also this &lt;A href="https://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/identity-based-networking-services/whitepaper_C11-729965.html" title="https://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/identity-based-networking-services/whitepaper_C11-729965.html"&gt;https://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/identity-based-networking-services/whitepaper_C11-7…&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 07 Jun 2018 20:20:24 GMT</pubDate>
    <dc:creator>creserva1</dc:creator>
    <dc:date>2018-06-07T20:20:24Z</dc:date>
    <item>
      <title>Guest CWA - portal not redirecting</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-cwa-portal-not-redirecting/m-p/3597106#M504297</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have been testing WebAuth on a switch but I have been stuck and unable to get the url redirection comes up. The policy for authentication and authorization it hits on ISE but the redirections is not working. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/5&lt;/P&gt;&lt;P&gt; switchport access vlan 14&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; ip access-group ACL-DEFAULT in&lt;/P&gt;&lt;P&gt; authentication periodic&lt;/P&gt;&lt;P&gt; authentication timer reauthenticate server&lt;/P&gt;&lt;P&gt; access-session port-control auto&lt;/P&gt;&lt;P&gt; access-session control-direction in&lt;/P&gt;&lt;P&gt; mab&lt;/P&gt;&lt;P&gt; dot1x pae authenticator&lt;/P&gt;&lt;P&gt; dot1x timeout tx-period 10&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt; spanning-tree bpduguard enable&lt;/P&gt;&lt;P&gt; service-policy type control subscriber DOT1X-DEFAULT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3560X#show access-session int gi 0/5 de&lt;/P&gt;&lt;P&gt;3560X#show access-session int gi 0/5 details &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface:&amp;nbsp; GigabitEthernet0/5&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MAC Address:&amp;nbsp; XX-XX-XX-XX&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IPv6 Address:&amp;nbsp; Unknown&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IPv4 Address:&amp;nbsp; 10.x.x.x&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; User-Name:&amp;nbsp; XX-XX-XX-XX&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Status:&amp;nbsp; Unauthorized&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Domain:&amp;nbsp; DATA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper host mode:&amp;nbsp; multi-auth&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper control dir:&amp;nbsp; in&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Session timeout:&amp;nbsp; N/A&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Common Session ID:&amp;nbsp; 0A0A0110000005C686B230A0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Acct Session ID:&amp;nbsp; Unknown&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Handle:&amp;nbsp; 0x0D00050C&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Current Policy:&amp;nbsp; DOT1X-DEFAULT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Method status list:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; State&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dot1x&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Stopped&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; mab&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Authc Success&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACL Switch&lt;/P&gt;&lt;P&gt;ip access-list extended ACL-DEFAULT&lt;/P&gt;&lt;P&gt; permit udp any eq bootpc any eq bootps&lt;/P&gt;&lt;P&gt; permit udp any any eq domain&lt;/P&gt;&lt;P&gt; permit icmp any any&lt;/P&gt;&lt;P&gt; permit udp any any eq tftp&lt;/P&gt;&lt;P&gt; permit tcp any host 10.96.50.181 eq www&lt;/P&gt;&lt;P&gt; permit tcp any host 10.96.50.181 eq 443&lt;/P&gt;&lt;P&gt; permit tcp any host 10.96.50.181 eq 8443&lt;/P&gt;&lt;P&gt; permit tcp any host 10.96.50.182 eq www&lt;/P&gt;&lt;P&gt; permit tcp any host 10.96.50.182 eq 443&lt;/P&gt;&lt;P&gt; permit tcp any host 10.96.50.182 eq 8443&lt;/P&gt;&lt;P&gt; deny&amp;nbsp;&amp;nbsp; ip any any log&lt;/P&gt;&lt;P&gt;ip access-list extended ACL-WEBAUTH-REDIRECT&lt;/P&gt;&lt;P&gt; deny&amp;nbsp;&amp;nbsp; udp any any eq domain&lt;/P&gt;&lt;P&gt; deny&amp;nbsp;&amp;nbsp; tcp any any eq 8905&lt;/P&gt;&lt;P&gt; deny&amp;nbsp;&amp;nbsp; tcp any any eq 8443&lt;/P&gt;&lt;P&gt; permit tcp any any eq www&lt;/P&gt;&lt;P&gt; permit tcp any any eq 443&lt;/P&gt;&lt;P&gt; deny&amp;nbsp;&amp;nbsp; ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DACL&lt;/P&gt;&lt;P&gt;permit udp any any eq bootps&lt;/P&gt;&lt;P&gt;permit udp any any eq domain&lt;/P&gt;&lt;P&gt;permit tcp any any eq domain&lt;/P&gt;&lt;P&gt;remark ping for troubleshooting&lt;/P&gt;&lt;P&gt;permit icmp any any echo&lt;/P&gt;&lt;P&gt;permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;remark allow web traffic to kick off redirect&lt;/P&gt;&lt;P&gt;permit tcp any any eq www&lt;/P&gt;&lt;P&gt;permit tcp any any eq 443&lt;/P&gt;&lt;P&gt;remark mandatory for ISE PSN for Guest Portal Access&lt;/P&gt;&lt;P&gt;permit tcp any host 10.96.50.181 eq 8443&lt;/P&gt;&lt;P&gt;permit tcp any host 10.96.50.181 eq 8905&lt;/P&gt;&lt;P&gt;permit tcp any host 10.96.50.181 eq 8909&lt;/P&gt;&lt;P&gt;permit tcp any host 10.96.50.181 range 8905 8906&lt;/P&gt;&lt;P&gt;permit udp any host 10.96.50.181 eq 8909&lt;/P&gt;&lt;P&gt;permit tcp any host 10.96.50.182 eq 8443&lt;/P&gt;&lt;P&gt;permit tcp any host 10.96.50.182 eq 8905&lt;/P&gt;&lt;P&gt;permit tcp any host 10.96.50.182 eq 8909&lt;/P&gt;&lt;P&gt;permit tcp any host 10.96.50.182 range 8905 8906&lt;/P&gt;&lt;P&gt;permit udp any host 10.96.50.182 eq 8909&lt;/P&gt;&lt;P&gt;deny ip any any&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jun 2018 20:26:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-cwa-portal-not-redirecting/m-p/3597106#M504297</guid>
      <dc:creator>creserva1</dc:creator>
      <dc:date>2018-06-06T20:26:05Z</dc:date>
    </item>
    <item>
      <title>Re: Guest CWA - portal not redirecting</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-cwa-portal-not-redirecting/m-p/3597107#M504298</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you referencing ACL-WEBAUTH-REDIRECT in your authorization result?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;-Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jun 2018 13:26:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-cwa-portal-not-redirecting/m-p/3597107#M504298</guid>
      <dc:creator>Timothy Abbott</dc:creator>
      <dc:date>2018-06-07T13:26:37Z</dc:date>
    </item>
    <item>
      <title>Re: Guest CWA - portal not redirecting</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-cwa-portal-not-redirecting/m-p/3597108#M504299</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you check this document as well?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;https://communities.cisco.com/docs/DOC-77590&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jun 2018 15:05:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-cwa-portal-not-redirecting/m-p/3597108#M504299</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-06-07T15:05:43Z</dc:date>
    </item>
    <item>
      <title>Re: Guest CWA - portal not redirecting</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-cwa-portal-not-redirecting/m-p/3597109#M504300</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes I am. I have that on under profile authorizations then CWA then ACL were I added the name ACL-WEBAUTH-REDIRECT.&amp;nbsp; It is applying authentication and authorization it is just the CWA does not comes up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also tried remove the dot1x system auth kind a disabling the dot1x globally and then re-adding it back. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jun 2018 20:19:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-cwa-portal-not-redirecting/m-p/3597109#M504300</guid>
      <dc:creator>creserva1</dc:creator>
      <dc:date>2018-06-07T20:19:11Z</dc:date>
    </item>
    <item>
      <title>Re: Guest CWA - portal not redirecting</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-cwa-portal-not-redirecting/m-p/3597110#M504301</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes I did follow that guide and also this &lt;A href="https://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/identity-based-networking-services/whitepaper_C11-729965.html" title="https://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/identity-based-networking-services/whitepaper_C11-729965.html"&gt;https://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/identity-based-networking-services/whitepaper_C11-7…&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jun 2018 20:20:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-cwa-portal-not-redirecting/m-p/3597110#M504301</guid>
      <dc:creator>creserva1</dc:creator>
      <dc:date>2018-06-07T20:20:24Z</dc:date>
    </item>
    <item>
      <title>Re: Guest CWA - portal not redirecting</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-cwa-portal-not-redirecting/m-p/3597111#M504302</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;﻿Would recommend contacting the tac to see what you’re doing wrong then&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jun 2018 20:22:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-cwa-portal-not-redirecting/m-p/3597111#M504302</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-06-07T20:22:21Z</dc:date>
    </item>
    <item>
      <title>Re: Guest CWA - portal not redirecting</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-cwa-portal-not-redirecting/m-p/3597112#M504303</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not sure, but one thing we have that I don't see&amp;nbsp; is permitting DNS? I also only have a redirect on wireless, so may be different.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jun 2018 21:30:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-cwa-portal-not-redirecting/m-p/3597112#M504303</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2018-06-07T21:30:28Z</dc:date>
    </item>
    <item>
      <title>Re: Guest CWA - portal not redirecting</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-cwa-portal-not-redirecting/m-p/3597113#M504304</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Since the session is mac authc success but unauthorized, I would suggest to double check the text typed in as the redirect ACL. It can be a problem when copied from a word doc or PDF file such that "-" is not regular ASCII character. If that does not help, then please look it up in the Cisco IOS release used on the switch and find what debug commands equivalent to "debug aaa attr" and "debug aaa authorization".&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jun 2018 22:29:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-cwa-portal-not-redirecting/m-p/3597113#M504304</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-06-07T22:29:09Z</dc:date>
    </item>
    <item>
      <title>Re: Guest CWA - portal not redirecting</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-cwa-portal-not-redirecting/m-p/3597114#M504305</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 13.3333px;"&gt;Here is my &lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Switch ACL&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;ACL-DEFAULT&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;10 permit udp any eq bootpc any eq bootps&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;20 permit udp any any eq domain&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;30 permit icmp any any&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;40 permit udp any any eq tftp&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;50 permit tcp any host 10.x.x.x eq www&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;60 permit tcp any host &lt;SPAN style="font-size: 13.3333px;"&gt;10.x.x.x&lt;/SPAN&gt; eq 443&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;70 permit tcp any host &lt;SPAN style="font-size: 13.3333px;"&gt;10.x.x.x&lt;/SPAN&gt; eq 8443&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;80 permit tcp any host &lt;SPAN style="font-size: 13.3333px;"&gt;10.x.x.x&lt;/SPAN&gt; eq www&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;90 permit tcp any host &lt;SPAN style="font-size: 13.3333px;"&gt;10.x.x.x&lt;/SPAN&gt; eq 443&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;100 permit tcp any host &lt;SPAN style="font-size: 13.3333px;"&gt;10.x.x.x&lt;/SPAN&gt; eq 8443&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Switch ACL&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;ACL-WEBAUTH-REDIRECT&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;9 deny udp any any eq domain (2 matches)&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;20 permit tcp any any eq www (10 matches)&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;30 permit tcp any any eq 443 (28 matches)&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;ISE - DACL-pre-WebAuth&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;permit udp any any eq bootps&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;permit udp any any eq domain&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;permit tcp any any eq domain&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;remark ping for troubleshooting&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;permit icmp any any echo&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;permit icmp any any echo-reply&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;remark allow web traffic to kick off redirect&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;permit tcp any any eq www&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;permit tcp any any eq 443&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;remark mandatory for ISE PSN for Guest Portal Access&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;permit tcp any host &lt;SPAN style="font-size: 13.3333px;"&gt;10.x.x.x&lt;/SPAN&gt; eq 8443&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;permit tcp any host &lt;SPAN style="font-size: 13.3333px;"&gt;10.x.x.x&lt;/SPAN&gt; eq 8905&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;permit tcp any host &lt;SPAN style="font-size: 13.3333px;"&gt;10.x.x.x&lt;/SPAN&gt; eq 8909&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;permit tcp any host &lt;SPAN style="font-size: 13.3333px;"&gt;10.x.x.x&lt;/SPAN&gt; range 8905 8906&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;permit udp any host &lt;SPAN style="font-size: 13.3333px;"&gt;10.x.x.x&lt;/SPAN&gt; eq 8909&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;permit tcp any host &lt;SPAN style="font-size: 13.3333px;"&gt;10.x.x.x&lt;/SPAN&gt; eq 8443&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;permit tcp any host &lt;SPAN style="font-size: 13.3333px;"&gt;10.x.x.x&lt;/SPAN&gt; eq 8905&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;permit tcp any host &lt;SPAN style="font-size: 13.3333px;"&gt;10.x.x.x&lt;/SPAN&gt; eq 8909&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;permit tcp any host &lt;SPAN style="font-size: 13.3333px;"&gt;10.x.x.x&lt;/SPAN&gt; range 8905 8906&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;permit udp any host &lt;SPAN style="font-size: 13.3333px;"&gt;10.x.x.x&lt;/SPAN&gt; eq 8909&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Profile-GuestWebAuth&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Access Type = ACCESS_ACCEPT&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;DACL = DACL-pre-WebAuth&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;cisco-av-pair = url-redirect-acl=ACL_WEBAUTH_REDIRECT&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;SPAN&gt;cisco-av-pair = url-redirect=&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://10.x.x.x:port/portal/gateway?sessionId=(I" rel="nofollow" target="_blank"&gt;https://10.x.x.x:port/portal/gateway?sessionId=(I&lt;/A&gt;&lt;SPAN&gt; removed the sessions id)=cwa&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;I turn on debug for radius&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Log Buffer (4096 bytes):&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&amp;nbsp; 8 14:00:54.026: RADIUS:&amp;nbsp; Vendor, Cisco&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [26]&amp;nbsp; 47&amp;nbsp; &lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.026: RADIUS:&amp;nbsp;&amp;nbsp; Cisco AVpair&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [1]&amp;nbsp;&amp;nbsp; 41&amp;nbsp; "ip:inacl#2=permit udp any any eq domain"&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.026: RADIUS:&amp;nbsp; Vendor, Cisco&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [26]&amp;nbsp; 47&amp;nbsp; &lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.026: RADIUS:&amp;nbsp;&amp;nbsp; Cisco AVpair&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [1]&amp;nbsp;&amp;nbsp; 41&amp;nbsp; "ip:inacl#3=permit tcp any any eq domain"&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.026: RADIUS:&amp;nbsp; Vendor, Cisco&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [26]&amp;nbsp; 50&amp;nbsp; &lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.026: RADIUS:&amp;nbsp;&amp;nbsp; Cisco AVpair&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [1]&amp;nbsp;&amp;nbsp; 44&amp;nbsp; "ip:inacl#4=remark ping for troubleshooting"&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.026: RADIUS:&amp;nbsp; Vendor, Cisco&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [26]&amp;nbsp; 43&amp;nbsp; &lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.026: RADIUS:&amp;nbsp;&amp;nbsp; Cisco AVpair&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [1]&amp;nbsp;&amp;nbsp; 37&amp;nbsp; "ip:inacl#5=permit icmp any any echo"&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.026: RADIUS:&amp;nbsp; Vendor, Cisco&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [26]&amp;nbsp; 49&amp;nbsp; &lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.026: RADIUS:&amp;nbsp;&amp;nbsp; Cisco AVpair&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [1]&amp;nbsp;&amp;nbsp; 43&amp;nbsp; "ip:inacl#6=permit icmp any any echo-reply"&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.026: RADIUS:&amp;nbsp; Vendor, Cisco&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [26]&amp;nbsp; 64&amp;nbsp; &lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.026: RADIUS:&amp;nbsp;&amp;nbsp; Cisco AVpair&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [1]&amp;nbsp;&amp;nbsp; 58&amp;nbsp; "ip:inacl#7=remark allow web traffic to kick off redirect"&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.026: RADIUS:&amp;nbsp; Vendor, Cisco&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [26]&amp;nbsp; 44&amp;nbsp; &lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.026: RADIUS:&amp;nbsp;&amp;nbsp; Cisco AVpair&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [1]&amp;nbsp;&amp;nbsp; 38&amp;nbsp; "ip:inacl#8=permit tcp any any eq www"&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.026: RADIUS:&amp;nbsp; Vendor, Cisco&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [26]&amp;nbsp; 44&amp;nbsp; &lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.026: RADIUS:&amp;nbsp;&amp;nbsp; Cisco AVpair&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [1]&amp;nbsp;&amp;nbsp; 38&amp;nbsp; "ip:inacl#9=permit tcp any any eq 443"&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.026: RADIUS:&amp;nbsp; Vendor, Cisco&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [26]&amp;nbsp; 72&amp;nbsp; &lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.026: RADIUS:&amp;nbsp;&amp;nbsp; Cisco AVpair&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [1]&amp;nbsp;&amp;nbsp; 66&amp;nbsp; "ip:inacl#10=remark mandatory for ISE PSN for Guest Portal Access"&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.026: RADIUS:&amp;nbsp; Vendor, Cisco&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [26]&amp;nbsp; 60&amp;nbsp; &lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.026: RADIUS:&amp;nbsp;&amp;nbsp; Cisco AVpair&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [1]&amp;nbsp;&amp;nbsp; 54&amp;nbsp; "ip:inacl#11=permit tcp any host 10.x.x.x eq 8443"&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.026: RADIUS:&amp;nbsp; Vendor, Cisco&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [26]&amp;nbsp; 60&amp;nbsp; &lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.026: RADIUS:&amp;nbsp;&amp;nbsp; Cisco AVpair&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [1]&amp;nbsp;&amp;nbsp; 54&amp;nbsp; "ip:inacl#12=permit tcp any host 10.x.x.x eq 8905"&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.026: RADIUS:&amp;nbsp; Vendor, Cisco&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [26]&amp;nbsp; 60&amp;nbsp; &lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.026: RADIUS:&amp;nbsp;&amp;nbsp; Cisco AVpair&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [1]&amp;nbsp;&amp;nbsp; 54&amp;nbsp; "ip:inacl#13=permit tcp any host 10.x.x.x eq 8909"&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.026: RADIUS:&amp;nbsp; Vendor, Cisco&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [26]&amp;nbsp; 68&amp;nbsp; &lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.026: RADIUS:&amp;nbsp;&amp;nbsp; Cisco AVpair&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [1]&amp;nbsp;&amp;nbsp; 62&amp;nbsp; "ip:inacl#14=permit tcp any host 10.x.x.x range 8905 8906"&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.026: RADIUS:&amp;nbsp; Vendor, Cisco&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [26]&amp;nbsp; 60&amp;nbsp; &lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.026: RADIUS:&amp;nbsp;&amp;nbsp; Cisco AVpair&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [1]&amp;nbsp;&amp;nbsp; 54&amp;nbsp; "ip:inacl#15=permit udp any host 10.x.x.x eq 8909"&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.026: RADIUS:&amp;nbsp; Vendor, Cisco&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [26]&amp;nbsp; 60&amp;nbsp; &lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.026: RADIUS:&amp;nbsp;&amp;nbsp; Cisco AVpair&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [1]&amp;nbsp;&amp;nbsp; 54&amp;nbsp; "ip:inacl#16=permit tcp any host 10.x.x.x eq 8443"&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.026: RADIUS:&amp;nbsp; Vendor, Cisco&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [26]&amp;nbsp; 60&amp;nbsp; &lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.026: RADIUS:&amp;nbsp;&amp;nbsp; Cisco AVpair&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [1]&amp;nbsp;&amp;nbsp; 54&amp;nbsp; "ip:inacl#17=permit tcp any host 10.x.x.x eq 8905"&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.026: RADIUS:&amp;nbsp; Vendor, Cisco&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [26]&amp;nbsp; 60&amp;nbsp; &lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.026: RADIUS:&amp;nbsp;&amp;nbsp; Cisco AVpair&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [1]&amp;nbsp;&amp;nbsp; 54&amp;nbsp; "ip:inacl#18=permit tcp any host 10.x.x.x eq 8909"&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.026: RADIUS:&amp;nbsp; Vendor, Cisco&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [26]&amp;nbsp; 68&amp;nbsp; &lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.026: RADIUS:&amp;nbsp;&amp;nbsp; Cisco AVpair&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [1]&amp;nbsp;&amp;nbsp; 62&amp;nbsp; "ip:inacl#19=permit tcp any host 10.x.x.x range 8905 8906"&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.026: RADIUS:&amp;nbsp; Vendor, Cisco&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [26]&amp;nbsp; 60&amp;nbsp; &lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.026: RADIUS:&amp;nbsp;&amp;nbsp; Cisco AVpair&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [1]&amp;nbsp;&amp;nbsp; 54&amp;nbsp; "ip:inacl#20=permit udp any host 10.x.x.x eq 8909"&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.026: RADIUS(00000000): Received from id 1645/167&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.387: %AUTHMGR-5-FAIL: Authorization failed or unapplied for client (xxxx.xxxx.xxxx) on Interface Gi0/5 AuditSessionID xxxx.xxxx.xxxx&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:00:54.832: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0/5, changed state to up&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:01:24.844: %DOT1X-5-FAIL: Authentication failed for client (xxxx.xxxx.xxxx) on Interface Gi0/5 AuditSessionID xxxx.xxxx.xxxx&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:01:24.844: %AUTHMGR-7-STOPPING: Stopping 'dot1x' for client xxxx.xxxx.xxxx on Interface Gi0/5 AuditSessionID xxxx.xxxx.xxxx&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:01:26.455: %SYS-5-CONFIG_I: Configured from console by xxxx.xxxx.xxxx on vty0 (xxxx.xxxx.xxxx)&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 14:01:40.085: %SYS-5-CONFIG_I: Configured from console by xxxx.xxxx.xxxx on vty0 (xxxx.xxxx.xxxx)&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;C3560X# &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2018 14:09:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-cwa-portal-not-redirecting/m-p/3597114#M504305</guid>
      <dc:creator>creserva1</dc:creator>
      <dc:date>2018-06-08T14:09:19Z</dc:date>
    </item>
    <item>
      <title>Re: Guest CWA - portal not redirecting</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-cwa-portal-not-redirecting/m-p/3597115#M504306</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I see you have 8909 UDP/TCP twice. ISE is no longer using 8909.&lt;/P&gt;&lt;P&gt;I would suggest to try a simpler DACL (e.g. permit ip any any) and see if that work, then adding more entries to narrow down which one(s) causing the problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2018 15:02:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-cwa-portal-not-redirecting/m-p/3597115#M504306</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-06-08T15:02:09Z</dc:date>
    </item>
    <item>
      <title>Re: Guest CWA - portal not redirecting</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-cwa-portal-not-redirecting/m-p/3597116#M504307</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;This may seem slightly odd but I remember there being a bug causing mab authz failures when there was a remark present in the DACL.&amp;nbsp; If it was me I would remove the remarks and test again, easy to check.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2018 15:33:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-cwa-portal-not-redirecting/m-p/3597116#M504307</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2018-06-08T15:33:39Z</dc:date>
    </item>
    <item>
      <title>Re: Guest CWA - portal not redirecting</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-cwa-portal-not-redirecting/m-p/3597117#M504308</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That worths a shot. Hari said,&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;TABLE border="1"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;
&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Helvetica; font-size: 12px;"&gt;IP ACLs with remarks has worked for me all the times. ACEs with additional options have issues. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Helvetica; font-size: 12px;"&gt;There are couple of release notes for the 4500 software that states this limitation :&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;TABLE border="1" cellpadding="0" cellspacing="0" style="color: #000000; font-family: Helvetica; border: none;"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style="border: 1pt solid windowtext; padding: 0 5.4pt;" valign="top" width="426"&gt;
&lt;P style="font-size: 12pt; font-family: Cambria;"&gt;&lt;SPAN style="font-size: 11pt; font-family: 'Times New Roman';"&gt;•Dynamic ACLs do not function correctly if they include advanced operators, including dscp/ipp/tos, log/log-input, fragments and/or tcp flag operators.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P style="font-size: 12pt; font-family: Cambria;"&gt;&lt;SPAN style="font-size: 11pt; font-family: 'Times New Roman';"&gt;Workaround: Remove these operators from any dynamic ACLs. CSCts05302&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG style="color: #000000; font-family: Helvetica; font-size: 12px;"&gt;Open Caveats in Cisco IOS Release 15.0(2)SG7&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A class="moz-txt-link-freetext" href="http://www.cisco.com/en/US/docs/switches/lan/catalyst4500/release/note/OL_24730.html#wp932647" style="font-family: Helvetica; font-size: 12px;"&gt;http://www.cisco.com/en/US/docs/switches/lan/catalyst4500/release/note/OL_24730.html#wp932647&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG style="color: #000000; font-family: Helvetica; font-size: 12px;"&gt;Open Caveats for Cisco IOS XE Release 3.2.7SG&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A class="moz-txt-link-freetext" href="http://www.cisco.com/en/US/docs/switches/lan/catalyst4500/release/note/OL_24726.html#wp2594827" style="font-family: Helvetica; font-size: 12px;"&gt;http://www.cisco.com/en/US/docs/switches/lan/catalyst4500/release/note/OL_24726.html#wp2594827&lt;/A&gt;&lt;/P&gt;
&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And, "debug epm all" or similar might help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2018 15:47:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-cwa-portal-not-redirecting/m-p/3597117#M504308</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-06-08T15:47:43Z</dc:date>
    </item>
    <item>
      <title>Re: Guest CWA - portal not redirecting</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-cwa-portal-not-redirecting/m-p/3597118#M504309</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 13.3333px;"&gt;Here are the debu using emp all. The dACL on ISE is just using permit ip any any and local ACL on and this acl is on ISE authorization profile common task Centralized Web Auth -&amp;nbsp; ACL-WEBAUTH-REDIRECT are also permit ip any any. The ACL-DEFAULT which is applied&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;STRONG&gt;Jun&amp;nbsp; 8 18:32:27.591: EPM_SESS_EVENT: Executed [ip access-list extended xACSACLx-IP-DACL-pre-WebAuth-5b1aafd6] command through parse_cmd. Result= 0&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;STRONG&gt;Jun&amp;nbsp; 8 18:32:27.591: EPM_SESS_EVENT: Executed [1 permit ip any any] command through parse_cmd. Result= 0&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 18:32:27.591: EPM_API: Inside epm_cache_mgr_acl_modified&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 18:32:27.591: EPM_API: Inside epm_cache_mgr_attr_modified&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 18:32:27.591: EPM_API: Inside epm_cache_mgr_get_entry&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 18:32:27.591: EPM_API: Inside epm_cache_mgr_attr_modified&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 18:32:27.591: EPM_API: Inside epm_cache_mgr_get_entry&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 18:32:27.591: EPM_SESS_EVENT: Executed [end] command through parse_cmd. Result= 0&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 18:32:27.591: EPM_API: Inside epm_cache_mgr_sync_attr_template&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 18:32:27.591: EPM_API: Inside epm_cache_mgr_get_attr_fv&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 18:32:27.591: EPM_SESS_EVENT: EPM_HA: Sync not required&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 18:32:27.591: EPM_API: Inside epm_cache_mgr_notify_status_change&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 18:32:27.591: EPM_API: Inside fn epm_acl_cache_mgr_updates&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 18:32:27.591: EPM_API: Inside epm_dl_mgr_cleanup_context&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 18:32:27.591: EPM_API: [0x52000031]:Inside Function epm_acl_create_nacl_feature_config&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 18:32:27.591: EPM_API: Inside epm_acl_policy_process_action&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 18:32:27.591: EPM_SESS_EVENT: IN ACL configured.. not attaching def ACL&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 18:32:27.591: EPM_API: [0x52000031]:Inside epm_acl_check_open_dir_acl&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 18:32:27.591: EPM_API: [0x52000031]:Applying Open dir for current session&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 18:32:27.600: EPM_API: [0x52000031]:ACL Feat available for session open dir not required&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 18:32:27.600: EPM_API: In Function epm_acl_apply_feature_order&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 18:32:27.600: EPM_SESS_EVENT: Feature re-order required&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 18:32:27.600: EPM_API: [0x52000031]:In function epm_acl_apply_access_policies&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 18:32:27.600: EPM_API: [0x52000031]:In function epm_acl_apply_nacl&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 18:32:27.600: EPM_API: [0x52000031]:[0xE4000039]:In function epm_acl_add_item&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 18:32:27.600: EPM_API: Inside Function epm_acl_host_policy_update&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 18:32:27.600: EPM_API: In Function epm_acl_check_tcam_opt&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 18:32:27.600: EPM_SESS_EVENT: open access in non MH mode no tcam opt&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;STRONG&gt;Jun&amp;nbsp; 8 18:32:27.600: EPM_SESS_EVENT: Applying policy in PD for IP 10.x.x.x ip_flag 1 type 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;STRONG&gt;Jun&amp;nbsp; 8 18:32:27.600: EPM_SESS_EVENT: ACL xACSACLx-IP-DACL-pre-WebAuth-5b1aafd6 provisioning successful&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;STRONG&gt;Jun&amp;nbsp; 8 18:32:27.600: EPM_API: [0x52000031]:Inside epm_acl_appn_success_action&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 18:32:27.600: EPM_API: Inside epm_feature_notify_status&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 18:32:27.600: EPM_API: Inside epm_get_feature_info_from_hdl&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 18:32:27.600: EPM_API: Inside epm_get_authz_info_from_hdl&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 18:32:27.608: EPM_SESS_EVENT: Feature (EPM ACL PLUG-IN) Status (1) Notified&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 18:32:27.608: EPM_API: [0x30000DE]:Inside epm_update_authz_terminal_status&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 18:32:27.608: EPM_SESS_EVENT: Successful feature attrs provided for SM ACCOUNTING PLUG-IN&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;STRONG&gt;Jun&amp;nbsp; 8 18:32:27.608: EPM_SESS_EVENT: Failed feature attrs provided for EPM URL PLUG-IN&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 18:32:27.608: EPM_SESS_EVENT: Successful feature attrs provided for EPM ACL PLUG-IN&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Jun&amp;nbsp; 8 18:32:27.608: EPM_API: [0x30000DE]:Inside epm_notify_authz_terminal_status&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2018 19:39:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-cwa-portal-not-redirecting/m-p/3597118#M504309</guid>
      <dc:creator>creserva1</dc:creator>
      <dc:date>2018-06-08T19:39:22Z</dc:date>
    </item>
    <item>
      <title>Re: Guest CWA - portal not redirecting</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-cwa-portal-not-redirecting/m-p/3597119#M504310</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE&gt;&lt;TABLE border="1"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;
&lt;P style="font-size: 13.3333px; font-family: arial; color: #3d3d3d;"&gt;&lt;SPAN style="font-style: inherit; font-family: inherit;"&gt;&lt;STRONG&gt;Jun&amp;nbsp; 8 18:32:27.608: EPM_SESS_EVENT: Failed feature attrs provided for EPM URL PLUG-IN&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;




&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN style="font-style: inherit; font-family: inherit;"&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;My guess is the problem around the web redirect ACL name. Please verify it by disabling web redirect. I would suggest to try a simpler name without any punctuation characters; e.g. urlacl. Also, try typing it in but not copy-and-paste and ensure no preceding or trailing space characters.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, you may remove the first ACE "deny udp any any domain" as it's implicitly denied.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If that still not helping, try reloading the switch once. It might be some IOS switch bug and you might consider a different IOS train.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2018 22:20:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-cwa-portal-not-redirecting/m-p/3597119#M504310</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-06-08T22:20:21Z</dc:date>
    </item>
    <item>
      <title>Re: Guest CWA - portal not redirecting</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-cwa-portal-not-redirecting/m-p/3597120#M504311</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I got it this on figured out. It was something on to do on ACL naming. It is very easy to missed this kind of mis configurations. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 09 Jun 2018 13:46:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-cwa-portal-not-redirecting/m-p/3597120#M504311</guid>
      <dc:creator>creserva1</dc:creator>
      <dc:date>2018-06-09T13:46:43Z</dc:date>
    </item>
  </channel>
</rss>

