<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE CWA with client proxy settings in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-cwa-with-client-proxy-settings/m-p/3718928#M507189</link>
    <description>&lt;P&gt;If Windows clients use a statically configured proxy server in their browser for HTTP/HTTPS traffic is there anyway of still getting CWA to work without turning the client proxy off?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 04 Oct 2018 06:29:35 GMT</pubDate>
    <dc:creator>firestartest</dc:creator>
    <dc:date>2018-10-04T06:29:35Z</dc:date>
    <item>
      <title>ISE CWA with client proxy settings</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cwa-with-client-proxy-settings/m-p/3718928#M507189</link>
      <description>&lt;P&gt;If Windows clients use a statically configured proxy server in their browser for HTTP/HTTPS traffic is there anyway of still getting CWA to work without turning the client proxy off?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Oct 2018 06:29:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cwa-with-client-proxy-settings/m-p/3718928#M507189</guid>
      <dc:creator>firestartest</dc:creator>
      <dc:date>2018-10-04T06:29:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE CWA with client proxy settings</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cwa-with-client-proxy-settings/m-p/3718953#M507190</link>
      <description>&lt;P&gt;&lt;SPAN&gt;You can try bypassing the PSN FQDN/IP address in proxy.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Oct 2018 06:59:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cwa-with-client-proxy-settings/m-p/3718953#M507190</guid>
      <dc:creator>Aravind Ravichandran</dc:creator>
      <dc:date>2018-10-04T06:59:46Z</dc:date>
    </item>
    <item>
      <title>Re: ISE CWA with client proxy settings</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cwa-with-client-proxy-settings/m-p/3719041#M507192</link>
      <description>&lt;P&gt;Yeah I was thinking that and maybe getting clients to manually type in a URL of a site that is also bypassed to force the portal up.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Oct 2018 08:55:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cwa-with-client-proxy-settings/m-p/3719041#M507192</guid>
      <dc:creator>firestartest</dc:creator>
      <dc:date>2018-10-04T08:55:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISE CWA with client proxy settings</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cwa-with-client-proxy-settings/m-p/3719157#M507193</link>
      <description>&lt;P&gt;Bypassing the PSN IPs in the proxy setting won't help with the actual redirect, but would help when they get the redirect.&amp;nbsp; To actually get the redirect you would have to do as you suggested bypass a specific site and have the users go to that site.&amp;nbsp;&amp;nbsp;It could be any site that resolves.&amp;nbsp; You could even use the fake site, enroll.cisco.com, which the posture module uses for discovery.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Oct 2018 11:22:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cwa-with-client-proxy-settings/m-p/3719157#M507193</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-10-04T11:22:43Z</dc:date>
    </item>
    <item>
      <title>Re: ISE CWA with client proxy settings</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cwa-with-client-proxy-settings/m-p/3719296#M507316</link>
      <description>&lt;P&gt;Best option is to exempt ISE PSN IP and hostnames from going through proxy and also add in following hosts to the proxy exemption list:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="http://www.msftncsi.com" target="_blank"&gt;www.msftncsi.com&lt;/A&gt;&amp;nbsp;(Microsoft)&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://www.msftconnecttest.com" target="_blank"&gt;www.msftconnecttest.com&lt;/A&gt; (Microsoft; Windows 10 Edge browser)&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://www.gstatic.com" target="_blank"&gt;www.gstatic.com&lt;/A&gt; (Google)&lt;/LI&gt;
&lt;LI&gt;captive.apple.com (Apple)&lt;/LI&gt;
&lt;LI&gt;nmcheck.gnome.org (Linux)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Background: These are destinations for respective OS vendor to check on whether the network access has captive portal for hotspot or webauth enabled (AKA captive portal detection or captive portal assistant). By&amp;nbsp;exempting these hosts from proxy, the traffic to these hosts can hit the redirect ACL and gets redirected to ISE portal page which lets the OS know that there is a captive portal to deal with prior to getting full Internet access. This allows the mini browser or task bar balloon to pop-up for the user to take action, which is better than forcing them to enter a URL manually in the browser. FYI, here are the actual URL for each vendor (May have been changed, since I collected them few years ago:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="http://www.msftncsi.com/ncsi.txt" target="_blank"&gt;http://www.msftncsi.com/ncsi.txt&lt;/A&gt; (Microsoft)&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://www.msftconnecttest.com/redirect&amp;nbsp;" target="_blank"&gt;http://www.msftconnecttest.com/redirect&amp;nbsp;&lt;/A&gt;&lt;SPAN&gt;(Microsoft; Windows 10 Edge browser)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://www.gstatic.com/generate_204" target="_blank"&gt;http://www.gstatic.com/generate_204&lt;/A&gt; (Google)&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://captive.apple.com/hotspot-detect.html" target="_blank"&gt;http://captive.apple.com/hotspot-detect.html&lt;/A&gt; (Apple)&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://nmcheck.gnome.org/check_network_status.txt" target="_blank"&gt;http://nmcheck.gnome.org/check_network_status.txt&lt;/A&gt; (Linux)&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 08 Oct 2018 22:12:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cwa-with-client-proxy-settings/m-p/3719296#M507316</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2018-10-08T22:12:59Z</dc:date>
    </item>
  </channel>
</rss>

