<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE CWA Flow Validation in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-cwa-flow-validation/m-p/3575227#M511748</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;I'm working on an ISE POC with a customer and we ran into an issue with ISE CWA on switches without SVI's in the Data/Access VLAN's. The customer is using an ASA as their default GW for all vlans so every vlan needs to go through policy for communication.&amp;nbsp; I have put together the attached flow based on information I have read but would like to verify this is correct and I'm not missing anything. Due to the asymmetry of how URL Redirection works, I can see how this will cause a problem with Firewalls.&amp;nbsp; I have also added some alternative designs in the image.&amp;nbsp; Is there any Best Practice Designs with this type of scenario?&amp;nbsp; Also, Is this flow accurate?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ISE CWA Flow_Access Switch WO SVI.jpg" class="image-1 jive-image" src="/legacyfs/online/fusion/115798_ISE CWA Flow_Access Switch WO SVI.jpg" style="height: 349px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 07 Mar 2018 17:01:13 GMT</pubDate>
    <dc:creator>tolarosa@cisco.com</dc:creator>
    <dc:date>2018-03-07T17:01:13Z</dc:date>
    <item>
      <title>ISE CWA Flow Validation</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cwa-flow-validation/m-p/3575227#M511748</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;I'm working on an ISE POC with a customer and we ran into an issue with ISE CWA on switches without SVI's in the Data/Access VLAN's. The customer is using an ASA as their default GW for all vlans so every vlan needs to go through policy for communication.&amp;nbsp; I have put together the attached flow based on information I have read but would like to verify this is correct and I'm not missing anything. Due to the asymmetry of how URL Redirection works, I can see how this will cause a problem with Firewalls.&amp;nbsp; I have also added some alternative designs in the image.&amp;nbsp; Is there any Best Practice Designs with this type of scenario?&amp;nbsp; Also, Is this flow accurate?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ISE CWA Flow_Access Switch WO SVI.jpg" class="image-1 jive-image" src="/legacyfs/online/fusion/115798_ISE CWA Flow_Access Switch WO SVI.jpg" style="height: 349px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Mar 2018 17:01:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cwa-flow-validation/m-p/3575227#M511748</guid>
      <dc:creator>tolarosa@cisco.com</dc:creator>
      <dc:date>2018-03-07T17:01:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE CWA Flow Validation</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cwa-flow-validation/m-p/3575228#M511749</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Summation is correct and yes, we have seen customer's hit issue when default GW is a firewall due to reasons noted.&lt;/P&gt;&lt;P&gt;I have also posted a number of flows here &lt;A href="https://community.cisco.com/docs/DOC-76491"&gt;ISE Auth-Feature Flows_v1.pdf&lt;/A&gt; and similar scenario is highlighted in an "oldie but goody" guide here &lt;A href="https://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/identity-based-networking-services/app_note_c27-577494.html?dtid=osscdc000283" title="https://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/identity-based-networking-services/app_note_c27-577494.html?dtid=osscdc000283"&gt;IBNS: Web Authentication Deployment and Configuration Guide - Cisco&lt;/A&gt; in section titled "TCP Traffic Flow for Login Page When No Layer 3 SVI for Host VLAN Exists on Access Switch".&amp;nbsp;&amp;nbsp; This older guide is talking about local web auth, but the redirection concepts are the same. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Mar 2018 05:00:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cwa-flow-validation/m-p/3575228#M511749</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-03-08T05:00:36Z</dc:date>
    </item>
  </channel>
</rss>

