<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE POSTURE POPPING UP BROWSER AND REDIRECTING TO CPP NOT DESIRED in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-posture-popping-up-browser-and-redirecting-to-cpp-not/m-p/3442614#M527008</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not redirecting all port 80 traffic only port 80 traffic to the default gateway.  So say your customer’s network is a 10.x.x.x network and their default gateways are .1.  Your posture redirect ACL can look like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip access-list extended POSTURE-REDIRECT&lt;/P&gt;&lt;P&gt;  permit tcp any 10.0.0.1 0.255.255.0 eq 80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That will only redirect port 80 to the DGs.  Then your DACL can allow the required access you want before posture is assessed.  I believe the DACL is applied before the redirect so a DACL like this should work at a minimum:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;permit udp any any eq domain&lt;/P&gt;&lt;P&gt;permit tcp any 10.0.0.1 0.255.255.0 eq 80&lt;/P&gt;&lt;P&gt;permit ip any host &lt;/P&gt;&lt;P&gt;etc. to permit traffic to the PSNs&lt;/P&gt;&lt;P&gt;deny ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not sure what you are blocking in your posture unknown state currently.  Blocking too much in the unknown state can break a lot of things.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paul Haferman&lt;/P&gt;&lt;P&gt;Office- 920.996.3011&lt;/P&gt;&lt;P&gt;Cell- 920.284.9250&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 05 Sep 2017 23:15:13 GMT</pubDate>
    <dc:creator>paul</dc:creator>
    <dc:date>2017-09-05T23:15:13Z</dc:date>
    <item>
      <title>ISE POSTURE POPPING UP BROWSER AND REDIRECTING TO CPP NOT DESIRED</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-popping-up-browser-and-redirecting-to-cpp-not/m-p/3442609#M527003</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 14px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #58585b;"&gt;I am deploying ISE for a client and they complaint about web browser popping up and redirecting to Clients Provisioning Portal (CPP) on user’s PC during posture. Although, it doesn’t require any user interaction/intervention but it is not desired.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 14px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #58585b;"&gt;What can be done to ensure posture stop’s popping up client’s browser and redirecting to CPP?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Sep 2017 19:56:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-popping-up-browser-and-redirecting-to-cpp-not/m-p/3442609#M527003</guid>
      <dc:creator>kajibola</dc:creator>
      <dc:date>2017-09-04T19:56:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE POSTURE POPPING UP BROWSER AND REDIRECTING TO CPP NOT DESIRED</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-popping-up-browser-and-redirecting-to-cpp-not/m-p/3442610#M527004</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Change your redirect ACL on the switch.&amp;nbsp; Assuming you don't need ISE to install the AnyConnect Posture Module (which you really shouldn't) then you don't need to redirect all traffic to the client provisioning portal.&amp;nbsp; You really only need to redirect port 80 to the default gateway to allow posture module discovery to work.&amp;nbsp; You can use a DACL to block the traffic you want preposture.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Sep 2017 01:39:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-popping-up-browser-and-redirecting-to-cpp-not/m-p/3442610#M527004</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2017-09-05T01:39:08Z</dc:date>
    </item>
    <item>
      <title>Re: ISE POSTURE POPPING UP BROWSER AND REDIRECTING TO CPP NOT DESIRED</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-popping-up-browser-and-redirecting-to-cpp-not/m-p/3442611#M527005</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Paul.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did not understand your solution very well hence couldn't get it to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I did was to disable CPP on the authorization policy for posture. In-as-much that Anyconnect is already installed and they don't need anyconnect installation through browser, that solves the issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Sep 2017 14:51:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-popping-up-browser-and-redirecting-to-cpp-not/m-p/3442611#M527005</guid>
      <dc:creator>kajibola</dc:creator>
      <dc:date>2017-09-05T14:51:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE POSTURE POPPING UP BROWSER AND REDIRECTING TO CPP NOT DESIRED</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-popping-up-browser-and-redirecting-to-cpp-not/m-p/3442612#M527006</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;By removing the CPP redirect you are probably breaking posturing for clients that haven’t postured before.  Read up on how posture discovery works in order to understand why the CPP redirect is there and how the ACL on the switch to redirect plays into posture discovery.  The sequence for discovery is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. http discovery probe on port 80 to default gateway if no discovery host&lt;/P&gt;&lt;P&gt;2. http discovery probe on port 80 to discovery host, if configured (via HTTP Redirect)&lt;/P&gt;&lt;P&gt;3. https discovery probe on port 8905 to discovery host, if configured&lt;/P&gt;&lt;P&gt;4. http discovery probe on port 80 to default gateway (via HTTP Redirect)&lt;/P&gt;&lt;P&gt;5. https reconnect probe on port 8905 to previously contacted ISE Policy Services node&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are probably working because you are hitting step 5 and have a previous PSN you reported posture to.  New clients won’t have that and they will fail discovery and get “no policy server found” most likely.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paul Haferman&lt;/P&gt;&lt;P&gt;Office- 920.996.3011&lt;/P&gt;&lt;P&gt;Cell- 920.284.9250&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Sep 2017 17:57:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-popping-up-browser-and-redirecting-to-cpp-not/m-p/3442612#M527006</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2017-09-05T17:57:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE POSTURE POPPING UP BROWSER AND REDIRECTING TO CPP NOT DESIRED</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-popping-up-browser-and-redirecting-to-cpp-not/m-p/3442613#M527007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have never tried with a PC that have never contacted ISE before to see if the process will be broken.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The initial solution you give which is redirecting only traffic to port 80 and using DACL to block the traffic I don't want pre-posture doesn't work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestion?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Sep 2017 23:05:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-popping-up-browser-and-redirecting-to-cpp-not/m-p/3442613#M527007</guid>
      <dc:creator>kajibola</dc:creator>
      <dc:date>2017-09-05T23:05:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE POSTURE POPPING UP BROWSER AND REDIRECTING TO CPP NOT DESIRED</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-popping-up-browser-and-redirecting-to-cpp-not/m-p/3442614#M527008</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not redirecting all port 80 traffic only port 80 traffic to the default gateway.  So say your customer’s network is a 10.x.x.x network and their default gateways are .1.  Your posture redirect ACL can look like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip access-list extended POSTURE-REDIRECT&lt;/P&gt;&lt;P&gt;  permit tcp any 10.0.0.1 0.255.255.0 eq 80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That will only redirect port 80 to the DGs.  Then your DACL can allow the required access you want before posture is assessed.  I believe the DACL is applied before the redirect so a DACL like this should work at a minimum:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;permit udp any any eq domain&lt;/P&gt;&lt;P&gt;permit tcp any 10.0.0.1 0.255.255.0 eq 80&lt;/P&gt;&lt;P&gt;permit ip any host &lt;/P&gt;&lt;P&gt;etc. to permit traffic to the PSNs&lt;/P&gt;&lt;P&gt;deny ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not sure what you are blocking in your posture unknown state currently.  Blocking too much in the unknown state can break a lot of things.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paul Haferman&lt;/P&gt;&lt;P&gt;Office- 920.996.3011&lt;/P&gt;&lt;P&gt;Cell- 920.284.9250&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Sep 2017 23:15:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-popping-up-browser-and-redirecting-to-cpp-not/m-p/3442614#M527008</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2017-09-05T23:15:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE POSTURE POPPING UP BROWSER AND REDIRECTING TO CPP NOT DESIRED</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-popping-up-browser-and-redirecting-to-cpp-not/m-p/3442615#M527009</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 13.3333px;"&gt;Try permitting (Not redirecting traffic) for the captive portal detection packet. It depends on the OS but different vendors have different ways to test the network to see if there is a captive network like guest portal that is waiting for user interaction. Typically the OS sends a test packet to a predefined site and see if it gets expected response. If something other than expected response is received then it opens a browser window as it thinks there is a guest portal waiting for user interaction. In general this is not an issue, but ISE posture may take longer than the captive portal test interval which may cause the OS browser to popup.&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;- MS: &lt;A href="http://www.msftncsi.com/ncsi.txt" title="http://www.msftncsi.com/ncsi.txt"&gt;http://www.msftncsi.com/ncsi.txt&lt;/A&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;SPAN&gt;- Apple: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://captive.apple.com/hotspot-detect.html" rel="nofollow" target="_blank"&gt;http://captive.apple.com/hotspot-detect.html&lt;/A&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;- Google: &lt;A href="http://www.gstatic.com/generate_204" title="http://www.gstatic.com/generate_204"&gt;http://www.gstatic.com/generate_204&lt;/A&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;You just need to find out what IP the host maps to and allow http to the host in the redirect ACL for posture. This will prevent the browser pop-up during posture.&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Hosuk&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Sep 2017 15:11:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-popping-up-browser-and-redirecting-to-cpp-not/m-p/3442615#M527009</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2017-09-06T15:11:09Z</dc:date>
    </item>
    <item>
      <title>Re: ISE POSTURE POPPING UP BROWSER AND REDIRECTING TO CPP NOT DESIRED</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-popping-up-browser-and-redirecting-to-cpp-not/m-p/3442616#M527010</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;@Paul, your solution works. Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Sep 2017 20:42:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-popping-up-browser-and-redirecting-to-cpp-not/m-p/3442616#M527010</guid>
      <dc:creator>kajibola</dc:creator>
      <dc:date>2017-09-06T20:42:05Z</dc:date>
    </item>
    <item>
      <title>Re: ISE POSTURE POPPING UP BROWSER AND REDIRECTING TO CPP NOT DESIRED</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-popping-up-browser-and-redirecting-to-cpp-not/m-p/3442617#M527011</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Paul,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once again thanks for the solution, it works perfectly well for the wired deployment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to confirm if you have ever implemented it for wireless deployment using the WLC Posture Redirect ACL and Airespace ACL also.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am also planning to implement it on wireless but not yet available to go to site.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Sep 2017 07:13:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-popping-up-browser-and-redirecting-to-cpp-not/m-p/3442617#M527011</guid>
      <dc:creator>kajibola</dc:creator>
      <dc:date>2017-09-27T07:13:28Z</dc:date>
    </item>
  </channel>
</rss>

