<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Central Web Authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-central-web-authentication/m-p/3569880#M535488</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;there's no match on your "wireless guess" authz policy after a successful web-auth that's why you get stuck in a authz loop.&lt;/P&gt;&lt;P&gt;take a look at your guest portal configurations&amp;gt;&amp;gt;guest type. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;your "wireless guess" policy is matching on " "GuestEndpoints", so you need to make sure you assign the guest device to GuestEndpoints in Guest Types.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2017-07-31 at 11.31.15 PM.png" class="image-1 jive-image" src="/legacyfs/online/fusion/109850_Screen Shot 2017-07-31 at 11.31.15 PM.png" style="height: 100px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 31 Jul 2017 15:34:11 GMT</pubDate>
    <dc:creator>tertang@cisco.com</dc:creator>
    <dc:date>2017-07-31T15:34:11Z</dc:date>
    <item>
      <title>ISE Central Web Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-central-web-authentication/m-p/3569879#M535487</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin-bottom: 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.4px;"&gt;hi all,&lt;/P&gt;&lt;P style="margin-bottom: 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.4px;"&gt;now I faced this issue&lt;/P&gt;&lt;P style="margin-bottom: 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.4px;"&gt;-First I login to SSID and then redirect to ISE guess portal.&lt;/P&gt;&lt;P style="margin-bottom: 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.4px;"&gt;-login with ISE local account and successful authentication.&lt;/P&gt;&lt;P style="margin-bottom: 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.4px;"&gt;-After that, I tried to use internet browsing and then Redirect again and again to ISE guess portal.&lt;/P&gt;&lt;P style="margin-bottom: 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.4px;"&gt;&lt;/P&gt;&lt;P style="margin-bottom: 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.4px;"&gt;Please Check My ISE Authorization Rule as follow.&lt;/P&gt;&lt;P style="margin-bottom: 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.4px;"&gt;&lt;/P&gt;&lt;P style="margin-bottom: 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.4px;"&gt;Thanks You&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Jul 2017 09:21:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-central-web-authentication/m-p/3569879#M535487</guid>
      <dc:creator>the.prince.of.nyinyizin</dc:creator>
      <dc:date>2017-07-31T09:21:00Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Central Web Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-central-web-authentication/m-p/3569880#M535488</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;there's no match on your "wireless guess" authz policy after a successful web-auth that's why you get stuck in a authz loop.&lt;/P&gt;&lt;P&gt;take a look at your guest portal configurations&amp;gt;&amp;gt;guest type. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;your "wireless guess" policy is matching on " "GuestEndpoints", so you need to make sure you assign the guest device to GuestEndpoints in Guest Types.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2017-07-31 at 11.31.15 PM.png" class="image-1 jive-image" src="/legacyfs/online/fusion/109850_Screen Shot 2017-07-31 at 11.31.15 PM.png" style="height: 100px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Jul 2017 15:34:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-central-web-authentication/m-p/3569880#M535488</guid>
      <dc:creator>tertang@cisco.com</dc:creator>
      <dc:date>2017-07-31T15:34:11Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Central Web Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-central-web-authentication/m-p/3569881#M535489</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Nyi,&lt;/P&gt;&lt;P&gt;Its hard for me to say as I dont know how you setup your authz profile&lt;/P&gt;&lt;P&gt;Basically you should have 2 rules , the second one being the redirect and the first to permit access .&lt;/P&gt;&lt;P&gt;The second rule is the first rule to be hit ( match the re-direction ) once user logins he is sent a CoA for re-authentication and will hit the first rule which permits the access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Check this guide to verify your setup.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/docs/DOC-68165"&gt;How To: ISE Guest &amp;amp;amp; Web-Authentication Design Guide&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Danny&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Jul 2017 15:53:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-central-web-authentication/m-p/3569881#M535489</guid>
      <dc:creator>ldanny</dc:creator>
      <dc:date>2017-07-31T15:53:21Z</dc:date>
    </item>
  </channel>
</rss>

