<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Posture pending in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-posture-pending/m-p/3433540#M536850</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also check if ip http and ip http secure services are enabled on switch&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 01 Dec 2016 19:39:16 GMT</pubDate>
    <dc:creator>Neelesh Marathe</dc:creator>
    <dc:date>2016-12-01T19:39:16Z</dc:date>
    <item>
      <title>ISE Posture pending</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-pending/m-p/3433538#M536848</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin-bottom: 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.4px;"&gt;Hello,&lt;/P&gt;&lt;P style="margin-bottom: 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.4px;"&gt;I am newly configuring and testing&amp;nbsp; Posturing/Client Provisioning on ISE.&amp;nbsp; I configured Client_Provisioning Policy with a Posture_Policy.&lt;/P&gt;&lt;P style="margin-bottom: 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.4px;"&gt;The redirection is being pushed to the switch but when the client opens a webpage they are not redirected to the ISE page.&lt;/P&gt;&lt;P style="margin-bottom: 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.4px;"&gt;See configs below&lt;/P&gt;&lt;P style="margin-bottom: 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.4px;"&gt;SW#show authentication sessions interface g1/0/44&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface:&amp;nbsp; GigabitEthernet1/0/44&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MAC Address:&amp;nbsp; 00b5.6d00.6fc3&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP Address:&amp;nbsp; 10.128.32.58&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; User-Name:&amp;nbsp; username&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Status:&amp;nbsp; Authz Success&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Domain:&amp;nbsp; DATA&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper host mode:&amp;nbsp; multi-auth&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper control dir:&amp;nbsp; both&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Authorized By:&amp;nbsp; Authentication Server&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Vlan Policy:&amp;nbsp; N/A&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ACS ACL:&amp;nbsp; xACSACLx-IP-PERMIT_ALL_TRAFFIC-5484c0cc&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; URL Redirect ACL:&amp;nbsp; TAC-Redirect&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; URL Redirect:&amp;nbsp; &lt;A href="https://10.128.1.20:8443/portal/gateway?sessionId=0A80041C00000A053AFFCBAC&amp;amp;portal=a2eef740-7e54-11e4-9ebe-005056bf01c7&amp;amp;action=cpp&amp;amp;token=4d8ad888c678873e7f8455b036b804c5" style="color: #4a7399;"&gt;https://10.128.1.20:8443/portal/gateway?sessionId=0A80041C00000A053AFFCB...&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Session timeout:&amp;nbsp; N/A&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Idle timeout:&amp;nbsp; N/A&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Common Session ID:&amp;nbsp; 0A80041C00000A053AFFCBAC&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Acct Session ID:&amp;nbsp; 0x00000AF8&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Handle:&amp;nbsp; 0x9F000A06&lt;/P&gt;&lt;P style="margin-bottom: 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.4px;"&gt;Runnable methods list:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&amp;nbsp;&amp;nbsp; State&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dot1x&amp;nbsp;&amp;nbsp;&amp;nbsp; Authc Success&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; mab&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Not run&lt;/P&gt;&lt;P style="margin-bottom: 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.4px;"&gt;Extended IP access list TAC-Redirect&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10 deny udp any eq bootpc any eq bootps&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 20 deny udp any any eq domain&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 30 deny ip any host 10.128.1.20&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 40 deny ip any host 10.129.1.20&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 50 permit tcp any any eq www&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 60 permit tcp any any eq 443&lt;/P&gt;&lt;P style="margin-bottom: 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.4px;"&gt;The dynamic ACL xACSACLx-IP-PERMIT_ALL_TRAFFIC-5484c0cc is a permit ip any any&lt;/P&gt;&lt;P style="margin-bottom: 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.4px;"&gt;I did a debug epm logging and debug ip http on the switch and this is what I am getting - &lt;A href="http://pastebin.com/4b5gGjR4" title="http://pastebin.com/4b5gGjR4"&gt;[Python] synise - Pastebin.com&lt;/A&gt;&lt;/P&gt;&lt;P style="margin-bottom: 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.4px;"&gt;&lt;SPAN style="font-size: 14.4px;"&gt;Any help would be greatly appreciated.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Dec 2016 11:40:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-pending/m-p/3433538#M536848</guid>
      <dc:creator>Wesoley</dc:creator>
      <dc:date>2016-12-01T11:40:01Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Posture pending</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-pending/m-p/3433539#M536849</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Wesley,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the version of ISE?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can check for following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1 if using proxy, try to bypass ISE ip address&lt;/P&gt;&lt;P&gt;2. Check if ISE ip address is reachable from Endpoint on 8443&lt;/P&gt;&lt;P&gt;3. Make sure you have layer 3 connectivity between endpoint subnet and switch management subnet as switch intercept the http traffic and reply on behalf of destination URL.&lt;/P&gt;&lt;P&gt;4. If ISE 2.1, check on ISE if portal is responding on port 8443. Because i have seen issues where port 8443 on ISE stopped working&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Neelesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Dec 2016 19:28:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-pending/m-p/3433539#M536849</guid>
      <dc:creator>Neelesh Marathe</dc:creator>
      <dc:date>2016-12-01T19:28:09Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Posture pending</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-pending/m-p/3433540#M536850</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also check if ip http and ip http secure services are enabled on switch&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Dec 2016 19:39:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-pending/m-p/3433540#M536850</guid>
      <dc:creator>Neelesh Marathe</dc:creator>
      <dc:date>2016-12-01T19:39:16Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Posture pending</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-pending/m-p/3433541#M536851</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am using ISE 2.1. I can verify that the client can ping the gateway. The client does not use any proxy server. If I copy and paste the URL in the browser, I get the prompt to download the agent.&lt;/P&gt;&lt;P&gt;I can ping the switch and the ISE server. ip http and http secure server are enabled. Did you check the pastebin above?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Dec 2016 21:21:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-pending/m-p/3433541#M536851</guid>
      <dc:creator>Wesoley</dc:creator>
      <dc:date>2016-12-01T21:21:22Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Posture pending</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-pending/m-p/3433542#M536852</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you try to assign a dns name to the psn you are redirecting to and changing your web redirect URL to the dns name Instead of the ip? I believe for redirection to take place that some form of dns resolution has to happen.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ofcourse make sure your client has dns set and can properly resolve what ever url is in your browser when you open it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ALso, I know for a fact that the initial URL has to be resolvable (let's say your home page was google) before redirection will even take place. I see similar behavor in web authenticated wireless setups when home pages are set to intranet sites and redirection never happens because that's not resolvable on guest wifi.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 04 Dec 2016 05:56:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-pending/m-p/3433542#M536852</guid>
      <dc:creator>DavidCiciora</dc:creator>
      <dc:date>2016-12-04T05:56:28Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Posture pending</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-pending/m-p/3433543#M536853</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It somehow seemed to be a routing issue. The setup is like this - access switch----&amp;gt;core switch----&amp;gt;Firewall. The default gw of the access switch is the core switch. The core switch has SVIs for all of the other VLANs but not the one we were testing with. Routing for that VLAN is done on the firewall. So I moved the user to another VLAN on the access switch and got the redirection page &lt;IMG src="https://community.cisco.com/legacyfs/online/emoticons/happy.png" /&gt;. I added an SVI on the core switch and got the redirection page also.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 04 Dec 2016 11:56:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-pending/m-p/3433543#M536853</guid>
      <dc:creator>Wesoley</dc:creator>
      <dc:date>2016-12-04T11:56:27Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Posture pending</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-pending/m-p/3433544#M536854</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dear,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;how did you sort it out this issue?&lt;/P&gt;&lt;P&gt;i have same network layout like yours and have same issue with ISE new version but not sure how i can sort it out wth Routing?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Feb 2018 14:42:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-pending/m-p/3433544#M536854</guid>
      <dc:creator>apatel2489</dc:creator>
      <dc:date>2018-02-12T14:42:13Z</dc:date>
    </item>
  </channel>
</rss>

