<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic In workaround 1, you can in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cscus64320-cwa-redirect-uses-ip-instead-of-fqdn-for-non-gig0/m-p/2747944#M54214</link>
    <description>&lt;P&gt;In workaround 1, you can create two authz rules for your redirect instead of just one, with different fqdn's in the authz result, one for each ise server. Then use the condition for the two different ise server names, which will be filled with either the primary or secondary, depending on which one received the radius request from your wireless controller.&lt;/P&gt;</description>
    <pubDate>Tue, 01 Sep 2015 16:25:39 GMT</pubDate>
    <dc:creator>jan.nielsen</dc:creator>
    <dc:date>2015-09-01T16:25:39Z</dc:date>
    <item>
      <title>CSCus64320 - CWA Redirect uses IP instead of FQDN for non gig0 intf for guest portal</title>
      <link>https://community.cisco.com/t5/network-access-control/cscus64320-cwa-redirect-uses-ip-instead-of-fqdn-for-non-gig0/m-p/2747943#M54204</link>
      <description>&lt;P&gt;Hi Community&amp;nbsp;&lt;/P&gt;&lt;P&gt;I walked around this bug, but was not able to find the real reason and solution for it. The setup is like this:&lt;/P&gt;&lt;P&gt;=== PRIMARY HOST:&lt;/P&gt;&lt;P&gt;Int Gig 0&amp;nbsp;&lt;BR /&gt;ip addr 1.1.1.1/24&lt;/P&gt;&lt;P&gt;Int Gig 1&lt;BR /&gt;ip addr 2.2.2.2/24&lt;/P&gt;&lt;P&gt;FQDN: ise1-gig0.adm-abc.com&lt;/P&gt;&lt;P&gt;default Gateway 2.2.2.1&lt;/P&gt;&lt;P&gt;=== SECONDARY HOST&lt;/P&gt;&lt;P&gt;Int Gig 0&amp;nbsp;&lt;BR /&gt;ip addr 1.1.1.2/24&lt;/P&gt;&lt;P&gt;Int Gig 1&lt;BR /&gt;ip addr 2.2.2.3/24&lt;/P&gt;&lt;P&gt;FQDN: ise2-gig0.adm-abc.com&lt;/P&gt;&lt;P&gt;default Gateway 2.2.2.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The sync and management traffic is using gig 0 with cert using the FQDN's. Guest Portal is active in Int gig 1 with special certificates (SAN) for FQDN on Gig1 (ise1-gig1.abc.com and is-gig1.abc.com).&lt;/P&gt;&lt;P&gt;DNS is resolvable for both interfaces on both host's. So why should I use the ip-host?&lt;/P&gt;&lt;P&gt;Fact is in this setup (ISE 1.4 with Patch3), the redirect url for CWA is always sent using the ip address instead of the FQDN, which ends up in a certificate error.&lt;/P&gt;&lt;P&gt;I found two workaround, but both not make me happy:&lt;/P&gt;&lt;P&gt;Workaournd 1:&lt;BR /&gt;Use static FQDN in the redirect: ise1-gig1-abc.com&lt;BR /&gt;This wordks good as long as PRIMARY Host is available. If primary host is down, clients are redirected into a black-hole... &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Workaround 2:&lt;BR /&gt;Use IP Addresses in the SAN field. This would probably work, but the Certificate Authority does not allow me to do so... &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Any suggestions, or experiences with such a use-case? Many thanks for any help or input.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:01:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cscus64320-cwa-redirect-uses-ip-instead-of-fqdn-for-non-gig0/m-p/2747943#M54204</guid>
      <dc:creator>mstraessle</dc:creator>
      <dc:date>2019-03-11T06:01:04Z</dc:date>
    </item>
    <item>
      <title>In workaround 1, you can</title>
      <link>https://community.cisco.com/t5/network-access-control/cscus64320-cwa-redirect-uses-ip-instead-of-fqdn-for-non-gig0/m-p/2747944#M54214</link>
      <description>&lt;P&gt;In workaround 1, you can create two authz rules for your redirect instead of just one, with different fqdn's in the authz result, one for each ise server. Then use the condition for the two different ise server names, which will be filled with either the primary or secondary, depending on which one received the radius request from your wireless controller.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2015 16:25:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cscus64320-cwa-redirect-uses-ip-instead-of-fqdn-for-non-gig0/m-p/2747944#M54214</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2015-09-01T16:25:39Z</dc:date>
    </item>
    <item>
      <title>Hi JanThis is a great idea. I</title>
      <link>https://community.cisco.com/t5/network-access-control/cscus64320-cwa-redirect-uses-ip-instead-of-fqdn-for-non-gig0/m-p/2747945#M54216</link>
      <description>&lt;P&gt;Hi Jan&lt;/P&gt;&lt;P&gt;This is a great idea. I will try next week and give feedback if it worked like this. But I think yes. Anyhow, it is still a workaround. What is the correct solution, if there is any?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2015 20:34:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cscus64320-cwa-redirect-uses-ip-instead-of-fqdn-for-non-gig0/m-p/2747945#M54216</guid>
      <dc:creator>mstraessle</dc:creator>
      <dc:date>2015-09-01T20:34:36Z</dc:date>
    </item>
    <item>
      <title>I'm not sure if there is an</title>
      <link>https://community.cisco.com/t5/network-access-control/cscus64320-cwa-redirect-uses-ip-instead-of-fqdn-for-non-gig0/m-p/2747946#M54219</link>
      <description>&lt;P&gt;I'm not sure if there is an actual solution, if it's a bug then obviously the solution is for Cisco to fix it, in older versions of ise (pre-1.3) i did this with no problems, at one customer, so it has not always been like in 1.4, which might give credit to the bug theory. One thing i was thinking about. but I can't remember if there is an "interface" select menu for different ports, like there was in 1.2, if there is maybe that is how ISE gets confused as to which interface you want to use for guest.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2015 20:52:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cscus64320-cwa-redirect-uses-ip-instead-of-fqdn-for-non-gig0/m-p/2747946#M54219</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2015-09-01T20:52:43Z</dc:date>
    </item>
  </channel>
</rss>

