<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE CWA pre-authentication and post-authentication and Umbrella DNS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-cwa-pre-authentication-and-post-authentication-and-umbrella/m-p/3847407#M542635</link>
    <description>&lt;P&gt;&lt;BR /&gt;Hello, guys&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Right now I'm having an issue with a customer.&amp;nbsp; He wants to point his DNS to umbrella but in a Guest Wireless.&amp;nbsp; It sounds that it is easy to do, but the difficult situation I found is that the customer has to point to an internal server because of the internal CA when pre authentication occurs, and point to umbrella DNS when authentication is success. Because of it, we thought that making a change of vlan when post authentication it was a good idea, but we found that only Windows machines behaves good.&amp;nbsp; It was not the same situation for Android and iOS.&amp;nbsp; &amp;nbsp;We considered mounting the umbrella virtual machine for doing this, but he has a license that does not support umbrella VM.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will appreciate any help you can give me.&amp;nbsp; Thank you in advance.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 29 Apr 2019 18:56:20 GMT</pubDate>
    <dc:creator>drivera_</dc:creator>
    <dc:date>2019-04-29T18:56:20Z</dc:date>
    <item>
      <title>ISE CWA pre-authentication and post-authentication and Umbrella DNS</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cwa-pre-authentication-and-post-authentication-and-umbrella/m-p/3847407#M542635</link>
      <description>&lt;P&gt;&lt;BR /&gt;Hello, guys&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Right now I'm having an issue with a customer.&amp;nbsp; He wants to point his DNS to umbrella but in a Guest Wireless.&amp;nbsp; It sounds that it is easy to do, but the difficult situation I found is that the customer has to point to an internal server because of the internal CA when pre authentication occurs, and point to umbrella DNS when authentication is success. Because of it, we thought that making a change of vlan when post authentication it was a good idea, but we found that only Windows machines behaves good.&amp;nbsp; It was not the same situation for Android and iOS.&amp;nbsp; &amp;nbsp;We considered mounting the umbrella virtual machine for doing this, but he has a license that does not support umbrella VM.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will appreciate any help you can give me.&amp;nbsp; Thank you in advance.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2019 18:56:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cwa-pre-authentication-and-post-authentication-and-umbrella/m-p/3847407#M542635</guid>
      <dc:creator>drivera_</dc:creator>
      <dc:date>2019-04-29T18:56:20Z</dc:date>
    </item>
    <item>
      <title>Re: ISE CWA pre-authentication and post-authentication and Umbrella DNS</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cwa-pre-authentication-and-post-authentication-and-umbrella/m-p/3847437#M542636</link>
      <description>Sounds just like this issue. Nothing to do with an internal CA, its that your ISE needs to resolve using internal DNS as its an internal service&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/identity-services-engine-ise/ise-guest-dns/td-p/3734037" target="_blank"&gt;https://community.cisco.com/t5/identity-services-engine-ise/ise-guest-dns/td-p/3734037&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 29 Apr 2019 19:32:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cwa-pre-authentication-and-post-authentication-and-umbrella/m-p/3847437#M542636</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-04-29T19:32:17Z</dc:date>
    </item>
    <item>
      <title>Re: ISE CWA pre-authentication and post-authentication and Umbrella DNS</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cwa-pre-authentication-and-post-authentication-and-umbrella/m-p/3847468#M542637</link>
      <description>&lt;P&gt;Hi, Jason&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for the answer.&amp;nbsp; I had seen that post before but I'm a little confused because I'm not sure if it is the same issue I'm having, because our pre authetication portal is inside the customer network (obviously) and what we need is that when post authentication occurss, an endpoint have the umbrella for content filter.&amp;nbsp;&amp;nbsp; I hope you can understand me.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2019 20:16:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cwa-pre-authentication-and-post-authentication-and-umbrella/m-p/3847468#M542637</guid>
      <dc:creator>drivera_</dc:creator>
      <dc:date>2019-04-29T20:16:59Z</dc:date>
    </item>
    <item>
      <title>Re: ISE CWA pre-authentication and post-authentication and Umbrella DNS</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cwa-pre-authentication-and-post-authentication-and-umbrella/m-p/3847498#M542638</link>
      <description>You need to have the umbrella apply DND on pre and post authentication, it would need to resolve your internal service, you can’t switch VLANs. Seems to me to be the same thing. Did you check with umbrella?&lt;BR /&gt;</description>
      <pubDate>Mon, 29 Apr 2019 21:10:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cwa-pre-authentication-and-post-authentication-and-umbrella/m-p/3847498#M542638</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-04-29T21:10:17Z</dc:date>
    </item>
    <item>
      <title>Re: ISE CWA pre-authentication and post-authentication and Umbrella DNS</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cwa-pre-authentication-and-post-authentication-and-umbrella/m-p/3847520#M542639</link>
      <description>Hi,&lt;BR /&gt;Why not build a Linux server to act as a DNS server for the guest network, configure it to only resolve the ISE portal DNS addresses with a forwarder to Umbrella for all other DNS requests. Alternatively if you had an ISR4K router as the default gateway this can transparently intercept DNS requests and forward to Umbrella cloud&lt;BR /&gt;&lt;BR /&gt;HTH</description>
      <pubDate>Mon, 29 Apr 2019 22:03:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cwa-pre-authentication-and-post-authentication-and-umbrella/m-p/3847520#M542639</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-04-29T22:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: ISE CWA pre-authentication and post-authentication and Umbrella DNS</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cwa-pre-authentication-and-post-authentication-and-umbrella/m-p/3847554#M542640</link>
      <description>&lt;P&gt;Hi, guys&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The thing is that when doing the pre authentication we have to resolve the web auth url from inside, because there is no a public DNS register for that url, and the customer does not want to give the web auth with the IP address, instead of that he wants the url to be resolved by DNS. And when doing the post authentication, it is necessary to get the umbrella DNS IP addresses..&amp;nbsp;&amp;nbsp; We don't know how to do it.&amp;nbsp; I hope you guys can understand me.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2019 23:59:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cwa-pre-authentication-and-post-authentication-and-umbrella/m-p/3847554#M542640</guid>
      <dc:creator>drivera_</dc:creator>
      <dc:date>2019-04-29T23:59:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE CWA pre-authentication and post-authentication and Umbrella DNS</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cwa-pre-authentication-and-post-authentication-and-umbrella/m-p/3847856#M542641</link>
      <description>You can’t switch DNS servers. This would require a change of VLAN which is not recommended as there is no mechanism for the client to change its IP without using dot1x&lt;BR /&gt;&lt;BR /&gt;Again as suggested before. You will need to setup DNS to resolve ISE and to also proxy to umbrella. Or umbrella to resolve your internal ISE name&lt;BR /&gt;&lt;BR /&gt;Have you reached out to them for a solution?&lt;BR /&gt;</description>
      <pubDate>Tue, 30 Apr 2019 10:33:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cwa-pre-authentication-and-post-authentication-and-umbrella/m-p/3847856#M542641</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-04-30T10:33:17Z</dc:date>
    </item>
    <item>
      <title>Re: ISE CWA pre-authentication and post-authentication and Umbrella DNS</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cwa-pre-authentication-and-post-authentication-and-umbrella/m-p/3851177#M542642</link>
      <description>&lt;P&gt;Hi Jason,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your answer again.&amp;nbsp; Where can I configure that proxy? Is this configuration needs to be made in the L3 router on in the DNS server?.&amp;nbsp; I think you are telling me to do something like this, aren't you? &lt;A href="https://www.juniper.net/documentation/en_US/junos/topics/concept/dns-proxy-overview.html&amp;nbsp;" target="_blank"&gt;https://www.juniper.net/documentation/en_US/junos/topics/concept/dns-proxy-overview.html&amp;nbsp;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2019 00:32:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cwa-pre-authentication-and-post-authentication-and-umbrella/m-p/3851177#M542642</guid>
      <dc:creator>drivera_</dc:creator>
      <dc:date>2019-05-07T00:32:40Z</dc:date>
    </item>
    <item>
      <title>Re: ISE CWA pre-authentication and post-authentication and Umbrella DNS</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cwa-pre-authentication-and-post-authentication-and-umbrella/m-p/3860315#M542643</link>
      <description>Sorry this is not a DNS forum. You would need to discuss overall architecture with umbrella folks.</description>
      <pubDate>Tue, 21 May 2019 16:08:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cwa-pre-authentication-and-post-authentication-and-umbrella/m-p/3860315#M542643</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-05-21T16:08:49Z</dc:date>
    </item>
    <item>
      <title>Re: ISE CWA pre-authentication and post-authentication and Umbrella DNS</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cwa-pre-authentication-and-post-authentication-and-umbrella/m-p/3860334#M542644</link>
      <description>&lt;P&gt;Hi Jason,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know this is not a DNS forum, but as we all know, DNS is a very important topic in Umbrella.&amp;nbsp; It's ok if you don't have the answer or if you don't want to waste your precious time here, but I think thare are better ways to respond.&amp;nbsp; Thank you again.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2019 16:30:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cwa-pre-authentication-and-post-authentication-and-umbrella/m-p/3860334#M542644</guid>
      <dc:creator>drivera_</dc:creator>
      <dc:date>2019-05-21T16:30:26Z</dc:date>
    </item>
  </channel>
</rss>

