<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco 3750G not redirecting HTTP/HTTPS even though redirect ACL pushed to switch in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-3750g-not-redirecting-http-https-even-though-redirect-acl/m-p/3351010#M549659</link>
    <description>&lt;P&gt;Confirming that dot1x and MAB are functioning.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As requested:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;aaa new-model&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa group server radius RAD&lt;BR /&gt; server 10.223.2.2&lt;BR /&gt; server 10.223.10.4&lt;BR /&gt; server 10.223.10.5&lt;BR /&gt;!&lt;BR /&gt;aaa group server tacacs+ TAC&lt;BR /&gt; server 10.223.2.2&lt;BR /&gt; ip tacacs source-interface Vlan99&lt;BR /&gt;!&lt;BR /&gt;aaa authentication login default group tacacs+ group radius local&lt;BR /&gt;aaa authentication enable default group tacacs+ group radius enable&lt;BR /&gt;aaa authentication dot1x default group radius&lt;BR /&gt;aaa authorization exec default group tacacs+ local&lt;BR /&gt;aaa authorization commands 15 default group tacacs+ local&lt;BR /&gt;aaa authorization network default group radius&lt;BR /&gt;aaa accounting dot1x default start-stop group radius&lt;BR /&gt;aaa accounting exec default start-stop group tacacs+ group radius&lt;BR /&gt;aaa accounting system default start-stop group tacacs+ group radius&lt;BR /&gt;!&lt;BR /&gt;aaa server radius dynamic-author&lt;BR /&gt; client 10.223.2.2 server-key&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;aaa session-id common&lt;/P&gt;</description>
    <pubDate>Mon, 19 Mar 2018 16:42:37 GMT</pubDate>
    <dc:creator>glenn.dalcourt</dc:creator>
    <dc:date>2018-03-19T16:42:37Z</dc:date>
    <item>
      <title>Cisco 3750G not redirecting HTTP/HTTPS even though redirect ACL pushed to switch</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-3750g-not-redirecting-http-https-even-though-redirect-acl/m-p/3350991#M549655</link>
      <description>&lt;P&gt;ISE &lt;SPAN&gt;2.3.0.298&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Cisco IOS&amp;nbsp;15.0(2)SE11&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cisco 3750G allowing full network access even though 'show auth sess int' conveys that the switch should be redirecting traffic to guest web portal. I also see hits on the redirect ACL.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How can I troubleshoot the redirection of web traffic to ISE (10.223.2.2).&amp;nbsp;(The switch is not a router on the pre-web-auth VLAN. I haven't seen in documentation where the switch needs to be L3 capable on the pre-web-auth VLAN to intercept ARPs however.)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;***RUNTIME SNIPPETS***&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;LAB-S3750-1#show auth sess int g1/0/19&lt;BR /&gt; Interface: GigabitEthernet1/0/19&lt;BR /&gt; MAC Address: 000e.c68f.4089&lt;BR /&gt; IP Address: 10.223.254.11&lt;BR /&gt; User-Name: 00-0E-C6-8F-40-89&lt;BR /&gt; Status: Authz Success&lt;BR /&gt; Domain: DATA&lt;BR /&gt; Security Policy: Should Secure&lt;BR /&gt; Security Status: Unsecure&lt;BR /&gt; Oper host mode: multi-domain&lt;BR /&gt; Oper control dir: both&lt;BR /&gt; Authorized By: Authentication Server&lt;BR /&gt; Vlan Policy: 254&lt;BR /&gt; ACS ACL: xACSACLx-IP-WEBAUTH-5a9da3c9&lt;BR /&gt; URL Redirect ACL: ACL_WEBAUTH_REDIRECT&lt;BR /&gt; URL Redirect: &lt;A href="https://LAB-ISE-PRI.labratory.local:8443/portal/gateway?sessionId=0ADF63020000001C003758F2&amp;amp;portal=f0ae43f0-7159-11e7-a355-005056aba474&amp;amp;action=cwa&amp;amp;token=3295083fba9273cff940b58a47b621fc" target="_blank"&gt;https://LAB-ISE-PRI.labratory.local:8443/portal/gateway?sessionId=0ADF63020000001C003758F2&amp;amp;portal=f0ae43f0-7159-11e7-a355-005056aba474&amp;amp;action=cwa&amp;amp;token=3295083fba9273cff940b58a47b621fc&lt;/A&gt;&lt;BR /&gt; Session timeout: N/A&lt;BR /&gt; Idle timeout: 300s (local), Remaining: 209s&lt;BR /&gt; Common Session ID: 0ADF63020000001C003758F2&lt;BR /&gt; Acct Session ID: 0x00000024&lt;BR /&gt; Handle: 0xA300001D&lt;/P&gt;
&lt;P&gt;Runnable methods list:&lt;BR /&gt; Method State&lt;BR /&gt; dot1x Failed over&lt;BR /&gt; mab Authc Success&lt;BR /&gt; webauth Not run&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;LAB-S3750-1#show access-list&lt;BR /&gt;Extended IP access list ACL_WEBAUTH_REDIRECT&lt;BR /&gt; 10 deny ip any host 10.223.2.2&lt;BR /&gt; 20 permit tcp any any eq www (332 matches)&lt;BR /&gt; 30 permit tcp any any eq 443 (692 matches)&lt;BR /&gt; 40 permit tcp any any eq 8443&lt;BR /&gt; 50 deny ip any any log&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Extended IP access list INTERFACE_DEFAULT&lt;BR /&gt; 10 permit udp any eq bootpc any eq bootps&lt;BR /&gt; 20 permit udp any any eq domain&lt;BR /&gt; 30 permit tcp any any eq 443&lt;BR /&gt; 40 permit tcp any any eq www&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Extended IP access list xACSACLx-IP-PERMIT_ALL_TRAFFIC-57f6b0d3 (per-user)&lt;BR /&gt; 10 permit ip any any&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Extended IP access list xACSACLx-IP-WEBAUTH-5a9da3c9 (per-user)&lt;BR /&gt; 10 permit tcp any any eq www&lt;BR /&gt; 20 permit tcp any any eq 443&lt;BR /&gt; 30 permit tcp any any eq 8443&lt;BR /&gt; 40 permit udp any any eq domain&lt;BR /&gt; 50 deny ip any any&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;***CODE SNIPPETS***&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;ip dhcp snooping&lt;BR /&gt;ip device tracking&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;ip admission name PROXY_HTTP proxy http&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;fallback profile WEBAUTH-PROFILE&lt;BR /&gt; ip access-group INTERFACE_DEFAULT in&lt;BR /&gt; ip admission PROXY_HTTP&lt;BR /&gt;!&lt;/P&gt;
&lt;P&gt;interface GigabitEthernet1/0/19&lt;BR /&gt; switchport access vlan 254&lt;BR /&gt; switchport mode access&lt;BR /&gt; ip access-group INTERFACE_DEFAULT in&lt;BR /&gt; authentication event fail action next-method&lt;BR /&gt; authentication event server dead action authorize vlan 254&lt;BR /&gt; authentication event server dead action authorize voice&lt;BR /&gt; authentication event no-response action authorize vlan 254&lt;BR /&gt; authentication event server alive action reinitialize&lt;BR /&gt; authentication host-mode multi-domain&lt;BR /&gt; authentication order dot1x mab webauth&lt;BR /&gt; authentication priority dot1x mab webauth&lt;BR /&gt; authentication port-control auto&lt;BR /&gt; authentication timer inactivity 300&lt;BR /&gt; authentication fallback WEBAUTH-PROFILE&lt;BR /&gt; mab&lt;BR /&gt; dot1x pae authenticator&lt;BR /&gt; dot1x timeout quiet-period 5&lt;BR /&gt; dot1x timeout server-timeout 5&lt;BR /&gt; dot1x timeout tx-period 5&lt;BR /&gt; dot1x timeout supp-timeout 2&lt;BR /&gt; dot1x max-req 1&lt;BR /&gt; dot1x max-reauth-req 1&lt;BR /&gt; spanning-tree portfast&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;ip access-list extended ACL_WEBAUTH_REDIRECT&lt;BR /&gt; deny ip any host 10.223.2.2&lt;BR /&gt; permit tcp any any eq www&lt;BR /&gt; permit tcp any any eq 443&lt;BR /&gt; permit tcp any any eq 8443&lt;BR /&gt; deny ip any any log&lt;/P&gt;
&lt;P&gt;!&lt;BR /&gt;ip access-list extended INTERFACE_DEFAULT&lt;BR /&gt; permit udp any eq bootpc any eq bootps&lt;BR /&gt; permit udp any any eq domain&lt;BR /&gt; permit tcp any any eq 443&lt;BR /&gt; permit tcp any any eq www&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:49:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-3750g-not-redirecting-http-https-even-though-redirect-acl/m-p/3350991#M549655</guid>
      <dc:creator>glenn.dalcourt</dc:creator>
      <dc:date>2020-02-21T18:49:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 3750G not redirecting HTTP/HTTPS even though redirect ACL pushed to switch</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-3750g-not-redirecting-http-https-even-though-redirect-acl/m-p/3350995#M549656</link>
      <description>Hi,&lt;BR /&gt;You need "ip http server" configured for redirect, I can't see it in your config output. Can you confirm you have it configured?</description>
      <pubDate>Mon, 19 Mar 2018 16:29:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-3750g-not-redirecting-http-https-even-though-redirect-acl/m-p/3350995#M549656</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-03-19T16:29:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 3750G not redirecting HTTP/HTTPS even though redirect ACL pushed to switch</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-3750g-not-redirecting-http-https-even-though-redirect-acl/m-p/3351000#M549657</link>
      <description>&lt;P&gt;Confirmed this is configured. Accidentally left it out of the code snippets.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;***CODE SNIPPETS***&lt;/P&gt;
&lt;P&gt;ip http server&lt;BR /&gt;ip http secure-server&lt;BR /&gt;ip http secure-active-session-modules none&lt;BR /&gt;ip http active-session-modules none&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 16:33:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-3750g-not-redirecting-http-https-even-though-redirect-acl/m-p/3351000#M549657</guid>
      <dc:creator>glenn.dalcourt</dc:creator>
      <dc:date>2018-03-19T16:33:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 3750G not redirecting HTTP/HTTPS even though redirect ACL pushed to switch</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-3750g-not-redirecting-http-https-even-though-redirect-acl/m-p/3351005#M549658</link>
      <description>What aaa commands do you have defined?</description>
      <pubDate>Mon, 19 Mar 2018 16:38:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-3750g-not-redirecting-http-https-even-though-redirect-acl/m-p/3351005#M549658</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-03-19T16:38:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 3750G not redirecting HTTP/HTTPS even though redirect ACL pushed to switch</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-3750g-not-redirecting-http-https-even-though-redirect-acl/m-p/3351010#M549659</link>
      <description>&lt;P&gt;Confirming that dot1x and MAB are functioning.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As requested:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;aaa new-model&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa group server radius RAD&lt;BR /&gt; server 10.223.2.2&lt;BR /&gt; server 10.223.10.4&lt;BR /&gt; server 10.223.10.5&lt;BR /&gt;!&lt;BR /&gt;aaa group server tacacs+ TAC&lt;BR /&gt; server 10.223.2.2&lt;BR /&gt; ip tacacs source-interface Vlan99&lt;BR /&gt;!&lt;BR /&gt;aaa authentication login default group tacacs+ group radius local&lt;BR /&gt;aaa authentication enable default group tacacs+ group radius enable&lt;BR /&gt;aaa authentication dot1x default group radius&lt;BR /&gt;aaa authorization exec default group tacacs+ local&lt;BR /&gt;aaa authorization commands 15 default group tacacs+ local&lt;BR /&gt;aaa authorization network default group radius&lt;BR /&gt;aaa accounting dot1x default start-stop group radius&lt;BR /&gt;aaa accounting exec default start-stop group tacacs+ group radius&lt;BR /&gt;aaa accounting system default start-stop group tacacs+ group radius&lt;BR /&gt;!&lt;BR /&gt;aaa server radius dynamic-author&lt;BR /&gt; client 10.223.2.2 server-key&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;aaa session-id common&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 16:42:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-3750g-not-redirecting-http-https-even-though-redirect-acl/m-p/3351010#M549659</guid>
      <dc:creator>glenn.dalcourt</dc:creator>
      <dc:date>2018-03-19T16:42:37Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 3750G not redirecting HTTP/HTTPS even though redirect ACL pushed to switch</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-3750g-not-redirecting-http-https-even-though-redirect-acl/m-p/3351019#M549660</link>
      <description>When the redirect acl is active on the interface and redirect is not working, is the client computer able to resolve the portal fqdn of the PSN?&lt;BR /&gt;&lt;BR /&gt;Can you take a packet capture from the PSN when the client attempts to connect to the portal? See what, if any traffic hits the PSN.</description>
      <pubDate>Mon, 19 Mar 2018 16:55:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-3750g-not-redirecting-http-https-even-though-redirect-acl/m-p/3351019#M549660</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-03-19T16:55:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 3750G not redirecting HTTP/HTTPS even though redirect ACL pushed to switch</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-3750g-not-redirecting-http-https-even-though-redirect-acl/m-p/3351079#M549661</link>
      <description>&lt;P&gt;See attached. (change extension to pcap)&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 18:09:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-3750g-not-redirecting-http-https-even-though-redirect-acl/m-p/3351079#M549661</guid>
      <dc:creator>glenn.dalcourt</dc:creator>
      <dc:date>2018-03-19T18:09:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 3750G not redirecting HTTP/HTTPS even though redirect ACL pushed to switch</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-3750g-not-redirecting-http-https-even-though-redirect-acl/m-p/3351087#M549662</link>
      <description>&lt;P&gt;The host is not resolving lab-ise-pri.labratory.local. Changed the authorization policy to point to ISE's IP as opposed to hostname. Still a no go. No redirection:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;LAB-S3750-1#&lt;BR /&gt;Mar 19 18:21:51.528: %AUTHMGR-5-SUCCESS: Authorization succeeded for client (000e.c68f.4089) on Interface Gi1/0/19 AuditSessionID 0ADF63020000003400A9E542&lt;BR /&gt;LAB-S3750-1#show auth sess int g1/0/19&lt;BR /&gt; Interface: GigabitEthernet1/0/19&lt;BR /&gt; MAC Address: 000e.c68f.4089&lt;BR /&gt; IP Address: 10.223.254.11&lt;BR /&gt; User-Name: 00-0E-C6-8F-40-89&lt;BR /&gt; Status: Authz Success&lt;BR /&gt; Domain: DATA&lt;BR /&gt; Security Policy: Should Secure&lt;BR /&gt; Security Status: Unsecure&lt;BR /&gt; Oper host mode: multi-domain&lt;BR /&gt; Oper control dir: both&lt;BR /&gt; Authorized By: Authentication Server&lt;BR /&gt; Vlan Policy: 254&lt;BR /&gt; ACS ACL: xACSACLx-IP-WEBAUTH-5a9da3c9&lt;BR /&gt; URL Redirect ACL: ACL_WEBAUTH_REDIRECT&lt;BR /&gt; URL Redirect: &lt;A href="https://10.223.2.2:8443/portal/gateway?sessionId=0ADF63020000003400A9E542&amp;amp;portal=f0ae43f0-7159-11e7-a355-005056aba474&amp;amp;action=cwa&amp;amp;token=37634fa389238c30cfa47fe499ab6df3" target="_blank"&gt;https://10.223.2.2:8443/portal/gateway?sessionId=0ADF63020000003400A9E542&amp;amp;portal=f0ae43f0-7159-11e7-a355-005056aba474&amp;amp;action=cwa&amp;amp;token=37634fa389238c30cfa47fe499ab6df3&lt;/A&gt;&lt;BR /&gt; Session timeout: N/A&lt;BR /&gt; Idle timeout: 300s (local), Remaining: 297s&lt;BR /&gt; Common Session ID: 0ADF63020000003400A9E542&lt;BR /&gt; Acct Session ID: 0x00000047&lt;BR /&gt; Handle: 0x4F000035&lt;/P&gt;
&lt;P&gt;Runnable methods list:&lt;BR /&gt; Method State&lt;BR /&gt; dot1x Failed over&lt;BR /&gt; mab Authc Success&lt;BR /&gt; webauth Not run&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 18:22:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-3750g-not-redirecting-http-https-even-though-redirect-acl/m-p/3351087#M549662</guid>
      <dc:creator>glenn.dalcourt</dc:creator>
      <dc:date>2018-03-19T18:22:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 3750G not redirecting HTTP/HTTPS even though redirect ACL pushed to switch</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-3750g-not-redirecting-http-https-even-though-redirect-acl/m-p/3351095#M549663</link>
      <description>&lt;P&gt;I know the portal is functioning because if I manually input the Redirect URL from the 'show auth sess int' command into the browser on the client I can authenticate against AD and CoA occurs and places me on the correct VLAN.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 18:31:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-3750g-not-redirecting-http-https-even-though-redirect-acl/m-p/3351095#M549663</guid>
      <dc:creator>glenn.dalcourt</dc:creator>
      <dc:date>2018-03-19T18:31:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 3750G not redirecting HTTP/HTTPS even though redirect ACL pushed to switch</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-3750g-not-redirecting-http-https-even-though-redirect-acl/m-p/3351135#M549664</link>
      <description>&lt;P&gt;So the client is not attempting to resolve any DNS names? From your previous output below, I would have thought DNS should hit ace # 50.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;LAB-S3750-1#show access-list&lt;BR /&gt;Extended IP access list ACL_WEBAUTH_REDIRECT&lt;BR /&gt; 10 deny ip any host 10.223.2.2&lt;BR /&gt; 20 permit tcp any any eq www (332 matches)&lt;BR /&gt; 30 permit tcp any any eq 443 (692 matches)&lt;BR /&gt; 40 permit tcp any any eq 8443&lt;BR /&gt; 50 deny ip any any log&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise/design-zone-security/howto_40_webauthentication_dg.pdf" target="_self"&gt;This guide&lt;/A&gt; says to explicitly "deny udp any any eq 53"&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 19:39:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-3750g-not-redirecting-http-https-even-though-redirect-acl/m-p/3351135#M549664</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-03-19T19:39:48Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 3750G not redirecting HTTP/HTTPS even though redirect ACL pushed to switch</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-3750g-not-redirecting-http-https-even-though-redirect-acl/m-p/3351262#M549665</link>
      <description>&lt;P&gt;I don't fully understand the flow of packets nor the sources of the packets when redirection occurs...When I take the firewall out of the picture redirection occurs fine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What I can say is that the client traffic flowed through the firewall. The switches control plane traffic bypassed the firewall and hit the upstream router. I think some sort of asymmetric routing was the issue somewhere in the flow of redirect traffic.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Client &amp;gt; L2 switch &amp;gt; ASA &amp;gt; R1 &amp;gt; ISE&lt;/P&gt;
&lt;P&gt;L2 Switch Control Plane &amp;gt; R1 &amp;gt; ISE&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I redesigned the lab based off of this:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/113362-config-web-auth-ise-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/113362-config-web-auth-ise-00.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"Important Note about Switch SVIs&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At this time, the switch needs a switch virtual interface (SVI) in order to reply to the client and send the web portal redirection to the client. This SVI does not necessarily have to be on the client subnet/VLAN. However, if the switch has no SVI in the client subnet/VLAN, it has to use any of the other SVIs and send traffic as defined in the client routing table. This typically means traffic is sent to another gateway in the core of the network; this traffic comes back to the access switch inside the client subnet.&lt;/P&gt;
&lt;P&gt;Firewalls typically block traffic from and to the same switch, as in this scenario, so redirection might not work properly. Workarounds are to allow this behavior on the firewall or to create an SVI on the access switch in the client subnet."&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 22:55:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-3750g-not-redirecting-http-https-even-though-redirect-acl/m-p/3351262#M549665</guid>
      <dc:creator>glenn.dalcourt</dc:creator>
      <dc:date>2018-03-19T22:55:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 3750G not redirecting HTTP/HTTPS even though redirect ACL pushed to switch</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-3750g-not-redirecting-http-https-even-though-redirect-acl/m-p/3351264#M549666</link>
      <description>&lt;P&gt;If you could detail out the packet flow/paths in CWA redirection via a link that'd be greatly appreciated.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 22:59:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-3750g-not-redirecting-http-https-even-though-redirect-acl/m-p/3351264#M549666</guid>
      <dc:creator>glenn.dalcourt</dc:creator>
      <dc:date>2018-03-19T22:59:01Z</dc:date>
    </item>
  </channel>
</rss>

