<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Posture redirection behind IP-Phone in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/posture-redirection-behind-ip-phone/m-p/4042395#M558653</link>
    <description>&lt;P&gt;I need assistance in getting URL redirection for client provisioning to work when my PC is connected behind an IP-Phone.Redirection is working fine when the PC is connected directly to the switch but somehow, redirection is not even attempted when the PC is connected to a phone.The portal page is perfectly reachable when I copy and paste it to my browser, even when connected to the phone.&lt;/P&gt;</description>
    <pubDate>Sun, 08 Mar 2020 14:00:38 GMT</pubDate>
    <dc:creator>jay3</dc:creator>
    <dc:date>2020-03-08T14:00:38Z</dc:date>
    <item>
      <title>Posture redirection behind IP-Phone</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-redirection-behind-ip-phone/m-p/4042395#M558653</link>
      <description>&lt;P&gt;I need assistance in getting URL redirection for client provisioning to work when my PC is connected behind an IP-Phone.Redirection is working fine when the PC is connected directly to the switch but somehow, redirection is not even attempted when the PC is connected to a phone.The portal page is perfectly reachable when I copy and paste it to my browser, even when connected to the phone.&lt;/P&gt;</description>
      <pubDate>Sun, 08 Mar 2020 14:00:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-redirection-behind-ip-phone/m-p/4042395#M558653</guid>
      <dc:creator>jay3</dc:creator>
      <dc:date>2020-03-08T14:00:38Z</dc:date>
    </item>
    <item>
      <title>Re: Posture redirection behind IP-Phone</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-redirection-behind-ip-phone/m-p/4042450#M558655</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; Post your switch configuration for AAA, RADIUS and port configuration. What phone do you have? Is authentication/authorization successful for both phone and PC?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cristian Matei.&lt;/P&gt;</description>
      <pubDate>Sun, 08 Mar 2020 17:43:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-redirection-behind-ip-phone/m-p/4042450#M558655</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2020-03-08T17:43:19Z</dc:date>
    </item>
    <item>
      <title>Re: Posture redirection behind IP-Phone</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-redirection-behind-ip-phone/m-p/4042611#M558668</link>
      <description>&lt;P&gt;Hi Cristian,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your response.I tried this with a Cisco IP Phone 7821 &amp;amp; 8945 but still get the same result, authentication and authorization are successful for both the pc and the phone but no redirection.Please find the information you requested attached.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 07:18:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-redirection-behind-ip-phone/m-p/4042611#M558668</guid>
      <dc:creator>jay3</dc:creator>
      <dc:date>2020-03-09T07:18:54Z</dc:date>
    </item>
    <item>
      <title>Re: Posture redirection behind IP-Phone</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-redirection-behind-ip-phone/m-p/4045921#M558892</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;Per the posted config, it looks like you don't actually enable/enforce authentication on the port. You're missing the following commands at the port-level:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;authentication port-control auto&lt;/P&gt;&lt;P&gt;dot1x pae authenticator&lt;/P&gt;&lt;P&gt;mab&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the output of command "show access-session interface GigabitEthernet1/0/4 detail" or "show authentication-session interface GigabitEthernet1/0/4"?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Use this guide to validate your implementation:&amp;nbsp;&lt;A href="https://community.cisco.com/t5/security-documents/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cristian Matei.&lt;/P&gt;</description>
      <pubDate>Sat, 14 Mar 2020 16:23:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-redirection-behind-ip-phone/m-p/4045921#M558892</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2020-03-14T16:23:33Z</dc:date>
    </item>
    <item>
      <title>Re: Posture redirection behind IP-Phone</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-redirection-behind-ip-phone/m-p/4045942#M558895</link>
      <description>&lt;P&gt;Hi Cristian, Thanks again for your response. You seem to have mistakenly missed those three commands.If you check again, you can see that I in fact do have those commands at port level.I have gone through the prescriptive deployment a couple of times but still can't identify the challenge.The output for "show authentication sessions interface g1/0/4 details" is exactly the same with and without the phone,&amp;nbsp; but surprisingly, redirection fails to work behind the phone.&lt;/P&gt;&lt;P&gt;Regards..&lt;/P&gt;</description>
      <pubDate>Sat, 14 Mar 2020 17:47:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-redirection-behind-ip-phone/m-p/4045942#M558895</guid>
      <dc:creator>jay3</dc:creator>
      <dc:date>2020-03-14T17:47:22Z</dc:date>
    </item>
    <item>
      <title>Re: Posture redirection behind IP-Phone</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-redirection-behind-ip-phone/m-p/4045950#M558897</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;Apologies, i'm sure i looked all the way in the attachment, maybe it was not loaded completely. Anyways, it doesn't matter. Can you try to reconfigure your redirect ACL, so that only HTTP/HTTPS traffic is being redirected to the switch? Depending on how chatty the host is, the switches CPU may be flooded with useless data. So remove "permit ip any any", and add "permit tcp any any eq 80, permit tcp any any eq 443".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cristian Matei.&lt;/P&gt;</description>
      <pubDate>Sat, 14 Mar 2020 18:22:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-redirection-behind-ip-phone/m-p/4045950#M558897</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2020-03-14T18:22:57Z</dc:date>
    </item>
  </channel>
</rss>

