<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Client Certificate Error on Portal Redirect in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/client-certificate-error-on-portal-redirect/m-p/4155326#M562948</link>
    <description>&lt;P&gt;Hi Rob,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As per my previous post, we are experiencing the same issue as the link below albeit on the LAN rather than WLC.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/ise-cwa-url-redirection-for-https/td-p/3426840" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/ise-cwa-url-redirection-for-https/td-p/3426840&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas/suggestions on how to resolve this so the user experience is smooth?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Tue, 22 Sep 2020 14:31:57 GMT</pubDate>
    <dc:creator>InfraISE2020</dc:creator>
    <dc:date>2020-09-22T14:31:57Z</dc:date>
    <item>
      <title>Client Certificate Error on Portal Redirect</title>
      <link>https://community.cisco.com/t5/network-access-control/client-certificate-error-on-portal-redirect/m-p/4154842#M562929</link>
      <description>&lt;P&gt;&lt;SPAN&gt;We've created a policy on ISE so that users connecting to the LAN on non-corporate devices are redirected to a portal where they can enter their active directory credentials and connect to the network on the VLANX. The CWA redirect policy works however the clients get a certificate error as the switch they are connected to is presenting them with a self-signed certificate rather than the certificate assigned to the "default portal certificate group". Our network support team have confirmed that http active session modules have been disabled on the switch using the commands below: ip http secure-active-session-modules none ip http active-session-modules none.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Has anyone come across this issue before and what did they do to resolve it? I've attached a copy of the initial DACL for reference.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2020 19:03:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/client-certificate-error-on-portal-redirect/m-p/4154842#M562929</guid>
      <dc:creator>InfraISE2020</dc:creator>
      <dc:date>2020-09-21T19:03:26Z</dc:date>
    </item>
    <item>
      <title>Re: Client Certificate Error on Portal Redirect</title>
      <link>https://community.cisco.com/t5/network-access-control/client-certificate-error-on-portal-redirect/m-p/4154890#M562930</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1008639"&gt;@InfraISE2020&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTTPS redirection is not recommended for production environments because of the following reasons:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&amp;nbsp;&lt;STRONG&gt;Security concern&lt;/STRONG&gt;-HTTPS redirection is intended to hijack a secure web connection initiated by an endpoint, which is not a good idea.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Failure to work&lt;/STRONG&gt;-Most web browsers block intercepted HTTPS connections.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Certificate warnings&lt;/STRONG&gt;-Even if web browsers allow access, there can be certificate warnings because the switch presents its own certificate for TLS handshake.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Scalability issues&lt;/STRONG&gt;-Multiple HTTPS redirections can overload the switch CPU there by degrading the Switch performance&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515" target="_self"&gt;https://community.cisco.com/t5/security-documents/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you don't use HTTPS redirect then you won't receive the certificate presented by the switch nor the error.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2020 20:44:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/client-certificate-error-on-portal-redirect/m-p/4154890#M562930</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-09-21T20:44:44Z</dc:date>
    </item>
    <item>
      <title>Re: Client Certificate Error on Portal Redirect</title>
      <link>https://community.cisco.com/t5/network-access-control/client-certificate-error-on-portal-redirect/m-p/4155147#M562940</link>
      <description>&lt;P&gt;Hi Rob,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the quick reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm a little confused as the only ports available on the portal configuration are for HTTPS (8000 - 8999).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you saying that we can run&amp;nbsp;&lt;STRONG&gt;&lt;SPAN class="keyword kwd"&gt;no&amp;nbsp;ip&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="keyword kwd"&gt;http&amp;nbsp;s&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN class="keyword kwd"&gt;&lt;STRONG&gt;ecure-server&lt;/STRONG&gt; on our switches and the URL redirect will still work?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="keyword kwd"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 09:30:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/client-certificate-error-on-portal-redirect/m-p/4155147#M562940</guid>
      <dc:creator>InfraISE2020</dc:creator>
      <dc:date>2020-09-22T09:30:06Z</dc:date>
    </item>
    <item>
      <title>Re: Client Certificate Error on Portal Redirect</title>
      <link>https://community.cisco.com/t5/network-access-control/client-certificate-error-on-portal-redirect/m-p/4155156#M562941</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1008639"&gt;@InfraISE2020&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The switch itself does not need to be listening on the port you are using in the ISE portals. You just need to enable http server, which will redirect tcp/80 traffic to the ISE portal. Yes, you can use that command to disable https, as long as "ip http server" is enabled.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 09:42:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/client-certificate-error-on-portal-redirect/m-p/4155156#M562941</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-09-22T09:42:04Z</dc:date>
    </item>
    <item>
      <title>Re: Client Certificate Error on Portal Redirect</title>
      <link>https://community.cisco.com/t5/network-access-control/client-certificate-error-on-portal-redirect/m-p/4155212#M562945</link>
      <description>&lt;P&gt;thanks Rob, the switch certificate error has now disappeared.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue we now face is that users are only redirected to the portal if they browse to a http website, having an https website as their homepage and opening the browser doesn't automatically redirect them to the portal, any ideas?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 11:49:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/client-certificate-error-on-portal-redirect/m-p/4155212#M562945</guid>
      <dc:creator>InfraISE2020</dc:creator>
      <dc:date>2020-09-22T11:49:49Z</dc:date>
    </item>
    <item>
      <title>Re: Client Certificate Error on Portal Redirect</title>
      <link>https://community.cisco.com/t5/network-access-control/client-certificate-error-on-portal-redirect/m-p/4155326#M562948</link>
      <description>&lt;P&gt;Hi Rob,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As per my previous post, we are experiencing the same issue as the link below albeit on the LAN rather than WLC.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/ise-cwa-url-redirection-for-https/td-p/3426840" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/ise-cwa-url-redirection-for-https/td-p/3426840&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas/suggestions on how to resolve this so the user experience is smooth?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 14:31:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/client-certificate-error-on-portal-redirect/m-p/4155326#M562948</guid>
      <dc:creator>InfraISE2020</dc:creator>
      <dc:date>2020-09-22T14:31:57Z</dc:date>
    </item>
    <item>
      <title>Re: Client Certificate Error on Portal Redirect</title>
      <link>https://community.cisco.com/t5/network-access-control/client-certificate-error-on-portal-redirect/m-p/4155632#M562968</link>
      <description>&lt;P&gt;Please re-read Rob's original answer about Concerns, Warnings and Failures. Browsers won't do it.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2020 04:28:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/client-certificate-error-on-portal-redirect/m-p/4155632#M562968</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2020-09-23T04:28:04Z</dc:date>
    </item>
    <item>
      <title>Re: Client Certificate Error on Portal Redirect</title>
      <link>https://community.cisco.com/t5/network-access-control/client-certificate-error-on-portal-redirect/m-p/4155665#M562970</link>
      <description>&lt;P&gt;Hi Thomas,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I’m not sure robs reply answers my question re the browser redirection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If we disable HTTPS redirection on the switch, how do we get users to the portal page as ISE will only allow us to set the portal port to HTTPS? Currently the only way for users to reach it is to browse to a HTTP webpage manually, this is not a good user experience.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking at other posts it seems that the redirection works with a WLC so surely this is achievable on the LAN?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2020 06:06:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/client-certificate-error-on-portal-redirect/m-p/4155665#M562970</guid>
      <dc:creator>InfraISE2020</dc:creator>
      <dc:date>2020-09-23T06:06:03Z</dc:date>
    </item>
  </channel>
</rss>

