<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic We have it on a separate in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-hotspot-captive-web-portal-with-http-not-https/m-p/2755569#M57158</link>
    <description>&lt;P&gt;We have it on a separate interface currently, but I'm still looking for documentation on how to, or whether it's possible to restrict it to guest portal flows only / ACL it within the ISE.&lt;/P&gt;</description>
    <pubDate>Thu, 15 Oct 2015 13:44:29 GMT</pubDate>
    <dc:creator>Toivo Voll</dc:creator>
    <dc:date>2015-10-15T13:44:29Z</dc:date>
    <item>
      <title>ISE Hotspot / Captive Web Portal with HTTP (not HTTPS)?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-hotspot-captive-web-portal-with-http-not-https/m-p/2755565#M57151</link>
      <description>&lt;P&gt;We're setting up an ISE PoC for a hotspot (guests get redirected to an AUP page, and have to click "accept") and was wondering whether HTTPS (and certs, cert chains and all that stuff) is really necessary for this.&lt;/P&gt;&lt;P&gt;Perhaps I'm missing something obvious, but since there's no actual information (passwords, emails, names) being transferred, what's the need for HTTPS? Is there any way to allow plain old HTTP to the portal?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:09:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-hotspot-captive-web-portal-with-http-not-https/m-p/2755565#M57151</guid>
      <dc:creator>Toivo Voll</dc:creator>
      <dc:date>2019-03-11T06:09:03Z</dc:date>
    </item>
    <item>
      <title>Right now this is not</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-hotspot-captive-web-portal-with-http-not-https/m-p/2755566#M57153</link>
      <description>&lt;P&gt;Right now this is not possible. ISE is a&amp;nbsp; security appliance&amp;nbsp; and HTTP support for Portal flows isn't even on the roadmap.&lt;/P&gt;&lt;P&gt;But that's actually a&amp;nbsp; good point. I can see some room for an enhancement request to have the ability to disable HTTPS on HotSpots flows if there is no access code enabled(optional)&amp;nbsp; since there are no credentials to protect during this stage.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Oct 2015 13:22:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-hotspot-captive-web-portal-with-http-not-https/m-p/2755566#M57153</guid>
      <dc:creator>Antonio Torres</dc:creator>
      <dc:date>2015-10-15T13:22:04Z</dc:date>
    </item>
    <item>
      <title>Thanks for the response.That</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-hotspot-captive-web-portal-with-http-not-https/m-p/2755567#M57154</link>
      <description>&lt;P&gt;Thanks for the response.&lt;/P&gt;&lt;P&gt;That's our use case; we only need users to agree to an AUP. There's just the "accept" button, no email field, no pin or anything else.&lt;/P&gt;&lt;P&gt;The challenge is that the clients are in private IP space but rely on public DNS, so as far as I can tell either we have to expose the ISE portal interface to the Internet, publish a public DNS record pointing at RFC1918 space or we can't have a valid cert for the guest portal. (Or we have to re-engineer guest DNS to allow for split views, but that's a different group and involves buying things.)&lt;/P&gt;</description>
      <pubDate>Thu, 15 Oct 2015 13:35:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-hotspot-captive-web-portal-with-http-not-https/m-p/2755567#M57154</guid>
      <dc:creator>Toivo Voll</dc:creator>
      <dc:date>2015-10-15T13:35:34Z</dc:date>
    </item>
    <item>
      <title>If you go with exposing ISE </title>
      <link>https://community.cisco.com/t5/network-access-control/ise-hotspot-captive-web-portal-with-http-not-https/m-p/2755568#M57156</link>
      <description>&lt;P&gt;If you go with exposing ISE&amp;nbsp; you may select a dedicated interface for the HotSpot portal and even modify the port we'll be listening on&amp;nbsp; to avoid exposing other flows and management access as well.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Oct 2015 13:41:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-hotspot-captive-web-portal-with-http-not-https/m-p/2755568#M57156</guid>
      <dc:creator>Antonio Torres</dc:creator>
      <dc:date>2015-10-15T13:41:49Z</dc:date>
    </item>
    <item>
      <title>We have it on a separate</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-hotspot-captive-web-portal-with-http-not-https/m-p/2755569#M57158</link>
      <description>&lt;P&gt;We have it on a separate interface currently, but I'm still looking for documentation on how to, or whether it's possible to restrict it to guest portal flows only / ACL it within the ISE.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Oct 2015 13:44:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-hotspot-captive-web-portal-with-http-not-https/m-p/2755569#M57158</guid>
      <dc:creator>Toivo Voll</dc:creator>
      <dc:date>2015-10-15T13:44:29Z</dc:date>
    </item>
    <item>
      <title>I can see that from the Linux</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-hotspot-captive-web-portal-with-http-not-https/m-p/2755570#M57161</link>
      <description>&lt;P&gt;I can see that from the Linux side&amp;nbsp; but from ISE application side there is no way you can restrict this based on the interface you're hitting.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Oct 2015 13:55:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-hotspot-captive-web-portal-with-http-not-https/m-p/2755570#M57161</guid>
      <dc:creator>Antonio Torres</dc:creator>
      <dc:date>2015-10-15T13:55:29Z</dc:date>
    </item>
  </channel>
</rss>

