<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ise reauthentication after antivirus check in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-reauthentication-after-antivirus-check/m-p/4553339#M572815</link>
    <description>&lt;P&gt;No, also this one must be created automatically when authentication started&lt;/P&gt;</description>
    <pubDate>Wed, 16 Feb 2022 08:19:07 GMT</pubDate>
    <dc:creator>Rovshan91</dc:creator>
    <dc:date>2022-02-16T08:19:07Z</dc:date>
    <item>
      <title>Ise reauthentication after antivirus check</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-reauthentication-after-antivirus-check/m-p/4551686#M572765</link>
      <description>&lt;P&gt;Hello everybody. A have interesting problem. I have a rule on my cisco ise , that sends you&amp;nbsp; to the portal and checks is there anyconnect and antivirus on your pc, after it&amp;nbsp; gives you your vlan.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I have same config on 2 difference switches&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;C9200-48T&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;16.12.3a&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;CAT9K_LITE_IOSXE&lt;/P&gt;&lt;P&gt;&amp;nbsp;WS-C2960L-48TS-LL&amp;nbsp; 15.2(7)E3&amp;nbsp; &amp;nbsp;C2960L-UNIVERSALK9-M&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and it unfortunately works in second one ( 2960 lite) but didn`t work on C9200&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only thing that i found strange that c9200 didn`t automatically&amp;nbsp; create acl (Auth-Default-ACL-OPEN)&amp;nbsp; but he must to do it so reauth works. (also 2960l do this thing)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Extended IP access list Auth-Default-ACL-OPEN&lt;BR /&gt;10 permit ip any any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Config example&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ip access-list extended CISCO-CWA-URL-REDIRECT-ACL&lt;/P&gt;&lt;P&gt;10 deny udp any any eq domain&lt;BR /&gt;20 deny tcp any any eq domain&lt;BR /&gt;30 deny udp any eq bootps any&lt;BR /&gt;40 deny udp any any eq bootpc&lt;BR /&gt;50 deny udp any eq bootpc any&lt;BR /&gt;60 deny tcp any any eq 8443&lt;BR /&gt;70 deny udp any any eq 8443&lt;BR /&gt;80 permit tcp any any eq domain&lt;BR /&gt;90 permit tcp any any eq www&lt;BR /&gt;authentication command bounce-port ignore&lt;BR /&gt;authentication command disable-port ignore&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;aaa server radius dynamic-author&lt;BR /&gt;client *.*.*.*&lt;/P&gt;&lt;P&gt;server-key xxxxxxxxxxx&lt;BR /&gt;auth-type all&lt;BR /&gt;ignore session-key&lt;BR /&gt;ignore server-key&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The ony thing that i found&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Feb 2022 07:12:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-reauthentication-after-antivirus-check/m-p/4551686#M572765</guid>
      <dc:creator>Rovshan91</dc:creator>
      <dc:date>2022-02-14T07:12:23Z</dc:date>
    </item>
    <item>
      <title>Re: Ise reauthentication after antivirus check</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-reauthentication-after-antivirus-check/m-p/4552088#M572776</link>
      <description>&lt;P&gt;I don't believe you would need that ACL to get this to work, I think in this case the CoA would be the key factory to trigger the reauthentication. Probably the 9200 switch is not configured correctly for the CoA? or maybe has some wrong CoA configs on ISE?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Feb 2022 17:48:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-reauthentication-after-antivirus-check/m-p/4552088#M572776</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-02-14T17:48:57Z</dc:date>
    </item>
    <item>
      <title>Re: Ise reauthentication after antivirus check</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-reauthentication-after-antivirus-check/m-p/4552452#M572781</link>
      <description>&lt;P&gt;Without this acl 90% of&amp;nbsp; traffic is blocked + same config works on&amp;nbsp;&amp;nbsp;WS-C2960L-48TS-LL, only difference is this acl&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Feb 2022 05:39:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-reauthentication-after-antivirus-check/m-p/4552452#M572781</guid>
      <dc:creator>Rovshan91</dc:creator>
      <dc:date>2022-02-15T05:39:54Z</dc:date>
    </item>
    <item>
      <title>Re: Ise reauthentication after antivirus check</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-reauthentication-after-antivirus-check/m-p/4552574#M572783</link>
      <description>&lt;P&gt;Are there any other ACLs applied to the switch ports by default?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Feb 2022 09:44:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-reauthentication-after-antivirus-check/m-p/4552574#M572783</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-02-15T09:44:54Z</dc:date>
    </item>
    <item>
      <title>Re: Ise reauthentication after antivirus check</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-reauthentication-after-antivirus-check/m-p/4553339#M572815</link>
      <description>&lt;P&gt;No, also this one must be created automatically when authentication started&lt;/P&gt;</description>
      <pubDate>Wed, 16 Feb 2022 08:19:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-reauthentication-after-antivirus-check/m-p/4553339#M572815</guid>
      <dc:creator>Rovshan91</dc:creator>
      <dc:date>2022-02-16T08:19:07Z</dc:date>
    </item>
  </channel>
</rss>

