<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Redirection in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-redirection/m-p/4701064#M577676</link>
    <description>&lt;P&gt;hslai&lt;/P&gt;&lt;P&gt;I appreciate your response.&amp;nbsp; However, the Cat9800 does point me to all those logs etc in that URL.&amp;nbsp; My issue is there is just too much there and I'm looking for specific debugs that may assist rather than a great big load of output that takes significant time, or TAC, to look through.&amp;nbsp; I was hoping for a debug to maybe show traffic the WLC has decided to redirect.&amp;nbsp; Sometimes there are debugs that throw up a concise nugget of info that points us to the issue rather than grabbing lots of logs and captures and having to plough through them looking for the nuggets.&lt;/P&gt;&lt;P&gt;I do appreciate your contribution though.&lt;/P&gt;&lt;P&gt;Kev.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 11 Oct 2022 07:44:45 GMT</pubDate>
    <dc:creator>KevinR99</dc:creator>
    <dc:date>2022-10-11T07:44:45Z</dc:date>
    <item>
      <title>ISE Redirection</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-redirection/m-p/4700241#M577657</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I have a strange issue and no doubt I'm missing something basic but it has me scratching my head.&lt;/P&gt;&lt;P&gt;I've been playing around with Guest portals.&amp;nbsp; I have Guest 1 on Gig1 and Guest 2 on Gig 2.&amp;nbsp; In my authorization profile I supply the portal IP address to bypass DNS resolution.&amp;nbsp; The policy is pretty simple.&amp;nbsp; The authentication rule checks Guest Users and has the options set to Auth fail and User not found to continue.&amp;nbsp; The Authorization policy is as standard.&amp;nbsp; The first rule matches Wireless MAB and Guest flow then permits.&amp;nbsp; The second rule matched MAB and the SSID name and invokes an authorization profile pointing to the Guest Self register portal.&amp;nbsp; The portal is enabled on Gig1 and the profile applies a redirect ACL that is on the WLC and the Guest self register portal is chosen.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've been testing this over the last few days.&amp;nbsp; I know my redirect ACL is good as it's not changed from when it was working.&amp;nbsp; Prior to a test connection I delete the client from the Context visibility - Endpoints area and I make sure the WLC doesn't have the client as connected.&amp;nbsp; I then try to connect.&amp;nbsp; This time the client just connects.&amp;nbsp; No redirection attempted.&amp;nbsp; When I look in the ISE live logs it says the client is authenticated based on their MAC address and the correct redirect URL has been sent.&amp;nbsp; But my clients never redirect anymore.&lt;/P&gt;&lt;P&gt;I have done this lots of times before and the usual issue I have to solve is the client gets redirected but can't get to the portal for some reason.&amp;nbsp; I can usually fix that no problem.&amp;nbsp; This time it just lets the client on and in the WLC log it has been authenticated based on the MAC.&amp;nbsp; I see the following in the ISE logs&lt;/P&gt;&lt;TABLE border="0" cellpadding="3"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;The host is not found in the internal endpoints identity store&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15048&lt;/TD&gt;&lt;TD&gt;Queried PIP - Radius.Called-Station-ID&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15016&lt;/TD&gt;&lt;TD&gt;Selected Authorization Profile - XXX-portal-redirect&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11002&lt;/TD&gt;&lt;TD&gt;Returned RADIUS Access-Accept&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;So I expect the client to be redirected to allow me to enter credentials and then the registered username is what is successfully authenticated for access on the ISE and WLC.&lt;/P&gt;&lt;P&gt;Anyone have any ideas on this one?&lt;/P&gt;&lt;P&gt;Thanks, Kev.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 08 Oct 2022 15:37:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-redirection/m-p/4700241#M577657</guid>
      <dc:creator>KevinR99</dc:creator>
      <dc:date>2022-10-08T15:37:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Redirection</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-redirection/m-p/4700433#M577664</link>
      <description>&lt;P&gt;I decided to do a rebuild of my lab and all is ok now.&amp;nbsp; Not quite sure what the issue was but I have it working now.&amp;nbsp; As a troubleshooting aid does anyone have recommended debugs I can use on Cat9800's for such issues?&amp;nbsp; I find the radioactive trace on a client MAC produces way too much info and it's difficult to find what you're looking for.&lt;/P&gt;&lt;P&gt;Thanks, Kev.&lt;/P&gt;</description>
      <pubDate>Sun, 09 Oct 2022 14:35:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-redirection/m-p/4700433#M577664</guid>
      <dc:creator>KevinR99</dc:creator>
      <dc:date>2022-10-09T14:35:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Redirection</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-redirection/m-p/4700489#M577666</link>
      <description>&lt;P&gt;See &lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/215523-quick-start-guide-on-what-logs-and-debug.html#anc17" target="_self"&gt;Cisco Catalyst 9800 WLC &amp;gt; Troubleshooting TechNotes &amp;gt; Collect Logs and Debugs from Catalyst 9800 WLC for Various Scenarios &amp;gt; Guest Central Web Authentication(CWA) or Local Web Authentication(LWA) Issues&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Oct 2022 20:39:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-redirection/m-p/4700489#M577666</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2022-10-09T20:39:20Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Redirection</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-redirection/m-p/4701064#M577676</link>
      <description>&lt;P&gt;hslai&lt;/P&gt;&lt;P&gt;I appreciate your response.&amp;nbsp; However, the Cat9800 does point me to all those logs etc in that URL.&amp;nbsp; My issue is there is just too much there and I'm looking for specific debugs that may assist rather than a great big load of output that takes significant time, or TAC, to look through.&amp;nbsp; I was hoping for a debug to maybe show traffic the WLC has decided to redirect.&amp;nbsp; Sometimes there are debugs that throw up a concise nugget of info that points us to the issue rather than grabbing lots of logs and captures and having to plough through them looking for the nuggets.&lt;/P&gt;&lt;P&gt;I do appreciate your contribution though.&lt;/P&gt;&lt;P&gt;Kev.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2022 07:44:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-redirection/m-p/4701064#M577676</guid>
      <dc:creator>KevinR99</dc:creator>
      <dc:date>2022-10-11T07:44:45Z</dc:date>
    </item>
  </channel>
</rss>

