<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco switch url web-redirect is not working in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-switch-url-web-redirect-is-not-working/m-p/4719993#M578194</link>
    <description>&lt;P&gt;Are you sure that ClearPass supports a downloadable ACL to Cisco switches? Downloadable ACLs are not a RADIUS standard feature.&lt;/P&gt;
&lt;P&gt;You might need to use pre-configured ACLs and send the ACL name only.&lt;/P&gt;</description>
    <pubDate>Fri, 11 Nov 2022 22:48:07 GMT</pubDate>
    <dc:creator>thomas</dc:creator>
    <dc:date>2022-11-11T22:48:07Z</dc:date>
    <item>
      <title>Cisco switch url web-redirect is not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-switch-url-web-redirect-is-not-working/m-p/4706187#M577832</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;I have a problem with web redirection url. When I connect my PC to the switch (s2960), the PC is authenticated. And the Switch received URL redirect and&amp;nbsp;URL Redirect ACL. PC requested&amp;nbsp; an ip address using dhcp and&amp;nbsp;is receiving it. The browser opens on the computer and it starts opening the redirect URL over and over again, like in a loop.&amp;nbsp;And the captive portal page won't open.&lt;BR /&gt;&lt;BR /&gt;I configured&amp;nbsp;ip http server,&amp;nbsp;ip http secure-server,&amp;nbsp;ip device tracking, ACL.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;The "show authentication sessions interface gigabitEthernet x/x details" command give the next result&amp;nbsp;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Interface: gigabitEthernet x/x&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;MAC Address: xxxx.xxxx.xxxx&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;IPv6 Address: Unknown&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;IPv4 Address: 10.1.4.23&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;User-Name: xxxxxxxxxxxx&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Status: Authorized&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Domain: DATA&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Oper host mode: multi-domain&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Oper control dir: both&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Session timeout: N/A&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Restart timeout: N/A&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Periodic Acct timeout: 172800s (local), Remaining: 171245s&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Session Uptime: 1568s&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Common Session ID: 0Axxxxxxxxxxxxxx&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Acct Session ID: 0x0XXXXXX&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Handle: 0x8XXXXXXXX&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Current Policy: POLICY_Gix/x&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Local Policies:&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Service Template: DEFAULT_LINKSEC_POLICY_SHOULD_SECURE (priority 150)&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Server Policies:&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;URL Redirect: &lt;A href="https://10.1.1.15" target="_blank"&gt;https://10.1.1.15&lt;/A&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;URL Redirect ACL: Captive_Portal_Redirect&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Method status list: &lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Method State&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;dot1x Stopped&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;mab Authc Success&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;what could be the problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2022 06:26:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-switch-url-web-redirect-is-not-working/m-p/4706187#M577832</guid>
      <dc:creator>Almas</dc:creator>
      <dc:date>2022-10-20T06:26:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco switch url web-redirect is not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-switch-url-web-redirect-is-not-working/m-p/4706201#M577834</link>
      <description>&lt;P&gt;what ISE version are you using for this Authentication?&lt;/P&gt;
&lt;P&gt;is the redirection issue only with one device or is this a new setup or are all devices having the same issue?&lt;/P&gt;
&lt;P&gt;i also suggested checking directly access the portal is that works ?&lt;/P&gt;
&lt;P&gt;check some docs to help :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2022 06:48:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-switch-url-web-redirect-is-not-working/m-p/4706201#M577834</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-10-20T06:48:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco switch url web-redirect is not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-switch-url-web-redirect-is-not-working/m-p/4706261#M577837</link>
      <description>&lt;P&gt;I use ClearPass. All devices have same problem. I switch off dot1x and mab on the Switch, and the computers can connect to the portal.&lt;/P&gt;&lt;P&gt;I capture packet on the PC, ClearPass (Portal), Firewall. I see packet with SYN, SYN,ACK, between PC ip address and Portal ip address on the PC, but I don't see this packet on the Firewall and the&amp;nbsp; Clerpass.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Connection look like there:&lt;BR /&gt;&amp;nbsp;PC &amp;gt; Switch &amp;gt; Firewall &amp;gt; ClearPass.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2022 08:35:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-switch-url-web-redirect-is-not-working/m-p/4706261#M577837</guid>
      <dc:creator>Almas</dc:creator>
      <dc:date>2022-10-20T08:35:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco switch url web-redirect is not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-switch-url-web-redirect-is-not-working/m-p/4706921#M577867</link>
      <description>&lt;UL&gt;
&lt;LI&gt;What is the exact model of the switch captured from 'show inventory'?&lt;/LI&gt;
&lt;LI&gt;What IOS version is it running?&lt;/LI&gt;
&lt;LI&gt;What does your redirect ACL look like?&lt;/LI&gt;
&lt;LI&gt;What does your interface configuration look like? Do you have an ACL applied to the switchport?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;You might try sending an downloadable ACL that allows all traffic along with your redirect ACL to see if that makes a difference. If it does, you can modify the DACL to permit just the required traffic (usually the reverse of the redirect ACL).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2022 21:34:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-switch-url-web-redirect-is-not-working/m-p/4706921#M577867</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2022-10-20T21:34:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco switch url web-redirect is not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-switch-url-web-redirect-is-not-working/m-p/4707014#M577869</link>
      <description>&lt;P&gt;I have next model of the switch:&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;show inventory &lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;NAME: "1", DESCR: "WS-C2960L-48PS-LL"&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;Next IOS version:&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;Model&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;SW Version&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; SW Image &lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;&amp;nbsp;-----&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;----- ----------&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;---------- &lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;WS-C2960L-48PS-LL&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 15.2(7)E4&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; C2960L-UNIVERSALK9-M&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;ACL:&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;ip access-list extended Captive_Portal_Redirect&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;deny icmp any any&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;deny udp any eq bootpc any eq bootps&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;deny udp any any eq domain&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;permit tcp any any eq www&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;permit tcp any any eq 443&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT size="3"&gt;Interface configuration:&lt;/FONT&gt;&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;interface GigabitEthernet0/4&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;switchport access vlan 334&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;switchport mode access&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;switchport voice vlan 12&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;ip arp inspection trust&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;logging event trunk-status&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;logging event spanning-tree&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;logging event status&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;authentication event fail action next-method&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;authentication event server alive action reinitialize &lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;authentication host-mode multi-domain&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;authentication order dot1x mab&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;authentication priority dot1x mab&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;authentication port-control auto&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;authentication periodic&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;authentication timer reauthenticate server&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;authentication violation restrict&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;mab&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;dot1x pae authenticator&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;dot1x timeout tx-period 3&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;arp log threshold entries 2048&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;spanning-tree portfast edge&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;end&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="3"&gt;I sent an downloadable ACL that allows all traffic along with my redirect ACL, but i didn't see difference.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Oct 2022 04:06:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-switch-url-web-redirect-is-not-working/m-p/4707014#M577869</guid>
      <dc:creator>Almas</dc:creator>
      <dc:date>2022-10-21T04:06:28Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco switch url web-redirect is not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-switch-url-web-redirect-is-not-working/m-p/4719993#M578194</link>
      <description>&lt;P&gt;Are you sure that ClearPass supports a downloadable ACL to Cisco switches? Downloadable ACLs are not a RADIUS standard feature.&lt;/P&gt;
&lt;P&gt;You might need to use pre-configured ACLs and send the ACL name only.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Nov 2022 22:48:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-switch-url-web-redirect-is-not-working/m-p/4719993#M578194</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2022-11-11T22:48:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco switch url web-redirect is not working</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-switch-url-web-redirect-is-not-working/m-p/4719996#M578195</link>
      <description>&lt;P&gt;We tried a Pilot with ClearPass at one site before deciding to stay with Cisco ISE.&amp;nbsp; ClearPass could not send downloadable ACLs (at that time) to switches.&amp;nbsp; It could send roles, radius ACLS as attributes, but could not handle downloadable ACLs for Cisco switches.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Nov 2022 23:03:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-switch-url-web-redirect-is-not-working/m-p/4719996#M578195</guid>
      <dc:creator>davidgfriedman</dc:creator>
      <dc:date>2022-11-11T23:03:47Z</dc:date>
    </item>
  </channel>
</rss>

