<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Portals in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-portals/m-p/4736342#M578757</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/415766"&gt;@KelvinT&lt;/a&gt;&amp;nbsp;If WLC is 9800, possibly&amp;nbsp;CSCvz93375, which affecting IOS-XE 17.6.1.&lt;/P&gt;</description>
    <pubDate>Sat, 10 Dec 2022 21:11:45 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2022-12-10T21:11:45Z</dc:date>
    <item>
      <title>ISE Portals</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-portals/m-p/4700790#M577671</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Before I start describing my issues can someone conform I can do the following.&lt;/P&gt;&lt;P&gt;I want to enable 2 Guest portals on ISE but host them on different interfaces.&amp;nbsp; So, for example, a sponsored portal for day to day visitors.&amp;nbsp; I want to enable that on G1 which I have assigned an IP address to and on any port, let's say 8999.&amp;nbsp; I then want to enable a second portal for trusted contractors on G2 and have them use the self registered portal.&amp;nbsp; So I put an IP address on G2 and use port 8888.&amp;nbsp; The ports are arbitrary.&amp;nbsp; I then create 2 SSIDs and point them to ISE.&amp;nbsp; Based on the Called-Station-ID I either send them to an authorization rule for the portal on G1 or the one on G2.&amp;nbsp; The users will be in the same subnet as the portal they should go to so no routing issues.&amp;nbsp; So is this a supported method?&amp;nbsp; I don't see why it wouldn't be.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Usually I can get one portal working.&amp;nbsp; Then as soon as I try to get the second one working I get all sorts of issues with redirection failing.&amp;nbsp; Not sure if this is a valid troubleshooting step but when I go the the ISE CLI and look for ports 8999 and 8888 with "show ports" I sometimes see them attached to the wrong IP address.&amp;nbsp; Sometimes I see the port attached to the Gig0 address.&amp;nbsp; What I also noticed is when I first boot up the ISE and try to connect to a previously working portal it fails.&amp;nbsp; If I then edit the portal and simply change its port it kicks into life.&lt;/P&gt;&lt;P&gt;The next issue I get is when I have a portal working I usually test with Windows and Android to start with.&amp;nbsp; This works.&amp;nbsp; However, when I try an iPhone or iPad redirection doesn't kick in.&amp;nbsp; I have found a few references to issues with ISE3.1 and the Apple mini-browser but I tried workarounds such as adding some script to the optional content 2 area of the portal or by selecting Captive Portal bypass in the global parameter map of my Cat9800.&amp;nbsp; Neither seem to work.&amp;nbsp; So considering most of my Guests will be unknown devices and a great many of them will be Apple of some sort I can't roll this out until I get a stable working portal on all types of clients.&lt;/P&gt;&lt;P&gt;Any help would be greatly appreciated, Kev.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Oct 2022 16:00:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-portals/m-p/4700790#M577671</guid>
      <dc:creator>KevinR99</dc:creator>
      <dc:date>2022-10-10T16:00:29Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Portals</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-portals/m-p/4703163#M577756</link>
      <description>&lt;P&gt;Hi Kev,&lt;/P&gt;
&lt;P&gt;By any chance, are you running the portal on a node that is also acting as the PAN? Or is this a dedicated PSN?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 05:39:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-portals/m-p/4703163#M577756</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2022-10-14T05:39:02Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Portals</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-portals/m-p/4703254#M577760</link>
      <description>&lt;P&gt;Arne&lt;/P&gt;&lt;P&gt;This is a standalone node I am testing on.&lt;/P&gt;&lt;P&gt;Thanks, Kev.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 09:23:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-portals/m-p/4703254#M577760</guid>
      <dc:creator>KevinR99</dc:creator>
      <dc:date>2022-10-14T09:23:19Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Portals</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-portals/m-p/4703280#M577762</link>
      <description>&lt;P&gt;ISE allows you to enable different interfaces that will be only used for guest users traffic.&lt;/P&gt;
&lt;P&gt;-The guest portal redirects to FQDN and configured port. Have you configured the FQDN per ip address on the ISE.&lt;/P&gt;
&lt;P&gt;For CWA using a particular interface, please refer this: &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-0/cli_ref_guide/b_ise_CLIReferenceGuide_20/Cisco_ISE_CLI_Commands_in_Configuration_Mode.html#wp5773065010" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-0/cli_ref_guide/b_ise_CLIReferenceGuide_20/Cisco_ISE_CLI_Commands_in_Configuration_Mode.html#wp5773065010&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You need to configure the ip host [host alias/fqdn] command on ISE and then restart the ISE service to set the interface for CWA.&lt;/P&gt;
&lt;P&gt;-Else try by replacing the FQDN with ip address in the browser while trying to access the portal.&lt;/P&gt;
&lt;P&gt;-Make sure to map the correct certificate on the portal as well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 10:08:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-portals/m-p/4703280#M577762</guid>
      <dc:creator>poongarg</dc:creator>
      <dc:date>2022-10-14T10:08:37Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Portals</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-portals/m-p/4703875#M577778</link>
      <description>&lt;P&gt;Poongarg&lt;/P&gt;&lt;P&gt;Thank you for your reply.&amp;nbsp; I have done all of the suggestions in your response.&amp;nbsp; The main issue is that the portal fails to respond frequently.&amp;nbsp; Usually on 1st boot but sometimes after changing portal settings.&amp;nbsp; When I put a wired device on the same subnet and try to connect to telnet to the portal on its port the ISE rejects the connection with a tcp reset.&amp;nbsp; All I need to do to get it to work is simply change the portal port and wait a few minutes.&lt;/P&gt;&lt;P&gt;The Apple issue I had has been resolved with a WLC upgrade but I can't find any bug related to the code I was using.&amp;nbsp; To be honest I'm not spending more time on that.&amp;nbsp; I have a working version with redirection happening correctly on all my devices apart from occasionally needing to change the portal port.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kev.&lt;/P&gt;</description>
      <pubDate>Sun, 16 Oct 2022 10:44:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-portals/m-p/4703875#M577778</guid>
      <dc:creator>KevinR99</dc:creator>
      <dc:date>2022-10-16T10:44:49Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Portals</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-portals/m-p/4735022#M578728</link>
      <description>&lt;P&gt;Hello Kev,&lt;/P&gt;
&lt;P&gt;Thanks for your post.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What version your WLC was on before the upgrade and what did you upgrade to that fixed it?&lt;/P&gt;
&lt;P&gt;Thanks again Kev.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Dec 2022 16:34:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-portals/m-p/4735022#M578728</guid>
      <dc:creator>KelvinT</dc:creator>
      <dc:date>2022-12-08T16:34:58Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Portals</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-portals/m-p/4736342#M578757</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/415766"&gt;@KelvinT&lt;/a&gt;&amp;nbsp;If WLC is 9800, possibly&amp;nbsp;CSCvz93375, which affecting IOS-XE 17.6.1.&lt;/P&gt;</description>
      <pubDate>Sat, 10 Dec 2022 21:11:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-portals/m-p/4736342#M578757</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2022-12-10T21:11:45Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Portals</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-portals/m-p/4736421#M578760</link>
      <description>&lt;P&gt;Thanks for that. &amp;nbsp;I was running 17.5.1 when I saw the problem and now run 17.7.1&lt;/P&gt;&lt;P&gt;That bug looks to be the problem.&lt;/P&gt;&lt;P&gt;I appreciate your input, Kev.&lt;/P&gt;</description>
      <pubDate>Sun, 11 Dec 2022 09:29:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-portals/m-p/4736421#M578760</guid>
      <dc:creator>KevinR99</dc:creator>
      <dc:date>2022-12-11T09:29:05Z</dc:date>
    </item>
  </channel>
</rss>

