<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE Posture Redirection - HTTP &amp;amp;amp; HTTPS on NAD device in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-redirection-http-amp-amp-https-on-nad-device/m-p/4948871#M584868</link>
    <description>&lt;P&gt;On IOS-XE devices that don't require access to the web UI, it is recommended to use the following commands to prevent access to the web UI while still allowing the ISE redirect use cases:&lt;/P&gt;
&lt;PRE class="lia-indent-padding-left-30px"&gt;ip http active-session-modules none&lt;BR /&gt;ip http secure-active-session-modules none&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 26 Oct 2023 12:58:17 GMT</pubDate>
    <dc:creator>Charlie Moreton</dc:creator>
    <dc:date>2023-10-26T12:58:17Z</dc:date>
    <item>
      <title>Cisco ISE Posture Redirection - HTTP &amp;amp; HTTPS on NAD device.</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-redirection-http-amp-amp-https-on-nad-device/m-p/4948418#M584865</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are having ISE 2.7 patch 9 and it is used for for endpoint posturing. For unknown clients posture reduction we have enabled the http and https redirection on cisco NAD switches.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But now we have reported http and https vulnerability from our SOC team and to disable the same.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please suggest if there is any alternative way for redirection without enabling http &amp;amp; https on NAD switches or else if there is any way to use http &amp;amp; https without any impacting.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2023 07:10:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-redirection-http-amp-amp-https-on-nad-device/m-p/4948418#M584865</guid>
      <dc:creator>wavarevivek1</dc:creator>
      <dc:date>2023-10-26T07:10:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Posture Redirection - HTTP &amp;amp; HTTPS on NAD device</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-redirection-http-amp-amp-https-on-nad-device/m-p/4948420#M584866</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1621738"&gt;@wavarevivek1&lt;/a&gt; there are redirectionless posture options, you'd need to predeploy the call home server list to the clients:-&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/210523-ISE-posture-style-comparison-for-pre-and.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/210523-ISE-posture-style-comparison-for-pre-and.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/policy-access-management/220394-implementing-ise-redirectionless-posture.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/policy-access-management/220394-implementing-ise-redirectionless-posture.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2023 07:16:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-redirection-http-amp-amp-https-on-nad-device/m-p/4948420#M584866</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-10-26T07:16:45Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Posture Redirection - HTTP &amp;amp; HTTPS on NAD device</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-redirection-http-amp-amp-https-on-nad-device/m-p/4948871#M584868</link>
      <description>&lt;P&gt;On IOS-XE devices that don't require access to the web UI, it is recommended to use the following commands to prevent access to the web UI while still allowing the ISE redirect use cases:&lt;/P&gt;
&lt;PRE class="lia-indent-padding-left-30px"&gt;ip http active-session-modules none&lt;BR /&gt;ip http secure-active-session-modules none&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2023 12:58:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-redirection-http-amp-amp-https-on-nad-device/m-p/4948871#M584868</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2023-10-26T12:58:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Posture Redirection - HTTP &amp;amp; HTTPS on NAD device</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-redirection-http-amp-amp-https-on-nad-device/m-p/4954641#M585033</link>
      <description>&lt;P&gt;The recommendation provided by &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/317086"&gt;@Charlie Moreton&lt;/a&gt; is documented in &lt;A href="https://www.cisco.com/c/en/us/support/docs/ios-nx-os-software/ios-xe-17/221144-cisco-tac-technical-faqs-for-cisco-ios-x.html" target="_self"&gt;Cisco TAC Technical FAQs for Cisco IOS XE Software Web UI Privilege Escalation Vulnerability - CVE-2023-20198&lt;/A&gt; &amp;gt; &lt;A href="https://www.cisco.com/c/en/us/support/docs/ios-nx-os-software/ios-xe-17/221144-cisco-tac-technical-faqs-for-cisco-ios-x.html#toc-hId-1498375900" target="_blank"&gt;3. I am using Identity Services Engine (ISE) redirect use cases and can't disable the http/https servers. What can I do?&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2023 00:42:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-redirection-http-amp-amp-https-on-nad-device/m-p/4954641#M585033</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2023-11-07T00:42:07Z</dc:date>
    </item>
  </channel>
</rss>

