<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE URL redirection not work when the gateway for the vlan is on f in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-url-redirection-not-work-when-the-gateway-for-the-vlan-is-on/m-p/5151724#M590871</link>
    <description>&lt;P&gt;yes, for the NGFW, we need to disable the tcp syn check&amp;nbsp; of source zone, then the&amp;nbsp;&lt;SPAN&gt;one-way traffic can through the NGFW.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Hevin27_0-1721982375786.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/224559iA61FFC6835A67C21/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Hevin27_0-1721982375786.png" alt="Hevin27_0-1721982375786.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 26 Jul 2024 08:26:47 GMT</pubDate>
    <dc:creator>Hevin27</dc:creator>
    <dc:date>2024-07-26T08:26:47Z</dc:date>
    <item>
      <title>ISE URL redirection not work when the gateway for the vlan is on firew</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-url-redirection-not-work-when-the-gateway-for-the-vlan-is-on/m-p/5143472#M590554</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;I'm new to ISE and recently we are deploying ISE to production to authenticate users. The issue currently encountered is guest self-registration. For security reasons, the network where the guest is located is a separate area on the firewall, when a guest accesses the network, ISE will deliver a redirect URL for the visitor to self-register. ISE is able to deliver the redirect URL and call the ACL to the interface, but the client does not automatically pop up the browser and redirect to the self-registration page, and redirects cannot be triggered by manual access a website either, but copying the redirect URL delivered by ISE to the switch interface to the client is accessible .(There is a policy on the firewall to allow the switch to manage the IP to the guest network.). I checked the forums and found that the firewall might be blocking the one-way traffic from spoofed IP to client VLAN. With the same configuration, if I modify the vlan-id delivered by ISE to the SVI which is on the core switch, it is no problem at all. So I believe it's the firewall that implicitly blocks this traffic. Has anyone ever been in this situation? How should it be resolved?&lt;/P&gt;&lt;P&gt;1. I enabled a guest SVI on the authentication switch as suggested on the forum and it works.&lt;BR /&gt;2. Someone suggested enabling redirects for L2, but I don't know how to do it and don't know if it works.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2024 10:21:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-url-redirection-not-work-when-the-gateway-for-the-vlan-is-on/m-p/5143472#M590554</guid>
      <dc:creator>Hevin27</dc:creator>
      <dc:date>2024-07-11T10:21:23Z</dc:date>
    </item>
    <item>
      <title>Re: ISE URL redirection not work when the gateway for the vlan is on f</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-url-redirection-not-work-when-the-gateway-for-the-vlan-is-on/m-p/5143528#M590560</link>
      <description>&lt;P&gt;FW must have policy allow guest IP to access ise url&lt;/P&gt;
&lt;P&gt;If you add this policy and not work' then check if url redirect is use IP or hostname' if it use hostname then check dns from guest by using dns lookup.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2024 12:13:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-url-redirection-not-work-when-the-gateway-for-the-vlan-is-on/m-p/5143528#M590560</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-07-11T12:13:06Z</dc:date>
    </item>
    <item>
      <title>Re: ISE URL redirection not work when the gateway for the vlan is on f</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-url-redirection-not-work-when-the-gateway-for-the-vlan-is-on/m-p/5150778#M590844</link>
      <description>&lt;P&gt;In fact, we found that the underlying situation is that stateful firewalls drop traffic that is modified. In the case of a stateful firewall, he sees a one-way traffic that is dropped even if a policy is established.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 07:53:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-url-redirection-not-work-when-the-gateway-for-the-vlan-is-on/m-p/5150778#M590844</guid>
      <dc:creator>Hevin27</dc:creator>
      <dc:date>2024-07-25T07:53:07Z</dc:date>
    </item>
    <item>
      <title>Re: ISE URL redirection not work when the gateway for the vlan is on f</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-url-redirection-not-work-when-the-gateway-for-the-vlan-is-on/m-p/5151108#M590849</link>
      <description>&lt;P&gt;so this issue is solved ?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 13:47:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-url-redirection-not-work-when-the-gateway-for-the-vlan-is-on/m-p/5151108#M590849</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-07-25T13:47:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE URL redirection not work when the gateway for the vlan is on f</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-url-redirection-not-work-when-the-gateway-for-the-vlan-is-on/m-p/5151724#M590871</link>
      <description>&lt;P&gt;yes, for the NGFW, we need to disable the tcp syn check&amp;nbsp; of source zone, then the&amp;nbsp;&lt;SPAN&gt;one-way traffic can through the NGFW.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Hevin27_0-1721982375786.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/224559iA61FFC6835A67C21/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Hevin27_0-1721982375786.png" alt="Hevin27_0-1721982375786.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jul 2024 08:26:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-url-redirection-not-work-when-the-gateway-for-the-vlan-is-on/m-p/5151724#M590871</guid>
      <dc:creator>Hevin27</dc:creator>
      <dc:date>2024-07-26T08:26:47Z</dc:date>
    </item>
  </channel>
</rss>

