<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Auth VLAN, URL Redirect and DNS Sinkhole... in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/auth-vlan-url-redirect-and-dns-sinkhole/m-p/5239805#M593927</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/146869"&gt;@rezaalikhani&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;All similar implementation I can see, uses CoA. Does you device support CoA. &lt;/P&gt;
&lt;P&gt;&amp;nbsp; &lt;A href="https://www.linkedin.com/pulse/cisco-ise-dns-sinkhole-functionality-smart-way-support-alikhani/" target="_blank"&gt;https://www.linkedin.com/pulse/cisco-ise-dns-sinkhole-functionality-smart-way-support-alikhani/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 22 Dec 2024 12:29:29 GMT</pubDate>
    <dc:creator>Flavio Miranda</dc:creator>
    <dc:date>2024-12-22T12:29:29Z</dc:date>
    <item>
      <title>Auth VLAN, URL Redirect and DNS Sinkhole...</title>
      <link>https://community.cisco.com/t5/network-access-control/auth-vlan-url-redirect-and-dns-sinkhole/m-p/5239788#M593926</link>
      <description>&lt;P&gt;Hi all;&lt;/P&gt;&lt;P&gt;I use Ubiquiti access points in my network and want to implement Guest Services (Central Web Authentication). As far as I know, this type of devices does not support &lt;STRONG&gt;RADIUS URL Redirection&lt;/STRONG&gt; from ISE. Therefore, I decided to circumvent this limitation using &lt;STRONG&gt;DNS Sinkhole&lt;/STRONG&gt; functionality in ISE. As you can see in the following figures, the endpoint (after connecting to the appropriate SSID), receives required IP Address and DNS info correctly (I have added a second interface to ISE with IP address of &lt;STRONG&gt;&lt;EM&gt;172.16.10.120&lt;/EM&gt;&lt;/STRONG&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="1000.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/236407i169D8933040772F6/image-size/large?v=v2&amp;amp;px=999" role="button" title="1000.png" alt="1000.png" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="1000.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/236408i44C7762A44085B64/image-size/large?v=v2&amp;amp;px=999" role="button" title="1000.png" alt="1000.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;After successfully acquiring the required DHCP information from ISE, the client opens the following browser window:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="1000.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/236409iC11530F7D6E8D669/image-size/large?v=v2&amp;amp;px=999" role="button" title="1000.png" alt="1000.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;As you can see above, the redirection process times out.&amp;nbsp;&lt;SPAN&gt;The following figures show the Wireshark capture of the process:&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="1000.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/236405iFB5362D908B67E9F/image-size/large?v=v2&amp;amp;px=999" role="button" title="1000.png" alt="1000.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="2000.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/236406i5BA38A0CDEDC9E1C/image-size/large?v=v2&amp;amp;px=999" role="button" title="2000.png" alt="2000.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Dec 2024 10:53:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/auth-vlan-url-redirect-and-dns-sinkhole/m-p/5239788#M593926</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2024-12-22T10:53:49Z</dc:date>
    </item>
    <item>
      <title>Re: Auth VLAN, URL Redirect and DNS Sinkhole...</title>
      <link>https://community.cisco.com/t5/network-access-control/auth-vlan-url-redirect-and-dns-sinkhole/m-p/5239805#M593927</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/146869"&gt;@rezaalikhani&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;All similar implementation I can see, uses CoA. Does you device support CoA. &lt;/P&gt;
&lt;P&gt;&amp;nbsp; &lt;A href="https://www.linkedin.com/pulse/cisco-ise-dns-sinkhole-functionality-smart-way-support-alikhani/" target="_blank"&gt;https://www.linkedin.com/pulse/cisco-ise-dns-sinkhole-functionality-smart-way-support-alikhani/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Dec 2024 12:29:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/auth-vlan-url-redirect-and-dns-sinkhole/m-p/5239805#M593927</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2024-12-22T12:29:29Z</dc:date>
    </item>
    <item>
      <title>Re: Auth VLAN, URL Redirect and DNS Sinkhole...</title>
      <link>https://community.cisco.com/t5/network-access-control/auth-vlan-url-redirect-and-dns-sinkhole/m-p/5239808#M593928</link>
      <description>&lt;P&gt;Thanks for your reply;&lt;/P&gt;&lt;P&gt;Yes, it does...&lt;/P&gt;&lt;P&gt;I want to know that, if I have several portals published in the dedicated interface, how ISE determines which to offer to the endpoint?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 22 Dec 2024 13:52:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/auth-vlan-url-redirect-and-dns-sinkhole/m-p/5239808#M593928</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2024-12-22T13:52:06Z</dc:date>
    </item>
    <item>
      <title>Re: Auth VLAN, URL Redirect and DNS Sinkhole...</title>
      <link>https://community.cisco.com/t5/network-access-control/auth-vlan-url-redirect-and-dns-sinkhole/m-p/5239815#M593929</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/146869"&gt;@rezaalikhani&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Similar question address here&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/multiple-different-guest-portals-for-same-fqdn-and-port/td-p/4391499" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/multiple-different-guest-portals-for-same-fqdn-and-port/td-p/4391499&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Dec 2024 14:29:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/auth-vlan-url-redirect-and-dns-sinkhole/m-p/5239815#M593929</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2024-12-22T14:29:53Z</dc:date>
    </item>
    <item>
      <title>Re: Auth VLAN, URL Redirect and DNS Sinkhole...</title>
      <link>https://community.cisco.com/t5/network-access-control/auth-vlan-url-redirect-and-dns-sinkhole/m-p/5239817#M593930</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply;&lt;/P&gt;&lt;P&gt;I do not think the provided link answers my question because based on my assumption we cannot specify any portals in the Authorization profile, because the target device does not support URL Redirection RADIUS attribute. Right?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Dec 2024 14:47:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/auth-vlan-url-redirect-and-dns-sinkhole/m-p/5239817#M593930</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2024-12-22T14:47:09Z</dc:date>
    </item>
    <item>
      <title>Re: Auth VLAN, URL Redirect and DNS Sinkhole...</title>
      <link>https://community.cisco.com/t5/network-access-control/auth-vlan-url-redirect-and-dns-sinkhole/m-p/5239824#M593931</link>
      <description>&lt;P&gt;Actually the post in question address you question related to support for multiples portal per interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Regarding your scenario, the first link have the answer as long as you can do CoA, which seems you are not doing as your attempt stop&amp;nbsp; in the 303 moved permanently.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Dec 2024 15:39:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/auth-vlan-url-redirect-and-dns-sinkhole/m-p/5239824#M593931</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2024-12-22T15:39:57Z</dc:date>
    </item>
  </channel>
</rss>

