<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE posture ACL in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-posture-acl/m-p/5315213#M597520</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158584"&gt;@Turki.A.Baqatada&lt;/a&gt;&amp;nbsp;the following screenshot from the Cisco guides, this is a good illustration of the configuration of the redirect ACL and the DACL.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RobIngram_0-1753784664569.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/249373i04AA8CE003BAF5B1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="RobIngram_0-1753784664569.png" alt="RobIngram_0-1753784664569.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/210523-ISE-posture-style-comparison-for-pre-and.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/210523-ISE-posture-style-comparison-for-pre-and.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Jul 2025 10:26:03 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2025-07-29T10:26:03Z</dc:date>
    <item>
      <title>ISE posture ACL</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-acl/m-p/5314572#M597479</link>
      <description>&lt;HR /&gt;&lt;HR /&gt;&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am configuring wired posture with web redirect and everything looks good even endpoints got the url acl but there is still access to cisco ise which i denied in url acl then i found also taking the default permit acl in the switch so when i denied ip any any fixed the ise access but still&amp;nbsp; no redirect happens and also pc not able to&amp;nbsp; get an ip&lt;/P&gt;&lt;P&gt;So my question do i have to add some lines in the default acl to permit some ports and hosts if so could you please mention that to fix web redirection&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 27 Jul 2025 18:28:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-acl/m-p/5314572#M597479</guid>
      <dc:creator>Turki.A.Baqatada</dc:creator>
      <dc:date>2025-07-27T18:28:43Z</dc:date>
    </item>
    <item>
      <title>Re: ISE posture ACL</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-acl/m-p/5314574#M597480</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158584"&gt;@Turki.A.Baqatada&lt;/a&gt; you use Redirection ACL for Client Provisioning , Central Web Authentication , and Posture Discovery and a DACL is used to limit Network Access to only the required resources and is applied only to non redirected Traffic.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/configuring-posture-services-with-the-cisco-identity-services/ta-p/3154278" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/configuring-posture-services-with-the-cisco-identity-services/ta-p/3154278&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 27 Jul 2025 18:40:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-acl/m-p/5314574#M597480</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-07-27T18:40:45Z</dc:date>
    </item>
    <item>
      <title>Re: ISE posture ACL</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-acl/m-p/5314575#M597481</link>
      <description>&lt;P&gt;Redirect ACL need to be&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Deny from and to ISE IP&lt;/P&gt;
&lt;P&gt;Permit IP any any in end&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sun, 27 Jul 2025 18:42:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-acl/m-p/5314575#M597481</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-07-27T18:42:14Z</dc:date>
    </item>
    <item>
      <title>Re: ISE posture ACL</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-acl/m-p/5314611#M597482</link>
      <description>&lt;P&gt;"no redirect happens and also pc not able to get an ip"&amp;nbsp;&lt;BR /&gt;you can not expect a redirect without an IP on PC, so fix DHCP issue first, then DNS (essential for redirect to work, unless you are using static IP for redirect URL), follow the ACL in link refereed by Rob&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jul 2025 02:28:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-acl/m-p/5314611#M597482</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2025-07-28T02:28:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE posture ACL</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-acl/m-p/5314638#M597485</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/325330"&gt;@Ambuj M&lt;/a&gt;&amp;nbsp;yes I know that and i am asking what is the best DACL that will fix issue becuse it is working with default ACL which permit any any and redirect happens i tried to fix it by deny and i got another which no ip assignment&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jul 2025 06:24:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-acl/m-p/5314638#M597485</guid>
      <dc:creator>Turki.A.Baqatada</dc:creator>
      <dc:date>2025-07-28T06:24:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE posture ACL</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-acl/m-p/5314640#M597486</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;I will try this &lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jul 2025 06:26:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-acl/m-p/5314640#M597486</guid>
      <dc:creator>Turki.A.Baqatada</dc:creator>
      <dc:date>2025-07-28T06:26:18Z</dc:date>
    </item>
    <item>
      <title>Re: ISE posture ACL</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-acl/m-p/5315092#M597512</link>
      <description>&lt;P&gt;Actually I have 2 ACLs needs to be configured&amp;nbsp;&lt;/P&gt;&lt;P&gt;1- ACL configured in the switch that allow access to ISE to authenticate&lt;/P&gt;&lt;P&gt;2- URL ACL which I deny access to ISE and permit 80 443&lt;/P&gt;&lt;P&gt;If thats right what should both ACLs contain lines&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jul 2025 06:34:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-acl/m-p/5315092#M597512</guid>
      <dc:creator>Turki.A.Baqatada</dc:creator>
      <dc:date>2025-07-29T06:34:08Z</dc:date>
    </item>
    <item>
      <title>Re: ISE posture ACL</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-acl/m-p/5315143#M597513</link>
      <description>&lt;P&gt;Most engineer confuse here&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are indeed two ACL&lt;/P&gt;
&lt;P&gt;Pre auth ACL.&lt;/P&gt;
&lt;P&gt;Allow traffic to dhcp/dns/https to &lt;STRONG&gt;ISE&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Redirect ACL (this not real acl' but it use to inform SW if you see this traffic redirect to ISE)&lt;/P&gt;
&lt;P&gt;Deny traffic to ISE&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Permit any any https/http&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jul 2025 08:32:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-acl/m-p/5315143#M597513</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-07-29T08:32:01Z</dc:date>
    </item>
    <item>
      <title>Re: ISE posture ACL</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-acl/m-p/5315213#M597520</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158584"&gt;@Turki.A.Baqatada&lt;/a&gt;&amp;nbsp;the following screenshot from the Cisco guides, this is a good illustration of the configuration of the redirect ACL and the DACL.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RobIngram_0-1753784664569.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/249373i04AA8CE003BAF5B1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="RobIngram_0-1753784664569.png" alt="RobIngram_0-1753784664569.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/210523-ISE-posture-style-comparison-for-pre-and.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/210523-ISE-posture-style-comparison-for-pre-and.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jul 2025 10:26:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-acl/m-p/5315213#M597520</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-07-29T10:26:03Z</dc:date>
    </item>
  </channel>
</rss>

