<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Guest portal Redirection issue &amp;lt;&amp;gt; [ 404 ] Resource Not F in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-guest-portal-redirection-issue-lt-gt-404-resource-not-found/m-p/5546871#M600293</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1968077"&gt;@Ryan2K&lt;/a&gt;&amp;nbsp;try explicitly enter guest.domain.com into portal FQDN within ur specific guest portal settings so ise know excatly which page to serve &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 20 Apr 2026 19:02:35 GMT</pubDate>
    <dc:creator>Stefan Mihajlov</dc:creator>
    <dc:date>2026-04-20T19:02:35Z</dc:date>
    <item>
      <title>ISE Guest portal Redirection issue &lt;&gt; [ 404 ] Resource Not Found</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-portal-redirection-issue-lt-gt-404-resource-not-found/m-p/5545813#M600259</link>
      <description>&lt;P&gt;Hi everyone,&lt;BR /&gt;&lt;BR /&gt;Recently, I have made couple of changes to the customer's system certificates, Now&lt;/P&gt;&lt;P&gt;I’m starting to face an issue with the Sponsor/Guest portal redirection in Cisco ISE and would appreciate your input.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Observed Behavior:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;When accessing the portal directly (redirection is not working as expected):&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;A href="https://guest.domain.com:8443" target="_blank" rel="noopener"&gt;https://guest.domain.com:8443&lt;/A&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;No certificate warning is shown (the certificate appears valid)&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;However, the page returns: &lt;STRONG&gt;404 – Resource Not Found&lt;/STRONG&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Current Setup:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;No wildcard certificates are being used&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;The Admin certificate is signed by a private CA (not publicly trusted)&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;The Admin certificate does &lt;STRONG&gt;not&lt;/STRONG&gt; include the Guest portal FQDN in its SAN&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;The Guest portal certificate is signed by a public CA (DigiCert) and includes:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;guest.domain.com&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Issue:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;When accessing:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;A href="https://guest.domain.com&amp;nbsp;" target="_blank" rel="noopener"&gt;https://guest.domain.com&amp;nbsp;&lt;/A&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;The browser initially connects to the Admin interface (port 443)&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;The Admin certificate is presented&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Since this certificate is not publicly trusted and does not include the Guest FQDN in the SAN, the browser displays a certificate warning&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;This occurs before the redirect to the Guest portal&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Question:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Based on Cisco ISE design and best practices, is it required to:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Install a publicly trusted certificate on the Admin interface, and&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Include the Guest portal FQDN (e.g., guest.domain.com) in the Admin certificate SAN&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;even though a valid public certificate is already installed for the Guest portal?&lt;/P&gt;&lt;P&gt;Or is there an alternative design to avoid this initial certificate mismatch during redirection?&lt;/P&gt;&lt;P&gt;Additionally, I came across references to HSTS behaviour in this context but would appreciate clarification on how it impacts this scenario.&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;BR /&gt;&lt;BR /&gt;Ryan,&lt;/P&gt;</description>
      <pubDate>Thu, 16 Apr 2026 12:17:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-portal-redirection-issue-lt-gt-404-resource-not-found/m-p/5545813#M600259</guid>
      <dc:creator>Ryan2K</dc:creator>
      <dc:date>2026-04-16T12:17:37Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest portal Redirection issue &lt;&gt; [ 404 ] Resource Not F</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-portal-redirection-issue-lt-gt-404-resource-not-found/m-p/5546866#M600292</link>
      <description>&lt;P&gt;You should not attempt to manually connect to the URL. the 404 is expected as the portal redirect requires the generated URL sent in the authz.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You should troubleshoot why redirection is not working as expected.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2026 18:55:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-portal-redirection-issue-lt-gt-404-resource-not-found/m-p/5546866#M600292</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2026-04-20T18:55:15Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest portal Redirection issue &lt;&gt; [ 404 ] Resource Not F</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-portal-redirection-issue-lt-gt-404-resource-not-found/m-p/5546871#M600293</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1968077"&gt;@Ryan2K&lt;/a&gt;&amp;nbsp;try explicitly enter guest.domain.com into portal FQDN within ur specific guest portal settings so ise know excatly which page to serve &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2026 19:02:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-portal-redirection-issue-lt-gt-404-resource-not-found/m-p/5546871#M600293</guid>
      <dc:creator>Stefan Mihajlov</dc:creator>
      <dc:date>2026-04-20T19:02:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Guest portal Redirection issue &lt;&gt; [ 404 ] Resource Not F</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-portal-redirection-issue-lt-gt-404-resource-not-found/m-p/5548369#M600319</link>
      <description>&lt;P&gt;It is best to have a separate public cert for the guest portal instead of combining multiple functions into one cert, especially when using different issuing CAs.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;For the redirect ISE automatically adds in&amp;nbsp;&lt;STRONG&gt;/portal/PortalSetup.action?portal=&amp;lt;ID string&amp;gt;&amp;nbsp;&lt;/STRONG&gt;which needs to be included for it to function. If you try to hit the URL without the portal info either using standard HTTPS or 8443 you will see what you are experiencing, this is expected.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you want to test either try the process as a user would or from ISE go to Work Centers &amp;gt; Guest Access &amp;gt; Portals and Components and select your guest portal, from there there should be a Portal test URL link.&lt;/P&gt;&lt;P&gt;If you hadn't already after changing any certs on ISE nodes the ISE service should be restarted. If you redirect isn't working it might be something else in the config for the portal itself or in the guest redirect policy.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2026 15:16:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-portal-redirection-issue-lt-gt-404-resource-not-found/m-p/5548369#M600319</guid>
      <dc:creator>Ben Walters</dc:creator>
      <dc:date>2026-04-27T15:16:44Z</dc:date>
    </item>
  </channel>
</rss>

