<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE guest redirect in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ise-guest-redirect/m-p/4644018#M1091568</link>
    <description>&lt;P&gt;Doing a quick search online I found this Mohammed, it is kinda talking about same behaviour:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://quickview.cloudapps.cisco.com/quickview/bug/CSCut16630" target="_blank"&gt;Cisco Bug: CSCut16630 - ISE : https to sponsor portal using Admin cert not sponsor cert&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 05 Jul 2022 11:42:32 GMT</pubDate>
    <dc:creator>Aref Alsouqi</dc:creator>
    <dc:date>2022-07-05T11:42:32Z</dc:date>
    <item>
      <title>ISE guest redirect</title>
      <link>https://community.cisco.com/t5/network-security/ise-guest-redirect/m-p/4643490#M1091545</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am implementing Guest wireless nw via Cisco ISE, wherein am utilizing the sponsor page registration for the Guest users.&lt;/P&gt;&lt;P&gt;Now my question is for the Portal certificate can i use an ip based certificate instead of Fqdn ? Since i do not want the fqdn to get resolved via our internal DNS server. Instead using an ip based certificate which gets redirected on Guests Users mobiles/Pcs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jul 2022 16:05:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-guest-redirect/m-p/4643490#M1091545</guid>
      <dc:creator>shaikh.zaid22</dc:creator>
      <dc:date>2022-07-04T16:05:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISE guest redirect</title>
      <link>https://community.cisco.com/t5/network-security/ise-guest-redirect/m-p/4643962#M1091560</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;You can use FQDN in the CN and IP address in SAN names. This way you are&lt;BR /&gt;covered.&lt;BR /&gt;&lt;BR /&gt;***** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Tue, 05 Jul 2022 09:43:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-guest-redirect/m-p/4643962#M1091560</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2022-07-05T09:43:31Z</dc:date>
    </item>
    <item>
      <title>Re: ISE guest redirect</title>
      <link>https://community.cisco.com/t5/network-security/ise-guest-redirect/m-p/4643964#M1091561</link>
      <description>&lt;P&gt;Thanks Mohammed for the reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DO you mean while generating the CSR. The fqdn will be under CN and ip address wil be under SAN ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 09:49:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-guest-redirect/m-p/4643964#M1091561</guid>
      <dc:creator>shaikh.zaid22</dc:creator>
      <dc:date>2022-07-05T09:49:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE guest redirect</title>
      <link>https://community.cisco.com/t5/network-security/ise-guest-redirect/m-p/4643976#M1091562</link>
      <description>Yes that is correct.&lt;BR /&gt;&lt;BR /&gt;**** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Tue, 05 Jul 2022 10:27:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-guest-redirect/m-p/4643976#M1091562</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2022-07-05T10:27:31Z</dc:date>
    </item>
    <item>
      <title>Re: ISE guest redirect</title>
      <link>https://community.cisco.com/t5/network-security/ise-guest-redirect/m-p/4643996#M1091563</link>
      <description>&lt;P&gt;One thing important to keep in mind when it comes to the sponsor portal is that there is a redirection that would happen in the background to the admin portal before the session is redirected to the sponsor portal. Essentially, you will be presented by two certificates, the first will be the admin certificate, and the second will be the sponsor portal certificate. This means that the sponsor portal FQDN and the IP address details should be added to the admin certificate, as well as to the sponsor portal certificate.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 11:11:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-guest-redirect/m-p/4643996#M1091563</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-07-05T11:11:47Z</dc:date>
    </item>
    <item>
      <title>Re: ISE guest redirect</title>
      <link>https://community.cisco.com/t5/network-security/ise-guest-redirect/m-p/4644001#M1091565</link>
      <description>Hi Aref,&lt;BR /&gt;&lt;BR /&gt;I don't think this is needed if you hit the sponsor portal directly. I will&lt;BR /&gt;be grateful, if you can share a doc for this as it's new to me.&lt;BR /&gt;&lt;BR /&gt;**** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Tue, 05 Jul 2022 11:22:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-guest-redirect/m-p/4644001#M1091565</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2022-07-05T11:22:31Z</dc:date>
    </item>
    <item>
      <title>Re: ISE guest redirect</title>
      <link>https://community.cisco.com/t5/network-security/ise-guest-redirect/m-p/4644010#M1091566</link>
      <description>&lt;P&gt;Hi Mohammed, unfortunately I don't have any Cisco doc at handy on this, but I ran into this issue personally before I learned this behaviour and I could prove it by doing the sessions inspections where I could actually see the admin certificate presented before the sponsor portal certificate is presented.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 11:38:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-guest-redirect/m-p/4644010#M1091566</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-07-05T11:38:00Z</dc:date>
    </item>
    <item>
      <title>Re: ISE guest redirect</title>
      <link>https://community.cisco.com/t5/network-security/ise-guest-redirect/m-p/4644018#M1091568</link>
      <description>&lt;P&gt;Doing a quick search online I found this Mohammed, it is kinda talking about same behaviour:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://quickview.cloudapps.cisco.com/quickview/bug/CSCut16630" target="_blank"&gt;Cisco Bug: CSCut16630 - ISE : https to sponsor portal using Admin cert not sponsor cert&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 11:42:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-guest-redirect/m-p/4644018#M1091568</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-07-05T11:42:32Z</dc:date>
    </item>
    <item>
      <title>Re: ISE guest redirect</title>
      <link>https://community.cisco.com/t5/network-security/ise-guest-redirect/m-p/4646558#M1091722</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;at last we solved the redirect issue, by configuring a DNS doctoring( Translate DNS replies in AUTO NAT in FTD).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This way we published the fqdn with a public ip on public dns and internally via Auto Nat and ACL we controlled the traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hence the guest resolves the fqdn through public dns and when the traffic comes back to the FTD fw, Auto Nat transplate the DNS replies to the ISE guest ip add.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jul 2022 10:55:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-guest-redirect/m-p/4646558#M1091722</guid>
      <dc:creator>shaikh.zaid22</dc:creator>
      <dc:date>2022-07-08T10:55:04Z</dc:date>
    </item>
  </channel>
</rss>

