01-28-2021 11:27 PM
Hi Experts,
Setup:
ISE 2.7, single node as off now, in the process of migration.
Posture setup, ACL are configured on switch and DACL are pushed from ISE
Issue:
When using mixed stack of switches of model 3750V2 (IOS 12.2) and 3750X (IOS 15.0) models, redirection does not work and endpoint remains stuck in no policy server detected.
While if all the lines from DACL are removed and only one line wiht, permit ip any any is added, then the posture works.
The same flow works using standalong switches.
Any ideas what is missing?
Or is the mixed stack switches is something not support with ISE 2.7? Since its working a setup in production with ISE 2.2.
01-29-2021 02:56 AM
Ca you post the configuration of these device to understand the issue, also check the matrix and support some help :
https://www.cisco.com/c/en/us/support/docs/lan-switching/8021x/119374-technote-dacl-00.html#anc6
01-29-2021 03:33 AM
Hi @dgaikwad ,
if my understanding is correct, you are using a different Stack Switch for your test ... please use the command bellow to check who have the Master role:
show switch
Note: for reference ... Creation and Management of 3750 Stacks.
Hope this helps.
01-31-2021 03:25 PM
You are missing any Details for Reproducibility.
See the ISE Secure Wired Access Prescriptive Deployment Guide's section Web Authentication/URL Redirection and ACLs for the discussion about how they work.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: