Central Web Authentication on Cisco ISE
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-23-2023 04:33 AM
Hi All,
We have a Cisco ISE 3.1 VM, and we aim to enable guest centralized access using a self-sponsored site. In the Work Center Authorization Profile, there is a requirement for web redirection in both wired and wireless ACLs. Could you please guide me on creating an ACL that incorporates web redirection?
- Labels:
-
Identity Services Engine (ISE)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-23-2023 08:37 AM - edited 11-23-2023 08:41 AM
That is the redirect ACL that should be applied to the wired NADs as well as the WLC. Usually we deny (bypass) the traffic destined to ISE PSNs, specifically on port 8443/tcp (if it hasn't changed from its default), DNS, DHCP (I think it wouldn't be required though), and then we allow (redirect) web traffic on port 80. The name of the ACL in the authorization profile must match the name of the ACL created on the network devices. Take a look at this link please to get a better idea of how the ACL would look like:
