11-26-2018 03:53 AM
Hi Team,
We have the ISE 2.3 deployed at one of our customer and we are seeing an inconsistent issue for the PC's posturing and web redirection wherein it works good for few guest PC's and shows issue as unable to reach policy server for remaining. The more details are given below and seek your expert guidance on this. Log files and captures are also available in the SR-685644334...
Problem Description:
==================
Action Taken:
-------------------
In ISE logs
--------------
Result
User-Name A4-4C-C8-18-6E-89
State ReauthSession:048E680A000011761D3726D4
Class CACS:048E680A000011761D3726D4:CTSNLAMSVISE3/328277493/4193253
cisco-av-pair url-redirect-acl=ACL_WEBAUTH_REDIRECT
cisco-av-pair url-redirect=https://10.142.105.8:8443/portal/gateway?sessionId=048E680A000011761D3726D4&portal=283258a0-e96e-11e4-a30a-005056bf01c9&action=cpp&token=d0bf677e2b27b39a1603a283a752c900
cisco-av-pair coa-skip-logical-profile=
Here is the posture log
-------------------------------
[Fri Nov 16 17:16:10.072 2018][-=unknown=-]Function: GetIseDiscoveryAttr Thread Id: 0x738 File: C:\temp\build\thehoff\Mera_fcs0.0760282695592\Mera_fcs\posture\ise\libnaccommon\ExtractName.cpp Line: 339 Level: info :ISE Discovery attributes - FQDN(CTSNLAMSVISE3.CTS.COM), Port(8443), Session ID(JL8li4FjSLaV0bYYD3OEmg)
[Fri Nov 16 17:16:10.103 2018][-=unknown=-]Function: hs_transport_winhttp_get Thread Id: 0x738 File: C:\temp\build\thehoff\Mera_fcs0.0760282695592\Mera_fcs\posture\ise\libhstransport\hs_transport_winhttp.c Line: 4808 Level: debug :unable to send request: 12007
11-26-2018 05:22 AM
What does your ACL_WEBAUTH_REDIRECT look like?
11-27-2018 12:58 AM
Here is the redirect ACL for validation...
ip access-list extended ACL_WEBAUTH_REDIRECT
deny udp any eq bootpc any eq bootps
deny udp any any eq domain
deny tcp any any eq domain
deny icmp any any
deny udp any host 10.142.105.8 eq 8443
deny tcp any host 10.142.105.8 eq 8443
deny tcp any any eq 8905
deny udp any any eq 8905
deny tcp any any eq 8909
deny udp any any eq 8909
permit ip any any
11-28-2018 06:57 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide