03-20-2020 07:19 AM
Setup is ISE 2.6.0.156
Switch 2960 Lanbase IOS 15.0(2)SE11
Windows 10
AnyConnect version 4.7.04056
While testing I saw that there are two different redirection URLs being pushed, I see the same thing in live logs and on the authentication session that is applied for the endpoint.
Is this something that is new or am I missing some configuration here.
The policy set at this time is pretty simple, posture status = unknown, redirect to CPP
With the ACL on switch as follows:
Solved! Go to Solution.
03-20-2020 11:59 PM
Hi,
I've seen this happening couple of times, it was always an ISE bug, for example, see attached. Apply the latest patch and if behaviour is still there, upgrade to a newer recommended release, like ISE 2.6.0 patch 5.
Regards,
Cristian Matei.
03-20-2020 11:37 AM
I personally have not seen this behavior before and I have done countless ISE deployments. I am curious if it is actually sending both URL's in the Radius Access-Accept or if it is just a cosmetic bug in the GUI. Can you do a tcpdump on the PSN and take a look at the Radius packets? But either way, this looks like a bug. I would recommend opening a TAC case.
03-20-2020 11:59 PM
Hi,
I've seen this happening couple of times, it was always an ISE bug, for example, see attached. Apply the latest patch and if behaviour is still there, upgrade to a newer recommended release, like ISE 2.6.0 patch 5.
Regards,
Cristian Matei.
03-23-2020 01:24 PM
CSCvp77017 is duplicate to CSCvj05563, which addressed in ISE 2.6 Patch 1.
04-01-2020 10:50 AM
WIll have to work with the customer on this and post an update once its done.
Thanks for the pointer.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide