<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Web Redirect to captive portal for Cisco switch with Per-User-ACL (dACL) in ExtremeCloud IQ- Site Engine Management Center</title>
    <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/web-redirect-to-captive-portal-for-cisco-switch-with-per-user/m-p/90955#M9560</link>
    <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;I have a few questions based on your screenshots.&lt;BR /&gt;If you check the "Authorization" column in control what was actually sent for authorization? Did Control actually send the per-user ACL lines or did it send the custom2 and customer3 AVPs which is typically what we seen when using cisco.&lt;BR /&gt;&lt;BR /&gt;These custom2 and custom3 attributes use a web based redirect and not a PBR. You should only need one or the other, so if you're using the redirect ACL with URL redirect you don't need PBR to redirect as well. You won't need to redirect packets that have already been redirected to NAC URL.&lt;BR /&gt;&lt;BR /&gt;If you take a packet capture on a client in this state do you see the clients web packets get a 307 Temporary Redirect with the URL you configured?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Yes we have per-user-ACL capabilities with Cisco where we can send the ACL lines through RADIUS attributes, but you appear to not be using that by using the cisco-avipair=redirecturl attribute.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;-Ryan&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 16 May 2022 03:59:23 GMT</pubDate>
    <dc:creator>Ryan_Yacobucci</dc:creator>
    <dc:date>2022-05-16T03:59:23Z</dc:date>
    <item>
      <title>Web Redirect to captive portal for Cisco switch with Per-User-ACL (dACL)</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/web-redirect-to-captive-portal-for-cisco-switch-with-per-user/m-p/90954#M9559</link>
      <description>Hi, I'm adding a Cisco catalyst swicth 2960G with IOS version 15.0(2)SE11 to my lab environment with a x450-G2 and XIQ-SIte engine (complete of ExtremeControl engine).&lt;BR /&gt;I've defined the new switch in the NAC engine with the follow radius attributes:&lt;BR /&gt;
&lt;DIV class="media" style="overflow: hidden"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="uCORHrzSXe2w22LBG56g_Cisco_Radius_Attributes.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/5081i47FD6AF6584677BC/image-size/large?v=v2&amp;amp;px=999" role="button" title="uCORHrzSXe2w22LBG56g_Cisco_Radius_Attributes.png" alt="uCORHrzSXe2w22LBG56g_Cisco_Radius_Attributes.png" /&gt;&lt;/span&gt;And my Policy mapping for the role were user assume for the web authentication redirection is:&lt;BR /&gt;
&lt;DIV class="media" style="overflow: hidden"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="mhvKz6yjTkKyzY0NqRFN_Policy Mapping.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/3562i352953181555CE05/image-size/large?v=v2&amp;amp;px=999" role="button" title="mhvKz6yjTkKyzY0NqRFN_Policy Mapping.png" alt="mhvKz6yjTkKyzY0NqRFN_Policy Mapping.png" /&gt;&lt;/span&gt;&lt;BR /&gt;If I try to use the redirect method that use Policy Based Routing as I do for X450-G2, I've got and error that Cisco don't support CoS defined as I do in the redirect rule for EXOS:&lt;BR /&gt;
&lt;DIV class="media" style="overflow: hidden"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="Q7N3ASQWSWmNjGtALxeS_CoS.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/2524iB6A554D24BEB292C/image-size/large?v=v2&amp;amp;px=999" role="button" title="Q7N3ASQWSWmNjGtALxeS_CoS.png" alt="Q7N3ASQWSWmNjGtALxeS_CoS.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;
Another problem is that I need to define also ACL on the Redirect ACL on the Cisco switch because if I don't do the authentication fail.&lt;BR /&gt;
&lt;DIV class="media" style="overflow: hidden"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="ujnfHBZQAu6PhdrVUtc5_ACL_redirect.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/2667iB8BB15AC60CDAA9E/image-size/large?v=v2&amp;amp;px=999" role="button" title="ujnfHBZQAu6PhdrVUtc5_ACL_redirect.png" alt="ujnfHBZQAu6PhdrVUtc5_ACL_redirect.png" /&gt;&lt;/span&gt;&lt;BR /&gt;When the device is authenticated, is not redirected to the Extreme NAC captive portal (my ip in the lab is 192.168.30.35)&lt;/DIV&gt;
&lt;DIV class="media" style="overflow: hidden"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="S4j3IeIeS5yXYtZDMeNE_CIsco port Per-User-ACL.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/3876i60E0BB0FC147AF4A/image-size/large?v=v2&amp;amp;px=999" role="button" title="S4j3IeIeS5yXYtZDMeNE_CIsco port Per-User-ACL.png" alt="S4j3IeIeS5yXYtZDMeNE_CIsco port Per-User-ACL.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
How can i do Web Redirect using Per-User-ACL method?&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;&lt;BR /&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 13 May 2022 18:26:58 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/web-redirect-to-captive-portal-for-cisco-switch-with-per-user/m-p/90954#M9559</guid>
      <dc:creator>Antonio_Opromol</dc:creator>
      <dc:date>2022-05-13T18:26:58Z</dc:date>
    </item>
    <item>
      <title>Re: Web Redirect to captive portal for Cisco switch with Per-User-ACL (dACL)</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/web-redirect-to-captive-portal-for-cisco-switch-with-per-user/m-p/90955#M9560</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;I have a few questions based on your screenshots.&lt;BR /&gt;If you check the "Authorization" column in control what was actually sent for authorization? Did Control actually send the per-user ACL lines or did it send the custom2 and customer3 AVPs which is typically what we seen when using cisco.&lt;BR /&gt;&lt;BR /&gt;These custom2 and custom3 attributes use a web based redirect and not a PBR. You should only need one or the other, so if you're using the redirect ACL with URL redirect you don't need PBR to redirect as well. You won't need to redirect packets that have already been redirected to NAC URL.&lt;BR /&gt;&lt;BR /&gt;If you take a packet capture on a client in this state do you see the clients web packets get a 307 Temporary Redirect with the URL you configured?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Yes we have per-user-ACL capabilities with Cisco where we can send the ACL lines through RADIUS attributes, but you appear to not be using that by using the cisco-avipair=redirecturl attribute.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;-Ryan&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 May 2022 03:59:23 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/web-redirect-to-captive-portal-for-cisco-switch-with-per-user/m-p/90955#M9560</guid>
      <dc:creator>Ryan_Yacobucci</dc:creator>
      <dc:date>2022-05-16T03:59:23Z</dc:date>
    </item>
    <item>
      <title>Re: Web Redirect to captive portal for Cisco switch with Per-User-ACL (dACL)</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/web-redirect-to-captive-portal-for-cisco-switch-with-per-user/m-p/90956#M9561</link>
      <description>&lt;P&gt;Hi Ryan,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;my intention is to use only Per-user-ACL with Cisco in my configuration, so if Custom2 and Custom3 attributes are not necessary with this method, I remove these from my configuration, but in this case I don’t know how to redirect my guest user to the NAC porta using only the Policy Roles and&amp;nbsp; services associated to my Redirect Role Profile (I’m using PBR only for the Extreme’s switches and I use the CoS in the http rule in the Policy Domain associated to these switches only).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have and example on how use dACL with web redirect?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Antonio&lt;/P&gt;</description>
      <pubDate>Mon, 16 May 2022 12:33:03 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/web-redirect-to-captive-portal-for-cisco-switch-with-per-user/m-p/90956#M9561</guid>
      <dc:creator>Antonio_Opromol</dc:creator>
      <dc:date>2022-05-16T12:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: Web Redirect to captive portal for Cisco switch with Per-User-ACL (dACL)</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/web-redirect-to-captive-portal-for-cisco-switch-with-per-user/m-p/90957#M9562</link>
      <description>I Ryan,&lt;BR /&gt;&lt;BR /&gt;now web redirection with Per-User-ACL works in my lab.&lt;BR /&gt;My access ports are configured as:&lt;BR /&gt;&lt;STRONG&gt;interface GigabitEthernet0/x&lt;BR /&gt;switchport access vlan 10&lt;BR /&gt;switchport mode access&lt;BR /&gt;&lt;/STRONG&gt;&lt;BR /&gt;and the uplink port between my cisco and x450-g2 is&amp;nbsp;&lt;BR /&gt;&lt;STRONG&gt;interface GigabitEthernet0/1&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;description "Uplink with X450-G2 port 16"&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;switchport trunk native vlan 10&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;switchport mode trunk&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;If I use the VLAN 10 in my policy mapping for the Policy Role, and all works well, in the sense that the web redirection works well, and also if I connect with a user with a policy role in where I set a different VLAN, this is correctly set in the port.&lt;BR /&gt;But If I use a different VLAN in the Policy role used for the web redirection (for example a different on-boarding vlan that is not the native VLAN defined in my trunk uplink interface) , the redirection on cisco switch in this case don't work.&lt;BR /&gt;Any ideas?&lt;BR /&gt;Thanks&lt;BR /&gt;</description>
      <pubDate>Thu, 26 May 2022 23:05:44 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/web-redirect-to-captive-portal-for-cisco-switch-with-per-user/m-p/90957#M9562</guid>
      <dc:creator>Antonio_Opromol</dc:creator>
      <dc:date>2022-05-26T23:05:44Z</dc:date>
    </item>
    <item>
      <title>Re: Web Redirect to captive portal for Cisco switch with Per-User-ACL (dACL)</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/web-redirect-to-captive-portal-for-cisco-switch-with-per-user/m-p/90958#M9563</link>
      <description>Solved.&lt;BR /&gt;The problem was my http server on cisco switch with no ip address on the non default vlan ...giving an IP the redirect works.</description>
      <pubDate>Wed, 01 Jun 2022 16:04:01 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/web-redirect-to-captive-portal-for-cisco-switch-with-per-user/m-p/90958#M9563</guid>
      <dc:creator>Antonio_Opromol</dc:creator>
      <dc:date>2022-06-01T16:04:01Z</dc:date>
    </item>
  </channel>
</rss>

