cancel
Showing results for 
Search instead for 
Did you mean: 

Redirect @ AP NAC enforce deleting rules

Redirect @ AP NAC enforce deleting rules

Anonymous
Not applicable
Hi,

Currently running Extreme Control version 8.1.2.59 and Extreme Wireless (identiFi) 10.41.02.0014.

I'm in the process of configuring redirection at the AP which works with the following rules:

0532182da2de47afb70945af65593bed_RackMultipart20180620-46089-k37sit-RackMultipart20170922-101466-1s2xkw8-Rule_inline.png



Which I entered in the wireless controller first and then did an import from the wireless device into NAC. The rules in the NAC now look like the following:

0532182da2de47afb70945af65593bed_RackMultipart20180620-27871-ba1zre-NAC-Redirect2_inline.png



When I then do an enforce back to the EWC it wipes out the redirect rules and now looks like the following (ignore the change in IP's for a moment, just a couple of different shots from different systems, but the results are the same):

0532182da2de47afb70945af65593bed_RackMultipart20180620-11328-way5bt-NAC-Redirect3_inline.png



I notice in the NAC rule configuration an option for HTTP Redirect, perhaps I have to configure the redirect rules using this form, which will successfully write the redirect rules back to the EWC on enforce?

0532182da2de47afb70945af65593bed_RackMultipart20180620-71205-12ym40n-NAC-Redirect1_inline.png



Thought that maybe the values in the 'Listen Sockets' might be 80,8080,443

0532182da2de47afb70945af65593bed_RackMultipart20180620-26573-omuyx6-NAC-Redirect4_inline.png



But whenever I 'OK' it the 'HTTP redirect' option comes back 'Disabled':

0532182da2de47afb70945af65593bed_RackMultipart20180620-54778-qq6jeo-NAC-Redirect5_inline.png



I'm probably driving this completely wrong, but would appreciate any advise.

Many thanks in advance.
4 REPLIES 4

Anonymous
Not applicable
Hi Tyler,

No problem.

Not sure what happened but I did post a large reply with lots more screenshots, as I managed to work it out in the end.

But you are correct, that's exactly what I missed, and it all worked as expected after that.

Thanks for replying anyway.

Cheers,

Martin

TylerMarcotte
Extreme Employee
Hi Martin,

Sorry, I missed a part of your screenshot when I first read it. After you define the sockets to listen on in the redirect config, you need to add a Redirect Group that is your redirect URL. If you are redirecting to NAC there should already be pre-configured ones available in the drop down. If you're using something else then you can list the URL. Just be sure to include the port number (:80 or :443) in the URL.



See if that gets you a bit further. I think that's the piece you're missing though.

Tyler

Anonymous
Not applicable
Hi Tyler,

Thanks for replying. So had a bit more of a play around and it does remain disabled, and when you go into the 'Listen Sockets' is still there, but I can't see anything anywhere that says 'HTTP Redirect 1'?

a917898d333b4e4aac34c419c8d6c323_RackMultipart20180620-52931-d4i0gc-NAC-Redirect9_inline.png



I did change the rule to permit and set the rule type to 'Wireless Controller', and then when I did an enforce it looked like the redirect are there:

a917898d333b4e4aac34c419c8d6c323_RackMultipart20180620-49486-1gtd2xy-NAC-Redirect6_inline.png



Now the rules on the wireless controller look like the following:

a917898d333b4e4aac34c419c8d6c323_RackMultipart20180620-97729-qesci3-NAC-Redirect7_inline.png


So as you can see the rules for ports 80, 8080 and 443 are not showing up as redirect.

Here is the example https (443) rule that I configured:

a917898d333b4e4aac34c419c8d6c323_RackMultipart20180620-119316-6bg2v5-NAC-Redirect8_inline.png



a917898d333b4e4aac34c419c8d6c323_RackMultipart20180620-76164-9m2aku-NAC-Redirect11_inline.png



Don't suppose you can see where I'm going wrong?

Many thanks.

TylerMarcotte
Extreme Employee
Hi Martin,

The redirect rule is most likely there, just hidden in the dropdown list. If you drop down the item that says "Disabled" you should see one item that says "HTTP Redirect 1" or something along those lines.

Tyler
GTM-P2G8KFN