<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LWA Guest Access with ISE and WLC in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/lwa-guest-access-with-ise-and-wlc/m-p/2165758#M138502</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thx for your reply Peter, your solution is right, &lt;/P&gt;&lt;P&gt;i don't choose CWA, because their DNS is not stable...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i've found the problem...&lt;/P&gt;&lt;P&gt;the third-party CA is revoked, so there is no way it will success until it fixed...&lt;/P&gt;&lt;P&gt;and there is no guarantee, they will fix it soon..&lt;/P&gt;&lt;P&gt;so solution that we choose is by disable "HTTPS" on WLC...&lt;/P&gt;&lt;P style="position: absolute; top: -1999px; left: -1988px;"&gt;&lt;STRONG&gt;"config network web-auth secureweb disable"&lt;/STRONG&gt;. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="position: absolute; top: -1999px; left: -1988px;"&gt;&lt;STRONG&gt;"config network web-auth secureweb disable"&lt;/STRONG&gt;. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="position: absolute; top: -1999px; left: -1988px;"&gt;&lt;STRONG&gt;"config network web-auth secureweb disable"&lt;/STRONG&gt;. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="position: absolute; top: -1999px; left: -1988px;"&gt;&lt;STRONG&gt;"config network web-auth secureweb disable"&lt;/STRONG&gt;. &lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; "config network web-auth secureweb disable" &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;thank you all...&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 27 Feb 2013 09:57:20 GMT</pubDate>
    <dc:creator>myanznki</dc:creator>
    <dc:date>2013-02-27T09:57:20Z</dc:date>
    <item>
      <title>LWA Guest Access with ISE and WLC</title>
      <link>https://community.cisco.com/t5/network-access-control/lwa-guest-access-with-ise-and-wlc/m-p/2165756#M138465</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;Our Company try to implement Guest Access with ISE dan WLC with Local Web Auth Method. But there is problem that comes up with the certificate. This is the scenario :&lt;/P&gt;&lt;P&gt;1. Guests try to connect wifi with SSID Guest&lt;/P&gt;&lt;P&gt;2. Once it connect, guests open the browser and try to open a webpage (example: cisco.com)&lt;/P&gt;&lt;P&gt;3. Because, guests didn't login, so it redirect to "ISE Guest Login Page" (url became &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;: &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://ise-hostname:8443/guestportal/Login.action?switch_url=https://1.1.1.1/login.html&amp;amp;wlan=Guest&amp;amp;redirect=www.cisco.com/" target="_blank"&gt;https://ise-hostname:8443/guestportal/Login.action?switch_url=https://1.1.1.1/login.html&amp;amp;wlan=Guest&amp;amp;redirect=www.cisco.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;)&lt;/P&gt;&lt;P&gt;4. If there is no ISE Guest Login Page installed, message Untrusted Connection message will appear, but it will be fine if they "Add Exception and install the certificate"&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/8/6/9/129968-oke1.png" alt="oke1.png" class="jive-image-thumbnail jive-image" onclick="" style="display: block; margin-left: auto; margin-right: auto;" width="450" /&gt;&lt;/P&gt;&lt;P&gt;5. After that the Guest Login Page will appear, and guests input their username and password.&lt;/P&gt;&lt;P style="text-align: center;"&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/0/7/9/129970-oke2.png" alt="oke2.png" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;&lt;P&gt;6. Login success and they will be redirected to &lt;A href="https://community.cisco.com/www.cisco.com" target="_blank"&gt;www.cisco.com&lt;/A&gt; and there is pop up from 1.1.1.1 (WLC Virtual Interface IP) with logout button.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem happen in scenario 6, after login success, the webpage with ISE IP address and message certificate error for 1.1.1.1 is appear.&lt;/P&gt;&lt;P style="text-align: center;"&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/2/7/9/129972-oke3.png" alt="oke3.png" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;&lt;P&gt;I know it happened when guests didn't have the WLC Login Page Certificate...&lt;/P&gt;&lt;P&gt;My Question is, is there a way to tunneling WLC Certificate on ISE ? Or what can we do to make ISE validate WLC Certificate, so guests doesn't need to install WLC Certificate/ Root Certificate before connect to Wifi ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx 4 your answer and sorry for my bad English....&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:07:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/lwa-guest-access-with-ise-and-wlc/m-p/2165756#M138465</guid>
      <dc:creator>myanznki</dc:creator>
      <dc:date>2019-03-11T03:07:14Z</dc:date>
    </item>
    <item>
      <title>LWA Guest Access with ISE and WLC</title>
      <link>https://community.cisco.com/t5/network-access-control/lwa-guest-access-with-ise-and-wlc/m-p/2165757#M138483</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Don't mix WLC Local Web Authentication with ISE Guest Portal. Choose either one or the other. I would suggest Guest Portal + WLC CWA.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Feb 2013 08:50:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/lwa-guest-access-with-ise-and-wlc/m-p/2165757#M138483</guid>
      <dc:creator>Peter Koltl</dc:creator>
      <dc:date>2013-02-27T08:50:56Z</dc:date>
    </item>
    <item>
      <title>Re: LWA Guest Access with ISE and WLC</title>
      <link>https://community.cisco.com/t5/network-access-control/lwa-guest-access-with-ise-and-wlc/m-p/2165758#M138502</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thx for your reply Peter, your solution is right, &lt;/P&gt;&lt;P&gt;i don't choose CWA, because their DNS is not stable...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i've found the problem...&lt;/P&gt;&lt;P&gt;the third-party CA is revoked, so there is no way it will success until it fixed...&lt;/P&gt;&lt;P&gt;and there is no guarantee, they will fix it soon..&lt;/P&gt;&lt;P&gt;so solution that we choose is by disable "HTTPS" on WLC...&lt;/P&gt;&lt;P style="position: absolute; top: -1999px; left: -1988px;"&gt;&lt;STRONG&gt;"config network web-auth secureweb disable"&lt;/STRONG&gt;. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="position: absolute; top: -1999px; left: -1988px;"&gt;&lt;STRONG&gt;"config network web-auth secureweb disable"&lt;/STRONG&gt;. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="position: absolute; top: -1999px; left: -1988px;"&gt;&lt;STRONG&gt;"config network web-auth secureweb disable"&lt;/STRONG&gt;. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="position: absolute; top: -1999px; left: -1988px;"&gt;&lt;STRONG&gt;"config network web-auth secureweb disable"&lt;/STRONG&gt;. &lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; "config network web-auth secureweb disable" &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;thank you all...&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Feb 2013 09:57:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/lwa-guest-access-with-ise-and-wlc/m-p/2165758#M138502</guid>
      <dc:creator>myanznki</dc:creator>
      <dc:date>2013-02-27T09:57:20Z</dc:date>
    </item>
    <item>
      <title>LWA Guest Access with ISE and WLC</title>
      <link>https://community.cisco.com/t5/network-access-control/lwa-guest-access-with-ise-and-wlc/m-p/2165759#M138533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would recommend that you get yourself a new certificate instead of disabling HTTPS. You can get a new public cert pretty cheap from godaddy, etc. That way your credentials are not passed unprotected. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Mar 2013 16:49:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/lwa-guest-access-with-ise-and-wlc/m-p/2165759#M138533</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2013-03-01T16:49:25Z</dc:date>
    </item>
  </channel>
</rss>

