<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CWA/ISE/WLC - client timeout when redirected to portal. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cwa-ise-wlc-client-timeout-when-redirected-to-portal/m-p/2125824#M138900</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Accoding with this behaviour, I have a similar problem with the renew of the IP address. In a similar scenario (ISE1.1.2 + vWLC 7.3.101. + CWA + DVLAN assigment); for test purposses I need to use the AP in flexconnect mode with central control and traffic data due to vWLC does not support APs in a local mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Applying WCA in a SSID with a "non-routed" interface and two interfaces for both different profiles. Client passes CWA profile in "non route" subnet when redirected;&amp;nbsp; after a successful web authetication ISE sends to WLC the new attributes including the new VLAN, new ACL and the access-accept, but the client is not trying to change the IP address through DHCP.&lt;/P&gt;&lt;P&gt; I use two rules for authentication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First: Guest Redirection; condition "Wireless MAB" then "WLC-CWA" (central authentication - ACL-POSTURE-REDIRECT)&lt;/P&gt;&lt;P&gt;Second (This rule above the first) Guest Traffic; Condition "Network access: UseCase EQUALS GuestFlow) then "Guest Permit Access"(with includes new vlan assigment in function of the role based - new ACL asigment - Termination-Action=0)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WLC shows me the data correctly, it changes the interface, the ACL and changes the client status to RUN but maintains the IP address belonging to the old VLAN (non-routed vlan)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could be possible that this bug will be hitting me?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are there any Radius Attribute to force a DHCP IP procces for this devices?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advanced.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 15 Feb 2013 12:34:35 GMT</pubDate>
    <dc:creator>Raul Manzano Barroso</dc:creator>
    <dc:date>2013-02-15T12:34:35Z</dc:date>
    <item>
      <title>CWA/ISE/WLC - client timeout when redirected to portal.</title>
      <link>https://community.cisco.com/t5/network-access-control/cwa-ise-wlc-client-timeout-when-redirected-to-portal/m-p/2125817#M138892</link>
      <description>&lt;P&gt;Problem: When connecting to the CWA ssid, the client gets redirected to: &lt;SPAN style="font-size: 10pt;"&gt;&lt;A class="jive-link-external-small" href="https://lab-ise01.lab.local:8443/guestportal/gateway?sessionId=3c02a8c00000000878430a51&amp;amp;action=cwa" target="_blank"&gt;https://lab-ise01.lab.local:8443/guestportal/gateway?sessionId=3c02a8c00000000878430a51&amp;amp;action=cwa&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;but the link times out.&lt;/P&gt;&lt;P&gt;I'm currently following this guide: &lt;A href="https://community.cisco.com/document/110031/central-web-authentication-cwa-guests-ise" target="_blank"&gt;https://supportforums.cisco.com/docs/DOC-26442&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thoughts or suggestions are appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Info: ISE 1.1.1 and vWLC 7.3.101.0 is installed on vmware. Identity Source: Internal Users. AP is in FlexConnect mode. MAC filtering enable, no layer 3 security. &lt;SPAN style="font-size: 10pt;"&gt;Allow AAA Override enabled. Radius NAC enabled.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Topology:&lt;/P&gt;&lt;P&gt;Win7/iPad -&amp;nbsp; -&amp;nbsp; - AP----labswitch-----switch-----switch-----VMware&lt;/P&gt;&lt;P&gt;(Traffic does not pass through FW and there are no ACL on the switches.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACL on WLC:&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/5/1/7/127715-acl_wlc.PNG" alt="acl_wlc.PNG" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;&lt;P&gt;Client on WLC&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/4/8/6/127684-client_on_wlc.PNG" alt="client_on_wlc.PNG" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:02:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cwa-ise-wlc-client-timeout-when-redirected-to-portal/m-p/2125817#M138892</guid>
      <dc:creator>c.s</dc:creator>
      <dc:date>2019-03-11T03:02:35Z</dc:date>
    </item>
    <item>
      <title>Re: CWA/ISE/WLC - client timeout when redirected to portal.</title>
      <link>https://community.cisco.com/t5/network-access-control/cwa-ise-wlc-client-timeout-when-redirected-to-portal/m-p/2125818#M138893</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;BR /&gt;Can you see if DNS is working for the client?&lt;BR /&gt;&lt;BR /&gt;Regard&lt;BR /&gt; Mikael&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;BR /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Feb 2013 16:13:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cwa-ise-wlc-client-timeout-when-redirected-to-portal/m-p/2125818#M138893</guid>
      <dc:creator>Mikael Gustafsson</dc:creator>
      <dc:date>2013-02-03T16:13:03Z</dc:date>
    </item>
    <item>
      <title>Re: CWA/ISE/WLC - client timeout when redirected to portal.</title>
      <link>https://community.cisco.com/t5/network-access-control/cwa-ise-wlc-client-timeout-when-redirected-to-portal/m-p/2125819#M138895</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The DNS work fine, but it can't reach the ISE for some reason. &lt;SPAN __jive_emoticon_name="confused" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/7/0/8/127807-nslookup.PNG" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The wlan works fine without web-auth (ise) btw&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Feb 2013 15:30:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cwa-ise-wlc-client-timeout-when-redirected-to-portal/m-p/2125819#M138895</guid>
      <dc:creator>c.s</dc:creator>
      <dc:date>2013-02-04T15:30:05Z</dc:date>
    </item>
    <item>
      <title>CWA/ISE/WLC - client timeout when redirected to portal.</title>
      <link>https://community.cisco.com/t5/network-access-control/cwa-ise-wlc-client-timeout-when-redirected-to-portal/m-p/2125820#M138896</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I thought I might be hitting the bug mentioned in the following thread. &lt;A _jive_internal="true" href="https://community.cisco.com/thread/2191587"&gt;https://supportforums.cisco.com/thread/2191587&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Oddly enough, updating the vWLC to &lt;SPAN style="font-size: 10pt;"&gt;v7.3.112.0 &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;did not resolve the problem.&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt; (ISE is v1.1.2)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;I still cannot reach anything from the the CWA wlan unless I remove CWA.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Feb 2013 12:57:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cwa-ise-wlc-client-timeout-when-redirected-to-portal/m-p/2125820#M138896</guid>
      <dc:creator>c.s</dc:creator>
      <dc:date>2013-02-08T12:57:17Z</dc:date>
    </item>
    <item>
      <title>Re:CWA/ISE/WLC - client timeout when redirected to portal.</title>
      <link>https://community.cisco.com/t5/network-access-control/cwa-ise-wlc-client-timeout-when-redirected-to-portal/m-p/2125821#M138897</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you sending the airespace acl so the client can hit the ise node with the dns services allowed. Please provide the screenshots of the client session from the wlc. Also hover over the green button in the ise live authentications portal and provide a screenshot of the radius attributes that are sent back to the controller.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support Android App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Feb 2013 02:10:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cwa-ise-wlc-client-timeout-when-redirected-to-portal/m-p/2125821#M138897</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2013-02-10T02:10:03Z</dc:date>
    </item>
    <item>
      <title>CWA/ISE/WLC - client timeout when redirected to portal.</title>
      <link>https://community.cisco.com/t5/network-access-control/cwa-ise-wlc-client-timeout-when-redirected-to-portal/m-p/2125822#M138898</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am having this exact issue as well. I followed the FlexConnect Wireless BYOD guide but I just timeout getting the redirect page. I've even opened the ACL to any/any. The guide makes mention of sending a flex ACL as the CWA Airespace-ACL-Name but that does not appear right. Controller is on 7.4 and ISE 1.1.2&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Feb 2013 20:16:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cwa-ise-wlc-client-timeout-when-redirected-to-portal/m-p/2125822#M138898</guid>
      <dc:creator>r.gergis</dc:creator>
      <dc:date>2013-02-14T20:16:26Z</dc:date>
    </item>
    <item>
      <title>CWA/ISE/WLC - client timeout when redirected to portal.</title>
      <link>https://community.cisco.com/t5/network-access-control/cwa-ise-wlc-client-timeout-when-redirected-to-portal/m-p/2125823#M138899</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Another test is to copy the redirect url from the WLC and swap domain name part in the url to the ISE IP address, then past it in the browser.&amp;nbsp; Just to test without DNS and narrow down the troubleshooting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ex&lt;/P&gt;&lt;P&gt;[hxxps://198.51.100.10:8443/guestportal/gateway?sessionId=3c02a8c00000000878430a51&amp;amp;action=cwa]&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Feb 2013 22:58:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cwa-ise-wlc-client-timeout-when-redirected-to-portal/m-p/2125823#M138899</guid>
      <dc:creator>Mikael Gustafsson</dc:creator>
      <dc:date>2013-02-14T22:58:05Z</dc:date>
    </item>
    <item>
      <title>CWA/ISE/WLC - client timeout when redirected to portal.</title>
      <link>https://community.cisco.com/t5/network-access-control/cwa-ise-wlc-client-timeout-when-redirected-to-portal/m-p/2125824#M138900</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Accoding with this behaviour, I have a similar problem with the renew of the IP address. In a similar scenario (ISE1.1.2 + vWLC 7.3.101. + CWA + DVLAN assigment); for test purposses I need to use the AP in flexconnect mode with central control and traffic data due to vWLC does not support APs in a local mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Applying WCA in a SSID with a "non-routed" interface and two interfaces for both different profiles. Client passes CWA profile in "non route" subnet when redirected;&amp;nbsp; after a successful web authetication ISE sends to WLC the new attributes including the new VLAN, new ACL and the access-accept, but the client is not trying to change the IP address through DHCP.&lt;/P&gt;&lt;P&gt; I use two rules for authentication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First: Guest Redirection; condition "Wireless MAB" then "WLC-CWA" (central authentication - ACL-POSTURE-REDIRECT)&lt;/P&gt;&lt;P&gt;Second (This rule above the first) Guest Traffic; Condition "Network access: UseCase EQUALS GuestFlow) then "Guest Permit Access"(with includes new vlan assigment in function of the role based - new ACL asigment - Termination-Action=0)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WLC shows me the data correctly, it changes the interface, the ACL and changes the client status to RUN but maintains the IP address belonging to the old VLAN (non-routed vlan)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could be possible that this bug will be hitting me?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are there any Radius Attribute to force a DHCP IP procces for this devices?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advanced.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Feb 2013 12:34:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cwa-ise-wlc-client-timeout-when-redirected-to-portal/m-p/2125824#M138900</guid>
      <dc:creator>Raul Manzano Barroso</dc:creator>
      <dc:date>2013-02-15T12:34:35Z</dc:date>
    </item>
    <item>
      <title>CWA/ISE/WLC - client timeout when redirected to portal.</title>
      <link>https://community.cisco.com/t5/network-access-control/cwa-ise-wlc-client-timeout-when-redirected-to-portal/m-p/2125825#M138901</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The client dosent know that the WLC changed VLAN and is not asking for a new IP.&lt;/P&gt;&lt;P&gt;To get that you need to use the 802.1x supplicant on the client, hence its better to only use ACL for MAB/guest flow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On a switch you can bounce the port but I dont think there is a good way to do that on wireless.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Feb 2013 13:02:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cwa-ise-wlc-client-timeout-when-redirected-to-portal/m-p/2125825#M138901</guid>
      <dc:creator>Mikael Gustafsson</dc:creator>
      <dc:date>2013-02-15T13:02:06Z</dc:date>
    </item>
    <item>
      <title>CWA/ISE/WLC - client timeout when redirected to portal.</title>
      <link>https://community.cisco.com/t5/network-access-control/cwa-ise-wlc-client-timeout-when-redirected-to-portal/m-p/2125826#M138902</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it's work only for windows.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Click on "Administration" menu&lt;/P&gt;&lt;P&gt;2. Click on "Guest Management"&lt;/P&gt;&lt;P&gt;3. Click on "Settings"&lt;/P&gt;&lt;P&gt;4.Expand "Guest". Expand "Mult-Portal Configuration"&lt;/P&gt;&lt;P&gt;5. Click on "DefaultGuestPortal" or the name of a custom portal you may have created&lt;/P&gt;&lt;P&gt;6. Enable "Vlan DHCP Release". &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here is a link: &lt;A _jive_internal="true" href="https://community.cisco.com/docs/DOC-18325" rel="nofollow"&gt;https://supportforums.cisco.com/docs/DOC-18325&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Feb 2013 13:14:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cwa-ise-wlc-client-timeout-when-redirected-to-portal/m-p/2125826#M138902</guid>
      <dc:creator>DumortierC</dc:creator>
      <dc:date>2013-02-15T13:14:03Z</dc:date>
    </item>
    <item>
      <title>Re: CWA/ISE/WLC - client timeout when redirected to portal.</title>
      <link>https://community.cisco.com/t5/network-access-control/cwa-ise-wlc-client-timeout-when-redirected-to-portal/m-p/4634397#M575597</link>
      <description>&lt;P&gt;Hi Raul, sorry my english is not good &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Yo say:"WLC shows me the data correctly, it changes the interface, the ACL and changes the client status to RUN but maintains the IP address belonging to the old VLAN (non-routed vlan)"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In spanish...&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Puede usted por favor revisar el grupo Flex Connect: wlan vlan mapping:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Aqui la wlan-id elegida debe indicar la "old vlan". A parte de indicar la vlan nativa para el AP. Por tantas wlan-id necesarias, deberán&amp;nbsp;indicarse a la "old vlan".&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Posteriormente su authorZ Profile debera indicar la vlan final a donde usted quiere autorizar.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Requisito importante es que la wlc soporte udp1700 (coa), el ise show ports | in 1700, el flex acl puede incluir 2 lineas que digan desde bootpccliente --- bootpcserver (y viceversa)&amp;nbsp; un timeout holgado (10seg) y una recomendación adicional habilite "Vlan DHCP Release" en al Guest Portal.&lt;/P&gt;
&lt;P&gt;Si no resulta preliminarmente valide en la wired que el dhcp pase a la vlan guest.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Quedo atento.&lt;/P&gt;
&lt;P&gt;Regards, Ivan.&lt;/P&gt;</description>
      <pubDate>Sun, 19 Jun 2022 02:07:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cwa-ise-wlc-client-timeout-when-redirected-to-portal/m-p/4634397#M575597</guid>
      <dc:creator>ivan.martin</dc:creator>
      <dc:date>2022-06-19T02:07:23Z</dc:date>
    </item>
    <item>
      <title>Re: CWA/ISE/WLC - client timeout when redirected to portal.</title>
      <link>https://community.cisco.com/t5/network-access-control/cwa-ise-wlc-client-timeout-when-redirected-to-portal/m-p/4634905#M575617</link>
      <description>&lt;P&gt;This is a post from 2013 (9 years ago!) I highly suggest making a new community post to help with your issue.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2022 11:56:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cwa-ise-wlc-client-timeout-when-redirected-to-portal/m-p/4634905#M575617</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2022-06-20T11:56:31Z</dc:date>
    </item>
  </channel>
</rss>

