<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE guest portal weird behaviour in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-guest-portal-weird-behaviour/m-p/5111286#M589504</link>
    <description>&lt;P&gt;Hi, Did you figure out this issue?&amp;nbsp; I'm having a very similar experience on 9800 WLCs and ISE 3.1 (patch &lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 20 May 2024 16:06:35 GMT</pubDate>
    <dc:creator>lornesilkes</dc:creator>
    <dc:date>2024-05-20T16:06:35Z</dc:date>
    <item>
      <title>ISE guest portal weird behaviour</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-portal-weird-behaviour/m-p/4888566#M582947</link>
      <description>&lt;P&gt;So i run a hotspot guest portal with it's proper SSID, but WLAN and guest portal are on separate networks.&lt;/P&gt;&lt;P&gt;So guest WLAN is on let's say 10.10.10.0/24 and the guest portal is on 10.20.20.0/24&lt;/P&gt;&lt;P&gt;Have Webauth redirect configured and working fine, together with needed policy on ISE for MAB and all related things.&lt;/P&gt;&lt;P&gt;Testing this on my mobile, connecting to the guest SSID, i get the captive portal popup, can accept the UAP and then you should click on the 'Continue' button.&lt;/P&gt;&lt;P&gt;But here comes the thing, once clicked on the continue button, i'm thrown back to the wifi settings without being connected to the guest wifi and i have to click on it once again, i even have to try a few times again to connect to this guest wifi while getting the message 'Cannot connect to the network', but eventually it will succeed.&lt;/P&gt;&lt;P&gt;Looking at ISE logs, i see my authentication failed with following event&lt;/P&gt;&lt;TABLE border="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Event&lt;/TD&gt;&lt;TD&gt;5422 Authorize-Only failed&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Failure Reason&lt;/TD&gt;&lt;TD&gt;15039 Rejected per authorization profile&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;wich as a result returns me a Radius DenyAccess response.&lt;/P&gt;&lt;P&gt;A few moments later though, authentication succeeded and i'm connected.&lt;/P&gt;&lt;P&gt;Any idea what's causing this weird behaviour?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2023 13:05:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-portal-weird-behaviour/m-p/4888566#M582947</guid>
      <dc:creator>Darkmatter</dc:creator>
      <dc:date>2023-07-20T13:05:01Z</dc:date>
    </item>
    <item>
      <title>Re: ISE guest portal weird behaviour</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-portal-weird-behaviour/m-p/4888576#M582948</link>
      <description>&lt;P&gt;Change of Authorization (CoA).&amp;nbsp; What is your NAD?&amp;nbsp; Do you have CoA enabled?&amp;nbsp; Do you see any CoA failed logs in ISE?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2023 13:16:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-portal-weird-behaviour/m-p/4888576#M582948</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2023-07-20T13:16:10Z</dc:date>
    </item>
    <item>
      <title>Re: ISE guest portal weird behaviour</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-portal-weird-behaviour/m-p/4888586#M582949</link>
      <description>&lt;P&gt;So the NAD for wireless is a WLC-9800 and CoA is configured.&lt;/P&gt;&lt;P&gt;Don't see any failed CoA logs though.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2023 13:26:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-portal-weird-behaviour/m-p/4888586#M582949</guid>
      <dc:creator>Darkmatter</dc:creator>
      <dc:date>2023-07-20T13:26:18Z</dc:date>
    </item>
    <item>
      <title>Re: ISE guest portal weird behaviour</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-portal-weird-behaviour/m-p/4888608#M582950</link>
      <description>&lt;P&gt;Do you have CoA success logs?&amp;nbsp; What version of ISE?&amp;nbsp; What version of 9800?&amp;nbsp; AAA override and NAC state enabled on the SSID/WLAN/Tag?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2023 13:59:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-portal-weird-behaviour/m-p/4888608#M582950</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2023-07-20T13:59:05Z</dc:date>
    </item>
    <item>
      <title>Re: ISE guest portal weird behaviour</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-portal-weird-behaviour/m-p/4888615#M582951</link>
      <description>&lt;P&gt;&lt;A href="https://www.linkedin.com/pulse/central-web-authentication-wlc-ise-understanding-flow-alessandro-don%C3%A0" target="_blank"&gt;https://www.linkedin.com/pulse/central-web-authentication-wlc-ise-understanding-flow-alessandro-don%C3%A0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;the condition must be config correctly, the condition must SSID, the guest will select SSID for guest and WLC send this info to ISE which use it to match the correct authz policy apply.&amp;nbsp;&lt;BR /&gt;that it&amp;nbsp;&lt;BR /&gt;I think you dont need more than that&amp;nbsp;&lt;BR /&gt;Thanks&amp;nbsp;&lt;BR /&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2023 14:01:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-portal-weird-behaviour/m-p/4888615#M582951</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-07-20T14:01:32Z</dc:date>
    </item>
    <item>
      <title>Re: ISE guest portal weird behaviour</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-portal-weird-behaviour/m-p/4888887#M582964</link>
      <description>&lt;P&gt;Strange enough, i don't see any CoA happening, although WLC is configured for that?&lt;/P&gt;&lt;P&gt;ISE 3.2 - WLC version 17.6.x&lt;/P&gt;&lt;P&gt;Have to check the AAA override and NAC as i'm not sure about that, but it should.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2023 22:56:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-portal-weird-behaviour/m-p/4888887#M582964</guid>
      <dc:creator>Darkmatter</dc:creator>
      <dc:date>2023-07-20T22:56:29Z</dc:date>
    </item>
    <item>
      <title>Re: ISE guest portal weird behaviour</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-portal-weird-behaviour/m-p/4925655#M584126</link>
      <description>&lt;P&gt;Summer holidays went by and didn't had much time to spent on it during this period, but picking it up again.&lt;/P&gt;&lt;P&gt;ISE 3.2 patch 3 and IOS XE17.6.5 on WLC 9800.&lt;BR /&gt;CoA success log is visible, AAA override and NAC state ISE is configured on the WLC.&lt;/P&gt;&lt;P&gt;The thing is that is works, but only when you connect to the guest wifi and let it sit for a couple of minutes.&lt;/P&gt;&lt;P&gt;What i'm seeing in the RADIUS logs on ISE is that there are 2 authorizations coming in for the same clients, where the first one is accepted and directly after that, the second auth is rejected.&lt;BR /&gt;As explained, this will auto resolve itself after a few minutes, but i want to get rid of it and have it working correctly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 10:08:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-portal-weird-behaviour/m-p/4925655#M584126</guid>
      <dc:creator>Darkmatter</dc:creator>
      <dc:date>2023-09-19T10:08:02Z</dc:date>
    </item>
    <item>
      <title>Re: ISE guest portal weird behaviour</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-portal-weird-behaviour/m-p/4925696#M584127</link>
      <description>&lt;P&gt;Seems to be caused by some delays between the WLC and ISE. Are both setting on the same network? if not, is there any firewall in between that is doing palyload inspection?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 11:29:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-portal-weird-behaviour/m-p/4925696#M584127</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2023-09-19T11:29:49Z</dc:date>
    </item>
    <item>
      <title>Re: ISE guest portal weird behaviour</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-portal-weird-behaviour/m-p/5111286#M589504</link>
      <description>&lt;P&gt;Hi, Did you figure out this issue?&amp;nbsp; I'm having a very similar experience on 9800 WLCs and ISE 3.1 (patch &lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2024 16:06:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-portal-weird-behaviour/m-p/5111286#M589504</guid>
      <dc:creator>lornesilkes</dc:creator>
      <dc:date>2024-05-20T16:06:35Z</dc:date>
    </item>
  </channel>
</rss>

