<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE CWA with Captive Portal Detection and DHCP Option 114 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-cwa-with-captive-portal-detection-and-dhcp-option-114/m-p/5230816#M593480</link>
    <description>&lt;DIV id="bodyDisplay_0" class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;
&lt;DIV class="lia-message-body-content"&gt;
&lt;P&gt;One of the reasons for asking is that I am finding the Captive Portal Detection process to be rather slow, taking around 10 seconds.&lt;/P&gt;
&lt;P&gt;This is using the traditional method of the HTTP GET request sent form the Apple iOS Device to&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://captive.apple.com/hotspot-detect.html" target="_blank" rel="nofollow noopener noreferrer"&gt;http://captive.apple.com/hotspot-detect.html&lt;/A&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV id="messagemediasnippetlist_0" class="lia-media-snippet-container lia-component-media-snippet lia-component-message-view-widget-media-snippet"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Sat, 30 Nov 2024 13:16:26 GMT</pubDate>
    <dc:creator>joshhunter</dc:creator>
    <dc:date>2024-11-30T13:16:26Z</dc:date>
    <item>
      <title>Cisco ISE CWA with Captive Portal Detection and DHCP Option 114</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-cwa-with-captive-portal-detection-and-dhcp-option-114/m-p/5230815#M593479</link>
      <description>&lt;P&gt;Hello, does Cisco ISE solution work with Captive Portal Detection Option 114 to modernise the Captive Portal Detection process on Apple iOS Devices that support iOS 14+ see below Apple article:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://developer.apple.com/news/?id=q78sq5rv" target="_blank" rel="nofollow noopener noreferrer"&gt;https://developer.apple.com/news/?id=q78sq5rv&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;On the Cisco Meraki support pages,&lt;/P&gt;
&lt;P&gt;&lt;A href="https://documentation.meraki.com/MR/Encryption_and_Authentication/CWA_-_Central_Web_Authentication_with_Cisco_ISE" target="_blank" rel="nofollow noopener noreferrer"&gt;https://documentation.meraki.com/MR/Encryption_and_Authentication/CWA_-_Central_Web_Authentication_with_Cisco_ISE&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-align-left lia-indent-padding-left-90px"&gt;&lt;SPAN&gt;Disabling CNA will require that users manually open their web browser before being presented with the splash page. Applications on the user's device that&amp;nbsp;require Internet connectivity will not function as expected until the user has opened their web browser and completed authentication via the splash page. If your network contains&amp;nbsp;Apple devices running iOS 14/macOS Big Sur and newer operating systems , DHCP option 114 can be leveraged instead of Apple's&amp;nbsp;legacy Captive Portal networks. For additional info, please see Apple's&amp;nbsp;&lt;/SPAN&gt;&lt;A class="link-https" title="https://developer.apple.com/news/?id=q78sq5rv" href="https://developer.apple.com/news/?id=q78sq5rv" target="_blank" rel="external noopener nofollow noreferrer"&gt;How to modernize your captive network&lt;/A&gt;&lt;SPAN&gt;documentation.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Nov 2024 13:15:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-cwa-with-captive-portal-detection-and-dhcp-option-114/m-p/5230815#M593479</guid>
      <dc:creator>joshhunter</dc:creator>
      <dc:date>2024-11-30T13:15:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE CWA with Captive Portal Detection and DHCP Option 114</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-cwa-with-captive-portal-detection-and-dhcp-option-114/m-p/5230816#M593480</link>
      <description>&lt;DIV id="bodyDisplay_0" class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;
&lt;DIV class="lia-message-body-content"&gt;
&lt;P&gt;One of the reasons for asking is that I am finding the Captive Portal Detection process to be rather slow, taking around 10 seconds.&lt;/P&gt;
&lt;P&gt;This is using the traditional method of the HTTP GET request sent form the Apple iOS Device to&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://captive.apple.com/hotspot-detect.html" target="_blank" rel="nofollow noopener noreferrer"&gt;http://captive.apple.com/hotspot-detect.html&lt;/A&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV id="messagemediasnippetlist_0" class="lia-media-snippet-container lia-component-media-snippet lia-component-message-view-widget-media-snippet"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Sat, 30 Nov 2024 13:16:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-cwa-with-captive-portal-detection-and-dhcp-option-114/m-p/5230816#M593480</guid>
      <dc:creator>joshhunter</dc:creator>
      <dc:date>2024-11-30T13:16:26Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE CWA with Captive Portal Detection and DHCP Option 114</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-cwa-with-captive-portal-detection-and-dhcp-option-114/m-p/5230817#M593481</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P class="lia-indent-padding-left-150px"&gt;&amp;nbsp;I failed to see this as an ISE feature. I would see this as a DHCP server / Client feature. When it comes to guest portal, the ISE will act as a web site where you hit, you present your credentials, the credential is validate against some kind of checker and the access is granted or denied.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-150px"&gt;&amp;nbsp;The option 114, therefore, happened way before all this process. In guest network, first the client gets the IP address and later it will be authenticated.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-150px"&gt;As I could read on the documentation, this is just a faster way to receive the Guest portal URL instead using the traditional intercept method used so far for Wireless Controller.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-150px"&gt;"&lt;/P&gt;
&lt;PRE class="lia-indent-padding-left-150px"&gt;2.  The Captive-Portal Option

   The Captive-Portal DHCP/RA Option informs the client that it may be
   behind a captive portal and provides the URI to access an API as
   defined by [RFC8908]"&lt;/PRE&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/178747"&gt;@Flavio Miranda&lt;/a&gt;&amp;nbsp; Thank you for your reply. I understand this is a DHCP Option and not ISE Specific. However, the DHCP Option needs to point to a URI. We know that URI for Cisco ISE is dynamic and contains the session ID.&lt;/P&gt;
&lt;P&gt;My question is if anyone has got it DHCP Option 114 to work with Cisco ISE Central Web Auth?&lt;/P&gt;
&lt;P class="lia-indent-padding-left-150px"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Nov 2024 13:18:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-cwa-with-captive-portal-detection-and-dhcp-option-114/m-p/5230817#M593481</guid>
      <dc:creator>joshhunter</dc:creator>
      <dc:date>2024-11-30T13:18:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE CWA with Captive Portal Detection and DHCP Option 114</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-cwa-with-captive-portal-detection-and-dhcp-option-114/m-p/5230818#M593482</link>
      <description>&lt;P&gt;why you not add op114 to DHCP ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sat, 30 Nov 2024 13:18:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-cwa-with-captive-portal-detection-and-dhcp-option-114/m-p/5230818#M593482</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-11-30T13:18:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE CWA with Captive Portal Detection and DHCP Option 114</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-cwa-with-captive-portal-detection-and-dhcp-option-114/m-p/5230824#M593485</link>
      <description>&lt;P&gt;Well, you add the Option 114 DHCP String but it must point to a JSON API, there is a question of where this should be hosted.&lt;/P&gt;
&lt;P&gt;Then, another question as to what the string should contain as the user portal URL is dynamic based on session ID.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="hljs-punctuation"&gt;{&lt;/SPAN&gt; &lt;SPAN class="hljs-attr"&gt;"captive"&lt;/SPAN&gt;&lt;SPAN class="hljs-punctuation"&gt;:&lt;/SPAN&gt; &lt;SPAN class="hljs-keyword"&gt;true&lt;/SPAN&gt;&lt;SPAN class="hljs-punctuation"&gt;,&lt;/SPAN&gt; &lt;SPAN class="hljs-attr"&gt;"user-portal-url"&lt;/SPAN&gt;&lt;SPAN class="hljs-punctuation"&gt;:&lt;/SPAN&gt; &lt;SPAN class="hljs-string"&gt;"&lt;A href="https://example.org/portal.html" target="_blank" rel="nofollow noopener noreferrer"&gt;https://example.org/portal.html&lt;/A&gt;"&lt;/SPAN&gt; &lt;SPAN class="hljs-punctuation"&gt;}&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Nov 2024 13:30:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-cwa-with-captive-portal-detection-and-dhcp-option-114/m-p/5230824#M593485</guid>
      <dc:creator>joshhunter</dc:creator>
      <dc:date>2024-11-30T13:30:31Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE CWA with Captive Portal Detection and DHCP Option 114</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-cwa-with-captive-portal-detection-and-dhcp-option-114/m-p/5230826#M593486</link>
      <description>&lt;P&gt;Thats make It a totally different question. But make Sense now.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Since the WLC manage the portal intercept for traditional guest portal, I would say the WLC should handle this. I dont see any Cisco WLC handlng this option.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Nov 2024 13:43:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-cwa-with-captive-portal-detection-and-dhcp-option-114/m-p/5230826#M593486</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2024-11-30T13:43:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE CWA with Captive Portal Detection and DHCP Option 114</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-cwa-with-captive-portal-detection-and-dhcp-option-114/m-p/5230827#M593487</link>
      <description>&lt;P&gt;I think op114 must include the portal of ISE&amp;nbsp;&lt;BR /&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sat, 30 Nov 2024 13:44:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-cwa-with-captive-portal-detection-and-dhcp-option-114/m-p/5230827#M593487</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-11-30T13:44:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE CWA with Captive Portal Detection and DHCP Option 114</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-cwa-with-captive-portal-detection-and-dhcp-option-114/m-p/5245914#M594135</link>
      <description>&lt;P&gt;Hello, any updates on this one?&lt;/P&gt;
&lt;P&gt;I am keen to improve the Captive Portal detection process, using Option 114 looks to be a good way of doing this.&lt;/P&gt;</description>
      <pubDate>Sat, 11 Jan 2025 11:33:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-cwa-with-captive-portal-detection-and-dhcp-option-114/m-p/5245914#M594135</guid>
      <dc:creator>joshhunter</dc:creator>
      <dc:date>2025-01-11T11:33:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE CWA with Captive Portal Detection and DHCP Option 114</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-cwa-with-captive-portal-detection-and-dhcp-option-114/m-p/5314816#M597500</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;A message to bring the thread back up to the top incase of any new updates.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jul 2025 14:01:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-cwa-with-captive-portal-detection-and-dhcp-option-114/m-p/5314816#M597500</guid>
      <dc:creator>joshhunter</dc:creator>
      <dc:date>2025-07-28T14:01:26Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE CWA with Captive Portal Detection and DHCP Option 114</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-cwa-with-captive-portal-detection-and-dhcp-option-114/m-p/5373805#M599932</link>
      <description>&lt;P&gt;Maybe a good question for TAC, but in the IETF documentation I see that option 114 must be the URI of the ISE so, would that be company URI for the portal like &lt;A href="https://guestportal.company.com:443," target="_blank"&gt;https://guestportal.company.com:443,&lt;/A&gt;&amp;nbsp;or something with the WLC format where the association ID is sent to ISE?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2026 12:00:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-cwa-with-captive-portal-detection-and-dhcp-option-114/m-p/5373805#M599932</guid>
      <dc:creator>JPavonM</dc:creator>
      <dc:date>2026-03-02T12:00:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE CWA with Captive Portal Detection and DHCP Option 114</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-cwa-with-captive-portal-detection-and-dhcp-option-114/m-p/5374991#M599988</link>
      <description>&lt;P&gt;I raised a 'wish' within Cisco ISE.&lt;/P&gt;
&lt;P&gt;Additionally, I found that a Cisco feature request has already been raised for this;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Need to use the JSON API on ISE to redirect the client using chrome browser.&amp;nbsp;&lt;/STRONG&gt;&lt;STRONG&gt;&lt;A title="Original URL: https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwd24573. Click or tap if you trust this link." href="https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fbst.cloudapps.cisco.com%2Fbugsearch%2Fbug%2FCSCwd24573&amp;amp;data=05%7C02%7Cjosh.hunter%40maintel.co.uk%7Cb6323978077943f7f30e08de7b716530%7Cbc8054cb91544fc287936321b1c07cd4%7C0%7C0%7C639083924184349558%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;amp;sdata=%2Ba%2BisRhlqjRupuzXeqptZZ8rRuMrZ%2FDh2lBMXzcuxlY%3D&amp;amp;reserved=0" target="_blank" rel="noopener" data-auth="NotApplicable" data-linkindex="13" data-ogsc="" data-olk-copy-source="MessageBody"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwd24573&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2026-03-06 at 11.27.11.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/260789i5A31CDB18DB41520/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2026-03-06 at 11.27.11.png" alt="Screenshot 2026-03-06 at 11.27.11.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;However, it's&amp;nbsp;not possible given the dynamic nature of the URL.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="x_xmsonormal"&gt;&lt;SPAN data-olk-copy-source="MessageBody"&gt;To provide a comprehensive understanding of the request to support DHCP Option 114 with ISE, here's an explanation:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="x_xmsonormal"&gt;&lt;SPAN&gt;&lt;STRONG&gt;How ISE Does WebAuth and Captive Portal:&lt;/STRONG&gt;&lt;BR /&gt;1. Device Connects to Network:&lt;BR /&gt;* The device connects to the Wi-Fi network&lt;BR /&gt;2. Authentication Request Sent to ISE:&lt;BR /&gt;* The device sends an authentication request to ISE via the NAD&lt;BR /&gt;3. ISE Processes Request:&lt;BR /&gt;* ISE evaluates the request and determines the appropriate policy&lt;BR /&gt;4. ISE Sends RADIUS Access-Accept:&lt;BR /&gt;* If required, ISE sends a RADIUS Access-Accept message with a unique captive portal URL for the session&lt;BR /&gt;5. Device Redirected by NAD:&lt;BR /&gt;* NAD redirects HTTP traffic to the ISE captive portal using the URL provided&lt;BR /&gt;6. User Authentication:&lt;BR /&gt;* The user authenticates on the ISE-hosted captive portal&lt;BR /&gt;7. Authorization and Network Access:&lt;BR /&gt;* ISE applies the authorization policy and grants network access&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;How DHCP Option 114 Works:&lt;/STRONG&gt;&lt;BR /&gt;1. Device Connects to Network:&lt;BR /&gt;* The device connects to the Wi-Fi network.&lt;BR /&gt;2. DHCP Server Provides IP and URL:&lt;BR /&gt;* DHCP server provides the IP address and a static captive portal URL via DHCP Option 114.&lt;BR /&gt;3. Device Redirects to Captive Portal:&lt;BR /&gt;* The device uses the URL to redirect to the captive portal.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Why DHCP Option 114 does not Work with ISE:&lt;/STRONG&gt;&lt;BR /&gt;1. Dynamic vs. Static URLs:&lt;BR /&gt;* ISE generates unique, session-specific URLs for each authentication session.&lt;BR /&gt;* DHCP Option 114 gets configured with a static URL, which cannot accommodate the dynamic nature of ISE URLs.&lt;BR /&gt;2. Session Management:&lt;BR /&gt;* ISE's session management requires unique URLs to track individual device sessions and ensure secure authentication.&lt;BR /&gt;* A static URL from DHCP Option 114 cannot fulfill this requirement.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Given these constraints, integrating DHCP Option 114 with ISE for WebAuth and captive portal redirection is not feasible. The recommended approach is to continue using RADIUS-based redirection with ACLs for HTTP traffic to ensure proper session management and secure authentication.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2026 11:30:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-cwa-with-captive-portal-detection-and-dhcp-option-114/m-p/5374991#M599988</guid>
      <dc:creator>joshhunter</dc:creator>
      <dc:date>2026-03-06T11:30:38Z</dc:date>
    </item>
  </channel>
</rss>

