<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Wireless guest in an SD Access network in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/wireless-guest-in-an-sd-access-network/m-p/5294783#M596540</link>
    <description>&lt;P&gt;All working now Boort.&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;</description>
    <pubDate>Thu, 29 May 2025 08:34:56 GMT</pubDate>
    <dc:creator>KevinR99</dc:creator>
    <dc:date>2025-05-29T08:34:56Z</dc:date>
    <item>
      <title>Wireless guest in an SD Access network</title>
      <link>https://community.cisco.com/t5/network-access-control/wireless-guest-in-an-sd-access-network/m-p/5292751#M596407</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I’ve been testing guest wireless using CWA in an SD Access network. &amp;nbsp;When I configure the SSID as a standard over the top deployment and tunnel the traffic back to the WLC all is ok. &amp;nbsp;However, when I change my SSID to fabric mode redirection to the ISE portal doesn’t work.&lt;/P&gt;&lt;P&gt;I’ve been thinking about the process involved and redirection relies on an ACL on the WLC. &amp;nbsp;Since fabric mode offloads the data at the edge switch that the AP is connected to I’m thinking the WLC doesn’t see that traffic and get a chance to use the WLC to intercept the traffic and cause a redirect to the ISE.&lt;/P&gt;&lt;P&gt;Can anyone advise if CWA can work in a fabric mode SSID?&lt;/P&gt;&lt;P&gt;AThanks, Kev.&lt;/P&gt;</description>
      <pubDate>Wed, 21 May 2025 22:00:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wireless-guest-in-an-sd-access-network/m-p/5292751#M596407</guid>
      <dc:creator>KevinR99</dc:creator>
      <dc:date>2025-05-21T22:00:48Z</dc:date>
    </item>
    <item>
      <title>Re: Wireless guest in an SD Access network</title>
      <link>https://community.cisco.com/t5/network-access-control/wireless-guest-in-an-sd-access-network/m-p/5292767#M596408</link>
      <description>&lt;P&gt;Unless I'm mistaken, I think the RADIUS + Redirect flow would happen in the CAPWAP Control Plane. The redirect URL and ACL would be sent from the WLC to the Fabric AP. At the point where the client needs to access the portal, that would be using the VXLAN Data Plane.&lt;/P&gt;
&lt;P&gt;If you haven't done so already, you might confirm that whatever VLAN/VN you are dropping the client onto as defined in the AuthZ Profile has routing and connectivity to the PSN Portal.&lt;/P&gt;
&lt;P&gt;All else fails, you might have to open a TAC case to investigate further and confirm the flow.&lt;/P&gt;</description>
      <pubDate>Thu, 22 May 2025 02:27:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wireless-guest-in-an-sd-access-network/m-p/5292767#M596408</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2025-05-22T02:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: Wireless guest in an SD Access network</title>
      <link>https://community.cisco.com/t5/network-access-control/wireless-guest-in-an-sd-access-network/m-p/5293544#M596455</link>
      <description>&lt;P&gt;Sounds like your APs is missing the redirect ACLs. They way this is done in a fabric mode deployment is to add the redirect ACLs to the default flex connect profile or which ever profile you have assigned. Even tho you are not using flexconnect it will still get pushed to the AP.&lt;/P&gt;</description>
      <pubDate>Sun, 25 May 2025 08:03:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wireless-guest-in-an-sd-access-network/m-p/5293544#M596455</guid>
      <dc:creator>Boort</dc:creator>
      <dc:date>2025-05-25T08:03:21Z</dc:date>
    </item>
    <item>
      <title>Re: Wireless guest in an SD Access network</title>
      <link>https://community.cisco.com/t5/network-access-control/wireless-guest-in-an-sd-access-network/m-p/5294053#M596477</link>
      <description>&lt;P&gt;Thank you Boort.&amp;nbsp; I've made some progress.&amp;nbsp; My wireless client is now attempting to be redirected.&lt;/P&gt;&lt;P&gt;Still some work to do but progress is being made.&lt;/P&gt;</description>
      <pubDate>Tue, 27 May 2025 11:05:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wireless-guest-in-an-sd-access-network/m-p/5294053#M596477</guid>
      <dc:creator>KevinR99</dc:creator>
      <dc:date>2025-05-27T11:05:57Z</dc:date>
    </item>
    <item>
      <title>Re: Wireless guest in an SD Access network</title>
      <link>https://community.cisco.com/t5/network-access-control/wireless-guest-in-an-sd-access-network/m-p/5294577#M596524</link>
      <description>&lt;P&gt;Great! Glad to help. Is there still problems getting the client authenticated?&lt;/P&gt;</description>
      <pubDate>Wed, 28 May 2025 15:46:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wireless-guest-in-an-sd-access-network/m-p/5294577#M596524</guid>
      <dc:creator>Boort</dc:creator>
      <dc:date>2025-05-28T15:46:36Z</dc:date>
    </item>
    <item>
      <title>Re: Wireless guest in an SD Access network</title>
      <link>https://community.cisco.com/t5/network-access-control/wireless-guest-in-an-sd-access-network/m-p/5294783#M596540</link>
      <description>&lt;P&gt;All working now Boort.&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;</description>
      <pubDate>Thu, 29 May 2025 08:34:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wireless-guest-in-an-sd-access-network/m-p/5294783#M596540</guid>
      <dc:creator>KevinR99</dc:creator>
      <dc:date>2025-05-29T08:34:56Z</dc:date>
    </item>
  </channel>
</rss>

