<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic WLC external web authentication in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wlc-external-web-authentication/m-p/2243277#M119216</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Vijay,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can you check what authorization policy are you hitting for L3 auth and L2 auth on ISE? maybe you will need add/modify a rule on ISE.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 18 Jul 2013 16:39:02 GMT</pubDate>
    <dc:creator>Viten Patel</dc:creator>
    <dc:date>2013-07-18T16:39:02Z</dc:date>
    <item>
      <title>WLC external web authentication</title>
      <link>https://community.cisco.com/t5/wireless/wlc-external-web-authentication/m-p/2243272#M119211</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are using auto anchor mechanism for guest clients . Anchor controller placed after the Firewall. Guest vlan will&amp;nbsp; be having reachabilty only to internet.&lt;/P&gt;&lt;P&gt;We want to use ISE for web authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since client subnet is not having reachbility to ISE , redirection page is not coming and we cant allow clients subnet to access internal resource . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So , is there a way WLC will forward the own web auth page to clients , but it needs to check with ISE for the&amp;nbsp; crdentials ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vijay.&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 07:27:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-external-web-authentication/m-p/2243272#M119211</guid>
      <dc:creator>vijay kumar</dc:creator>
      <dc:date>2021-07-04T07:27:14Z</dc:date>
    </item>
    <item>
      <title>WLC external web authentication</title>
      <link>https://community.cisco.com/t5/wireless/wlc-external-web-authentication/m-p/2243273#M119212</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a short cisco doc that would answer your queries. It also has a configurable example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a008076f974.shtml"&gt;http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a008076f974.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Jul 2013 03:00:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-external-web-authentication/m-p/2243273#M119212</guid>
      <dc:creator>mmangat</dc:creator>
      <dc:date>2013-07-18T03:00:11Z</dc:date>
    </item>
    <item>
      <title>WLC external web authentication</title>
      <link>https://community.cisco.com/t5/wireless/wlc-external-web-authentication/m-p/2243274#M119213</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mantej Magat ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your reply &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have gone through the document . As per it ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Login page is from&amp;nbsp; external web server , and authentication of users against local data base in WLC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But our requirement is, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Login page is from WLC , and authentication of users from ISE database .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IS that possible?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Jul 2013 03:16:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-external-web-authentication/m-p/2243274#M119213</guid>
      <dc:creator>vijay kumar</dc:creator>
      <dc:date>2013-07-18T03:16:34Z</dc:date>
    </item>
    <item>
      <title>Re: WLC external web authentication</title>
      <link>https://community.cisco.com/t5/wireless/wlc-external-web-authentication/m-p/2243275#M119214</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes that is possible.&lt;BR /&gt;&lt;BR /&gt;Under the wlan configurations&lt;BR /&gt;• set layer 2 security to none&lt;BR /&gt;• set layer 3 to webauth (override to local or make sure global is set to local)&lt;BR /&gt;• point to the radius server (ISE) on the AAA servers tab. On the same tab change the authentication priority for webauth to radius &amp;gt; local&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Jul 2013 05:57:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-external-web-authentication/m-p/2243275#M119214</guid>
      <dc:creator>Viten Patel</dc:creator>
      <dc:date>2013-07-18T05:57:32Z</dc:date>
    </item>
    <item>
      <title>WLC external web authentication</title>
      <link>https://community.cisco.com/t5/wireless/wlc-external-web-authentication/m-p/2243276#M119215</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Viten ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Really thanks for your help . It got worked .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But again , ISE and AD communication is not happening properly for L3 SSID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;When the user tries to get connect , he is getting redirect URL . But during the authentication , we are getting error in ISE as&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;"ise has problems communicating with active directory&amp;nbsp; using its machine credentials "&amp;nbsp; and authentication getting failed .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apart from this , we have one more SSID configured for L2 auth , and authentication is happening properly between client ,ISE and AD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But only for L3 it is not working. could you pls suggest &lt;SPAN __jive_emoticon_name="confused" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Jul 2013 12:41:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-external-web-authentication/m-p/2243276#M119215</guid>
      <dc:creator>vijay kumar</dc:creator>
      <dc:date>2013-07-18T12:41:25Z</dc:date>
    </item>
    <item>
      <title>WLC external web authentication</title>
      <link>https://community.cisco.com/t5/wireless/wlc-external-web-authentication/m-p/2243277#M119216</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Vijay,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can you check what authorization policy are you hitting for L3 auth and L2 auth on ISE? maybe you will need add/modify a rule on ISE.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Jul 2013 16:39:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-external-web-authentication/m-p/2243277#M119216</guid>
      <dc:creator>Viten Patel</dc:creator>
      <dc:date>2013-07-18T16:39:02Z</dc:date>
    </item>
    <item>
      <title>WLC external web authentication</title>
      <link>https://community.cisco.com/t5/wireless/wlc-external-web-authentication/m-p/2243278#M119217</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Viten ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have allowed the default permit access authorization policy for the clients once it get authenticates.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For authentication policy , in default list we are using external identity store as AD server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Jul 2013 20:24:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-external-web-authentication/m-p/2243278#M119217</guid>
      <dc:creator>vijay kumar</dc:creator>
      <dc:date>2013-07-18T20:24:13Z</dc:date>
    </item>
    <item>
      <title>WLC external web authentication</title>
      <link>https://community.cisco.com/t5/wireless/wlc-external-web-authentication/m-p/2243279#M119218</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per your query i can suggest you the following solution-&lt;/P&gt;&lt;H2&gt;Configure&lt;/H2&gt;&lt;P&gt;In this section, you are presented with the information to configure the features described in this document.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt; Use the &lt;A href="http://tools.cisco.com/Support/CLILookup/cltSearchAction.do"&gt;Command Lookup Tool&lt;/A&gt; (&lt;A href="http://tools.cisco.com/RPF/register/register.do"&gt;registered&lt;/A&gt; customers only) in order to find more information on the commands used in this document.&lt;/P&gt;&lt;P&gt;Complete these steps in order to configure the devices for EAP authentication:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;•1.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a0080665d18.shtml#c1"&gt;Configure the WLC for basic operation and register the Lightweight APs to the controller.&lt;/A&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;•2.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a0080665d18.shtml#c2"&gt;Configure the WLC for RADIUS authentication through an external RADIUS server.&lt;/A&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;•3.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a0080665d18.shtml#c3"&gt;Configure the WLAN parameters.&lt;/A&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;•4.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a0080665d18.shtml#c4"&gt;Configure Cisco Secure ACS as the external RADIUS server and create a user database for authenticating clients.&lt;/A&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this will help you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jul 2013 21:45:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-external-web-authentication/m-p/2243279#M119218</guid>
      <dc:creator>Abhishek Abhishek</dc:creator>
      <dc:date>2013-07-19T21:45:50Z</dc:date>
    </item>
  </channel>
</rss>

