<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Guest WLAN and Web Auth? in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/guest-wlan-and-web-auth/m-p/2280294#M164940</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you get the webauth page when you manually enter the following url&lt;BR /&gt;&lt;BR /&gt;Https://&lt;VIRTUAL ip=""&gt;/login.html&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/VIRTUAL&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 11 Sep 2013 01:17:34 GMT</pubDate>
    <dc:creator>Viten Patel</dc:creator>
    <dc:date>2013-09-11T01:17:34Z</dc:date>
    <item>
      <title>Guest WLAN and Web Auth?</title>
      <link>https://community.cisco.com/t5/wireless/guest-wlan-and-web-auth/m-p/2280293#M164939</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;Maybe someone can help me out?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just finished setting up a trial "Cisco Virtual Wireless Controller" with nearly the same configuration as our Physical &lt;/P&gt;&lt;P&gt;"Cisco Wireless Controller" with the exception of having 2 ports.&amp;nbsp; Anyhow, I managed to get everything working except for the WEB AUTH on the Guest WLAN.&amp;nbsp; When a client connects, he gets a DHCP address from our ASA but when we try to get to a website, we never reach the WEB AUTH page.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I tried so far is..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;add a DNS Host Name to the virtual interface and assign it to our internal DNS server.&lt;UL&gt;&lt;LI&gt;dns name was resolving but we were unable to ping 1.1.1.1&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;changed the virtual ip from 1.1.1.1 to 2.2.2.2 and modified the DNS entry&lt;UL&gt;&lt;LI&gt;dns name resoved but still could not ping 2.2.2.2(I think this is normal)&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;changed the virtual IP to a private address of 192.168.102.1 and modified the dns entry&lt;UL&gt;&lt;LI&gt;same result&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've attached some screenshots of our configuration.&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 07:48:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-wlan-and-web-auth/m-p/2280293#M164939</guid>
      <dc:creator>fbibeau</dc:creator>
      <dc:date>2021-07-04T07:48:21Z</dc:date>
    </item>
    <item>
      <title>Re: Guest WLAN and Web Auth?</title>
      <link>https://community.cisco.com/t5/wireless/guest-wlan-and-web-auth/m-p/2280294#M164940</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you get the webauth page when you manually enter the following url&lt;BR /&gt;&lt;BR /&gt;Https://&lt;VIRTUAL ip=""&gt;/login.html&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/VIRTUAL&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Sep 2013 01:17:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-wlan-and-web-auth/m-p/2280294#M164940</guid>
      <dc:creator>Viten Patel</dc:creator>
      <dc:date>2013-09-11T01:17:34Z</dc:date>
    </item>
    <item>
      <title>Re: Guest WLAN and Web Auth?</title>
      <link>https://community.cisco.com/t5/wireless/guest-wlan-and-web-auth/m-p/2280295#M164941</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;STRONG&gt;Troubleshooting Web Authentication&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;After you configure web authentication, if the feature does not work as expected, complete these&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;troubleshooting steps:&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Check if the client gets an IP address. If not, users can uncheck&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;DHCP Required&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;on the WLAN and&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;give the wireless client a static IP address. This assumes association with the access point. Refer to&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;the&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;IP addressing issues&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;section of&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Troubleshooting Client Issues in the Cisco Unified Wireless&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Network for troubleshooting DHCP related issues&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;1. &lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;On WLC versions earlier than 3.2.150.10, you must manually enter&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;A class="jive-link-external-small" href="https://1.1.1.1/login.html"&gt;https://1.1.1.1/login.html&lt;/A&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;in&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;order to navigate to the web authentication window.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;The next step in the process is DNS resolution of the URL in the web browser. When a WLAN client&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;connects to a WLAN configured for web authentication, the client obtains an IP address from the&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;DHCP server. The user opens a web browser and enters a website address. The client then performs&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;the DNS resolution to obtain the IP address of the website. Now, when the client tries to reach the&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;website, the WLC intercepts the HTTP Get session of the client and redirects the user to the web&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;authentication login page.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;2. &lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Therefore, ensure that the client is able to perform DNS resolution for the redirection to work. On&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Windows, choose&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Start &amp;gt; Run&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;, enter&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;CMD&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;in order to open a command window, and do a&amp;nbsp; nslookup&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;www.cisco.com" and see if the IP address comes back.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;On Macs/Linux: open a terminal window and do a&amp;nbsp; nslookup www.cisco.com" and see if the IP&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;address comes back.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;If you believe the client is not getting DNS resolution, you can either:&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN&gt;Enter either the IP address of the URL (for example, &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com"&gt;http://www.cisco.com&lt;/A&gt;&lt;SPAN&gt; is&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;A class="jive-link-external-small" href="http://198.133.219.25"&gt;http://198.133.219.25&lt;/A&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;♦ &lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Try to directly reach the controller's webauth page with&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;A class="jive-link-external-small" href="https://"&gt;https://&lt;/A&gt;&lt;SPAN&gt;&lt;VIRTUAL_INTERFACE_IP_ADDRESS&gt;/login.html. Typically this is &lt;/VIRTUAL_INTERFACE_IP_ADDRESS&gt;&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://1.1.1.1/login.html"&gt;http://1.1.1.1/login.html&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;♦ &lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Does entering this URL bring up the web page? If yes, it is most likely a DNS problem. It might also&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;be a certificate problem. The controller, by default, uses a self−signed certificate and most web&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;browsers warn against using them.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;3. &lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;For web authentication using customized web page, ensure that the HTML code for the customized&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;web page is appropriate.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;You can download a sample Web Authentication script from Cisco Software Downloads. For&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;example, for the 4400 controllers, choose&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Products &amp;gt; Wireless &amp;gt; Wireless LAN Controller &amp;gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Standalone Controllers &amp;gt; Cisco 4400 Series Wireless LAN Controllers &amp;gt; Cisco 4404 Wireless&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;LAN Controller &amp;gt; Software on Chassis &amp;gt; Wireless Lan Controller Web Authentication&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Bundle−1.0.1&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;and download the&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;webauth_bundle.zip&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;file.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;These parameters are added to the URL when the user's Internet browser is redirected to the&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;customized login page:&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;4. &lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;ap_mac The MAC address of the access point to which the wireless user is associated.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;♦ &lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;switch_url The URL of the controller to which the user credentials should be posted.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;♦ &lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;redirect The URL to which the user is redirected after authentication is successful.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;♦ &lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;statusCode The status code returned from the controller's web authentication server.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;♦ &lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;wlan The WLAN SSID to which the wireless user is associated.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;♦ &lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;These are the available status codes:&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Status Code 1: "You are already logged in. No further action is required on your part."&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;♦ &lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Status Code 2: "You are not configured to authenticate against web portal. No further action&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;is required on your part."&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;♦ &lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Status Code 3: "The username specified cannot be used at this time. Perhaps the username is&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;already logged into the system?"&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;♦ &lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Status Code 4: "You have been excluded."&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;♦ &lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Status Code 5: "The User Name and Password combination you have entered is invalid.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Please try again."&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;♦ &lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;All the files and pictures that need to appear on the Customized web page should be bundled into a&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;.tar file before uploading to the WLC. Ensure that one of the files included in the tar bundle is&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;login.html. You receive this error message if you do not include the login.html file:&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Refer to the Guidelines for Customized Web Authentication section of Wireless LAN Controller Web&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Authentication Configuration Example for more information on how to create a customized web&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;authentication window.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Note: &lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Files that are large and files that have long names will result in an extraction error. It is&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;recommended that pictures are in .jpg format.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;5. &lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Internet Explorer 6.0 SP1 or later is the browser recommended for the use of web authentication.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Other browsers may or may not work.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;6. &lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Ensure that the&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Scripting&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;option is not blocked on the client browser as the customized web page on&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;the WLC is basically an HTML script. On IE 6.0, this is disabled by default for security purposes.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;7. &lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Note: &lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;The Pop Up blocker needs to be disabled on the browser if you have configured any Pop Up&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;messages for the user.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Note: &lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;If you browse to an&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;https&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;site, redirection does not work. Refer to Cisco bug ID &lt;A href="https://www.cisco.com/cisco/psn/bssprt/bss?searchType=bstbugidsearch&amp;amp;page=bstBugDetail&amp;amp;BugID=CSCar04580" target="_blank"&gt;CSCar04580&lt;/A&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;(registered customers only) for more information.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;If you have a&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;host name&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;configured for the&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;virtual interface&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;of the WLC, make sure that the DNS&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;resolution is available for the host name of the virtual interface.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Note: &lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Navigate to the&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Controller &amp;gt; Interfaces&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;menu from the WLC GUI in order to assign a&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;DNS&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;hostname&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;to the virtual interface.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;8. &lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Sometimes the firewall installed on the client computer blocks the web authentication login page.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Disable the firewall before you try to access the login page. The firewall can be enabled again once&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;the web authentication is completed.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;9. &lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Topology/solution firewall can be placed between the client and web−auth server, which depends on&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;the network. As for each network design/solution implemented, the end user should make sure these&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;ports are allowed on the network firewall.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Protocol&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Port&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;HTTP/HTTPS Traffic&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;TCP port 80/443&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;CAPWAP Data/Control Traffic&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;UDP port 5247/5246&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;LWAPP Data/Control Traffic&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;(before rel 5.0)&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;UDP port 12222/12223&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;EOIP packets&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;IP protocol 97&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Mobility&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;UDP port 16666 (non&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;secured) UDP port 16667&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;(secured IPSEC tunnel)&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;10. &lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;For web authentication to occur, the client should first associate to the appropriate WLAN on the&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;WLC. Navigate to the&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Monitor &amp;gt; Clients&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;menu on the WLC GUI in order to see if the client is&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;associated to the WLC. Check if the client has a valid IP address.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;11. &lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Disable the Proxy Settings on the client browser until web authentication is completed.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;12. &lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;The default web authentication method is PAP. Ensure that PAP authentication is allowed on the&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;RADIUS server for this to work. In order to check the status of client authentication, check the&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;debugs and log messages from the RADIUS server. You can use the&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;debug aaa all&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;command on the&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;WLC to view the debugs from the RADIUS server.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;13. &lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Update the hardware driver on the computer to the latest code from manufacturer's website.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;14. &lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Verify settings in the supplicant (program on laptop).&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;15. &lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;When you use the Windows Zero Config supplicant built into Windows:&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Verify user has latest patches installed.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;♦ &lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Run debugs on supplicant.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;♦ &lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;16. &lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;On the client, turn on the EAPOL (WPA+WPA2) and RASTLS logs from a command window, Start&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&amp;gt; Run &amp;gt; CMD:&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;netsh ras set tracing eapol enable&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;netsh ras set tracing rastls enable&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;In order to disable the logs, run the same command but replace enable with disable. For XP, all logs&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;will be located in C:\Windows\tracing.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;17. &lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;If you still have no login web page, collect and analyze this output from a single client:&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;debug client &lt;MAC_ADDRESS in="" format="" xx:xx:xx:xx:xx=""&gt;&lt;/MAC_ADDRESS&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;debug dhcp message enable&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;18. &lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;debug aaa all enable&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;debug dot1x aaa enable&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;debug mobility handoff enable&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;If the issue is not resolved after you complete these steps, collect these debugs and use the TAC&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;Service Request Tool (registered customers only) in order to open a Service Request.&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;debug pm ssh−appgw enable&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;debug pm ssh−tcp enable&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;debug pm rules enable&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;debug emweb server enable&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt; line-height: normal;"&gt;debug pm ssh−engine enable packet &lt;CLIENT ip=""&gt;&lt;/CLIENT&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Sep 2013 02:37:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-wlan-and-web-auth/m-p/2280295#M164941</guid>
      <dc:creator>Saurav Lodh</dc:creator>
      <dc:date>2013-09-11T02:37:27Z</dc:date>
    </item>
    <item>
      <title>Re: Guest WLAN and Web Auth?</title>
      <link>https://community.cisco.com/t5/wireless/guest-wlan-and-web-auth/m-p/2280296#M164942</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is one good doc of web auth troubleshooting. Please find the same from the below link and try to tshoot&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps10315/products_tech_note09186a0080a38c11.shtml"&gt;http://www.cisco.com/en/US/products/ps10315/products_tech_note09186a0080a38c11.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Sep 2013 18:53:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-wlan-and-web-auth/m-p/2280296#M164942</guid>
      <dc:creator>Ravi Singh</dc:creator>
      <dc:date>2013-09-11T18:53:08Z</dc:date>
    </item>
  </channel>
</rss>

