<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 9800 External Webauth in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/9800-external-webauth/m-p/4642750#M243901</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm currently setting up External Webauth on a Cisco 9800 and I'm trying to work out what commands need to be configured under the global parameter map. So far I have the following&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;parameter-map type webauth global&lt;BR /&gt;&amp;nbsp;virtual-ip ipv4 192.0.2.1 virtual-host wifi.domain.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;trustpoint &amp;lt;trustpoint for wifi.domain.com&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However I'm unsure if I need any of the following commands&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;intercept-https-enable&lt;BR /&gt;webauth-http-enable&lt;BR /&gt;secure-webauth-disable&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is going to be used for a public hotspot. I know that some devices will complain if they are redirected to a non-secure site so I'm assuming that 'secure-webauth-disable' is probably not recommended, however I'm unsure about the other commands. What have other configured that works well for public guest wireless?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 02 Jul 2022 13:04:14 GMT</pubDate>
    <dc:creator>dm2020</dc:creator>
    <dc:date>2022-07-02T13:04:14Z</dc:date>
    <item>
      <title>9800 External Webauth</title>
      <link>https://community.cisco.com/t5/wireless/9800-external-webauth/m-p/4642750#M243901</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm currently setting up External Webauth on a Cisco 9800 and I'm trying to work out what commands need to be configured under the global parameter map. So far I have the following&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;parameter-map type webauth global&lt;BR /&gt;&amp;nbsp;virtual-ip ipv4 192.0.2.1 virtual-host wifi.domain.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;trustpoint &amp;lt;trustpoint for wifi.domain.com&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However I'm unsure if I need any of the following commands&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;intercept-https-enable&lt;BR /&gt;webauth-http-enable&lt;BR /&gt;secure-webauth-disable&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is going to be used for a public hotspot. I know that some devices will complain if they are redirected to a non-secure site so I'm assuming that 'secure-webauth-disable' is probably not recommended, however I'm unsure about the other commands. What have other configured that works well for public guest wireless?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 02 Jul 2022 13:04:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-external-webauth/m-p/4642750#M243901</guid>
      <dc:creator>dm2020</dc:creator>
      <dc:date>2022-07-02T13:04:14Z</dc:date>
    </item>
    <item>
      <title>Re: 9800 External Webauth</title>
      <link>https://community.cisco.com/t5/wireless/9800-external-webauth/m-p/4642783#M243904</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;EM&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - You may find these documents informational :&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/217457-configure-and-troubleshoot-external-web.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/217457-configure-and-troubleshoot-external-web.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/config-guide/web-authentication/b-configuring-web-based-authentication-on-cisco-catalyst-9800-series-controllers/m-external-web-authentication-configuration.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/config-guide/web-authentication/b-configuring-web-based-authentication-on-cisco-catalyst-9800-series-controllers/m-external-web-authentication-configuration.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Sat, 02 Jul 2022 16:51:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-external-webauth/m-p/4642783#M243904</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2022-07-02T16:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: 9800 External Webauth</title>
      <link>https://community.cisco.com/t5/wireless/9800-external-webauth/m-p/4642813#M243905</link>
      <description>&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've had a read and it appears that the behaviours have changed in IOS-XE 17.3 with regards to http/https for Webauth.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As we only want HTTPs access to the WLC for admin, and both HTTP and HTTPs access to the WLC for Webauth then we need to configure the following&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;parameter-map type webauth global&lt;BR /&gt;&amp;nbsp;virtual-ip ipv4 192.0.2.1 virtual-host wifi.domain.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;trustpoint &amp;lt;trustpoint for wifi.domain.com&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;webauth-http-enable&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;no ip http server&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;ip http secure-server&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Question - We also have the following configured on the WLC for hardening the web interface. Will this have an impact on Webauth or are these commands only applicable for the WLC admin web interface? I couldn't find this documented anywhere&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ip http access-class ipv4 &amp;lt;access list&amp;gt;&lt;BR /&gt;ip http authentication aaa&lt;/P&gt;&lt;P&gt;ip http tls-version TLSv1.2&lt;/P&gt;</description>
      <pubDate>Sat, 02 Jul 2022 19:13:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-external-webauth/m-p/4642813#M243905</guid>
      <dc:creator>dm2020</dc:creator>
      <dc:date>2022-07-02T19:13:44Z</dc:date>
    </item>
    <item>
      <title>Re: 9800 External Webauth</title>
      <link>https://community.cisco.com/t5/wireless/9800-external-webauth/m-p/4642864#M243906</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;nbsp; &amp;gt;...Will this have an impact on Webauth or are these commands only applicable for the WLC admin web interface? I couldn't find this documented anywhere&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;gt;...&lt;SPAN&gt;ip http tls-version TLSv1.2&lt;/SPAN&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; - I tend to believe this does not impact webauth ,&amp;nbsp; as a consistency check however for the current&amp;nbsp; 9800 configuration&amp;nbsp; you may&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;r&lt;/SPAN&gt;&lt;SPAN&gt;eview the it with the CLI command :&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#008000"&gt;show&amp;nbsp; tech&lt;STRONG&gt;&lt;U&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;wireless&lt;/U&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;, have the output analyzed by&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://cway.cisco.com/tools/WirelessAnalyzer/" target="_blank" rel="noopener nofollow noreferrer" data-saferedirecturl="https://www.google.com/url?q=https://cway.cisco.com/tools/WirelessAnalyzer/&amp;amp;source=gmail&amp;amp;ust=1656917221901000&amp;amp;usg=AOvVaw1CNWSe8fKXgkKI4o9HgAqN"&gt;https://cway.cisco.com/&lt;WBR /&gt;tools/WirelessAnalyzer/&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp; , please note do not use classical&lt;/SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;show tech-support&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;(short version) , use the command denoted in green for Wireless Analyzer&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;M.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 03 Jul 2022 06:49:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-external-webauth/m-p/4642864#M243906</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2022-07-03T06:49:05Z</dc:date>
    </item>
    <item>
      <title>Re: 9800 External Webauth</title>
      <link>https://community.cisco.com/t5/wireless/9800-external-webauth/m-p/4643010#M243913</link>
      <description>&lt;P&gt;Ours is:&lt;BR /&gt;parameter-map type webauth global&lt;BR /&gt;type webauth&lt;BR /&gt;virtual-ip ipv4 &amp;lt;ip&amp;gt; virtual-host &amp;lt;FQDN&amp;gt;&lt;BR /&gt;intercept-https-enable&lt;BR /&gt;trustpoint &amp;lt;trustpoint&amp;gt;.p12&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Don't know about the access-class or TLS and aaa definitely only applies to admin GUI.&amp;nbsp; But I do seem to recall breaking something when turning off ip http server (we have it enabled now) - possibly the device captive portal assistant redirect (which are always http to avoid cert errors).&amp;nbsp; Test with and without to confirm and let us know for the record.&lt;/P&gt;</description>
      <pubDate>Sun, 03 Jul 2022 22:51:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-external-webauth/m-p/4643010#M243913</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2022-07-03T22:51:47Z</dc:date>
    </item>
    <item>
      <title>Re: 9800 External Webauth</title>
      <link>https://community.cisco.com/t5/wireless/9800-external-webauth/m-p/4643015#M243914</link>
      <description>&lt;P&gt;Thanks for the reply. That is very helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regarding https intercept, do you have any issues with this and is there any noticeable performance issues/high CPU increase on the WLC?&lt;/P&gt;</description>
      <pubDate>Sun, 03 Jul 2022 23:43:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-external-webauth/m-p/4643015#M243914</guid>
      <dc:creator>dm2020</dc:creator>
      <dc:date>2022-07-03T23:43:27Z</dc:date>
    </item>
    <item>
      <title>Re: 9800 External Webauth</title>
      <link>https://community.cisco.com/t5/wireless/9800-external-webauth/m-p/4643154#M243917</link>
      <description>&lt;P&gt;&amp;gt;&amp;nbsp;&lt;SPAN&gt;Regarding https intercept, do you have any issues with this and is there any noticeable performance issues/high CPU increase on the WLC?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;We haven't seen any problems with it.&amp;nbsp; Obviously a user getting https redirected will get cert and/or security warnings but that's unavoidable.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jul 2022 07:50:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-external-webauth/m-p/4643154#M243917</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2022-07-04T07:50:19Z</dc:date>
    </item>
  </channel>
</rss>

