<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WLC 9800-80 fail to redurect to guest portal in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wlc-9800-80-fail-to-redurect-to-guest-portal/m-p/4926285#M260823</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1110274"&gt;@eeebbunee&lt;/a&gt;&amp;nbsp;either enable logging on your terminal emulator and log the output to file or if you're using ssh on a linux box then you can &lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;ssh &amp;lt;hostname&amp;gt; | tee &amp;lt;filename&amp;gt;&lt;/FONT&gt;&lt;/STRONG&gt; and the output will be logged to &amp;lt;filename&amp;gt;.&lt;/P&gt;</description>
    <pubDate>Tue, 19 Sep 2023 23:07:31 GMT</pubDate>
    <dc:creator>Rich R</dc:creator>
    <dc:date>2023-09-19T23:07:31Z</dc:date>
    <item>
      <title>WLC 9800-80 fail to redurect to guest portal</title>
      <link>https://community.cisco.com/t5/wireless/wlc-9800-80-fail-to-redurect-to-guest-portal/m-p/4688545#M246152</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We have WLC 9800-80 and use a third-party server to authenticate guest clients using guest portal.&amp;nbsp;&lt;/P&gt;&lt;P&gt;When a client try to authenticate, they get IP address but the guest portal behave differently every time we try to login. These behaviors happen with exact same configuration.&lt;/P&gt;&lt;P&gt;We face these three scenarios:&lt;/P&gt;&lt;P&gt;1- Client get the IP-address&amp;gt; the splash pages opens&amp;gt; client write the authentication information and the get connected. No problem at all!&lt;/P&gt;&lt;P&gt;2- Client get the IP-address, the splash page does not comes up but the browser page get into a loop and every few seconds, same url adds to the current url. For ex. if the guest urls is test.com, the loop types, test.com in the url and write again test.com after test.com every time the webpage loops. It continues without stopping and client does not get connect.&lt;/P&gt;&lt;P&gt;3- Client get the IP-address&amp;gt; the splash pages opens&amp;gt; client write the authentication information&amp;gt; Splash page redirect the client to another page with this url: &lt;EM&gt;&lt;A href="https://1.1.1.1/login.html" target="_blank" rel="noopener"&gt;https://1.1.1.1/login.html&lt;/A&gt;&lt;/EM&gt; and it warns for certificate error. (Even we have a valid certificate on our authenticator server).&lt;/P&gt;&lt;P&gt;The authentication server works well with our WLC 8540 but the new WLC 9800 get in trouble.&lt;/P&gt;&lt;P&gt;Any Idea how we can fix the guest authentication?&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2022 12:03:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-9800-80-fail-to-redurect-to-guest-portal/m-p/4688545#M246152</guid>
      <dc:creator>DexterRoot</dc:creator>
      <dc:date>2022-09-16T12:03:38Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 9800-80 fail to redurect to guest portal</title>
      <link>https://community.cisco.com/t5/wireless/wlc-9800-80-fail-to-redurect-to-guest-portal/m-p/4688609#M246158</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;SPAN&gt;-&amp;nbsp; For starters and or a good place to start r&lt;/SPAN&gt;eview the&lt;STRONG&gt;&lt;SPAN&gt;&amp;nbsp;current&amp;nbsp;&lt;/SPAN&gt;9800-80&lt;/STRONG&gt;&amp;nbsp; &amp;nbsp;&lt;STRONG&gt;configuration&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;with the CLI command :&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;FONT color="#008000"&gt;&lt;STRONG&gt;show&amp;nbsp; tech&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;&lt;U&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;wireless&lt;/U&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;, have the output analyzed by&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://cway.cisco.com/tools/WirelessAnalyzer/" target="_blank" rel="noopener nofollow noreferrer" data-saferedirecturl="https://www.google.com/url?q=https://cway.cisco.com/tools/WirelessAnalyzer/&amp;amp;source=gmail&amp;amp;ust=1662270212514000&amp;amp;usg=AOvVaw1v8X824xUFwNwiDM_o5Fxf"&gt;https://cway.cisco.com/&lt;WBR /&gt;tools/WirelessAnalyzer/&lt;/A&gt;&amp;nbsp; , please note do not use classical&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;show tech-support&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(short version) , use the command denoted in green for Wireless Analyzer.&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Checkout all advisories!&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2022 13:58:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-9800-80-fail-to-redurect-to-guest-portal/m-p/4688609#M246158</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2022-09-16T13:58:08Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 9800-80 fail to redurect to guest portal</title>
      <link>https://community.cisco.com/t5/wireless/wlc-9800-80-fail-to-redurect-to-guest-portal/m-p/4688940#M246185</link>
      <description>&lt;P&gt;You should not be using 1.1.1.1 for your captive portal - you need a FQDN DNS domain name which matches your certificate otherwise it simply won't be reliable.&lt;BR /&gt;Make sure your pre-auth URLs and ACLs allow access to all the resources needed to load the captive portal and content.&amp;nbsp; Watch out for 3rd party content included in any of those pages - like fonts, jscript, images, social media links, tracking tags etc which will all trigger redirects if not permitted.&lt;/P&gt;</description>
      <pubDate>Sat, 17 Sep 2022 13:06:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-9800-80-fail-to-redurect-to-guest-portal/m-p/4688940#M246185</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2022-09-17T13:06:15Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 9800-80 fail to redurect to guest portal</title>
      <link>https://community.cisco.com/t5/wireless/wlc-9800-80-fail-to-redurect-to-guest-portal/m-p/4688951#M246187</link>
      <description>&lt;P&gt;Make sure that you have a proper working DNS setup and all the pre-auth ACL's are configured to allow DNS, DHCP and HTTP access to your captive portal solution. Also share how is your paramter map is configured in you 9800 WLC, importantly make sure that ip http server is enabled in your WLC, this will enable http access to WLC management GUI as well. Below is my parameter map when HTTP server is disabled in my WLC, however I still recommend that you enable it and check.&lt;/P&gt;
&lt;P&gt;parameter-map type webauth global&lt;BR /&gt;type webauth&lt;BR /&gt;virtual-ip ipv4 192.0.2.1&lt;BR /&gt;webauth-http-enable&lt;/P&gt;
&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/244975"&gt;@Rich R&lt;/a&gt;&amp;nbsp;mentioned 1.1.1.1 is now a public IP, so not recommended by Cisco to use it anymore to be used within an organization. Consider changing that as well.&lt;/P&gt;
&lt;P&gt;Certificate error can be mostly due to DNS issues, make sure that clients can resolve DNS before authenticated to captive portal.&lt;/P&gt;</description>
      <pubDate>Sat, 17 Sep 2022 13:50:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-9800-80-fail-to-redurect-to-guest-portal/m-p/4688951#M246187</guid>
      <dc:creator>Arshad Safrulla</dc:creator>
      <dc:date>2022-09-17T13:50:21Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 9800-80 fail to redurect to guest portal</title>
      <link>https://community.cisco.com/t5/wireless/wlc-9800-80-fail-to-redurect-to-guest-portal/m-p/4689046#M246191</link>
      <description>&lt;P&gt;I had the similar issues&lt;/P&gt;
&lt;P&gt;You have to get CA signed certificate (that issued for your 9800 virtual IP address) installed on your 9800. Most likely you have to use OpenSSL (use v 1.1.1)&amp;nbsp; to generate CSR &amp;amp; follow the instruction given below document to install the cert for WebAuth&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213917-generate-csr-for-third-party-certificate.html#anc15" target="_self"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213917-generate-csr-for-third-party-certificate.html#anc15&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For external WebAuth, those ACL will created automatically, so you do not want to define them manually.&lt;/P&gt;
&lt;P&gt;HTH&lt;BR /&gt;Rasika&lt;BR /&gt;*** Pls rate all useful responses ***&lt;/P&gt;</description>
      <pubDate>Sat, 17 Sep 2022 22:33:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-9800-80-fail-to-redurect-to-guest-portal/m-p/4689046#M246191</guid>
      <dc:creator>Rasika Nayanajith</dc:creator>
      <dc:date>2022-09-17T22:33:53Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 9800-80 fail to redurect to guest portal</title>
      <link>https://community.cisco.com/t5/wireless/wlc-9800-80-fail-to-redurect-to-guest-portal/m-p/4689100#M246193</link>
      <description>&lt;P&gt;The automatically created ACL only includes the single external portal IP.&amp;nbsp; If there's more than one IP you need to use the parameter map to add extra lines (max 9 lines).&amp;nbsp; Also must use the URL ACL for any external content used in the portal content.&amp;nbsp; Many now offer social media login etc which all require domains to be included in URL list as well as for any tracking tags, fonts, scripts used in the page.&lt;/P&gt;</description>
      <pubDate>Sun, 18 Sep 2022 09:35:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-9800-80-fail-to-redurect-to-guest-portal/m-p/4689100#M246193</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2022-09-18T09:35:07Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 9800-80 fail to redurect to guest portal</title>
      <link>https://community.cisco.com/t5/wireless/wlc-9800-80-fail-to-redurect-to-guest-portal/m-p/4689102#M246194</link>
      <description>&lt;P&gt;Good points&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/244975"&gt;@Rich R&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Sep 2022 09:39:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-9800-80-fail-to-redurect-to-guest-portal/m-p/4689102#M246194</guid>
      <dc:creator>Rasika Nayanajith</dc:creator>
      <dc:date>2022-09-18T09:39:03Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 9800-80 fail to redurect to guest portal</title>
      <link>https://community.cisco.com/t5/wireless/wlc-9800-80-fail-to-redurect-to-guest-portal/m-p/4926066#M260819</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291804"&gt;@Mark Elsen&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your comment.&lt;/P&gt;&lt;P&gt;Is there any way that I can grab the 'sh tech wireless' as a file so that I can upload to Wireless Analyzer?&lt;/P&gt;&lt;P&gt;The result is too long to get, so I would get your opinion.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you so much.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 18:34:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-9800-80-fail-to-redurect-to-guest-portal/m-p/4926066#M260819</guid>
      <dc:creator>eeebbunee</dc:creator>
      <dc:date>2023-09-19T18:34:13Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 9800-80 fail to redurect to guest portal</title>
      <link>https://community.cisco.com/t5/wireless/wlc-9800-80-fail-to-redurect-to-guest-portal/m-p/4926285#M260823</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1110274"&gt;@eeebbunee&lt;/a&gt;&amp;nbsp;either enable logging on your terminal emulator and log the output to file or if you're using ssh on a linux box then you can &lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;ssh &amp;lt;hostname&amp;gt; | tee &amp;lt;filename&amp;gt;&lt;/FONT&gt;&lt;/STRONG&gt; and the output will be logged to &amp;lt;filename&amp;gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 23:07:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-9800-80-fail-to-redurect-to-guest-portal/m-p/4926285#M260823</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2023-09-19T23:07:31Z</dc:date>
    </item>
  </channel>
</rss>

