<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Clients can still access Internet while in Web Auth Pending state in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/clients-can-still-access-internet-while-in-web-auth-pending/m-p/5040756#M268310</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;FONT color="#FF6600"&gt;&lt;EM&gt; &amp;nbsp;- FYI :&amp;nbsp;&lt;/EM&gt;&lt;/FONT&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvu72447" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvu72447&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; Regardless of the bug report , relevance w.r.t current ios-xe version used , from a support point of view ; it becomes more &lt;STRONG&gt;relevant&lt;/STRONG&gt; if someone can &lt;STRONG&gt;repeat&lt;/STRONG&gt; the problem on that version as you are observing and or testing it ,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
    <pubDate>Fri, 15 Mar 2024 12:04:06 GMT</pubDate>
    <dc:creator>Mark Elsen</dc:creator>
    <dc:date>2024-03-15T12:04:06Z</dc:date>
    <item>
      <title>Clients can still access Internet while in Web Auth Pending state</title>
      <link>https://community.cisco.com/t5/wireless/clients-can-still-access-internet-while-in-web-auth-pending/m-p/5040737#M268307</link>
      <description>&lt;P&gt;Running a WLC-9800-80 running Cisco IOS-XE 17.9.5 in my lab, testing Web Auth Redirect for a simple consent page (Not collecting any email or data) on our open guest network.&lt;/P&gt;&lt;P&gt;Clients can successfully connect to the guest WLAN and are presented the proper consent page while being placed in a "Web Auth Pending" state. If I click the accept button, client move to Run. So that all works properly. The problem I have is that while still in the Web Auth Pending state, my clients can reach the Internet successfully by opening another browser tab, pinging Internet addresses, etc. Is this expected behavior for a device on an open network? I have tested this with Windows 10/11 clients, Apple devices, and Linux PCs. All exhibit the same behavior. Windows actually shows that the device is connected without Internet access, yet it does have Internet access!&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2024 11:31:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/clients-can-still-access-internet-while-in-web-auth-pending/m-p/5040737#M268307</guid>
      <dc:creator>lawrence.allhands</dc:creator>
      <dc:date>2024-03-15T11:31:27Z</dc:date>
    </item>
    <item>
      <title>Re: Clients can still access Internet while in Web Auth Pending state</title>
      <link>https://community.cisco.com/t5/wireless/clients-can-still-access-internet-while-in-web-auth-pending/m-p/5040756#M268310</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;FONT color="#FF6600"&gt;&lt;EM&gt; &amp;nbsp;- FYI :&amp;nbsp;&lt;/EM&gt;&lt;/FONT&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvu72447" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvu72447&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; Regardless of the bug report , relevance w.r.t current ios-xe version used , from a support point of view ; it becomes more &lt;STRONG&gt;relevant&lt;/STRONG&gt; if someone can &lt;STRONG&gt;repeat&lt;/STRONG&gt; the problem on that version as you are observing and or testing it ,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2024 12:04:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/clients-can-still-access-internet-while-in-web-auth-pending/m-p/5040756#M268310</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-03-15T12:04:06Z</dc:date>
    </item>
    <item>
      <title>Re: Clients can still access Internet while in Web Auth Pending state</title>
      <link>https://community.cisco.com/t5/wireless/clients-can-still-access-internet-while-in-web-auth-pending/m-p/5041283#M268399</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;I assume that you use LWA with type consent. Right ?&lt;/P&gt;&lt;P&gt;Can you share your preauth ACL ?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Sat, 16 Mar 2024 10:43:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/clients-can-still-access-internet-while-in-web-auth-pending/m-p/5041283#M268399</guid>
      <dc:creator>Jerome BERTHIER</dc:creator>
      <dc:date>2024-03-16T10:43:58Z</dc:date>
    </item>
    <item>
      <title>Re: Clients can still access Internet while in Web Auth Pending state</title>
      <link>https://community.cisco.com/t5/wireless/clients-can-still-access-internet-while-in-web-auth-pending/m-p/5041617#M268479</link>
      <description>&lt;P&gt;Correct. And I have the LWA address set to 192.168.199.199 for the test in my lab. Here is my pre-auth ACL&lt;/P&gt;&lt;P&gt;ip access-list extended utguest_preauth&lt;BR /&gt;10 permit ip any host 192.168.199.199&lt;BR /&gt;20 deny ip any any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 17 Mar 2024 11:31:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/clients-can-still-access-internet-while-in-web-auth-pending/m-p/5041617#M268479</guid>
      <dc:creator>lawrence.allhands</dc:creator>
      <dc:date>2024-03-17T11:31:10Z</dc:date>
    </item>
    <item>
      <title>Re: Clients can still access Internet while in Web Auth Pending state</title>
      <link>https://community.cisco.com/t5/wireless/clients-can-still-access-internet-while-in-web-auth-pending/m-p/5041695#M268515</link>
      <description>&lt;P&gt;I think this is the point.&lt;/P&gt;&lt;P&gt;AireOS and IOS-XE WLC do not behave the same with preauth ACL :&lt;/P&gt;&lt;P&gt;- on AireOS, use deny statement to trigger redirect&lt;/P&gt;&lt;P&gt;- on IOS-XE, use permit statement to trigger redirect&lt;/P&gt;&lt;P&gt;So to my understanding, you ACL should be the opposite :&lt;/P&gt;&lt;P&gt;ip access-list extended utguest_preauth&lt;BR /&gt;10 deny ip any host 192.168.199.199&lt;/P&gt;&lt;P&gt;11 deny udp any host &amp;lt;your DNS resolver&amp;gt; eq 53&lt;/P&gt;&lt;P&gt;! not sure about these two next entries but you may have to open for DHCP. I don't know&lt;/P&gt;&lt;P&gt;12 deny udp any eq 68 any eq 67&lt;/P&gt;&lt;P&gt;13 deny udp any eq 67 any eq 68&lt;/P&gt;&lt;P&gt;! final permit to trigger for all traffic except previous entries&lt;BR /&gt;20 permit ip any any&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Sun, 17 Mar 2024 15:24:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/clients-can-still-access-internet-while-in-web-auth-pending/m-p/5041695#M268515</guid>
      <dc:creator>Jerome BERTHIER</dc:creator>
      <dc:date>2024-03-17T15:24:59Z</dc:date>
    </item>
    <item>
      <title>Re: Clients can still access Internet while in Web Auth Pending state</title>
      <link>https://community.cisco.com/t5/wireless/clients-can-still-access-internet-while-in-web-auth-pending/m-p/5041712#M268523</link>
      <description>&lt;P&gt;Thanks for that - tried it and got the same results&lt;/P&gt;</description>
      <pubDate>Sun, 17 Mar 2024 16:18:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/clients-can-still-access-internet-while-in-web-auth-pending/m-p/5041712#M268523</guid>
      <dc:creator>lawrence.allhands</dc:creator>
      <dc:date>2024-03-17T16:18:06Z</dc:date>
    </item>
    <item>
      <title>Re: Clients can still access Internet while in Web Auth Pending state</title>
      <link>https://community.cisco.com/t5/wireless/clients-can-still-access-internet-while-in-web-auth-pending/m-p/5041875#M268589</link>
      <description>&lt;P&gt;OK so maybe you hit the bug pointed out by marce1000&lt;/P&gt;&lt;P&gt;Open a support case. That's the best way in your case.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Sun, 17 Mar 2024 20:27:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/clients-can-still-access-internet-while-in-web-auth-pending/m-p/5041875#M268589</guid>
      <dc:creator>Jerome BERTHIER</dc:creator>
      <dc:date>2024-03-17T20:27:37Z</dc:date>
    </item>
    <item>
      <title>Re: Clients can still access Internet while in Web Auth Pending state</title>
      <link>https://community.cisco.com/t5/wireless/clients-can-still-access-internet-while-in-web-auth-pending/m-p/5041931#M268594</link>
      <description>&lt;P&gt;Yes I have a TAC case open. Thanks all!&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 00:10:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/clients-can-still-access-internet-while-in-web-auth-pending/m-p/5041931#M268594</guid>
      <dc:creator>lawrence.allhands</dc:creator>
      <dc:date>2024-03-18T00:10:49Z</dc:date>
    </item>
  </channel>
</rss>

