<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Guest user captive portal redirection issue in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/guest-user-captive-portal-redirection-issue/m-p/5057016#M269788</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- Have the client debugs&amp;nbsp; further analyzed with&amp;nbsp;&lt;A href="https://cway.cisco.com/wireless-debug-analyzer/" target="_blank" rel="nofollow noopener noreferrer"&gt;Wireless Debug Analyzer&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; preferably with a longer trail. Also look into :&amp;nbsp;&lt;A href="https://logadvisor.cisco.com/logadvisor/wireless/9800/9800CWA" target="_blank"&gt;https://logadvisor.cisco.com/logadvisor/wireless/9800/9800CWA&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;For looking at a summarized view at&amp;nbsp; client issues have a look at&amp;nbsp; :&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/217738-monitor-catalyst-9800-kpis-key-performa.html#anc5" target="_blank" rel="nofollow noopener noreferrer"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/217738-monitor-catalyst-9800-kpis-key-performa.html#anc5&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;Checkout the 9800 WLC configuration too using the CLI command&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#008000"&gt;&lt;STRONG&gt;show tech wireless&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;and feed the output from that into&amp;nbsp;&lt;A href="https://cway.cisco.com/wireless-config-analyzer/" target="_blank" rel="nofollow noopener noreferrer"&gt;Wireless Config Analyzer&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;- Check 9800 WLC controller software version&amp;nbsp; ; advising to go for&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#008000"&gt;&lt;STRONG&gt;17.&lt;U&gt;9.5&lt;/U&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and check again ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
    <pubDate>Fri, 05 Apr 2024 08:48:26 GMT</pubDate>
    <dc:creator>Mark Elsen</dc:creator>
    <dc:date>2024-04-05T08:48:26Z</dc:date>
    <item>
      <title>Guest user captive portal redirection issue</title>
      <link>https://community.cisco.com/t5/wireless/guest-user-captive-portal-redirection-issue/m-p/5057013#M269787</link>
      <description>&lt;P&gt;Problem with Guest user captive portal redirection problem.&lt;/P&gt;
&lt;P&gt;Looking for the help in WLC.&lt;/P&gt;
&lt;P&gt;Guest user -&amp;gt; Cisco AP -&amp;gt; WLC -&amp;gt; ISE&lt;/P&gt;
&lt;P&gt;- This problem is happening for one particular site. Other sites captive portal is working properly from the same ISE server.&lt;/P&gt;
&lt;P&gt;- Auto captive portal is not opening at guest client pc&lt;/P&gt;
&lt;P&gt;- When I am giving captive portal manually in the guest pc browser, its working. However, auto redirecting to captive portal is not happening.&lt;/P&gt;
&lt;P&gt;at WLC side, ran debugs and below are the info what i have got.&lt;/P&gt;
&lt;P&gt;IP address is getting assigned to guest user:&lt;/P&gt;
&lt;P&gt;*DHCP Socket Task: Feb 29 11:43:15.079: [SA] 22:18:38:6e:c4:09 Plumbing web-auth redirect rule due to user logout&lt;BR /&gt;*DHCP Socket Task: Feb 29 11:43:15.079: [SA] 22:18:38:6e:c4:09 192.168.150.71 WEBAUTH_REQD (8) NO release MSCB&lt;BR /&gt;*DHCP Socket Task: Feb 29 11:43:15.079: [SA] 22:18:38:6e:c4:09 Assigning Address 192.168.xxx.xxx to mobile &lt;BR /&gt;*DHCP Socket Task: Feb 29 11:43:15.079: [SA] 22:18:38:6e:c4:09 DHCP success event for client. Clearing dhcp failure count for interface power-guest_100.&lt;BR /&gt;*DHCP Socket Task: Feb 29 11:43:15.079: [SA] 22:18:38:6e:c4:09 Initiating Accounting request(0) update for mobile&lt;BR /&gt;*DHCP Socket Task: Feb 29 11:43:15.079: [SA] 22:18:38:6e:c4:09 PemLocationConfigured [1]Adding VSA with NAS update and Role[1] with state[0]&lt;/P&gt;
&lt;P&gt;Communication with ISE is also happening:&lt;/P&gt;
&lt;P&gt;pemReceiveTask: Feb 29 11:43:15.079: [SA] 22:18:38:6e:c4:09 192.168.150.71 Added NPU entry of type 2, dtlFlags 0x0&lt;BR /&gt;*aaaQueueReader: Feb 29 11:43:15.079: [SA] 22:18:38:6e:c4:09 radiusServerFallbackPassiveStateUpdate: RADIUS server is ready 10.252.yyy.zz port 1813 index 2 active 1&lt;BR /&gt;*aaaQueueReader: Feb 29 11:43:15.080: [SA] 22:18:38:6e:c4:09 radiusServerFallbackPassiveStateUpdate: RADIUS server is maybe-ready 10.252.xxx.yy port 1813 index 3 active 1&lt;BR /&gt;*aaaQueueReader: Feb 29 11:43:15.080: [SA] 22:18:38:6e:c4:09 NAI-Realm not enabled on Wlan, radius servers will be selected as usual&lt;BR /&gt;*aaaQueueReader: Feb 29 11:43:15.080: [SA] 22:18:38:6e:c4:09 Send Radius Acct Request with pktId:148 into qid:1 of server at index:2&lt;BR /&gt;*apfReceiveTask: Feb 29 11:43:15.080: [SA] 22:18:38:6e:c4:09 Recieved MS IPv4 Addr= 192.168.xxx.yy&lt;BR /&gt;*apfReceiveTask: Feb 29 11:43:15.080: [SA] 22:18:38:6e:c4:09 Recieved IPv6 addresses count: 1&lt;BR /&gt;*aaaQueueReader: Feb 29 11:43:15.080: [SA] 22:18:38:6e:c4:09 Sending the packet to v4 host 10.252.yyy.zz 1813 of length 346&lt;BR /&gt;*pemReceiveTask: Feb 29 11:43:15.080: [SA] 22:18:38:6e:c4:09 Sent an XID frame&lt;BR /&gt;*apfReceiveTask: Feb 29 11:43:15.080: [SA] 22:18:38:6e:c4:09 Updating MS IPv6[1] Addr= fe80:0000:0000:0000:2018:38ff:fe6e:c409 &lt;BR /&gt;*aaaQueueReader: Feb 29 11:43:15.080: [SA] 22:18:38:6e:c4:09 Successful transmission of Accounting-Start (pktId 148) to 10.252.xxx.yy:1813 from server queue 1, proxy&lt;/P&gt;
&lt;P&gt;*radiusTransportThread: Feb 29 11:43:15.296: [SA] 22:18:38:6e:c4:09 Counted 0 AVPs (processed 20 bytes, left 0)&lt;BR /&gt;*radiusTransportThread: Feb 29 11:43:15.296: [SA] 22:18:38:6e:c4:09 Accounting-Response received from RADIUS server 10.252.xxx.yyy (qid:1) with port:1813, pktId:148&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;*apfMsConnTask_1: Feb 29 12:18:47.395: [SA] f0:d5:bf:fe:a4:a2 Scheduling deletion of Mobile Station: (callerId: 20) in 10 seconds&lt;BR /&gt;*apfReceiveTask: Feb 29 12:18:47.620: [SA] f0:d5:bf:fe:a4:a2 Received SGT for this Client.&lt;BR /&gt;*apfReceiveTask: Feb 29 12:18:47.620: [SA] f0:d5:bf:fe:a4:a2 SGT is not applied, sgtLen 0, sgt_stringp 0x1c3ec843&lt;BR /&gt;*apfReceiveTask: Feb 29 12:18:47.620: [SA] f0:d5:bf:fe:a4:a2 AAA Override Url-Redirect '&lt;A href="https://mgwgp.power.com:8442/portal/gateway?sessionId=8b807e9a000053bf65e09fe2&amp;amp;portal=a3cc6225-905d-4ced-acdf-bc72593301be&amp;amp;action=cwa&amp;amp;token=f" target="_blank" rel="noopener"&gt;https://mgwgp.power.com:8442/portal/gateway?sessionId=8b807e9a000053bf65e09fe2&amp;amp;portal=a3cc6225-905d-4ced-acdf-bc72593301be&amp;amp;action=cwa&amp;amp;token=f&lt;/A&gt;&lt;BR /&gt;*apfReceiveTask: Feb 29 12:18:47.620: [SA] f0:d5:bf:fe:a4:a2 Redirect URL received for client from RADIUS. Client will be moved to WebAuth_Reqd state to facilitate redirection. Skip web-auth Flag = 0&lt;BR /&gt;*apfReceiveTask: Feb 29 12:18:47.620: [SA] f0:d5:bf:fe:a4:a2 Resetting web IPv4 acl from 0 to 255&lt;/P&gt;
&lt;P&gt;*apfReceiveTask: Feb 29 12:18:47.620: [SA] f0:d5:bf:fe:a4:a2 Resetting web IPv4 Flex acl from 65535 to 65535&lt;/P&gt;
&lt;P&gt;*apfReceiveTask: Feb 29 12:18:47.620: [SA] f0:d5:bf:fe:a4:a2 AAA Override Url-Redirect-Acl 'CWA_powerGuest' mapped to ACL ID 0 and Flexconnect ACL ID 65535&lt;BR /&gt;*apfReceiveTask: Feb 29 12:18:47.620: [SA] f0:d5:bf:fe:a4:a2 Applying Fabric vnid override for client f0:d5:bf:fe:a4:a2, client-&amp;gt;reap 1 ,over bits 100100,isover FALSE&lt;BR /&gt;*apfReceiveTask: Feb 29 12:18:47.620: [SA] f0:d5:bf:fe:a4:a2 override for default ap group, marking intgrp NULL&lt;BR /&gt;*apfReceiveTask: Feb 29 12:18:47.620: [SA] f0:d5:bf:fe:a4:a2 Applying Interface(power-guest_900) policy on Mobile, role Local. Ms NAC State 2 Quarantine Vlan 0 Access Vlan 100&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2024 08:30:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-user-captive-portal-redirection-issue/m-p/5057013#M269787</guid>
      <dc:creator>singhsukdeep</dc:creator>
      <dc:date>2024-04-05T08:30:14Z</dc:date>
    </item>
    <item>
      <title>Re: Guest user captive portal redirection issue</title>
      <link>https://community.cisco.com/t5/wireless/guest-user-captive-portal-redirection-issue/m-p/5057016#M269788</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- Have the client debugs&amp;nbsp; further analyzed with&amp;nbsp;&lt;A href="https://cway.cisco.com/wireless-debug-analyzer/" target="_blank" rel="nofollow noopener noreferrer"&gt;Wireless Debug Analyzer&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; preferably with a longer trail. Also look into :&amp;nbsp;&lt;A href="https://logadvisor.cisco.com/logadvisor/wireless/9800/9800CWA" target="_blank"&gt;https://logadvisor.cisco.com/logadvisor/wireless/9800/9800CWA&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;For looking at a summarized view at&amp;nbsp; client issues have a look at&amp;nbsp; :&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/217738-monitor-catalyst-9800-kpis-key-performa.html#anc5" target="_blank" rel="nofollow noopener noreferrer"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/217738-monitor-catalyst-9800-kpis-key-performa.html#anc5&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;Checkout the 9800 WLC configuration too using the CLI command&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#008000"&gt;&lt;STRONG&gt;show tech wireless&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;and feed the output from that into&amp;nbsp;&lt;A href="https://cway.cisco.com/wireless-config-analyzer/" target="_blank" rel="nofollow noopener noreferrer"&gt;Wireless Config Analyzer&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;- Check 9800 WLC controller software version&amp;nbsp; ; advising to go for&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#008000"&gt;&lt;STRONG&gt;17.&lt;U&gt;9.5&lt;/U&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and check again ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2024 08:48:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-user-captive-portal-redirection-issue/m-p/5057016#M269788</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-04-05T08:48:26Z</dc:date>
    </item>
    <item>
      <title>Re: Guest user captive portal redirection issue</title>
      <link>https://community.cisco.com/t5/wireless/guest-user-captive-portal-redirection-issue/m-p/5058757#M269833</link>
      <description>&lt;P&gt;Do you have https intercept enabled in webauth parameter map ?&lt;/P&gt;&lt;P&gt;Try to disable http and https service on controller using 'no ip http server' and 'no ip http secure-server'.&lt;/P&gt;</description>
      <pubDate>Sat, 06 Apr 2024 17:49:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-user-captive-portal-redirection-issue/m-p/5058757#M269833</guid>
      <dc:creator>PSM</dc:creator>
      <dc:date>2024-04-06T17:49:44Z</dc:date>
    </item>
    <item>
      <title>Re: Guest user captive portal redirection issue</title>
      <link>https://community.cisco.com/t5/wireless/guest-user-captive-portal-redirection-issue/m-p/5059903#M269878</link>
      <description>&lt;P&gt;DO NOT DISABLE both http and https server in WLC otherwise it won't work.&lt;/P&gt;
&lt;P&gt;This seems to me like a DNS issue, are al sites using the same DNS? do the APs at all sites use the same WLC?&lt;/P&gt;
&lt;P&gt;This could also be a client side issue. Is that happening to specific devices types?&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 08:30:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-user-captive-portal-redirection-issue/m-p/5059903#M269878</guid>
      <dc:creator>JPavonM</dc:creator>
      <dc:date>2024-04-08T08:30:46Z</dc:date>
    </item>
    <item>
      <title>Re: Guest user captive portal redirection issue</title>
      <link>https://community.cisco.com/t5/wireless/guest-user-captive-portal-redirection-issue/m-p/5064172#M270094</link>
      <description>&lt;P&gt;Thanks for the suggestion..&lt;/P&gt;
&lt;P&gt;No WLCs are different for every site.. Where other sites are working except one.&lt;/P&gt;
&lt;P&gt;In case of DNS issue -&amp;nbsp;&lt;SPAN&gt;When I am giving captive portal URL manually in the guest pc browser, its working. However, auto redirecting to captive portal is not happening. Still do i need to check DNS side anything??&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2024 08:27:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-user-captive-portal-redirection-issue/m-p/5064172#M270094</guid>
      <dc:creator>singhsukdeep</dc:creator>
      <dc:date>2024-04-10T08:27:09Z</dc:date>
    </item>
    <item>
      <title>Re: Guest user captive portal redirection issue</title>
      <link>https://community.cisco.com/t5/wireless/guest-user-captive-portal-redirection-issue/m-p/5064872#M270109</link>
      <description>&lt;P&gt;Can you share the WLC model and version it is running on?&lt;/P&gt;
&lt;P&gt;Have you tried different client or a mobile device to test?&lt;/P&gt;
&lt;P&gt;Have you checked the "&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/216191-troubleshoot-common-cisco-ise-guest-acce.html#toc-hId--370296138" target="_self"&gt;Redirection to the Guest Portal Does not Work&lt;/A&gt;" section from the link?&lt;/P&gt;
&lt;P&gt;If the same config on other WLCs is working, you can compare the configs and see if you are missing any required config.&lt;/P&gt;
&lt;P&gt;Jagan Chowdam&lt;/P&gt;
&lt;P&gt;/**Pls rate useful responses**/&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2024 14:41:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-user-captive-portal-redirection-issue/m-p/5064872#M270109</guid>
      <dc:creator>jagan.chowdam</dc:creator>
      <dc:date>2024-04-10T14:41:33Z</dc:date>
    </item>
  </channel>
</rss>

