<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I hope the pre auth acl is in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/cisco-wlc-custom-web-auth-problem/m-p/2713728#M40784</link>
    <description>&lt;P&gt;I hope the pre auth acl is defined to access the server&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/wireless-mobility/wlan-security/115951-web-auth-wlc-guide-00.html#anc9&lt;/P&gt;</description>
    <pubDate>Wed, 20 May 2015 11:32:11 GMT</pubDate>
    <dc:creator>Saurav Lodh</dc:creator>
    <dc:date>2015-05-20T11:32:11Z</dc:date>
    <item>
      <title>Cisco WLC custom web auth problem</title>
      <link>https://community.cisco.com/t5/wireless/cisco-wlc-custom-web-auth-problem/m-p/2713727#M40783</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have configured Cisco WLC 5508 with a wired guest lan and a custom web authentication, i have downloaded the web-auth bundle on wlc. &amp;nbsp;I receive the splash screen but when i insert the credential or logout i receive an undefined page. If i use internal web, work perfectly...&lt;/P&gt;&lt;P&gt;this is my environment&lt;BR /&gt;wlc 7.6 with custom web-auth bundle installed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Who can help me&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 10:15:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-wlc-custom-web-auth-problem/m-p/2713727#M40783</guid>
      <dc:creator>Augustgood</dc:creator>
      <dc:date>2021-07-05T10:15:36Z</dc:date>
    </item>
    <item>
      <title>I hope the pre auth acl is</title>
      <link>https://community.cisco.com/t5/wireless/cisco-wlc-custom-web-auth-problem/m-p/2713728#M40784</link>
      <description>&lt;P&gt;I hope the pre auth acl is defined to access the server&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/wireless-mobility/wlan-security/115951-web-auth-wlc-guide-00.html#anc9&lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2015 11:32:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-wlc-custom-web-auth-problem/m-p/2713728#M40784</guid>
      <dc:creator>Saurav Lodh</dc:creator>
      <dc:date>2015-05-20T11:32:11Z</dc:date>
    </item>
    <item>
      <title>for testing purpose i use any</title>
      <link>https://community.cisco.com/t5/wireless/cisco-wlc-custom-web-auth-problem/m-p/2713729#M40785</link>
      <description>&lt;P&gt;for testing purpose i use any any any permit...&lt;/P&gt;</description>
      <pubDate>Thu, 21 May 2015 14:35:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-wlc-custom-web-auth-problem/m-p/2713729#M40785</guid>
      <dc:creator>Augustgood</dc:creator>
      <dc:date>2015-05-21T14:35:46Z</dc:date>
    </item>
    <item>
      <title>Verify your configuration as</title>
      <link>https://community.cisco.com/t5/wireless/cisco-wlc-custom-web-auth-problem/m-p/2713730#M40786</link>
      <description>&lt;P&gt;Verify your configuration as follows.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;H2&gt;How to Make an Internal (Local) WebAuth Work with an Internal Page&lt;/H2&gt;&lt;P&gt;If you need to configure a WLAN with an operational dynamic interface, the clients should also receive a DNS server IP address through DHCP. Before you set any &lt;STRONG&gt;webauth&lt;/STRONG&gt;, you should test that your WLAN works properly, that you can resolve DNS requests (&lt;STRONG&gt;nslookup&lt;/STRONG&gt;), and that you can browse web pages. Then, you can set the web authentication as Layer 3 security features. You can create your users in the local database or on an external RADIUS server, for example. Refer to the &lt;A href="http://www.cisco.com/c/en/us/support/docs/wireless-mobility/wlan-security/69340-web-auth-config.html" rel="nofollow"&gt;Wireless LAN Controller Web Authentication Configuration Example&lt;/A&gt; document.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;H3&gt;How to Configure a Custom Local WebAuth with Custom Page&lt;/H3&gt;&lt;P&gt;Custom &lt;STRONG&gt;webauth&lt;/STRONG&gt; can be configured with &lt;STRONG&gt;redirectUrl&lt;/STRONG&gt; from the &lt;STRONG&gt;Security&lt;/STRONG&gt; tab. This forces a redirect to a specific web page you enter. When the user is authenticated, it overrides the original URL the client requested and displays the page for which the redirect was assigned.&lt;/P&gt;&lt;P&gt;The custom feature allows you to use a custom HTML page instead of the default login page. Upload your html and image files bundle to the controller. In the upload page, look for &lt;STRONG&gt;webauth bundle&lt;/STRONG&gt; in a tar format. Usually, PicoZip creates tars that work compatibly with the WLC. For an example of a WebAuth bundle, refer to the &lt;A href="http://software.cisco.com/download/release.html?mdfid=283848165&amp;amp;flowid=24841&amp;amp;softwareid=282791507&amp;amp;release=1.0.2&amp;amp;relind=AVAILABLE&amp;amp;rellifecycle=&amp;amp;reltype=latest" rel="nofollow"&gt;Download Software page for Wireless Controller WebAuth Bundles&lt;/A&gt;. Be sure to select the appropriate release for your WLC. A good recommendation is to customize a bundle that exists; do not create a bundle from scratch.&lt;/P&gt;&lt;P&gt;There are some limitations with &lt;STRONG&gt;custom webauth&lt;/STRONG&gt; that vary with versions and bugs. Things to watch for include:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;the .tar file size (no more than 1Mb)&lt;BR /&gt;&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;the number of files in the .tar&lt;BR /&gt;&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;the filename length of the files (should be no more than 30 characters)&lt;BR /&gt;&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;If your customer package does not work, try with a simple custom package. Then add files and complexity one at a time to reach the package the customer tried to use. This should help you identify the problem. For an example on how to configure a custom page, refer to &lt;A href="http://www.cisco.com/en/US/docs/wireless/controller/7.0/configuration/guide/c70users.html#wp1049404" rel="nofollow"&gt;Creating a Customized Web Authentication Login Page&lt;/A&gt;, a section within the &lt;A href="http://www.cisco.com/en/US/docs/wireless/controller/7.0/configuration/guide/c70.html" rel="nofollow"&gt;Cisco Wireless LAN Controller Configuration Guide, Release 7.0&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;H3&gt;Override Global Configuration Technique&lt;/H3&gt;&lt;P&gt;For each WLAN, you configure with the &lt;STRONG&gt;override global config&lt;/STRONG&gt; command and set a WebAuth type for each WLAN. This means you can have an internal/default WebAuth with a custom internal/default WebAuth for another WLAN. This also allows you to configure different custom pages for each WLAN. You must combine all your pages in the same bundle and upload them to the WLC. Then, you can set your custom page with the &lt;STRONG&gt;override global config&lt;/STRONG&gt; command on each WLAN and select which file is the login page from all of the files within the bundle. You can choose a different login page inside the bundle for each WLAN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;H3&gt;Redirection Issue&lt;/H3&gt;&lt;P&gt;There is a variable within the HTML bundle that allows the redirection. Do not put your forced redirection URL there. For any redirection issues in custom WebAuth, Cisco recommends to check the bundle. If you enter a redirect URL with &lt;STRONG&gt;+=&lt;/STRONG&gt; in the WLC GUI, this could overwrite &lt;EM&gt;or&lt;/EM&gt; add to the URL defined inside the bundle. For example, in the WLC GUI, the &lt;STRONG&gt;redirectURL&lt;/STRONG&gt; field is set to &lt;A href="https://community.cisco.com/www.cisco.com" target="_blank"&gt;www.cisco.com&lt;/A&gt;; however, in the bundle it shows: &lt;STRONG&gt;redirectURL+= &lt;/STRONG&gt;'www.google.com'. The &lt;STRONG&gt;+=&lt;/STRONG&gt; redirects users to &lt;A href="https://community.cisco.com/www.cisco.comwww.google.com" target="_blank"&gt;www.cisco.comwww.google.com&lt;/A&gt;, which is an invalid URL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;H2&gt;How to Make an External (Local) Web Authentication Work with an External Page&lt;/H2&gt;&lt;P&gt;As already briefly explained, the utilization of an external WebAuth server is just an external repository for the login page. The user credentials are still authenticated by the WLC. The external web server only allows you to use a special or different login page. Here are the steps performed for an external WebAuth:&lt;/P&gt;&lt;OL type="1"&gt;&lt;LI&gt;The client (end user) opens a web browser and enters a URL.&lt;BR /&gt;&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;If the client is not authenticated and external web authentication is used, the WLC redirects the user to the external web server URL. In other words, the WLC sends an HTTP redirect to the client with the website's spoofed IP address and points to the external server IP address. The external web authentication login URL is appended with parameters such as the &lt;STRONG&gt;AP_Mac_Address&lt;/STRONG&gt;, the &lt;STRONG&gt;client_url&lt;/STRONG&gt; (www.website.com), and the &lt;STRONG&gt;action_URL&lt;/STRONG&gt; that the customer needs to contact the switch web server.&lt;BR /&gt;&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;The external web server URL sends the user to a login page. Then the user can use a pre-authentication access control list (ACL) in order to access the server. The ACL is needed for all WLC models except 4400 series and Wism1.&lt;BR /&gt;&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;The login page takes the user credentials input and sends the request back to the &lt;STRONG&gt;action_URL&lt;/STRONG&gt;, such as &lt;A href="http://1.1.1.1/login.html" target="_blank"&gt;http://1.1.1.1/login.html&lt;/A&gt;, of the WLC web server. This is provided as an input parameter to the customer redirect URL, where 1.1.1.1 is the virtual interface address on the switch.&lt;BR /&gt;&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;The WLC web server submits the username and password for authentication.&lt;BR /&gt;&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;The WLC initiates the RADIUS server request or uses the local database on the WLC, and then authenticates the user.&lt;BR /&gt;&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;If authentication is successful, the WLC web server either forwards the user to the configured redirect URL or to the URL the client entered.&lt;BR /&gt;&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;If authentication fails, then the WLC web server redirects the user back to the customer login URL.&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Thu, 21 May 2015 19:43:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-wlc-custom-web-auth-problem/m-p/2713730#M40786</guid>
      <dc:creator>gohussai</dc:creator>
      <dc:date>2015-05-21T19:43:41Z</dc:date>
    </item>
    <item>
      <title>Before you configure and</title>
      <link>https://community.cisco.com/t5/wireless/cisco-wlc-custom-web-auth-problem/m-p/2713731#M40787</link>
      <description>&lt;P&gt;Before you configure and customize WebAuth, ensure that your PC:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Has an IP address on an open Service Set Identifier (SSID)&lt;/LI&gt;&lt;LI&gt;Can ping the default gateway&lt;/LI&gt;&lt;LI&gt;Can identify and locate the Domain Name Server (DNS) (&lt;STRONG&gt;ipconfig/all&lt;/STRONG&gt;)&lt;/LI&gt;&lt;LI&gt;Can resolve names (with &lt;STRONG&gt;nslookup&lt;/STRONG&gt;)&lt;/LI&gt;&lt;LI&gt;Can access the Internet&lt;/LI&gt;&lt;LI&gt;&lt;A href="http://www.cisco.com/c/en/us/support/docs/wireless/5700-series-wireless-lan-controllers/117728-configure-wlc-00.html"&gt;http://www.cisco.com/c/en/us/support/docs/wireless/5700-series-wireless-lan-controllers/117728-configure-wlc-00.html&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Fri, 22 May 2015 10:40:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-wlc-custom-web-auth-problem/m-p/2713731#M40787</guid>
      <dc:creator>mohanak</dc:creator>
      <dc:date>2015-05-22T10:40:15Z</dc:date>
    </item>
  </channel>
</rss>

