<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WLC Slow web login authenticate in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wlc-slow-web-login-authenticate/m-p/2240262#M43621</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Really seems like there is a network issue like DNS or maybe a duplicate IP. I would connect a PC to the guest vlan and test if that PC gets an IP address and can access the Internet with no issues.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 09 Jun 2013 13:59:03 GMT</pubDate>
    <dc:creator>Scott Fella</dc:creator>
    <dc:date>2013-06-09T13:59:03Z</dc:date>
    <item>
      <title>WLC Slow web login authenticate</title>
      <link>https://community.cisco.com/t5/wireless/wlc-slow-web-login-authenticate/m-p/2240260#M43619</link>
      <description>&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Hi Guys,my visitor login page very slow to appears .Sometimes it takes 10 - 30minutes to appears even after I enter &lt;A href="http://1.1.1.1" target="_blank"&gt;http://1.1.1.1&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;How can i troubleshoot ?Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 07:12:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-slow-web-login-authenticate/m-p/2240260#M43619</guid>
      <dc:creator>haikalmesiniaga</dc:creator>
      <dc:date>2021-07-04T07:12:12Z</dc:date>
    </item>
    <item>
      <title>Re: WLC Slow web login authenticate</title>
      <link>https://community.cisco.com/t5/wireless/wlc-slow-web-login-authenticate/m-p/2240261#M43620</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This might be handy.&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/ps10315/products_tech_note09186a0080a38c11.shtml" rel="nofollow"&gt;http://www.cisco.com/en/US/products/ps10315/products_tech_note09186a0080a38c11.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but, are you using default page? or custom page?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amjad&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: blue;"&gt;Rating useful replies is more useful than saying &lt;SPAN style="color: green;"&gt; "&lt;SPAN style="text-decoration: underline;"&gt;Thank you&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 09 Jun 2013 07:02:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-slow-web-login-authenticate/m-p/2240261#M43620</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2013-06-09T07:02:32Z</dc:date>
    </item>
    <item>
      <title>Re: WLC Slow web login authenticate</title>
      <link>https://community.cisco.com/t5/wireless/wlc-slow-web-login-authenticate/m-p/2240262#M43621</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Really seems like there is a network issue like DNS or maybe a duplicate IP. I would connect a PC to the guest vlan and test if that PC gets an IP address and can access the Internet with no issues.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 09 Jun 2013 13:59:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-slow-web-login-authenticate/m-p/2240262#M43621</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2013-06-09T13:59:03Z</dc:date>
    </item>
    <item>
      <title>WLC Slow web login authenticate</title>
      <link>https://community.cisco.com/t5/wireless/wlc-slow-web-login-authenticate/m-p/2240263#M43622</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;BR /&gt;im using custom page...test nslookup,everyting ok.&lt;/P&gt;&lt;P&gt;my laptop also can get ip without no issue.&lt;/P&gt;&lt;P&gt;the only thing its hard to estbalish login page..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Jun 2013 02:15:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-slow-web-login-authenticate/m-p/2240263#M43622</guid>
      <dc:creator>haikalmesiniaga</dc:creator>
      <dc:date>2013-06-10T02:15:54Z</dc:date>
    </item>
    <item>
      <title>Re: WLC Slow web login authenticate</title>
      <link>https://community.cisco.com/t5/wireless/wlc-slow-web-login-authenticate/m-p/2240264#M43623</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you are performing the test, it has to be from the guest network. The nslookup has to be done from the guest subnet. If you can connect a laptop to the guest subnet and get an IP address and also have Internet access, then we can rule out the guest wired side of things.&lt;BR /&gt;&lt;BR /&gt;The thing is, are you anchoring? What is the setup like? Can you post your show run-config.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Jun 2013 12:02:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-slow-web-login-authenticate/m-p/2240264#M43623</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2013-06-10T12:02:28Z</dc:date>
    </item>
    <item>
      <title>WLC Slow web login authenticate</title>
      <link>https://community.cisco.com/t5/wireless/wlc-slow-web-login-authenticate/m-p/2240265#M43624</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Problem solved.Since it using local authenticate,i have remove AAA authenticate server IP under WLAN Settings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also adjust order used for authentication and remove radius and ldap.Its work like a champ&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD nowrap="nowrap"&gt;&lt;STRONG&gt;Order Used For&amp;nbsp; Authentication&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="width: 20%;"&gt;&lt;SELECT multiple="multiple" name="auth_prty1a" size="3"&gt; &lt;OPTION value="2"&gt;RADIUS&lt;/OPTION&gt;&lt;OPTION value="1"&gt;LDAP&lt;/OPTION&gt;&lt;/SELECT&gt; &lt;/TD&gt;&lt;TD width="20%"&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;INPUT name="show" style="width: 50px;" type="button" value="" /&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;INPUT name="hide" style="width: 50px;" type="button" value="" /&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;TD style="width: 20%;"&gt;&lt;SELECT multiple="multiple" name="auth_prty2a" size="3"&gt; &lt;OPTION value="3"&gt;LOCAL&lt;/OPTION&gt;&lt;/SELECT&gt; &lt;/TD&gt;&lt;TD align="left" width="40%"&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;INPUT name="button" style="width: 50px;" type="button" value="" /&gt; &lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;INPUT name="button" style="width: 50px;" type="button" value="" /&gt; &lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD colspan="3" style="padding-top: 10%;"&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;IMG height="1" src="https://10.112.221.11/screens/images/spacer.gif" width="1" /&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jul 2013 07:47:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-slow-web-login-authenticate/m-p/2240265#M43624</guid>
      <dc:creator>haikalmesiniaga</dc:creator>
      <dc:date>2013-07-03T07:47:00Z</dc:date>
    </item>
    <item>
      <title>WLC Slow web login authenticate</title>
      <link>https://community.cisco.com/t5/wireless/wlc-slow-web-login-authenticate/m-p/2240266#M43625</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Hi Haikal,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Thank you for sharing the valuable info.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;This is actually strange behavior with cisco WLC when using Web-Auth.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;When normal EAP authentication is going on (Local EAP for example), if one method has a reply (local DB or LDAP) either reject or accept, it does not fall to the next method (if local is on top, it will never fall back to the LDAP as the local DB will always reply with accept - if user credentials are found and correct - or reject - if user not found or bad credentials).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;With the Web-Auth this is not correct. If one method (local DB, LDAP and/or RADIUS) is replying with a access-reject radius message, the WLC continues to check the next method until it either finds a success or fails after trying all methods with no success.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In your situation it seems was trying to check the radius servers first. But that would have affected the time of the response after you previde the credentials. From your description I understood you have a problem with showing the login page!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amjad&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: blue;"&gt;Rating useful replies is more useful than saying &lt;SPAN style="color: green;"&gt; "&lt;SPAN style="text-decoration: underline;"&gt;Thank you&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jul 2013 13:16:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-slow-web-login-authenticate/m-p/2240266#M43625</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2013-07-03T13:16:26Z</dc:date>
    </item>
    <item>
      <title>Re: WLC Slow web login authenticate</title>
      <link>https://community.cisco.com/t5/wireless/wlc-slow-web-login-authenticate/m-p/2240267#M43626</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;can you try other ip else than 1.1.1.1? Afaik 1.1.1.1 is on internet...&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jul 2013 16:35:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-slow-web-login-authenticate/m-p/2240267#M43626</guid>
      <dc:creator>Shaoqin Li</dc:creator>
      <dc:date>2013-07-03T16:35:03Z</dc:date>
    </item>
    <item>
      <title>Re: WLC Slow web login authenticate</title>
      <link>https://community.cisco.com/t5/wireless/wlc-slow-web-login-authenticate/m-p/2240268#M43627</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H2&gt; &lt;A name="twa"&gt;Troubleshooting Web Authentication&lt;/A&gt; &lt;/H2&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After you configure web authentication, if the feature does not work as &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; expected, complete these troubleshooting steps:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL type="1"&gt;&lt;LI&gt;&lt;P&gt;Check if the client gets an IP address. If not, users can uncheck &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;DHCP Required&lt;/STRONG&gt; on the WLAN and give the wireless client a &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; static IP address. This assumes association with the access point. Refer to the &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;EM&gt;IP addressing issues&lt;/EM&gt; section of &lt;EM&gt;Troubleshooting &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Client Issues in the Cisco Unified Wireless Network for troubleshooting DHCP &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; related issues&lt;/EM&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;On WLC versions earlier than 3.2.150.10, you must manually enter &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;&lt;A class="jive-link-external-small" href="https://1.1.1.1/login.html"&gt;https://1.1.1.1/login.html&lt;/A&gt;&lt;/STRONG&gt; in order to navigate to the web &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; authentication window.&lt;/P&gt;&lt;P&gt;The next step in the process is DNS resolution of the URL in the &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; web browser. When a WLAN client connects to a WLAN configured for web &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; authentication, the client obtains an IP address from the DHCP server. The user &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; opens a web browser and enters a website address. The client then performs the &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DNS resolution to obtain the IP address of the website. Now, when the client &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; tries to reach the website, the WLC intercepts the HTTP Get session of the &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; client and redirects the user to the web authentication login page.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Therefore, ensure that the client is able to perform DNS resolution &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; for the redirection to work. On Windows, choose &lt;STRONG&gt;Start &amp;gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Run&lt;/STRONG&gt;, enter &lt;STRONG&gt;CMD&lt;/STRONG&gt; in order to open a command window, and &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; do a “nslookup www.cisco.com" and see if the IP address comes back.&lt;/P&gt;&lt;P&gt;On Macs/Linux: open a terminal window and do a “nslookup &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; www.cisco.com" and see if the IP address comes back.&lt;/P&gt;&lt;P&gt;If you believe the client is not getting DNS resolution, you can &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; either:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;Enter either the IP address of the URL (for example, &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com"&gt;http://www.cisco.com&lt;/A&gt;&lt;SPAN&gt; is &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://198.133.219.25"&gt;http://198.133.219.25&lt;/A&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;Try to directly reach the controller's webauth page with &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://"&gt;https://&lt;/A&gt;&lt;SPAN&gt;&lt;VIRTUAL_INTERFACE_IP_ADDRESS&gt;/login.html. Typically this is &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/VIRTUAL_INTERFACE_IP_ADDRESS&gt;&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://1.1.1.1/login.html"&gt;http://1.1.1.1/login.html&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Does entering this URL bring up the web page? If yes, it is most &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; likely a DNS problem. It might also be a certificate problem. The controller, &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; by default, uses a self-signed certificate and most web browsers warn against &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; using them.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;For web authentication using customized web page, ensure that the &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; HTML code for the customized web page is appropriate.&lt;/P&gt;&lt;P&gt;You can download a sample Web Authentication script from &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="http://www.cisco.com/cisco/software/navigator.html"&gt;Cisco Software &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Downloads&lt;/A&gt;. For example, for the 4400 controllers, choose &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;Products &amp;gt; Wireless &amp;gt; Wireless LAN Controller &amp;gt; Standalone &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Controllers &amp;gt; Cisco 4400 Series Wireless LAN Controllers &amp;gt; Cisco 4404 &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Wireless LAN Controller &amp;gt; Software on Chassis &amp;gt; Wireless Lan Controller &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Web Authentication Bundle-1.0.1&lt;/STRONG&gt; and download the &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;webauth_bundle.zip &lt;/STRONG&gt; file. &lt;/P&gt;&lt;P&gt;These parameters are added to the URL when the user's Internet &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; browser is redirected to the customized login page:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;ap_mac—The MAC address of the access point to which the wireless &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; user is associated.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;switch_url—The URL of the controller to which the user &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; credentials should be posted.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;redirect—The URL to which the user is redirected after &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; authentication is successful. &lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;statusCode—The status code returned from the controller's web &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; authentication server.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;wlan—The WLAN SSID to which the wireless user is &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; associated.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;These are the available status codes:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Status Code 1: "You are already logged in. No further action is &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; required on your part."&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Status Code 2: "You are not configured to authenticate against &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; web portal. No further action is required on your part."&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Status Code 3: "The username specified cannot be used at this &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; time. Perhaps the username is already logged into the &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; system?"&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Status Code 4: "You have been excluded."&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Status Code 5: "The User Name and Password combination you have &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; entered is invalid. Please try again."&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;All the files and pictures that need to appear on the Customized &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; web page should be bundled into a .tar file before uploading to the WLC. Ensure &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; that one of the files included in the tar bundle is login.html. You receive &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; this error message if you do not include the login.html &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; file:&lt;/P&gt;&lt;P&gt; &lt;IMG alt="webauth-tshoot1.gif" border="0" src="http://www.cisco.com/image/gif/paws/108501/webauth-tshoot1.gif" /&gt; &lt;/P&gt;&lt;P&gt;Refer to the &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a008067489f.shtml#guide"&gt;Guidelines &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; for Customized Web Authentication&lt;/A&gt; section of &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a008067489f.shtml"&gt;Wireless &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; LAN Controller Web Authentication Configuration Example&lt;/A&gt; for more &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; information on how to create a customized web authentication window.&lt;/P&gt;&lt;P&gt; &lt;STRONG&gt;Note: &lt;/STRONG&gt;Files that are large and files that have long names will result &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; in an extraction error. It is recommended that pictures are in .jpg &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; format.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Internet Explorer 6.0 SP1 or later is the browser recommended for &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; the use of web authentication. Other browsers may or may not &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; work.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Ensure that the &lt;STRONG&gt;Scripting&lt;/STRONG&gt; option is not blocked on &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; the client browser as the customized web page on the WLC is basically an HTML &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; script. On IE 6.0, this is disabled by default for security purposes.&lt;/P&gt;&lt;P&gt; &lt;STRONG&gt;Note: &lt;/STRONG&gt;The Pop Up blocker needs to be disabled on the browser if you &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; have configured any Pop Up messages for the user.&lt;/P&gt;&lt;P&gt; &lt;STRONG&gt;Note: &lt;/STRONG&gt;If you browse to an &lt;STRONG&gt;https&lt;/STRONG&gt; site, redirection does &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; not work. Refer to Cisco bug ID &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=%20CSCar04580"&gt;CSCar04580&lt;/A&gt; (&lt;A href="http://tools.cisco.com/RPF/register/register.do"&gt;registered&lt;/A&gt; customers only)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; for more information.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;If you have a &lt;STRONG&gt;host name&lt;/STRONG&gt; configured for the &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;virtual interface&lt;/STRONG&gt; of the WLC, make sure that the DNS &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; resolution is available for the host name of the virtual interface.&lt;/P&gt;&lt;P&gt; &lt;STRONG&gt;Note: &lt;/STRONG&gt;Navigate to the &lt;STRONG&gt;Controller &amp;gt; Interfaces&lt;/STRONG&gt; menu &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; from the WLC GUI in order to assign a &lt;STRONG&gt;DNS hostname&lt;/STRONG&gt; to the &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; virtual interface.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Sometimes the firewall installed on the client computer blocks the &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; web authentication login page. Disable the firewall before you try to access &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; the login page. The firewall can be enabled again once the web authentication &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; is completed.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Topology/solution firewall can be placed between the client and &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; web-auth server, which depends on the network. As for each network &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; design/solution implemented, the end user should make sure these ports are &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; allowed on the network firewall.&lt;/P&gt;&lt;TABLE bgcolor="#FFFFFF" border="1" cellpadding="3" cellspacing="1" width="60%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TH bgcolor="#FFFFFF" width="287"&gt; Protocol&lt;/TH&gt; &lt;TH bgcolor="#FFFFFF" width="257"&gt; Port&lt;/TH&gt; &lt;/TR&gt;&lt;TR&gt;&lt;TD bgcolor="#FFFFFF" width="287"&gt;HTTP/HTTPS Traffic&lt;/TD&gt;&lt;TD bgcolor="#FFFFFF" width="257"&gt;TCP port 80/443&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD bgcolor="#FFFFFF" width="287"&gt;CAPWAP Data/Control Traffic&lt;/TD&gt;&lt;TD bgcolor="#FFFFFF" width="257"&gt;UDP port 5247/5246&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD bgcolor="#FFFFFF" width="287"&gt;LWAPP Data/Control Traffic (before rel 5.0)&lt;/TD&gt;&lt;TD bgcolor="#FFFFFF" width="257"&gt;UDP port 12222/12223&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD bgcolor="#FFFFFF" width="287"&gt;EOIP packets &lt;/TD&gt;&lt;TD bgcolor="#FFFFFF" width="257"&gt;IP protocol 97&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD bgcolor="#FFFFFF" width="287"&gt;Mobility &lt;/TD&gt;&lt;TD bgcolor="#FFFFFF" width="257"&gt;UDP port 16666 (non secured)&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; UDP port 16667 (secured IPSEC tunnel)&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;For web authentication to occur, the client should first associate &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; to the appropriate WLAN on the WLC. Navigate to the &lt;STRONG&gt;Monitor &amp;gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Clients&lt;/STRONG&gt; menu on the WLC GUI in order to see if the client is &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; associated to the WLC. Check if the client has a valid IP &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; address.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Disable the Proxy Settings on the client browser until web &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; authentication is completed.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;The default web authentication method is PAP. Ensure that PAP &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; authentication is allowed on the RADIUS server for this to work. In order to &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; check the status of client authentication, check the debugs and log messages &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; from the RADIUS server. You can use the &lt;STRONG&gt;debug aaa &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; all&lt;/STRONG&gt; command on the WLC to view the debugs from the RADIUS &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; server.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Update the hardware driver on the computer to the latest code from &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; manufacturer's website.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Verify settings in the supplicant (program on &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; laptop).&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;When you use the Windows Zero Config supplicant built into &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Windows:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Verify user has latest patches installed.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Run debugs on supplicant.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;On the client, turn on the EAPOL (WPA+WPA2) and RASTLS logs from a &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; command window, Start &amp;gt; Run &amp;gt; CMD:&lt;/P&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;&lt;PRE&gt;netsh ras set tracing eapol enable
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; netsh ras set tracing rastls enable&lt;/PRE&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;In order to disable the logs, run the same command but replace &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; enable with disable. For XP, all logs will be located in &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; C:\Windows\tracing.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;If you still have no login web page, collect and analyze this &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; output from a single client:&lt;/P&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;&lt;PRE&gt;debug client &lt;MAC_ADDRESS in="" format="" xx:xx:xx:xx:xx=""&gt;
debug dhcp message enable
debug aaa all enable
debug dot1x aaa enable
debug mobility handoff enable&lt;/MAC_ADDRESS&gt;&lt;/PRE&gt;&lt;/BLOCKQUOTE&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;If the issue is not resolved after you complete these steps, &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; collect these debugs and use the &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="http://tools.cisco.com/ServiceRequestTool/create/"&gt;TAC Service Request Tool&lt;/A&gt; (&lt;A href="http://tools.cisco.com/RPF/register/register.do"&gt;registered&lt;/A&gt; customers only)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; in order to open a Service &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Request. &lt;/P&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;&lt;PRE&gt;debug pm ssh-appgw enable
debug pm ssh-tcp enable
debug pm rules enable
debug emweb server enable
debug pm ssh-engine enable packet &lt;CLIENT ip=""&gt;&lt;/CLIENT&gt;&lt;/PRE&gt;&lt;/BLOCKQUOTE&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jul 2013 05:10:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-slow-web-login-authenticate/m-p/2240268#M43627</guid>
      <dc:creator>mmangat</dc:creator>
      <dc:date>2013-07-08T05:10:50Z</dc:date>
    </item>
  </channel>
</rss>

