<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Web Redirect is not working in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/web-redirect-is-not-working/m-p/2225901#M67632</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For now could you uncheck AAA override in the WLAN config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does your Authentication policy on the ISE similar to below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IF (WLC_Web_Authentication and Wireless_Guest_WebAuth)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; THEN (Allow Default Network Access (or user defined access) and USE Guest_Portal_Sequence)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WLC_Web_Authentication is system generated compound condition that matches Service-Type and NAS port type&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wireless_Guest_WebAuth is user defined simple condition that matched open guest SSID i.e Airespace-Wlan-Id EQUALS (number of the guest SSID on the WLC).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How is the Authorization policy set up?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are the devices that you have problem with Apple or MAC OSX?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If so, you need to add the command on the anchor controller ---- configure network web-auth captive-bypass enable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Finally could you confirm that on the Pre-auth ACLs, you specified the port 8443 and not just any?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 16 Jul 2013 18:18:39 GMT</pubDate>
    <dc:creator>grabonlee</dc:creator>
    <dc:date>2013-07-16T18:18:39Z</dc:date>
    <item>
      <title>Web Redirect is not working</title>
      <link>https://community.cisco.com/t5/wireless/web-redirect-is-not-working/m-p/2225896#M67627</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We configured the web authentication in wlc 5508with ISE for the guest traffic. When client tries to connect it redirects to the different URL. That means the specified URL (that is default redirection page of ISE) '&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://" rel="nofollow" target="_blank"&gt;https://&lt;/A&gt;&lt;SPAN&gt;&amp;lt;ISE IP&amp;gt;:8443/guestportal/portal.jsp'&amp;nbsp; but client is getting redirected to &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;'&lt;SPAN style="font-size: 10pt;"&gt;&lt;A class="jive-link-external-small" href="https://" rel="nofollow" target="_blank"&gt;https://&lt;/A&gt;&lt;SPAN&gt;&amp;lt;ISE&amp;gt;:8443/guestportal/&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;SPAN&gt;login.action?switch_url=&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://" rel="nofollow" target="_blank"&gt;https://&lt;/A&gt;&lt;SPAN&gt;&amp;lt;virtual IP&amp;gt;/login.html&amp;amp;wlan...'. And finally page cannot be displayed now error message i am getting. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Why it happens..? Any quick help would be really appreciated &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Moreover i have doubts on the below points.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;1) Should both the Anchor and the foriegn controllers be configured for web auth security or only anchor ..?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;2) When external web redirection, the client has to get the DNS resolved entry for the Specified URL or WLC knows to take it to the external web page..? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;3) Any special configuration has to be done on ISE?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Thanks for your time &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;KVS&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Message was edited by: Prasan Venky&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 07:26:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/web-redirect-is-not-working/m-p/2225896#M67627</guid>
      <dc:creator>Prasan Venky</dc:creator>
      <dc:date>2021-07-04T07:26:11Z</dc:date>
    </item>
    <item>
      <title>Web Redirect is not working</title>
      <link>https://community.cisco.com/t5/wireless/web-redirect-is-not-working/m-p/2225897#M67628</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When a user-defined guest portal is implemented, the URL should be in the format below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https:/" rel="nofollow"&gt;https://&lt;ISE_SERVER_IP&gt;:8443/guestportal/portals/name_of_user_defined_portal/portal.jsp&lt;/ISE_SERVER_IP&gt;&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ISE_Server_IP should either be the IP address of the ISE server or the DNS resolvable hostname of the ISE Server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The external web authentication URL should only be specified in the Anchor Controller.&lt;/P&gt;&lt;P&gt;&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jul 2013 15:16:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/web-redirect-is-not-working/m-p/2225897#M67628</guid>
      <dc:creator>grabonlee</dc:creator>
      <dc:date>2013-07-16T15:16:47Z</dc:date>
    </item>
    <item>
      <title>Web Redirect is not working</title>
      <link>https://community.cisco.com/t5/wireless/web-redirect-is-not-working/m-p/2225898#M67629</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for your reply Osita.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are using default setting for the guest portal access in ISE . We are not sure about userdefined web page.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We even tried by giving direct ip of ISE as like &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://"&gt;https://&lt;/A&gt;&lt;SPAN&gt; ip address :8443/guestportal/portal.jsp&amp;nbsp;&amp;nbsp; , &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://"&gt;https://&lt;/A&gt;&lt;SPAN&gt; ip address :8443/guestportal/login.action .&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But still web page is not displaying.&amp;nbsp; What needs to be checked?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jul 2013 15:37:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/web-redirect-is-not-working/m-p/2225898#M67629</guid>
      <dc:creator>Prasan Venky</dc:creator>
      <dc:date>2013-07-16T15:37:05Z</dc:date>
    </item>
    <item>
      <title>Re:Web Redirect is not working</title>
      <link>https://community.cisco.com/t5/wireless/web-redirect-is-not-working/m-p/2225899#M67630</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did u specify the URL in the external web auth login on the anchor controller?&lt;BR /&gt;&lt;BR /&gt;Did u check the firewall to see if it may be blocking port 8443?&lt;BR /&gt;&lt;BR /&gt;Are u using pre-authentication ACL? If so, u have to make sure that there is both inbound and outbound ACL to and from the ISE on port 8443.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support Android App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jul 2013 15:52:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/web-redirect-is-not-working/m-p/2225899#M67630</guid>
      <dc:creator>grabonlee</dc:creator>
      <dc:date>2013-07-16T15:52:30Z</dc:date>
    </item>
    <item>
      <title>Web Redirect is not working</title>
      <link>https://community.cisco.com/t5/wireless/web-redirect-is-not-working/m-p/2225900#M67631</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did u specify the URL in the external web auth login on the anchor controller?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes , we have given on the anchor controller.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did u check the firewall to see if it may be blocking port 8443?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have allowed the port&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are u using pre-authentication ACL? If so, u have to make sure that&amp;nbsp; there is both inbound and outbound ACL to and from the ISE on port 8443.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have allowed &lt;/P&gt;&lt;P&gt;1.ise to any 2. any to ise 3. any to dns 4. dns to any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In wlan configuration , we specified L3 security as web auth with external server and the URL of ISE&amp;nbsp; (pre auth ACL chosen). In advanced tab we given AAA override .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In ISE we just allowed the permit access auth profile for the guest access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do we need to configure anything extra?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jul 2013 17:40:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/web-redirect-is-not-working/m-p/2225900#M67631</guid>
      <dc:creator>Prasan Venky</dc:creator>
      <dc:date>2013-07-16T17:40:52Z</dc:date>
    </item>
    <item>
      <title>Web Redirect is not working</title>
      <link>https://community.cisco.com/t5/wireless/web-redirect-is-not-working/m-p/2225901#M67632</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For now could you uncheck AAA override in the WLAN config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does your Authentication policy on the ISE similar to below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IF (WLC_Web_Authentication and Wireless_Guest_WebAuth)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; THEN (Allow Default Network Access (or user defined access) and USE Guest_Portal_Sequence)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WLC_Web_Authentication is system generated compound condition that matches Service-Type and NAS port type&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wireless_Guest_WebAuth is user defined simple condition that matched open guest SSID i.e Airespace-Wlan-Id EQUALS (number of the guest SSID on the WLC).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How is the Authorization policy set up?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are the devices that you have problem with Apple or MAC OSX?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If so, you need to add the command on the anchor controller ---- configure network web-auth captive-bypass enable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Finally could you confirm that on the Pre-auth ACLs, you specified the port 8443 and not just any?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jul 2013 18:18:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/web-redirect-is-not-working/m-p/2225901#M67632</guid>
      <dc:creator>grabonlee</dc:creator>
      <dc:date>2013-07-16T18:18:39Z</dc:date>
    </item>
    <item>
      <title>Web Redirect is not working</title>
      <link>https://community.cisco.com/t5/wireless/web-redirect-is-not-working/m-p/2225902#M67633</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Really thanks for the reply .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes , we have configured&amp;nbsp; &lt;/P&gt;&lt;P&gt;IF (WLC_Web_Authentication and Wireless_Guest_WebAuth)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; THEN (Allow Default Network Access &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For authorization , default permit any access . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We tried with windows 7 clients&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway anchor controller is placed after the firewall. we didn't open the port 443 for redirection. We will enable it tomorrow .We will check&amp;nbsp; and let you know tomorrow.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jul 2013 18:40:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/web-redirect-is-not-working/m-p/2225902#M67633</guid>
      <dc:creator>Prasan Venky</dc:creator>
      <dc:date>2013-07-16T18:40:14Z</dc:date>
    </item>
    <item>
      <title>Web Redirect is not working</title>
      <link>https://community.cisco.com/t5/wireless/web-redirect-is-not-working/m-p/2225903#M67634</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;A name="external"&gt;How to Make an External (Local) Web Authentication Work with an External Page&lt;/A&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As already briefly explained, the utilization of an external WebAuth &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; server is just an external repository for the login page. The user credentials &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; are still authenticated by the WLC. The external web server only allows you to &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; use a special or different login page. Here are the steps performed for an &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; external WebAuth:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL type="1"&gt;&lt;LI&gt;&lt;P&gt;The client (end user) opens a web browser and enters a &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;URL.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;If the client is not authenticated and external web authentication is &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;used, the WLC redirects the user to the external web server URL. In other &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;words, the WLC sends an HTTP redirect to the client with the website's spoofed &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;IP address and points to the external server IP address. The external web &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;authentication login URL is appended with parameters such as the &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;AP_Mac_Address&lt;/STRONG&gt;, the &lt;STRONG&gt;client_url&lt;/STRONG&gt; (www.website.com), and the &lt;STRONG&gt;action_URL&lt;/STRONG&gt; that the customer needs &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;to contact the switch web server.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;The external web server URL sends the user to a login page. Then the &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;user can use a pre-authentication access control list (ACL) in order to access &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;the server. The ACL is only needed for the Wireless LAN Controller 2000 &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;series.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;The login page takes the user credentials input and sends the request &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;back to the &lt;STRONG&gt;action_URL&lt;/STRONG&gt;&lt;SPAN&gt;, such as &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://1.1.1.1/login.html"&gt;http://1.1.1.1/login.html&lt;/A&gt;&lt;SPAN&gt;, of &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;the WLC web server. This is provided as an input parameter to the customer &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;redirect URL, where 1.1.1.1 is the virtual interface address on the &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;switch.&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;The WLC web server submits the username and password for &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;authentication.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;The WLC initiates the RADIUS server request or uses the local &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;database on the WLC, and then authenticates the user.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;If authentication is successful, the WLC web server either forwards &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;the user to the configured redirect URL or to the URL the client &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;entered.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;If authentication fails, then the WLC web server redirects the user &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;back to the customer login URL.&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;STRONG&gt;Note: &lt;/STRONG&gt;If the access points (APs) are in FlexConnect mode, a &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;preauth&lt;/STRONG&gt; ACL is irrelevant. Flex ACLs can be used to allow &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;access to the web server for clients that have not been authenticated. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For more details, please refer to the following:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/tech/tk722/tk809/technologies_tech_note09186a0080bf7d89.shtml#redirect"&gt;http://www.cisco.com/en/US/tech/tk722/tk809/technologies_tech_note09186a0080bf7d89.shtml#redirect&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Jul 2013 02:03:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/web-redirect-is-not-working/m-p/2225903#M67634</guid>
      <dc:creator>mmangat</dc:creator>
      <dc:date>2013-07-17T02:03:13Z</dc:date>
    </item>
    <item>
      <title>Web Redirect is not working</title>
      <link>https://community.cisco.com/t5/wireless/web-redirect-is-not-working/m-p/2225904#M67635</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mantej Mangat&amp;nbsp; ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All the guest credentials will be genereated in ISE thorugh sponsor portal. But how the WLC comes to know the guest credentials if we follow the above method as mentioned by you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Jul 2013 02:41:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/web-redirect-is-not-working/m-p/2225904#M67635</guid>
      <dc:creator>Prasan Venky</dc:creator>
      <dc:date>2013-07-17T02:41:53Z</dc:date>
    </item>
    <item>
      <title>Web Redirect is not working</title>
      <link>https://community.cisco.com/t5/wireless/web-redirect-is-not-working/m-p/2225905#M67636</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Prasan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: px; margin-bottom: px; line-height: normal;"&gt;In the above scenario WLC is sending the authentication request to server on behalf of USER and When WLC sent authentication request to external server it keep the track of this request. In this way it comes to know that authentication is successful.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jul 2013 02:05:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/web-redirect-is-not-working/m-p/2225905#M67636</guid>
      <dc:creator>Ravi Singh</dc:creator>
      <dc:date>2013-07-22T02:05:01Z</dc:date>
    </item>
    <item>
      <title>Web Redirect is not working</title>
      <link>https://community.cisco.com/t5/wireless/web-redirect-is-not-working/m-p/2225906#M67637</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In case you haven't resolved your problem. I would like to ask if you have created a DNS record for the ISE? Also if you're using pre-authentication ACL on the WLC, make sure that the Protocol is TCP and not UDP for port 8443&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Aug 2013 10:13:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/web-redirect-is-not-working/m-p/2225906#M67637</guid>
      <dc:creator>grabonlee</dc:creator>
      <dc:date>2013-08-14T10:13:04Z</dc:date>
    </item>
    <item>
      <title>I see this is a bit of an old</title>
      <link>https://community.cisco.com/t5/wireless/web-redirect-is-not-working/m-p/2225907#M67638</link>
      <description>&lt;P&gt;I see this is a bit of an old thread, right now I'm having the exact same problem. The weird thing is, It was working properly for a few weeks, suddenly today it started behaving &amp;nbsp;like this, the redirection to the ISE portal gets done, and when I log in ISE shows the authentication was done right and the users get redirected to &lt;A href="https://1.1.1.1/login.html" target="_blank"&gt;https://1.1.1.1/login.html&lt;/A&gt; but they can't access that URL so it gets stuck there. Anyone knows what's up with this?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2014 22:41:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/web-redirect-is-not-working/m-p/2225907#M67638</guid>
      <dc:creator>eric.ahernandez</dc:creator>
      <dc:date>2014-04-22T22:41:05Z</dc:date>
    </item>
    <item>
      <title>Oooook, now I feel dumb for</title>
      <link>https://community.cisco.com/t5/wireless/web-redirect-is-not-working/m-p/2225908#M67639</link>
      <description>&lt;P&gt;Oooook, now I feel dumb for replying at my own post with the answer.... &amp;nbsp;So it turns out I actually did some changes a day before problems started, I disabled the&amp;nbsp;WebAuth SecureWeb option (since I don't have a certificate right now and I was testing to see if stops doing the https redirection prompting for the certificate) &amp;nbsp;and the problem was after the authentication it still redirects to &lt;A href="https://1.1.1.1/login.html" target="_blank"&gt;https://1.1.1.1/login.html&lt;/A&gt; and it doesn't work because it's disabled. I'm trying to disable it but to keep working, is there any way to configure the redirection to the WLC virtual IP address to be HTTP instead of HTTPS? Disabling he secureweb option doesn't seem to do the trick...&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2014 23:39:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/web-redirect-is-not-working/m-p/2225908#M67639</guid>
      <dc:creator>eric.ahernandez</dc:creator>
      <dc:date>2014-04-22T23:39:32Z</dc:date>
    </item>
    <item>
      <title>Hi Eric, In your case, the</title>
      <link>https://community.cisco.com/t5/wireless/web-redirect-is-not-working/m-p/2225909#M67640</link>
      <description>&lt;P&gt;Hi Eric,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In your case, the redirect is handled by ISE and not the WLC. If you want HTTP to work, then you have to remove the ISE portal as the external redirect URL under the Security tab of the WLC and instead point to internal page of the WLC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Alternatively, if you still want to use ISE as the redirect server, try changing the port number from :8443 and specify your HTTP port, which can be 80, 8080 or other user defined ports. However, whatever port you choose has to be allowed through your firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Thu, 24 Apr 2014 08:39:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/web-redirect-is-not-working/m-p/2225909#M67640</guid>
      <dc:creator>grabonlee</dc:creator>
      <dc:date>2014-04-24T08:39:06Z</dc:date>
    </item>
    <item>
      <title>Well prasanesh i would</title>
      <link>https://community.cisco.com/t5/wireless/web-redirect-is-not-working/m-p/2225910#M67641</link>
      <description>&lt;P&gt;Well prasanesh i would suggest to go through cisco how to guide for step by step configuration of WLC with ISE and you can compare if any thing you have missed&lt;/P&gt;</description>
      <pubDate>Fri, 25 Apr 2014 07:34:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/web-redirect-is-not-working/m-p/2225910#M67641</guid>
      <dc:creator>kaaftab</dc:creator>
      <dc:date>2014-04-25T07:34:41Z</dc:date>
    </item>
    <item>
      <title>How is your pre-auth ACL</title>
      <link>https://community.cisco.com/t5/wireless/web-redirect-is-not-working/m-p/2225911#M67642</link>
      <description>&lt;P&gt;How is your pre-auth ACL configured in your WLC? This should be done on the anchor controller if you have one.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, if your DNS does not resolve the ISE IP address you can check the checkbox option to use the IP address instead of the FQDN, and the portal port has to be permitted on the firewall as well.&lt;/P&gt;</description>
      <pubDate>Thu, 29 May 2014 22:46:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/web-redirect-is-not-working/m-p/2225911#M67642</guid>
      <dc:creator>eric.ahernandez</dc:creator>
      <dc:date>2014-05-29T22:46:38Z</dc:date>
    </item>
  </channel>
</rss>

