<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: External webauth with flexconnect in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/external-webauth-with-flexconnect/m-p/1937164#M81053</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It has to do with the traffic flow. For external webauth you need the pre-auth acl configured allowing the client to reach the ISE. But the WLC doesn't have that control of the guest traffic is going to be locally switched. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 23 May 2012 21:24:28 GMT</pubDate>
    <dc:creator>Stephen Rodriguez</dc:creator>
    <dc:date>2012-05-23T21:24:28Z</dc:date>
    <item>
      <title>External webauth with flexconnect</title>
      <link>https://community.cisco.com/t5/wireless/external-webauth-with-flexconnect/m-p/1937163#M81052</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Trying to use ise (1.1) as an external webauth within a flexconnect/h-reap setup (WLC:7.2.103)... Can't get it to work.. After a lot of testing/troubleshooting found this: ﻿&lt;A href="http://www.cisco.com/en/US/products/ps10315/products_tech_note09186a0080736123.shtml#webauth" target="_blank"&gt;http://www.cisco.com/en/US/products/ps10315/products_tech_note09186a0080736123.shtml#webauth&lt;/A&gt;&lt;/P&gt;&lt;P&gt;That says: "External web Authentication is only supported on a centrally switched WLAN"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone can explain why/how this should be an issue....Anypne got it to work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BG&lt;/P&gt;&lt;P&gt;Kasper&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 05:12:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/external-webauth-with-flexconnect/m-p/1937163#M81052</guid>
      <dc:creator>Kasper Roholt</dc:creator>
      <dc:date>2021-07-04T05:12:16Z</dc:date>
    </item>
    <item>
      <title>Re: External webauth with flexconnect</title>
      <link>https://community.cisco.com/t5/wireless/external-webauth-with-flexconnect/m-p/1937164#M81053</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It has to do with the traffic flow. For external webauth you need the pre-auth acl configured allowing the client to reach the ISE. But the WLC doesn't have that control of the guest traffic is going to be locally switched. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2012 21:24:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/external-webauth-with-flexconnect/m-p/1937164#M81053</guid>
      <dc:creator>Stephen Rodriguez</dc:creator>
      <dc:date>2012-05-23T21:24:28Z</dc:date>
    </item>
    <item>
      <title>External webauth with flexconnect</title>
      <link>https://community.cisco.com/t5/wireless/external-webauth-with-flexconnect/m-p/1937165#M81054</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi Stephen,&lt;/P&gt;&lt;P&gt;&amp;nbsp; Can you please explain the traffic flow for HREAP AP with an SSID which is webauth configured and local switching enabled ? This is how i see it :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. client sends DHCP request and gets IP on locally defined VLAN on the HREAP AP&lt;/P&gt;&lt;P&gt;during this, the controller get to know of the client association via the CAPWAP control message from HREAP AP&lt;/P&gt;&lt;P&gt;2. Client opens browser and enter website address (google.com) and gets the controller webauth login page&lt;/P&gt;&lt;P&gt;is this step&amp;nbsp; happening in the capwap tunnel or outside it ? the TCP communication between client and WLC&lt;/P&gt;&lt;P&gt;3. Client enters username and password for webauth &lt;/P&gt;&lt;P&gt;but the wlc virtual IP is not routed anywhere, so how will the username and password reach the wlc ? (through the capwap tunnel ? )&lt;/P&gt;&lt;P&gt;4. controller checks the username/password eiither locally defined or can be on a nac guest server or ISE ?&lt;/P&gt;&lt;P&gt;if the username/password reaches the controller, it should be able to verify the credentials wtih an external entity like NGS oR ISE ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Joe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Sep 2012 14:28:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/external-webauth-with-flexconnect/m-p/1937165#M81054</guid>
      <dc:creator>wireless wlc</dc:creator>
      <dc:date>2012-09-21T14:28:00Z</dc:date>
    </item>
  </channel>
</rss>

