cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
756
Views
0
Helpful
5
Replies

Auth VLAN, URL Redirect and DNS Sinkhole...

Hi all;

I use Ubiquiti access points in my network and want to implement Guest Services (Central Web Authentication). As far as I know, this type of devices does not support RADIUS URL Redirection from ISE. Therefore, I decided to circumvent this limitation using DNS Sinkhole functionality in ISE. As you can see in the following figures, the endpoint (after connecting to the appropriate SSID), receives required IP Address and DNS info correctly (I have added a second interface to ISE with IP address of 172.16.10.120

 
1000.png

 1000.png

After successfully acquiring the required DHCP information from ISE, the client opens the following browser window:

1000.png

 As you can see above, the redirection process times out. The following figures show the Wireshark capture of the process:

1000.png

 2000.png

Any ideas?

Thanks

 

5 Replies 5

@rezaalikhani 

 All similar implementation I can see, uses CoA. Does you device support CoA.

  https://www.linkedin.com/pulse/cisco-ise-dns-sinkhole-functionality-smart-way-support-alikhani/

 

Thanks for your reply;

Yes, it does...

I want to know that, if I have several portals published in the dedicated interface, how ISE determines which to offer to the endpoint?

Thanks

 

Thanks for your reply;

I do not think the provided link answers my question because based on my assumption we cannot specify any portals in the Authorization profile, because the target device does not support URL Redirection RADIUS attribute. Right?

 

Actually the post in question address you question related to support for multiples portal per interface.

 Regarding your scenario, the first link have the answer as long as you can do CoA, which seems you are not doing as your attempt stop  in the 303 moved permanently.