cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
463
Views
1
Helpful
11
Replies

Cisco ISE and Aruba integration

JADF
Level 1
Level 1

Hi,

I have an ISE running version 3.3, and I have the Aruba IAP running Aruba virtual controller.

I'm trying to use ISE to generate a captive portal for the wireless users.

Now the users are able to get the portal but once they are authentoicated, they are receiving a white screen with no internet connection.

Any idea what could be the problem here?

P.S: I'm new to ISE.

Thanks in advance for your help.

Regards,

11 Replies 11

marce1000
Hall of Fame
Hall of Fame

 

  - @JADF          FYI : https://community.cisco.com/t5/security-knowledge-base/how-to-cisco-ise-captive-portals-with-aruba-wireless/ta-p/4633904
                                   (   https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/200270-ISE-2-0-3rd-Party-integration-with-Aruba.html )

  M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Hi Marce1000, and thank you for the response.

Actually i followed both guides, one is configuring the portal for BYOD access, which is different to waht we are trying to do, and the other is using mobility controller not a virtual one.

CoA defualt port  of ISE is 1700

I think aruba use different port check this point 

MHM

Thanks for your response, actually we are using port 3799

Any update about  this issue ?

Did you check radius live ?

MHM

marce1000
Hall of Fame
Hall of Fame

 

  -  @JADF    On ISE you can follow up on authentications using :  Operations > RADIUS > Live Logs
                     Now since apparently the user gets authenticated ; the white screen issue could be something else
                                  (but verify correct authentication on ISE first indeed)

   M..



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Aruba IAP does not support the necessary VSAs for dynamic URL redirection. You need to use AOS 10 managed by Aruba Central instead. If you must stick with IAP, then you need to use the ISE DHCP/DNS server instead.

https://cs.co/ise-berg#aruba 

Thank you, I appreciate your response. 

I guess you are pointing to the dns sinkholing.

Would you please lead me to any documentation on how to configure DNS sink hole in ISE?

Thanks,

Yes, however it’s an extremely rare and underutilized feature in the field. Why can you not just use AOS10? The user experience will also be far better.

Actually, upgrading is almost impossible. That's why I need a documentation about this particular case.

If you can help, it will great.

Thanks anyway,

“Almost impossible” what does that mean? No one should really be using IAP in 2025. AOS10 with Aruba Central is the way forward.