cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
855
Views
0
Helpful
1
Replies

Guest portal cannot auto redirect. ISE 2.7

ichsan5495
Level 1
Level 1

Hi.

My client have an issue with the BYOD guest portal cannot auto redirect and should manually type the other url to open it in browser. and the second issue. after login in the gues portal not have an internet access. it still going to open guest portal again. I check the config on WLC and ISE already follow the best practice. I guess it's on the cache MAC. but if I want to test it. I remove the mac on the live logs ISE first

have anyone fight with the same issue?

ISE 2.7 patch 2.5

WLC 5800 version 8.5.160

thank you

1 Reply 1

Arne Bier
VIP
VIP

Guest portal redirection issues are very common and the cause will vary depending on a few things. It's not automatically a fault in ISE. Most commonly it's either

- WLC has Apple CNA bypass enabled (CNA is the detection mechanism in iOS to bring up a type of browser to log a user into the guest wifi - the problem with BYOD is that you can't use this because BYOD flow executes code in the "browser" and CNA is not a real browser - hence why this has to be disabled to allow the Cisco ISE BYOD to work)

- ACLs in the WLC are not correct to trigger the URL redirection. In 9800 case the ACL logic is slightly different to the AireOS. The AirOS pre-auth ACL should allow DNS, DHCP and access to ISE PSN - and block everything else.  Ensure client DNS can resolve the ISE portal