cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
96
Views
0
Helpful
0
Replies

Guest Portal Redirect Timeout on Cisco ISE 3.5 – Multi-Node Cluster

MaErre21325
Level 1
Level 1

Hello everyone,
I’m facing an issue with Cisco ISE Guest Portal where the redirect page does not load and goes times out.

ISE version is 3.5 and the Cluster is made up of 4 nodes: 2 Admin/Monitoring nodes (with gi0 used for management) and 2 PSNs (one in LATAM, one in APAC) (with gi0 for management, gi1 for radius service and gi2 for guest)
Both WLC and ISE are configured to use the same redirect ACL and Guest portal is exposed on Gi2 of the PSNs (configured in ISE Guest settings).
Static route added on PSNs for guest network:

ip route 192.168.100.0 255.255.255.0 10.23.50.1

The Firewall rule allows traffic from Guest network to PSNs on TCP 8443.

However when a client connects, the redirect page times out.
Firewall logs show unidirectional traffic from client to PSN (Gi2 IP).
TCP dump confirms only one-way traffic.
Even a manual telnet from the client to PSN Gi2 IP on port 8443 fails (connection refused).

What should I check next?
Could this be a routing or interface binding issue on the PSN?
Any tips on troubleshooting why the portal is not responding?
In attachment the screenshot of the errors/trace

Thank you
Regards

 

 

 

  

0 Replies 0