02-26-2018 01:19 AM - edited 02-21-2020 10:46 AM
here is my deployment workflow
User >> GUEST_SSID >> AAA to PSN1 >> Redirect user to FQDN Guest.XXX.org >> Configure DNS load balance to resolved FQDN to PSN1 or PSN2
Should this workflow work? or i should configure it statically as
User >> Guest_SSID >> AAA to PSN1 >> Redirect user to FQDN Guest.xxx.org >> DNS must resolve Guest.xxx.org to PSN1 only .
02-26-2018 04:19 AM
i think that PSN are not syncing URL-redirect sessions as each session has unique ID to Each PSN , right??
02-27-2018 06:18 AM
Hi,
Each PSN can have a valid cert for it's own guest portal FQDN or one cert with SANs for all FQDNs.
In ISE you can configure something similar with what you wrote:
Guest SSID -> Request received by PSN1 -> Authz profile with CWA static URL - PSN1 guest FQDN
Guest SSID -> Request received by PSN2 -> Authz profile with CWA static URL - PSN2 guest FQDN
Thanks,
Octavian
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide