cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1045
Views
0
Helpful
2
Replies

Guest portal redundancy

Ahmed.Y.Eissa
Level 1
Level 1

here is my deployment workflow

 

User >> GUEST_SSID >> AAA to PSN1 >> Redirect user to FQDN Guest.XXX.org >> Configure DNS load balance to resolved FQDN to PSN1 or PSN2

 

Should this workflow work? or i should configure it statically as

 

User >> Guest_SSID >> AAA to PSN1 >> Redirect user to FQDN Guest.xxx.org >> DNS must resolve Guest.xxx.org to PSN1 only .

 

 

 

2 Replies 2

Ahmed.Y.Eissa
Level 1
Level 1

i think that PSN are not syncing URL-redirect sessions as each session has unique ID to Each PSN , right??

 

 

Octavian Szolga
Level 4
Level 4

Hi,

 

Each PSN can have a valid cert for it's own guest portal FQDN or one cert with SANs for all FQDNs.

 

In ISE you can configure something similar with what you wrote:

Guest SSID -> Request received by PSN1 -> Authz profile with CWA static URL - PSN1 guest FQDN

Guest SSID -> Request received by PSN2 -> Authz profile with CWA static URL - PSN2 guest FQDN

 

Thanks,

Octavian