cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2609
Views
0
Helpful
2
Replies

Guest Self Registration Portal - WLC AAA Authentication Server and redirected Portal on different PSN

Thomas Buergi
Level 1
Level 1

Hi All

I'm trying to setup Guest Self Registration Portal. I wanted to have the WLC Radius Requests handled by a PSN in the Secure Zone while the Portal redirection goes to another PSN in the DMZ.

As a result ISE throws a “400 Bad Request” to the client.

 

My Question:

Is it possible having Radius Server and Portal on different PSN or has it to be always on the same ?

 

Thanks Thomas

 

WLC AIR-CT5520-K9 SW:8.10.112.0

ISE Version:2.6.0.156 Patch 5

1 Accepted Solution

Accepted Solutions

thomas
Cisco Employee
Cisco Employee

All RADIUS requests for a given session should be handled by the same PSN. Even with load balancers we recommend "sticky" sessions to prevent confusion especially with multiple steps in a flow such as for Guest (AUP, registration, sponsor approval, etc.).

I think you're ultimately looking for a foreign/anchor wireless controller guest architecture:

image.png

 

image.png

View solution in original post

2 Replies 2

thomas
Cisco Employee
Cisco Employee

All RADIUS requests for a given session should be handled by the same PSN. Even with load balancers we recommend "sticky" sessions to prevent confusion especially with multiple steps in a flow such as for Guest (AUP, registration, sponsor approval, etc.).

I think you're ultimately looking for a foreign/anchor wireless controller guest architecture:

image.png

 

image.png

Hi Thomas

Thank you for your detailed information, this helps a lot.

 

Regards Thomas