cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
341
Views
0
Helpful
0
Replies

ISE CA BYOD and Anchor WLC

Hello!

I am having some trouble trying to configure BYOD using ISE internal CA in a Dual SSID deployment with an Anchor WLC that is used to perform the onboarding. I am able to go through the BYOD flow and issue certificates to my client when I am not using the Anchor function of the WLCs. 

WLC1 = has AP connect, foreign controller

WLC2 = no AP connect, anchor controller

When I activate the Anchor function to send traffic from WLC1 to WLC2 I am able to reach the BYOD Portal. After logging in I am asked to enter a name for my device  and they proceed with the onboarding process. On Windows 7 I am asked to download a wizard to complete the onboarding, but the download never starts and eventually the session is timed out. On iOS I am asked to use the Apple native supplicant to continue the onboarding process but clicking the button just show the loading icon until it finally times out.

The reason I am trying to use an Anchor WLC for the onboarding part is that we wish to disable the minibrowser poput for clients without actually disabling it on our "big" WLC. We have other guest networks that we wish to use minibrowser poput for but it works really bad for onboarding purposes which is why we are trying this solution. For the actual connection to the 802.1x network, WLC1 is used (no anchoring).

I am using ISE 2.3 and WLC 8.3 (foreign) and 8.4 (anchor). There are no firewalls between any of the devices (lab network).

Is onboarding using an Anchor WLC simply not supported?

0 Replies 0