ISE Guest Portal Certificate error
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-26-2022 07:21 AM
In a 2 node deployment for ISE 2.7 patch 5, we have sponsored guest setup, everytime the guest redirect, they are presented with this certificate with common name 10.1.1.1, this IP does not exist in our network, once you bypass the error, it redirects to guest page with correct certificate.
Don't think there is any issue configuration wise, its a standard guest config with portal pointing to a wildcard public cert and everything works except this error when clients get redirected to guest portal.
any suggestions ?
- Labels:
-
Guest
-
Identity Services Engine (ISE)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-26-2022 08:44 AM
What certificate tag is associate on your guest portal?
What is the NAD here? Cisco WLC? Something else?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-26-2022 02:58 PM - edited 07-26-2022 02:59 PM
NAD is 5520, portal is assigned a custom tag, associated with public cert for portal use.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-27-2022 06:08 AM
Are you performing SSL decryption anywhere within this flow?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-28-2022 07:53 PM
I don't think so, there is no firewall between client - wlc and ISE, I did find out that the cert we were getting was from WLC default cert and the problem is isolated to Apple devices only. Android and windows devices are working fine.
After reading couple of apple forums, I am going to try adding following URL to redirect ACL and enabling captive portal bypass and see if that helps, if you have any more suggestions let me know.
*.connectivitycheck.gstatic.com
*.clients3.google.com/generate_204
captive.apple.com
