cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2784
Views
0
Helpful
4
Replies

ISE integration with Arista Wifi

cxo-179682
Level 1
Level 1

Hello,

 

I'm currently testing integration between our ISE 2.6 with Arista AP for the Guest and BYOD portal, but running into some issues, the flow would be typically standard whereby user will connect to guest or byod SSID respectively, and get redirected to the ISE Portal page for authentication,  but im not getting any HTTP page redirection at all. 

 

Below are the documentation from Arista :

https://wifihelp.arista.com/post/integration-with-cisco-ise/?pdf=981

https://wifihelp.arista.com/post/role-based-access-control-for-radius-mac-authentication?term=role%20profile&page=1

 

I'm in the midst of checking with Arista on the AP configuration, but would like to cover my base for ISE configs as well, if anyone got any direction where i may have misconfigured

 

Thanks in advance

1 Accepted Solution

Accepted Solutions

cxo-179682
Level 1
Level 1

Found the redirection issue, and it's the laptop, used another laptop and ipad, redirection works perfectly. 

But im faced with another challenge which im trying for Guest Portal :

1- Client connect to Guest SSID

2- Arista AP redirects to ISE Guest Portal 

3- Client entered username and password, accepted AUP and then nothing happens.. 

Checked on the ISE logs, it's not hitting any policies at all, only stated it's a Guest Identity store, no matching Authentication/Authorization policy. But the client manages to logon and it just stuck there.. no OK button to proceed or anything.. 

 

Any clue ?

 

View solution in original post

4 Replies 4

I have not tested Aristra, but in Cisco WLC/AP you need to deny the traffic
to web on http and https (except http to ISE) for redirection to trigger.
This is in addition to enabling HTTP access.

Do you have this enabled? Otherwise, check in Arista docs on how to trigger
HTTP redirection.


**** please remember to rate useful posts

Thanks for your reply, I did check on Arista docs, nothing mentioned for the ACL, only need to enable HTTP Redirection with ISE URL. But i've tried your suggestion and it's still not popping any ISE Portal page when i connect to the SSID.

First make sure that you are browsing HTTP page. NOT HTTPs. Sometime the
browser will go to HTTPS page because its cached.

If still same, do a packet capture on your client and see if you receive
302 HTTP response from Arista when trying to browse google for example. If
not you need to open a ticket with Arista.

***** please remember to rate useful posts

cxo-179682
Level 1
Level 1

Found the redirection issue, and it's the laptop, used another laptop and ipad, redirection works perfectly. 

But im faced with another challenge which im trying for Guest Portal :

1- Client connect to Guest SSID

2- Arista AP redirects to ISE Guest Portal 

3- Client entered username and password, accepted AUP and then nothing happens.. 

Checked on the ISE logs, it's not hitting any policies at all, only stated it's a Guest Identity store, no matching Authentication/Authorization policy. But the client manages to logon and it just stuck there.. no OK button to proceed or anything.. 

 

Any clue ?