ā02-23-2017 05:33 PM - edited ā03-11-2019 12:29 AM
I've got Aruba instant AP's using ISE for Guest authentication.
Users are authenticated successfully but it returns to login page again instead of redirection to original URL.
Radius logs shows the authentication is successful but it's not picking any authorization policy for some reason.
Solved! Go to Solution.
ā09-20-2022 04:08 AM
Hello,
I had the same problem, but I have resolved it. I used two different roles on Aruba one guest-redirect where I would redirect it to the cisco ISE portal and the other one guest-authenticated where I give internet access only and make sure that you do not enable "Download Role" on the Access tab when you create the SSID. On the Cisco ISE side also create two authorization profiles one for CWA where you would send the "Aruba-User-Role = guest-redirect" and the other one where you would send the "Aruba-User-Role = guest-authenticated. This has worked for me. I hope that will help you too.
ā02-23-2017 08:30 PM
Hi,
Seems like COA is not happening. Could you please confirm the following:
1) Send the screenshot of ACL on WLC.
2) Check if WLC is configured for COA
Security > Radius > Authentication
Check if Support for COA is enabled.
http://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/115732-central-web-auth-00.html#anc5
Regards
Gagan
PS: rate helpful posts!!!!!
ā02-23-2017 09:21 PM
ā02-24-2017 08:39 AM
To be honest, I have never seen different ports on both WLC and SERVER.
If you can make it 3799 and see if that makes any difference.
Regards
Gagan
ā06-13-2022 07:23 PM
Hello,
I'm facing the same issue, portal page keeps looping.
Did you resolve the issue?
Please share
ā09-20-2022 04:08 AM
Hello,
I had the same problem, but I have resolved it. I used two different roles on Aruba one guest-redirect where I would redirect it to the cisco ISE portal and the other one guest-authenticated where I give internet access only and make sure that you do not enable "Download Role" on the Access tab when you create the SSID. On the Cisco ISE side also create two authorization profiles one for CWA where you would send the "Aruba-User-Role = guest-redirect" and the other one where you would send the "Aruba-User-Role = guest-authenticated. This has worked for me. I hope that will help you too.
ā09-20-2022 04:49 AM
This is the way^
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide