cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
998
Views
0
Helpful
4
Replies

Redirect ACL not received on WLCv from ISE. Guest Portal access

Carlos T
Level 1
Level 1

Hello,

 

Any help on this one?

 

I am testing Redirect URL/ACL from ISE to the WLCv for open guest portal access, so the user is authenticated on the portal.

The user is able to connect to the wireless network, receives IP from DHCP server, but is not redirected to the Portal.

 

Checking the Radius Live logs on ISE for the user connected, I see ISE sends the Av Pairs for Redirect ACL and Redirect URL to the WLCv, so I think ISE is working good, but on WLCv logs for the connected user (Monitor tab, Security Information Section, I see the field for "Redirect URL" correctly populated with the Redirect URL string sent from ISE (which is good), but the field for the redirect ACL is empty (AAA Override ACL Name). I think this field should show the name of the redirect ACL configured on the WLCv and not empty.

 

Looks like WLCv could be missing something?

 

Sending some screen shots from ISE and WLCv. Appreciate any help.

 

On ISE Live radius log detail I see the wireless user is successfuly connected, and the ISE sends the AV Pairs for ACL Redirect name, and Redirect URL.

 

Captura de pantalla 2020-01-19 a las 22.04.54.pngCaptura de pantalla 2020-01-19 a las 22.05.07.pngCaptura de pantalla 2020-01-19 a las 22.05.13.png

 

On WLCv, the client connected entry on Monitor Tab, the Field "AAA Override ACL" is empty (I should see here the  redirect ACL name, but is not showing). The Field "Redirect URL" is showing  the URL from ISE which is good.

 

Captura de pantalla 2020-01-19 a las 22.21.40.pngCaptura de pantalla 2020-01-19 a las 22.22.13.pngCaptura de pantalla 2020-01-19 a las 22.22.37.png

 

On WLCv, the Redirect ACL "ACL-WEBAUTH-REDIRECT" is configured, and is matching by name the one configured on ISE Authorization profile for this redirection.

 

Captura de pantalla 2020-01-19 a las 22.25.54.pngCaptura de pantalla 2020-01-19 a las 22.26.12.png

 

ISE config for the Policy set WIRELESS, Authz policy rule "Default" have the Authorization profile "Guest_Redirect" where the redirect ACL name is configured for CWA.

 

Captura de pantalla 2020-01-19 a las 22.27.57.png

 

Captura de pantalla 2020-01-19 a las 22.28.43.png

 

Thanks,

Carlos.

 

 

1 Accepted Solution

Accepted Solutions

If you copied/pasted the ACL name into the ISE AuthZ Profile, make sure you don't have any trailing whitespace characters as they are not really visible when looking at the configuration or logs. I've seen this cause issues in the past.

If there are none, I would suggest opening a TAC case to check for any known bugs in the WLCv code version you're running and investigate further.

 

Cheers,

Greg

View solution in original post

4 Replies 4

Colby LeMaire
VIP Alumni
VIP Alumni

On your WLC and under the SSID settings, Advanced tab, do you have "Allow AAA Override" checked?

Hi Colby,

 

I enabled "Allow AAA Override" for the SSID "p0-guest", but still is not showing the redirect ACL on the field "AAA Override ACL".

 

Captura de pantalla 2020-01-19 a las 23.42.18.pngCaptura de pantalla 2020-01-19 a las 23.42.53.png

If you copied/pasted the ACL name into the ISE AuthZ Profile, make sure you don't have any trailing whitespace characters as they are not really visible when looking at the configuration or logs. I've seen this cause issues in the past.

If there are none, I would suggest opening a TAC case to check for any known bugs in the WLCv code version you're running and investigate further.

 

Cheers,

Greg

You can also check the ISE guest prescriptive guide at http://cs.co/ise-guest

Also approach the TAC as we don't have resources to look at logs and debug here