ā11-06-2017 01:41 AM - edited ā02-21-2020 10:38 AM
Hi,
What could be the problem if the client is not getting back a redirect url from the wlc ? .
and if Wlc is getting redirect url
Thanks
ā11-06-2017 01:43 AM
ā11-06-2017 01:56 AM - edited ā11-06-2017 02:00 AM
Hi
I am using fqdn , client can resolve any fqdn including node .
If it is dns issue atleast I could see the something like below on the broswer
In my case Ican't see anything like that above
Thanks
ā11-06-2017 12:05 PM - edited ā11-06-2017 12:17 PM
Check wlc coa configuration on AAA Radius authentication,
Check SSID -- advance --- radius nac and aaa override
Check WLC preauth ACL pointing to the PSN on 8443
IF you are using an F5 solution, the static FQDN option does not work properly.
ā11-07-2017 08:22 AM
Hi,
Sorry .It's not static fqdn
Thanks
ā11-07-2017 08:38 AM
Hi,
Here is the preauth acl
ip access-list extended redirect_acl
deny udp any any eq bootps
deny udp any any eq bootpc
deny udp any any eq domain
deny ip any host 192.168.5.41 (ise)
deny ip any host 192.168.5.42
permit tcp any any eq www
permit tcp any any eq 443
Thanks
ā11-07-2017 09:09 AM - edited ā11-07-2017 09:16 AM
We are using hotspot portal, sponsor portal for guest account creation, guest webauth portal (WLC URL Redirect), etc with no issues. Try to keep it simple. AND Mohammed is correct.
The preauth acl is intended to keep the communication ONLY between enduser and ISE/DNS so no navigation is involved at all until your AUTHC/AUTHZ is completed (including AUP page accepted if it applies).
ā11-07-2017 09:24 AM - edited ā11-07-2017 09:25 AM
A few links that you could take a look:
ā11-07-2017 09:06 AM
ā11-07-2017 11:42 AM
Hi,
I could not follow what you have said ,Can you explain
Sorry for that
Thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide