cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
197
Views
1
Helpful
2
Replies

ISE guest hotspot post-auth issue

pb100
Level 1
Level 1

ISE 3.3.0 running on 3615 appliances

IOS-XE 17.9.5 on 9800-40 WLCs

We have some odd behaviour with a new hotspot portal. Everything up to authentication appears to be working correctly - user is prompted to sign in on connecting to the SSID, redirect is sent to the WLC, portal page is displayed, internet ACL is sent to the WLC when the user accepts the ToU, and the authentication success page is displayed.

However with some devices the user still does not have network access. This primarily appears to affect Android devices, but not all - I haven't observed it with iOS or Windows clients. Refreshing the auth success page does something which causes auth to be successful/the internet ACL to be applied correctly, and the network then shows as connected and the user has internet access.

The fact that this isn't universal in our deployment suggests it's a client issue, but I'm at a loss to understand how a client issue could apparently prevent the correct ACL from being applied by the WLC!

Has anyone come across this issue before? Any pointers on whether it's likely to be an ISE, WLC or client issue, and on where I can look to gather more information if it isn't client? Thanks!

 

2 Replies 2

balaji.bandi
Hall of Fame
Hall of Fame

how is the certs configured, is this FQDN or IP ?

Make sure the valid cert trusted by the client, always suggest to use cert Public signed one.

check the packet flow :

https://www.youtube.com/watch?v=MOIpRLpfGvo

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Cisco ISE TME Charlie Moreton shares how to get started with ISE Guest Services.

If device use randomize MAC then it will failed to access'

The ISE learn MAC and add it to identity group so it will use it after CoA'

If Android use this feature then it mac is change always and it failed to authc/authz by ISE

MHM

Review Cisco Networking for a $25 gift card