08-06-2026 05:46 AM - edited 08-06-2026 05:50 AM
I have an old ASA firewall that I want to replace. The FW is used for guest access, where clients are redirected to a portal when they first connect to the network.
After replacing the FW, clients were no longer redirected to the portal. I copied the exact CLI config from the old FW and pasted it onto the new firewall.
What could be the problem?
I think the portal is configured on a WLC, and maybe the redirect handled by an ISE. Is it possible that the APR table in the WLC/ISE must be flushed when the new FW is connected?
08-06-2026 05:59 AM
@Ab26 is the basics working such as routing working? From the firewall can you ping the source networks and the portal?
Run packet-tracer from the CLI to simulate the traffic flow, provide the output for review. Provide the configuration will also help understand your scenario better?
08-06-2026 09:22 AM
If the ASA config is identical, you should also look outside the firewall. If the captive portal is handled by the WLC and ISE, they may still have the old ASA's MAC address or ARP entry cached. Try clearing the ARP cache on the WLC (and ISE if applicable), then reconnect a test client. Also make sure the new ASA is using the same IP, interface settings, and NAT behavior as the old one. Even a small difference there can prevent the redirect from working.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide