cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1218
Views
0
Helpful
7
Replies

ISE Guest Authentication using WLC

danielnunes
Level 1
Level 1

Folks,

i am using the guest portal on ISE and WLC and i saw that all papers and guides are requesting that you need to use the Authentication (Web Policy) under Layer 3 security WLAN but for me just using the Passtrough option works fine, when i use the Passthrough option the guest cannot authenticate and the Auth Guest page still requesting me the credentials.

Thanks a lot

7 Replies 7

Richard Atkin
Level 4
Level 4

Please DO NOT use the WebAuth Config in the WLC, it doesn't work properly. Your best bet is to review the TrustSec 2.1 guide... It will show you how to do MAB and CWA to achieve your goal.

Richard.

Sent from Cisco Technical Support iPad App

Not all docs say use web policy as L3, only the docs that are about how to setup L3 Web Auth are.  Docs are normally written for a specific example in mind.  Depending on what your own policy and circumstances are you might need to use LWA, L3 external Web Auth, or maybe just L2 MAC filtering for CWA.

Guys, thanks for that responses, i ll check all this things.

If someone has a example or a good paper about CWA and MAD please post it to me.

Thanks a lot

what controller model and what software are you running?

I've checked and i am running 7.0 version, i saw on the Trust Sec 2.1 que i can not configure WLC usng the CWA, just under 7.2 or later.

this way i need still using web redirect on WLC.

thanks a lot

you can use LWA, but you must be carefull using WLC, it can't redirect HTTPS traffic due to bugs

https://tools.cisco.com/bugsearch/bug/CSCar04580

and i think there is still problem about certificate with LWA, so sometimes need to disable secure-web web-auth...

manjeets
Level 3
Level 3

                   Please find the attachment,

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: