cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3016
Views
0
Helpful
6
Replies

9800 / ISE Hotspot Portal

neteng1
Level 1
Level 1

I have configured a Hotspot portal and auth policies on ISE. A new client is successfully redirected to the portal and added to the GuestEndpoints group after accepting the policy. However, the client stays in Webauth Pending state on the 9800 WLC.

After disconnecting/reconnecting the client, it connects successfully without redirect. Any thoughts why the 9800 is not re-authorizing the client?

1 Accepted Solution

Accepted Solutions

neteng1
Level 1
Level 1

My problem was related to a combination of load balancing and authorization policy issues.

View solution in original post

6 Replies 6

neteng1
Level 1
Level 1

I may be encountering bug CSCvv52637.

neteng1
Level 1
Level 1

My problem was related to a combination of load balancing and authorization policy issues.

Can you elaborate on the solution?  I am seeing the same issue, however I am not load-balancing any of my connections.  We are in the process of upgrading from a 5508 to a 9800 WLC, and the auth policy that we were using was working fine for the 5508.  I'm not sure if disconnecting and reconnecting works, didn't try that.  In our case, after entering the hotspot password, it would try to redirect to the actual web site, then back to the psn, and bounce between the two without ever opening anything in the browser.  The bouncing was visible in the address bar.  Eventually, it would fully work.

The load balancing was because I needed a policy for CoA port 1700. After accepting the AUP, the user should be added to an identity group, re-authenticated, and then match a simple 'Permit' authorization policy based on their new identity group. Are any of those working for you? It sounds like your user may be in an authorization loop. Make sure the 'Permit' policy is before the 'Redirect' policy. Network Access --> Troubleshoot --> TCP Dump | will also help narrow down what's occurring.

Nope, I've got all of that.  Again this was all working fine with 5508 controller, it's only since moving to 9800 that the issue cropped up.  I have two rules for guest access - first rule checks if user is in guest identity group, second rule redirects to login page and valid password adds to identity group.  

Did a little more testing today, and it appears that in our case during the 15 minutes or so that it takes the client to become active, even though they are in the proper identity group, disabling WiFi or rebooting so it truly starts a new session makes no difference.  ISE error messages seem to imply that the WLC is not responding to the COA request.  We took debug logs from the WLC today, will see if anything turns up.

There is a checkbox in AAA settings on the 9800 to trust CoA from the radius server. That should be checked.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card