cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1048
Views
2
Helpful
5
Replies

browser won't pop up during cisco guest portal

seanxiao
Level 1
Level 1

GREETINGS all,

We  suddenly have an issue that guest user cannot complete the guest portal authentication because the browser cannot pop up.

From the ISE live log:

  1. device authentication successful;
  2. device get the configured IP address  (a guest VLAN);
  3. device can communicate with the guest DNS server with the assigned guest IP
  4. device hit the desired authentication policy and authorization policy

but the device cannot access guest portal even we manually input the URL , neither can the device access Internet. Please see the log as below:

Result

User-Name10-A5-1D-09-30-2B
ClassCACS:0af0c5080006598267e0c924:ZJK-SVAP-PSN01/524332189/308487
cisco-av-pairurl-redirect-acl=ACL_WEBAUTH_REDIRECT
cisco-av-pairurl-redirect=https://guestportal3.int.my-domain.com:8450/portal/gateway?sessionId=0af0c5080006598267e0c924&portal=021ff832-a158-4e12-be34-edf81c2d8efe&action=cwa&token=b9593114317c8774158992fe0c5c9796
cisco-av-pairprofile-name=Intel-Device
LicenseTypesEssential license consumed.

Session Events

2025-03-24 02:53:30.028RADIUS Accounting start request
2025-03-24 02:53:24.858Authentication succeeded
Event5200 Authentication succeeded
UsernameDevice-mac-address
Endpoint IdDevice-mac-address
Calling Station IdDevice-mac-address
Endpoint ProfileIntel-Device
Identity GroupProfiled
Audit Session Id0af0c5080006598267e0c924
Authentication Methodmab
Authentication ProtocolLookup
Service TypeCall Check
Network Devicewlc-name
Device TypeAll Device Types#WLC
LocationAll Locations#my-location
NAS IPv4 AddressMy-WLC-IP-address
NAS Port TypeWireless - IEEE 802.11
Authorization ProfileCisco_WebAuth_ZJK
Response Time58 milliseconds

Other Attributes

ConfigVersionId141
DestinationPort1812
ProtocolRadius
NAS-Port13
Framed-MTU1300
Acct-Session-Id67e0c924/10:a5:1d:09:30:2b/485408
Tunnel-Type(tag=0) VLAN
Tunnel-Medium-Type(tag=0) 802
OriginalUserName10a51d09302b
NetworkDeviceProfileIdb0699505-3150-4215-a80e-6753d45bf56c
IsThirdPartyDeviceFlowfalse
AcsSessionIDZJK-SVAP-PSN01/524332189/308487
SelectedAuthenticationIdentityStoresInternal Users
AuthenticationStatusUnknownUser
IdentityPolicyMatchedRuleMAB
AuthorizationPolicyMatchedRuleAurobay-Guest Redirect
EndPointMACAddressdevice-mac-address
ISEPolicySetNamepolicy-set-name
IdentitySelectionMatchedRuleMAB
TotalAuthenLatency58
ClientLatency0
DTLSSupportUnknown
HostIdentityGroupEndpoint Identity Groups:Profiled
Network Device ProfileCisco
LocationLocation#All Locations#my-location
Device TypeDevice Type#All Device Types#WLC
IPSECIPSEC#Is IPSEC Device#No
RADIUS UsernameDevice-mac-address
NAS-IdentifierWLC-Name
Device IP AddressWLC-IP
CPMSessionID0af0c5080006598267e0c924
Called-Station-ID2c-33-11-ba-78-00:SSID-NAME
CiscoAVPairaudit-session-id=0af0c5080006598267e0c924
UseCaseHost Lookup
5 Replies 5

Rich R
VIP
VIP

the device cannot access guest portal even we manually input the URL
What exactly happens?  Do you get an error message? Does it timeout?
Did you enable browser network trace to see what that shows?
Did you do a packet capture to see what that shows?
Are you using a valid public certificate for guestportal3.int.my-domain.com which is trusted by the client OS and browser?
Are you sure the certificate has not expired?

thanks for your reply

now the browser pops up, and the DNS works when we do nslookup www.google.com [DNS_For_Guest]

now the issue is that the end device can get IP from the guest VLAN, but cannot access any network resource, even cannot ping its guest VLAN gateway. When I do ping gateway from the device, all is time out. If I ping from where the gateway is residing (fortigate), it just showing icmp echo request, but never got a reply.

Scott Fella
Hall of Fame
Hall of Fame

Just to confirm, This exact configuration was working previously and now "SUDDENLY ALL" guest devices are no longer working?  So no matter if its an iPhone, Android, Windows or Mac, you are seeing the same issue?  If this is the case, I would think something has changed that broke this.

-Scott
*** Please rate helpful posts ***

thanks for your reply

now the browser pops up, and the DNS works when we do nslookup www.google.com [DNS_For_Guest]

now the issue is that the end device can get IP from the guest VLAN, but cannot access any network resource, even cannot ping its guest VLAN gateway. When I do ping gateway from the device, all is time out. If I ping from where the gateway is residing (fortigate), it just showing icmp echo request, but never got a reply.

have you check correct ip given from the dhcp pool and ise authz rules set up correctly ( Any override  Vlans configured ) . Check the log on the ise and switch port. If you accessing via Guest SSID why do you need access to network devices ? is you ssid set up for DMZ zone ?Check the Guess portal access-list if you have block icmp .

Review Cisco Networking for a $25 gift card