cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
998
Views
0
Helpful
4
Replies

C9800-CL - Web portal takes long time to load or simply not load

morabusa
Level 1
Level 1

Hi,

We are facing an issue where all guest clients are taking too long time (2 or 3 minutes) to load the web portal, or simply fail to load it in the first try. Then after the first try, everything works fine if clients disconnect and connect againt, and they are able to load the web portal pretty fast. When we detect the issue in the first try, I cannot see any traffic reaching the ISE, and if I try to ping the client from the local router, I cannot reach the client, despite of the client getting an IP address from DHCP server (which is the local router).

Are you aware of a bug or some parameter which could bring this issue?

The Guest WLAN is configured in Local Switching, and redirect ACL is correctly configured according to the lastest section in this guide:

https://community.cisco.com/t5/security-documents/ise-and-catalyst-9800-series-integration-guide/ta-p/3753060#toc-hId-186721248

Thanks.

 

EDIT: Adding more information:

C9800-CL - IOS: 7.3.3

AP1832I

Comparing the WLC debugs, the output is the same when it fails, compate to when it works fine. 

Currently checking the issue with the TAC but without success.

4 Replies 4

Rich R
VIP
VIP

get a packet capture (radioactive trace) on a client to see what's not working.

I have just edited the original message. Radioactive Trace does not show anything which could explain the issue. Both traces (when it works and when it does not) are identical, and the last message is: L3 Authentication initiated. CWA.

Yes, I got captures with wireshark. The client got an IP, and was trying to send traffic to the right default gateway's MAC address but without success. Then everything started working fine after some time for some reason (same happens with any device we try to connect to the guest network for first time, or if we connect the device again after some hours disconnected). I have been thinking that it is maybe something related to the LAN switches, but I really cannot find any valid reasoning about why this is happening. Maybe something related to STP, but it would be really weird that some ports would go to block state during some time, but this is something I am going to check in the next tests.

 

We do not have any kind of port security, so STP is the only thing which could bring this issue, but it would be really weird though. Thanks for answering.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card