cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
552
Views
10
Helpful
4
Replies

Cisco 9800 Guest Anchor Wireless Setup

bjmcveety
Level 1
Level 1

I need some clarification on the setup for guest wireless utilizing c9800-40 as Foreign and c9800-L as the Guest Anchor. The SSID is setup as open[MAC filtering] with a self registered portal through ISE. The Mobility Tunnels are up and both controllers have been added to ISE. Attached is an example of the "guest-redirect" for ISE.... Where do I apply this on the controllers? And do I need to add it to both controllers or just the Guest Anchor?

bjmcveety_0-1666725726711.png

 

1 Accepted Solution

Accepted Solutions

bjmcveety
Level 1
Level 1

Okay, thank you very much to both of you for your help!

 

View solution in original post

4 Replies 4

Haydn Andrews
VIP Alumni
VIP Alumni

 

The entries on the foreign don't matter as it will be the anchor WLC applying the ACL to the traffic. The only requirement is that it is there and has some entry. The entries on the anchor have to "deny" access to ISE on port 8443 and "permit" everything else. This ACL is only applied to traffic coming "in" from the client so rules for the return traffic are not needed. DHCP and DNS will pass through without entries in the ACL.

https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/216500-catalyst-9800-central-web-authenticati.html#anc11

*****Help out other by using the rating system and marking answered questions as "Answered"*****
*** Please rate helpful posts ***

Thanks Haydn. The guide does not describe where to apply the Redirect ACL on the anchor or the foreign controller.

Arshad Safrulla
VIP Alumni
VIP Alumni

You don't have to apply this ACL anywhere. It will be sent as an attribute in the Radius Accept message which ISE will send to WLC, so WLC can allow access from the client to ISE (URL redirection). Once user completes the Guest Flow ISE will send a COA again to the client to allow access to network/Internet.

bjmcveety
Level 1
Level 1

Okay, thank you very much to both of you for your help!

 

Review Cisco Networking for a $25 gift card