cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
136
Views
0
Helpful
0
Replies

Guest Management CWA on C9800 with ISE

huseyin
Level 1
Level 1

Hi everyone,

I try to work with CWA on C9800. I installed a LAB scenario on my LAB.

ADA LAB Guest Management with ISE

Inverment;

Cisco C3850 PoE+ 24 Port 10G Uplink switch (Last version IOS)

Cisco C9800-CL Wireless Controller ver17.12.4

Cisco 1815iAP (Last Version IOS)

Cisco ISE v3.1

Active Directory Windows 2022 Standart Evaluation (Last Update)

Cisco ISE ESXi Host Configuration

huseyin_0-1738667075879.png

Cisco C9800 ESXi Host Configuration

huseyin_1-1738667075880.png

Lab Local Network Table;

VLAN Name

VLAN ID

VLAN Network

Subnet

Gateway ASA

ISE IP

Management

40

192.168.40.1-254

\24

192.168.40.254

192.168.40.236

BYOD

91

10.10.91.1-254

\24

10.10.91.254

10.10.91.236

Guest

10

10.10.10.1-254

\24

10.10.10.254

10.10.10.236

Inside

90

10.10.90.1-254

\24

10.10.90.254

10.10.90.236

Quarantina

3

192.168.3.1-254

\24

192.168.3.254

192.168.3.236

Server

100

192.168.100.1-254

\24

192.168.100.254

192.168.100.236

 

We are configuring all Interfaces on Cisco ISE. We target is to seperate beetwen networks. Forthis reason; we have more security and just different links to Access for Guest or BYOD. Also we can use for Quarantina Operations.

For ISE Guest Portals Settings are;

Guest

IP

Port

Hotspot

10.10.10.236

8999

Self-Register

10.10.10.236

8997

Sponsored

10.10.10.236

8998

Sponsor

10.10.90.236

8945

 

Topology is like below; Radius and web server is actually same device; Cisco ISE.

huseyin_2-1738667075881.jpeg

 

All ports and links are very successfuly working in their VLANs. If we are using Preshared Key (PSK) to join relevant VLAN everythings fine. We can Access to all link.

But we try to 802.1x its not work! I guess this problem is network problem but I did not resolve. When The 802.1x Access be active; redirection is work but the relevant link is not come. I am waiting for a lot of minutes. After that I need to reset my labtop network settings.

When I creat a  Configuration->Security->Web Auth in C9800 Web GUI; The device automatically creat 2 dfferent gorup ACL’s.

huseyin_3-1738667075884.png

 

 

And Second ACL Group

huseyin_4-1738667075886.png

 

And unfortunatelly There are not doing update.

Does anyone have any suggestions?

Regards

0 Replies 0
Review Cisco Networking for a $25 gift card