cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
6109
Views
5
Helpful
3
Replies

Guest Traffic flow

benolyndav
Level 8
Level 8

Hi

Can someone please put down the steps for Guest access I se the documents online but I never really grasp it from these I'll try the steps below can you let mw know which steps are correct/wrong.

1. client connects to SSID the foreign controller then talks to ISE 

2. ISE checks Authentication and then Authorisation rules 

3. if there is a match permit ISE sends access accept to WLC. 

 

Now heres the grey area, 

What happens next please.??

 

also I see acl's on the Anchor and Foreign WLC's that match on both WLC's but the foreign acl's never have any hits, are the acl's needed on the Foreign WLC.??

3 Replies 3

JPavonM
VIP Alumni
VIP Alumni

I hope below graph helps you.

When the device connects to AP, if using MAC authentication bypass, the MAC is sent from foreign WLC to ISE to create the session and create the association. Then the device session is anchored and DHCP traffic is forwarded on the VLAN that is mapped on the anchor WLC (as best practice there should be any L3 device to relay the packet like a L3 switch, a router or a firewall).

IMPORTANT TO NOTE that pre-auth ACL must match in both Foreign and Anchor, and the pre-auth ACL name must match on ISE.

When the session is stablished, client is only allowed to receive DHCP and get access to DNS service to resolve the URL that ISE sent (as per pre-auth ACL, if not allowing more traffic).

IMPORTANT TO NOTE than on a pre-auth-acl, to permit a traffic==deny sentence on the ACL.

After openning the landing page sent from ISE, and followed any registration method there could be (self-registration, sponsorship, accept only) it is accepted and a change of authentication (CoA) packet is sent from ISE to Foreign WLC to release the session. Foreign WLC informs anchor to release the session and that's it, you are now connected.

 

Guest with MAB & CWAGuest with MAB & CWAHTH
-Jesus
*** Please rate helpful responses ***

Hi 

Thats excellent thankyou

So if im not using CWA  and just using mac filtering on WLC's then in ISE

Policy Set

        Wireless mab 

AND  Airespace-Wlan-id equals X

Authentication policy

default  = internal users

Authorisation policy

        Airespace-Wlan-id equals X

AND  Identitygroup Name

         equals    group I created

                      Results    and I have a acl here which I created with a vlan for the clients in the DMZ    

 

how would I need my acl's in this setup on WLC's and ISE

I can get a session but dont get DHCP/

 

thanks

 

 

JPavonM
VIP Alumni
VIP Alumni

Where are you configuring DHCP relay?

Best practice to do it is to configure DHCP relay on the Layer 3 switch's SVI where WLC's WLAN-2-VLAN maps Guest traffic. Or if that switch is L2, then the router that forward the rtraffic to your internal network, or the firewall if this is on a DMZ.

HTH
-Jesus
*** Please rate helpful responses ***

Review Cisco Networking for a $25 gift card