cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2188
Views
2
Helpful
3
Replies

Guest Wlan cannot access internet

waqas.arshad
Level 3
Level 3

Hi All,

I would like to ask for a help with our guest network no able to access internet.  I made few tests and here is the summary.

  • Client are getting ip address from DHCP
  • Authentication is successful.
  • Ping to 8.8.8.8 is working
  • Ping to google.com or any other website is working
  • DNS resolution is working

Everything is working as expected but still user cant browse the websites. They don’t have access to internet. Its very strange behavior and I am not able to understand what could be the issue. We are using Cisco ISE for authentication and i don't see any issue with Authentication. 

 

Regards,

Arshad

 

3 Replies 3

Hi

 Your clients are actually accessing the internet. If you can ping an url you are for sure leaving your network and going to the internet just fine. I mean, there is no connective issue and DNS is working fine. 

 I can see basically some possibilities here. 

First: you have proxy in your browser or maybe transparent proxy and it is blocking you. 

Second: You have a firewall and the firewall is not allowing http/https for guest 

Third: your guest ACL is missing  a permit ip any any at the end.. 

Rich R
VIP
VIP

What WLC?
What version of software?
What AP?
What troubleshooting have you done?
Have you tried to reboot the AP?
Was this working before or it's new and has never worked?

------------------------------
Please click Helpful if this post helped you and Accept as Solution (drop down menu at top right of this reply) if this answered your query.
------------------------------
TAC recommended codes for AireOS WLC's   and   TAC recommended codes for 9800 WLC's
Best Practices for AireOS WLC's,   Best Practices for 9800 WLC's   and   Cisco Wireless compatibility matrix
Check your 9800 WLC config with Wireless Config Analyzer using "show tech wireless" output or "config paging disable" then "show run-config" output on AireOS and use Wireless Debug Analyzer to analyze your WLC client debugs
Field Notice: FN63942 APs and WLCs Fail to Create CAPWAP Connections Due to Certificate Expiration
Field Notice: FN72424 Later Versions of WiFi 6 APs Fail to Join WLC - Software Upgrade Required
Field Notice: FN72524 IOS APs stuck in downloading state after 4 Dec 2022 due to Certificate Expired
- Fixed in 8.10.196.0, latest 9800 releases, 8.5.182.12 (8.5.182.13 for 3504) and 8.5.182.109 (IRCM, 8.5.182.111 for 3504)
Field Notice: FN70479 AP Fails to Join or Joins with 1 Radio due to Country Mismatch, RMA needed
Field Notice: FN74383 APs Running 17.12.4/5/6/6a May Run Out of Flash Space Preventing Upgrades
How to avoid boot loop due to corrupted image on Wave 2 and Catalyst 11ax Access Points (CSCvx32806)
Field Notice: FN74035 - Wave2 APs DFS May Not Detect Radar After Channel Availability Check Time
Leo's list of bugs affecting 2800/3800/4800/1560 APs
Default AP console baud rate from 17.12.x is 115200 - introduced by CSCwe88390

Scott Fella
Hall of Fame
Hall of Fame

Just to add, connect a laptop to a switch on the same vlan as your guest.  See if the wired laptop can access the internet.  Also, we don't know how you are using ISE, but if you create a test SSID that is open and map that to the vlan for guest, does it work.  You need to try to eliminate variables so you can understand where to really focus your troubleshooting.  Is it wireless or wired to, bypassing ISE, does it work?

-Scott
*** Please rate helpful posts ***
Review Cisco Networking for a $25 gift card