cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1353
Views
1
Helpful
9
Replies

ISE Guest redirect portal

emolstad
Level 1
Level 1

I a setting up a Guest network on 9800L WLC. I have it setup to the point where the user can join the network but no redirect page pops when they join. I am able to see in DNAC that they IP learn is successful and L3 Auth starts but on testing no Redirect to ISE portal pops. I have ISE polices setup correct as we have done this on old airos wlc just fine. I am thinking with the IOS based controllers there is something I am missing.

9 Replies 9

Scott Fella
Hall of Fame
Hall of Fame

The are a lot of moving parts here.  Have you tired to open a browser manually? Have you looked at the logs in ISE?  I'm also assuming that the configuration on the 9800 and ISE are 100% correct.

-Scott
*** Please rate helpful posts ***

emolstad_2-1678987222923.png

emolstad_3-1678987237716.png

 

So if you manually open a browser, do you not get the portal page or get redirected?

-Scott
*** Please rate helpful posts ***

no portal page when manually open browser

If you create a test said that is open, can the device associate and get an ip address?  if so, I think you need to review your configuration for the guest portal between the controller and ISE.  Seems like something might be missing.

-Scott
*** Please rate helpful posts ***

 

This is current ACl on WLC. Top 2 lines are our ISE servers. I have modified it a bit over time and maybe I am just leaving something out. The devices get an IP on the appropriate subnet. May be a DNS issue I am investigating still.

Screenshot 2023-03-17 at 2.48.01 PM.png

You don't say what ACL that is but if that's your pre-auth redirect ACL - you need to read this:
https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213920-central-web-authentication-cwa-on-cata.html#toc-hId-881505252

The ACL should deny traffic which is allowed (DNS & captive portal page) and permit traffic to be redirected (http).  Yours is blocking DNS and captive portal.

(By the way permit tcp any any www is totally redundant after a permit ip any any which already includes that)

marce1000
VIP
VIP

 

 - You may find these debugging tools useful : https://logadvisor.cisco.com/logadvisor/wireless/9800/9800CWA    , 
 also review the 9800 configuration with https://cway.cisco.com/wireless-config-analyzer/ , that needs the output of (CLI)  show tech wireless

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Rich R
VIP
VIP

Have you done a radioactive trace on the client and analysed results with https://cway.cisco.com/wireless-debug-analyzer/ ?

I'd also go through the config guides again step by step and make sure you haven't missed anything - very easy to do.

Review Cisco Networking for a $25 gift card