10-05-2024 02:00 AM
I am setting up Cisco WLC and ISE guest portal to use Azure AD account for web authentication prior to internet access
The Azure part is setup correctly and working as it should.
Clients redirection to Microsoft login page works perfectly and users were able to authenticate using their Microsoft account to access the internet through cisco ISE guest portal.
This flow works if I deny all TCP 443 traffic on the redirect ACL...see screenshot line 62.
Once I remove the ACL line, redirection to Microsoft login page stops working.
I have used URL Filters (both URL filters and Enhanced URL filters with permit and deny actions) on the WLC but seems not to be working.
Kindly assist, may be I'm missing out something on ISE or WLC.
10-06-2024 02:18 AM
The key part of the ACL is to permit www not ip any any.
10-06-2024 02:35 AM
In General the ACL should be top down model.
so you allow intresting traffic what you looking to allow, in the end you deny any any.
10-06-2024 02:38 AM
There is external web auth and there is CWA with ISE
I dont see before CWA with ISE and use external web for auth?
I think what you need is use external web auth' check link
MHM
10-06-2024 01:52 PM
The issue has been resolved.
The ACL used
The URL ACL used
I added the URL ACL to the profile attached the the WLAN-SSID
This link was also helpful
https://community.cisco.com/t5/security-knowledge-base/ise-byod-flow-using-entra-id/ta-p/4400675
10-06-2024 11:12 PM
This for SAML, but anyway glad issue is solve.
MHM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide