cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
422
Views
4
Helpful
5
Replies

Unable to redirect Cisco ISE guest clients to Microsoft login page

davennykayowo
Level 1
Level 1

I am setting up Cisco WLC and ISE guest portal to use Azure AD account for web authentication prior to internet access
The Azure part is setup correctly and working as it should.

Clients redirection to Microsoft login page works perfectly and users were able to authenticate using their Microsoft account to access the internet through cisco ISE guest portal.
This flow works if I deny all TCP 443 traffic on the redirect ACL...see screenshot line 62.
Once I remove the ACL line, redirection to Microsoft login page stops working.

I have used URL Filters (both URL filters and Enhanced URL filters with permit and deny actions) on the WLC but seems not to be working.
Kindly assist, may be I'm missing out something on ISE or WLC.

davennykayowo_0-1728118403658.png

davennykayowo_1-1728118428504.png

davennykayowo_2-1728118442996.png

davennykayowo_3-1728118459311.png

 

 

 

 

5 Replies 5

Rich R
VIP
VIP

See https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213920-central-web-authentication-cwa-on-cata.html#toc-hId-881505252

The key part of the ACL is to permit www not ip any any.

balaji.bandi
Hall of Fame
Hall of Fame

In General the ACL should be top down model.

so you allow intresting traffic what you looking to allow, in the end you deny any any.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/217457-configure-and-troubleshoot-external-web.html

There is external web auth and there is CWA with ISE 

I dont see before CWA with ISE and use external web for auth?

I think what you need is use external web auth' check link 

MHM

davennykayowo
Level 1
Level 1

The issue has been resolved. 

The ACL used

davennykayowo_0-1728247404981.png

The URL ACL used

davennykayowo_1-1728247459972.png

I added the URL ACL to the profile attached the the WLAN-SSID 

davennykayowo_3-1728247635118.png

This link was also helpful
https://community.cisco.com/t5/security-knowledge-base/ise-byod-flow-using-entra-id/ta-p/4400675 

 

This for SAML, but anyway glad issue is solve. 

MHM

Review Cisco Networking for a $25 gift card