10-03-2016 05:32 AM - edited 07-05-2021 05:54 AM
Currently working on a flexconnect deploment with serveral vWLC v8.2 and ISE 2.1 nodes.
We are having an issue with the HTTP redirect of the guestportal for the guest portal SSID.
We have 1 SSID with EAP/TLS working OK with the ISE.
The other SSID should be for guest users.
I have followed the below steps:
The only thing that is different (other then the software versions of the deployment) is that under de WLAN -> Advanced -> NAC STATE:RADIUS NAC we do not have this option with v8.2 it only says ISE NAC or SNMP NAC(I have selected ISE NAC).
We can see the ISE policy being hit and also the WLC passing the redirect URL.
If we check the client details we can also see the RADIUS_NAC_STATE:CENTRAL_WEB_AUTH and the redirect URL is also correctly visible in this view.
10-03-2016 06:33 AM
10-03-2016 07:10 AM
found the problem forgot to also create the ACL globally not just flexconmect ACL
10-24-2016 05:35 AM
Which acl have you made? Please guide me as well as i am also having same problem.
Thanks & Regards,
Muhammad Faraz
10-26-2016 04:12 AM
Well for me the problem was i did not create the flex-acl globally only under flexconnect. Step 7 of --> http://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/116087-configure-cwa-wlc-ise-00.html
So you need to create the identical ACL on two places
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide