cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1019
Views
0
Helpful
4
Replies

vWLC v8.2.121 ISE 2.1 and guest portal redirect issue

marc.groenen
Level 1
Level 1

Currently working on a flexconnect deploment with serveral vWLC v8.2 and ISE 2.1 nodes.

We are having an issue with the HTTP redirect of the guestportal for the guest portal SSID.

We have 1 SSID with EAP/TLS working OK with the ISE.

The other SSID should be for guest users.

I have followed the below steps:

http://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/116087-configure-cwa-wlc-ise-00.html

The only thing that is different (other then the software versions of the deployment) is that under de WLAN -> Advanced -> NAC STATE:RADIUS NAC we do not have this option with v8.2 it only says ISE NAC or SNMP NAC(I have selected ISE NAC).

We can see the ISE policy being hit and also the WLC passing the redirect URL.

If we check the client details we can also see the RADIUS_NAC_STATE:CENTRAL_WEB_AUTH and the redirect URL is also correctly visible in this view.

4 Replies 4

marc.groenen
Level 1
Level 1

Attached debugging from wlc client

And ISE logging from the policy's begin hit and URL sent to WLC

found the problem forgot to also create the ACL globally not just flexconmect ACL

Which acl have you made? Please guide me as well as i am also having same problem.

Thanks & Regards,

Muhammad Faraz

Well for me the problem was i did not create the flex-acl globally only under flexconnect. Step 7 of --> http://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/116087-configure-cwa-wlc-ise-00.html

So you need to create the identical ACL on two places

Review Cisco Networking for a $25 gift card