08-07-2019 06:31 AM - edited 07-05-2021 10:49 AM
When i connecting in my SSID, no automatic redirect to https://1.1.1.1/
But when i enter url https://1.1.1.1 with my hands everything is ok working !
My config:
WLAN Identifier.................................. 16
Profile Name..................................... Guest-WEB
Network Name (SSID).............................. Guest-WEB
Status........................................... Enabled
Web Based Authentication...................... Enabled
Web Authentication Timeout.................... 300
IPv4 ACL........................................ web-acl
IPv6 ACL........................................ Unconfigured
Web-Auth Flex ACL............................... Unconfigured
Web Authentication server precedence:
1............................................... ldap
2............................................... local
3............................................... radius
Web-Passthrough............................... Disabled
Mac-auth-server............................... 0.0.0.0
Web-portal-server............................. 0.0.0.0
Conditional Web Redirect...................... Disabled
Splash-Page Web Redirect...................... Disabled
##
(Cisco Controller) show>custom-web wlan 16
WLAN ID: 16
WLAN Status................................... Enabled
Web Security Policy........................... Web Based Authentication
Global Status................................. Enabled
WebAuth Type.................................. Internal
###
WLC -> Management -> HTTP-HTTPS
HTTP-HTTPS Configuration:
HTTP Access - Disable
HTTPS Access - Enabled
WebAuth SecureWeb - Enabled
HTTPS Redirection - Enabled
Web Session Timeout - 30 Minutes
##
My Preauthentication ACL :
(Cisco Controller) show>acl detailed web-acl
Source Destination Source Port Dest Port
Index Dir IP Address/Netmask IP Address/Netmask Prot Range Range DSCP Action Counter
------ --- ------------------------------- ------------------------------- ---- ----------- ----------- ----- ------- -----------
1 Any 0.0.0.0/0.0.0.0 10.0.253.20/255.255.255.255 17 0-65535 53-53 Any Permit 468
2 Any 10.0.253.20/255.255.255.255 0.0.0.0/0.0.0.0 17 53-53 0-65535 Any Permit 466
3 Any 0.0.0.0/0.0.0.0 10.1.254.20/255.255.255.255 17 0-65535 53-53 Any Permit 2
4 Any 10.1.254.20/255.255.255.255 0.0.0.0/0.0.0.0 17 53-53 0-65535 Any Permit 2
5 Any 0.0.0.0/0.0.0.0 1.1.1.1/255.255.255.255 Any 0-65535 0-65535 Any Permit 0
6 Any 1.1.1.1/255.255.255.255 0.0.0.0/0.0.0.0 Any 0-65535 0-65535 Any Permit 9159
DenyCounter : 12069
Full config in attachment.
04-24-2020 05:17 AM
04-24-2020 06:08 AM - edited 04-24-2020 06:09 AM
Check on the client if you already get the correct certificate offered.
Otherwise have a look at this bug, which might also affect ISE 2.3: https://bst.cloudapps.cisco.com/bugsearch/bug/CSCut26025/?rfs=iqvred
Or this one:
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvp75207/?rfs=iqvred
In any case, for both bugs it's recommended to install the latest ISE patch.
04-24-2020 07:58 AM
04-07-2023 06:46 AM
If you are here with same issue and using 9800 WLC's with codes before 17.7, please go to CLI and enable webauth-http-redirect.
conf t
parameter-map type webauth global
webauth-http-enable
After 17.7 this option is available on GUI under Configuring -- Security -- Webauth -- global
07-26-2023 10:02 AM
Ah look you can use some dynamic location ips to go through it or you may use some extension to break it down
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide