cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Bookmark
|
Subscribe
|
2051
Views
0
Helpful
3
Replies

Web Authentication with External Portal Server fail to redirect

Jia Hao
Level 1
Level 1

Hi,

I have set up a web authentication with the internal Portal, and it works fine.

Layer 2 security is none, Later 3 securiy is web Policy with "Authentication".

When I changed the Web Authentication Type to "External", it didn't work.

I have enabled the debug " web-auth redirect enable mac  xx:xx:xx:xx:xx:xx",  from the logs it shown "can not get the index of protal server"

And from the client's browser it shown the URL:

"http://10.75.156.50?switch_url=http://1.1.1.1/login.html&ap_mac=d8:b1:90:b2:a8:70&client_mac=7c:fa:df:88:be:87&wlan=Guest-Central&", but never shown the actual web page.

Also I have tried to disable the "WebAuth SecureWeb" and "HTTPS Redirection", after the WLC rebooting, it shown the same error.

I have tried the IPHONE and the windows 10, haven't tried the other devices yet.

Please someone tell me where am I wrong?

Error logs:

*webauthRedirect: Jul 06 15:27:29.515: 7c:fa:df:88:be:87- str1 is now http://10.75.156.50?switch_url=http://1.1.1.1/login.html&ap_mac=d8:b1:90:b2:a8:70&client_mac=7c:fa:df:88:be:87&wlan=Guest-Central&redirect=10.75.156.50/?swit
*webauthRedirect: Jul 06 15:27:29.515: 7c:fa:df:88:be:87- clen string is Content-Length: 661


*webauthRedirect: Jul 06 15:27:29.515: 7c:fa:df:88:be:87- Message to be sent is
HTTP/1.1 200 OK
Location: http://10.75.156.50?switch_url=http://1.1.1.1/login.html&ap_mac=d8:b1:90:b2:a8:70&client_mac=7c:fa:df:88:be:87&wlan=Gue
*webauthRedirect: Jul 06 15:27:29.515: 7c:fa:df:88:be:87- send data length=1146
*webauthRedirect: Jul 06 15:27:29.515: 7c:fa:df:88:be:87- Url:http://10.75.156.50
*webauthRedirect: Jul 06 15:27:29.515: 7c:fa:df:88:be:87- can not get the index of protal server
*webauthRedirect: Jul 06 15:27:29.515: 7c:fa:df:88:be:87- cleaning up after send

*webauthRedirect: Jul 06 15:27:29.515: 1520 - 7c:fa:df:88:be:87- closing socket= 83

3 Replies 3

Hello Jia

Please look in this configuration example once again and verify with your configuration setup .

http://www.cisco.com/c/en/us/support/docs/wireless-mobility/wlan-security/71881-ext-web-auth-wlc.html

Thank you

Hi Prakash,

Thank you for reply,

My WLC version is 8.0, so I don't have an "add web server" button, but the other is same.

And the WLC will show nothing when I set up a preauthentication ACL.(I enabled the counter, the acl hits number grows, but shown nothing from  "debug web-auth redirect enable mac xx:xx:xx:xx:xx:xx")

I'll post my config if it's necessary.

Here is the show wlan message

Review Cisco Networking for a $25 gift card