cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1533
Views
10
Helpful
13
Replies

Web portal cisco C9800 does not appear

Aimad Ghoudane
Level 1
Level 1

Hi

I have an issue with my Guest portal in my Cisco C9800.

Weh i try to connect to my SSID Guest, I have

An Ip

I can lunch the web portal by https://192.0.2.1

but the Web Portal not appear mannually or maybe 1 time / 5.

Do you know how to resolve it ?

 

Regards

13 Replies 13

balaji.bandi
Hall of Fame
Hall of Fame

Aimad Ghoudane
Level 1
Level 1

but the Web Portal not appear AUTOMATICALLY (soory) or maybe 1 time / 5.

maybe 1 time / 5.

You mean 1 works out of 5 times ?

on same device ?

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hi

You mean 1 works out of 5 times --> Yes exactly

on same device --> No, Multiple device (W10 / Iphone)

Regards

Arshad Safrulla
VIP Alumni
VIP Alumni

Are you using CWA or LWA? If CWA please post the ACL.

Can you post your web auth parameter map and also the http server configuration from the WLC. I would recommend having something similar. 

parameter-map type webauth global
type webauth
virtual-ip ipv4 192.0.2.1
virtual-ip ipv6 2001:DB8::1
webauth-http-enable

!

no ip http server
ip http secure server

!

 

Hello 

This is my config

parameter-map type webauth Web_Portal_MYNAME
type webauth
redirect on-success https://www.MYWEBSITE.ch/accueil
max-http-conns 120
cisco-logo-disable
!

I try 

it's seem to be better when i add

ip http server  ( iknow that normally is better when we desactivate http server).

Now I have a better situation ... I don't know how

The user has the web portal login but with an certificate error and he has to validate the connection before to connect to the web portal.

You can avoid enabling the http server in the WLC by adding "webauth-http-enable" under the web auth parameter map. Certificate is important, it is recommended to use publicly signed certificate. Please consider adding the parameter map config I shared before.

Thanks for your help

"webauth-http-enable" does not seems to exist on my WLC.

conf t

cwlc(config)#parameter-map type webauth Web_portal_MYNAME
wlc(config-params-parameter-map)#webauth-http-enable
^
% Invalid input detected at '^' marker.

wlc(config-params-parameter-map)#

 

 

Hi Aimad,
Looks like you are running a older code in box. Please consider upgrading your boxes to the latest Cisco TAC recommended code ASAP. Refer the signature for the links.
For the moment I would suggest that you have the "ip http server" configured in your WLC, as this is somewhat compulsory in the older codes for Web Auth to work properly. Also write your pre-auth ACL's properly to allow required communication to DNS, DHCP etc.

Rich R
VIP
VIP

As @Arshad Safrulla said you're running an old version of IOS-XE - update to current release.
webauth-http-enable was a feature enhancement to allow webauth to use http while disabling http server for GUI access.

To avoid certificate errors your splash/landing page must have a valid public certificate matching the DNS name of the URL for the page.

Hello
Thanks for your return.
Except error on my part, I use the last firmware available on cisco web site.

But now, my spalh page arrive quickly when I change my certificat.

But i would like to understand (for my understanding) the relationship between the certificate and the automatic launch of the splah page.

Rich R
VIP
VIP

Modern devices and browsers implement strict security protocols now.

That means any secure web page must have a valid certificate before it will load.  If you don't provide a valid certificate the page is considered insecure (= DANGEROUS/MITM/HACKERS/MALWARE) and will not load for the safety of the user and device.

Great ! many thanks for your return !

Review Cisco Networking for a $25 gift card