cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
681
Views
0
Helpful
3
Replies

Problems redirecting clients to the cisco 1.1.1.1 landing page

oscarihebom
Level 1
Level 1

I need some advise on a very unusual problem.

We have a cisco wireless lan controller which has a dsl connection out to the internet.

The way it works is that a client types in the url www.bbc.co.uk. The wireless controller will validate the authencity of the web address before presenting the client with a landing page for authentication which is 1.1.1.1.

If the web site is not valid, a page cannot be displayed error is returned. If it is valid , client authenticates on the 1.1.1.1 page and is allowed access.

This is the way it has always worked. But there is a new problem now where the wireless lan controller is not presenting us with the landing page , we are having to type it in the url manually which is an inconvinience for most end users.

Funny enough if you input the management address of the dsl router, you are immediately presented with the landing page.

Any ideas, guys and girls.

3 Replies 3

Stephen Rodriguez
Cisco Employee
Cisco Employee

what code is your WLC running? There is a change made in 4.0.179.11, that allows the client to directly query the DNS instead of the management interface proxing it.

One way to see if you're having a DNS issue is to browse to an IP address, so there is no need for DNS. If you get the redirect page correctly, then I would start tracing a client to see if DNS is getting blocked somewhere.

HTH,
Steve

------------------------------------------------------------------------------------------------
Please remember to rate useful posts, and mark questions as answered

We have the same problem and are running 4.0.179.11. If DNS fails, you get no landing page...actually we can't even get DNS. TAC had us put a Pre-Auth ACL in to allow DNS. This works as the firewall now sees the DNS request from the client, but the response never makes it back to the client because the firewall is ARP'ing for the client and never gets a response.

At this point TAC still has no solution. If we remove Web-Auth all is fine.

We have the same issue with a Linux based firewall. We have been promised a solution for several months now, however.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card