cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
704
Views
5
Helpful
11
Replies

LWAPP Controller 4400 - Web Auth Problem

nhaits
Level 1
Level 1

I have setup a lwapp system with about 6 AP's. Everything works great but on one of the WLAN's I have Web Authentication setup. For some reason, I cannot get this to work. I have tried every setting possible, played with the virtual interface but I can't get wireless clients to get the proxy page. As soon as I turn it on they get nothing.

11 Replies 11

fergusoni
Level 1
Level 1

Hi

Can you ensure that your wireless clients have correct local DNS entries before they try and autheticate to Controller. If no DNS, it wont work. The controller will then intercept the web request and you will be re-directed to virtual address to authenticate. You can also try browsing to the virtual address to see if you get the authentication page.

I have a DNS server available, but it is on the other side of the controller (not the wireless side). The strange thing is that it works sometimes and then it seems to quit.

CSCsb83130 The notes indicate this is only on the 2006, but I have seen it on the 4400 too.

I've seen this problem on a 4100 too! I've had it working on other types of controllers. I'll make a note of the 2006 bug and do some more testing when I can get at the controller in question. I have a Cisco TAC case logged for the issue and they've suggested running some debugs, but I haven't had a chance yet. If I progess anything I'll post the fix on this thread.

CSCsc68105 web auth bug for the 4400

bhbachman
Level 1
Level 1

Have you verified that on all your 4400 controllers you have the virtual interface set to the same address? That caught me a year or so ago.

I have had issues getting it to work consistently from time to time. But it is usually a setting I missed.

Hi, can multiple controllers in the same group have the same virtual interface IP address? (ie. 1.1.1.1)?

Nope. You need to use something like 1.1.1.1 for the first, 1.1.1.2 for the second and so on.

HTH.

According to Cisco/AIrespace engineers, you MUST use the same virtual address. Do NOT increment them if they are in the same mobility group.

If they aren't in the same mobility group, it also has no affect.. So, 1.1.1.1 should be used as virtual interface on all controllers from every case I've seen so far.

Their documentation is misleading on this interface, to say the least.

Yes, they can. and this is necessary for mobility groups to work properly.

HTH,
Steve

------------------------------------------------------------------------------------------------
Please remember to rate useful posts, and mark questions as answered

Dmitry Halavin
Level 1
Level 1

Numerous issues with webauth have been fixed in 3.2.150.6, please try this version.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card