Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

CWA hanging over FlexConnect

Wondering if anyone here has seen this before, it's got me scratching my head at present:

We have a working CWA implementation in a central site with APs in local mode, clients are redirected to ISE guest portal using MAB, can register & log in as expected.

For other sites that don't have local controllers we have APs configured for FlexConnect with central authentication, local switching, & VLAN support, which works fine for registered devices, but when a client atempts to use CWA the process hangs after the redirect to the guest portal (the portal screen never appears).  I've created FlexConnect ACLs identical to the local ACLs as per CSCue68065, but that made no difference.

The ISE shows that the first MAB authentication completes successfully; in the client details on the WLC I see the correct redirect URL & ACL, but the client never reaches the ISE for the second authentication. (nothing on live authentications screen for second auth, client browser times out)

Any ideas appreciated, I'm running out.

WLC is 2504 running 7.4.100.60

ISE is 3315 running 1.1.2 patch 1

thanks

JonS

6 REPLIES

CWA hanging over FlexConnect

JonS,

-What do you mean by it is working fine with registered devices? what do you mean by registered devices?

BTW, AFAIK FlexConnect does not support ACLs with local switched WLANs. Try centrally switched WLAN and let me know if that works.

HTH

Amjad

Rating useful replies is more useful than saying "Thank you"

Rating useful replies is more useful than saying "Thank you"
New Member

Hi,

Hi,

I am experiencing the exact same issue. But only difference is we are using flex ap on central site and it works fine. But the same thing is not working for remote branch office. Tried different settings but still no luck.

Thanks

Mo

CWA hanging over FlexConnect

Jon,

maybe this document helps (just in case you don't already know it):

http://www.cisco.com/en/US/products/ps11640/products_configuration_example09186a0080c090eb.shtml

regards

Stefan

Bronze

Re: CWA hanging over FlexConnect

the redirected web http flow goes with local switch... so make sure your local switch network can reach psn..

Sent from Cisco Technical Support iPad App

New Member

Re: CWA hanging over FlexConnect

Jon,

Try upgrading to 7.4.110.0 and retest the Flexconnect clients as this fixed exactly this interaction with ISE for one of my customers.

Keith.

Sent from Cisco Technical Support iPad App

New Member

Re: CWA hanging over FlexConnect

Kindly find the link for the security supported to Flex-connect with the WLC versions.
http://www.cisco.com/en/US/products/ps10315/products_tech_note09186a0080b3690b.shtml

This  document describes how to configure central web authentication with  FlexConnect Access Points (APs) on a Wireless LAN Controller (WLC) with  Identity Services Engine (ISE) in local switching mode.

http://www.cisco.com/en/US/products/ps11640/products_configuration_example09186a0080c090eb.shtml

559
Views
0
Helpful
6
Replies