Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Cisco Guest wireless malformed URL redirect

This thread has been viewed 2 times
  • 1.  Cisco Guest wireless malformed URL redirect

    Posted Jun 02, 2015 01:23 PM

    Here is the situation.

    Cisco WLC with version 7.6 and ClearPass 6.5.1

    Cisco WLC wlan is setup with mac filtering and on mac failure redirect to external we server.

    Pre-Auth ACL is to only allow http and https access to the ClearPass server.

     

    When a device connects, it attempts MAC authentication and is rejected since it's a new device.

    This is working as intended.

    The user opens a browser and types in www.google.com

    The browser is intercepted and redirects to a ClearPass captive portal

    The User logs in and is authenticated successfully.

    Here is the problem area. The User is never redirected to the original URL but is sent to something like this:
    https://clearpassserverip/guest/www.google.com

    The user receives a 404 error and never makes it to google. 

    Has anyone else experienced an issue similar to this?

     

    Andy Clelland

    Structured Communication Systems, Inc.

    ACMP, ACCP



  • 2.  RE: Cisco Guest wireless malformed URL redirect

    Posted Jun 03, 2015 12:56 PM

    Has anyone else seen this behavior?

     

    Andy Clelland



  • 3.  RE: Cisco Guest wireless malformed URL redirect

    Posted Jun 03, 2015 01:28 PM
    Do you have the following:
    - Controller Initiated selected in the guest registration page NAS Vendor settings > Login Method
    - Select Cisco Systems as the Vendor
    - Uncheck require HTTPs under Home » Configuration » Authentication
    And see if that works


  • 4.  RE: Cisco Guest wireless malformed URL redirect

    Posted Jun 08, 2015 09:19 AM

    Thank you Victor, the only piece I don't have setup is unchecking require HTTPS. I'll give that a try to see if that helps at all.

     

    Andy Clelland



  • 5.  RE: Cisco Guest wireless malformed URL redirect

    Posted Jun 21, 2015 04:48 AM


  • 6.  RE: Cisco Guest wireless malformed URL redirect
    Best Answer

    EMPLOYEE
    Posted Jul 09, 2015 06:12 PM

    Please paste the initial redirect URL from Cisco to CPPM. It should have a clear 'url' attribute.  Ensure that attribute is fully qualified with 'http://' otherwise it will link as a relative address.  If you have a fallback destination in the login setup ensure it is fully qualified as well otherwise the same situation occurs.