Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Cisco Wired Guest Webauth Service Question

This thread has been viewed 6 times
  • 1.  Cisco Wired Guest Webauth Service Question

    Posted Apr 12, 2017 02:11 PM

    Hi:

    I'm trying to get wired captive portal guest access working with a Cisco switch.

    I realize this needs two services. The initial mac-auth service is working fine... returning the redirect-url and redirect-url-acl to the switch.

     

    But I'm having problems with the captive portal.

    We are browsing to http://<clearpassIP>/guest/ciscowiredguest.php?mac=11:22:33:44:55:66, and that brings up the login form.

    But when I enter a known guest account and click submit, Access Tracker shows a REJECT. The message is: "Failed to classify request to service" The autentication attempt comes in with just the user name - no other info.

     

    I have an active service of type "Web-based Authentication" and the rule is:

    Host - Checktype - MATCHES_ANY - Authentication.

     

    Is there some other rule I need to make this work?

    Is there a special configuration needed for the captive portal login page?

    Am I correct in understanding that the switch is not involved in this part of the transaction (until it succeeds, of course, at which point it gets a CoA Terminate session)?

     

    Thanks.

     

     



  • 2.  RE: Cisco Wired Guest Webauth Service Question

    Posted Apr 12, 2017 02:24 PM
    How do you have your Captive Portal Page login method configured ?


  • 3.  RE: Cisco Wired Guest Webauth Service Question

    Posted Apr 12, 2017 02:37 PM

    I've tried several different options...

    right now it's set to:

    Vendor Settings: Cisco Systems

    Login method: Server Initiated - Change of Authorization (RFC 3576) sent to controller.

     

    What should it be set to?



  • 4.  RE: Cisco Wired Guest Webauth Service Question

    EMPLOYEE
    Posted Apr 12, 2017 02:42 PM
    That is correct. Do you have a WEBAUTH service?


  • 5.  RE: Cisco Wired Guest Webauth Service Question

    Posted Apr 12, 2017 02:51 PM
      |   view attached

    Yes.

    Here's a screenshot of how it's configured.



  • 6.  RE: Cisco Wired Guest Webauth Service Question
    Best Answer

    EMPLOYEE
    Posted Apr 12, 2017 02:54 PM
    Hm, definitely should be matching that.

    Please post a few screenshots of the access tracker request tabs.


  • 7.  RE: Cisco Wired Guest Webauth Service Question

    Posted Apr 14, 2017 01:38 PM

    Thanks for all your help.

     

    I found the Webauth service problems: I had inadvertantly selected a Pre-Auth-Check parameter in the guest login page.

    Once I set that to "None-no extra checks will be made," the webauth service is being hit successfully.

     

    Thank you.



  • 8.  RE: Cisco Wired Guest Webauth Service Question

    Posted May 17, 2017 03:23 PM

    Do you have any writeup that you can share? Looking at doing the same and don't want to reinvent the wheel.

     

    TIA.



  • 9.  RE: Cisco Wired Guest Webauth Service Question

    EMPLOYEE
    Posted May 17, 2017 03:25 PM
    There will be a full wired solution guide available in the next two weeks.


  • 10.  RE: Cisco Wired Guest Webauth Service Question

    Posted May 30, 2017 04:23 PM

    @cappalli wrote:
    There will be a full wired solution guide available in the next two weeks.

    Any updates on this :) ?



  • 11.  RE: Cisco Wired Guest Webauth Service Question

    EMPLOYEE
    Posted May 30, 2017 05:55 PM
    Friday.


  • 12.  RE: Cisco Wired Guest Webauth Service Question