Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Internal captive portal not reached

This thread has been viewed 2 times
  • 1.  Internal captive portal not reached

    Posted Sep 18, 2020 07:17 PM
      |   view attached

    Hi,

    Almost finished my network between 7220 controller and AP-375 access points but still have some problems. I am a beginner on wifi networks so i need to ask for help from time to time. 


    I want to use internal captive portal for my guests. I have used new wifi task from controller and created a guest ssid with internal captive portal. The role of this is automatically created "ssidname-guest-logon" with 26 policies (default from controller).

    When my guest is connecting to SSID, he obtain IP from dhcp but the captive portal is not showing up. I have tested from a laptop as a guest and i have ping successfully to router, controller, neighbours and to internet (8.8.8.8), but cannot open any webpage or controller web UI even those have ping. I think something from "ssidname-guest-logon" role block the access of guest to controller internal captive portal, and because the user not confirmed the agreement he cannot access the internet. I tried to change role "ssidname-guest-logon" to guest, logon on aaa profile but still not work. Tried to make a guest wifi without captive portal, same problem not work, only the pings to servers. The only way the internet was worked was with "authenticated" role and without captive portal.

    At the same time with my SSID with captive portal i have made another SSID "test" with "authenticated" role broadcasted at the same time with captive portal one. When my guest connected to SSID "test" and then connected to captive portal one, has worked like a charm, the portal showed up and guest can accept the agreement and worked but still have some internet restrictions (some apps like speedtest not work).

    I have attached an image with my configuration.

    If anyone can help me to make this internal captive portal to work I would appreciate it. Thanks



  • 2.  RE: Internal captive portal not reached

    MVP GURU
    Posted Sep 22, 2020 02:54 PM

    The Mobility Controller will need an IP on the Guest VLAN interface in order to re-direct the user to the captive portal. Does your controller have an IP on your guest vlan?

     

     



  • 3.  RE: Internal captive portal not reached

    Posted Sep 22, 2020 09:00 PM

    Hi. My controller have only one ip alocated to default vlan. This controller ip is in the same /23 range with the guest user. The ip of the controller responds to guest pings and to all internet pings, but only to ping, not have access to the web. I have only one ssid broadcasted, this one with guest.



  • 4.  RE: Internal captive portal not reached

    MVP GURU
    Posted Sep 23, 2020 08:18 AM

    Do you see what role the user has once on and performing those pings and https access? Can you also post what the user role has for rules by sharing the "show rights <role>" output?