Question

Unable to redirect to captive portal page while connecting to guest SSID

  • 4 February 2021
  • 5 replies
  • 101 views

Hi,

We are unable to redirect to captive portal page while connecting to guest SSID, client gets directly connected to guest SSID without any authentication and gets internet access. 

 

We already whitelisted the URL. Refer the below snap from controller config.

 

 

Please suggest how client gets redirect to captive portal page when he is trying to connect guest network. 


5 replies

Userlevel 5

Hi Shubha,

In that case, you need to reconfigure the captive portal because your current configuration is a mix of internal and external captive portal configurations. I will recommend you follow the “Captive Portal Device Self-registration” guide below and do a fresh captive portal configuration. 

 

https://documentation.extremenetworks.com/WiNG/Implementation_Guides/WiNG5_CaptivePortal_Onboard_Self_Registration-Rebranded-Final.pdf 

 

Regards,

Ovais

Hi Ovais,

 

Initially we are using external captive portal, but we want to use internal captive portal from now onwards.

We made changes as suggested by you, i.e we change authentication for guest SSID from none to MAC, also we have applied captive portal policy to AP profile only. Please suggest what changes can be done.

Userlevel 5

Hi, 

I had a quick look and have a couple of questions.

I can see an external captive portal is being used, does this captive portal registers device MAC address by using MAC auth or is it just plain and simple no auth redirection where users can accept terms and conditions and go through? 

If you could explain the eternal captive portal, that will help.

Under the guest wlan ssid config the authentication type is set to none, whereas it should be set to MAC auth because the captive portal policy is set to "registration". 

The captive portal policy is also applied to both AP and controller profile, you should either let the controller do the redirection or the AP.

 

Regards,

Ovais

Hi Ovais,

 

=~=~=~=~=~=~=~=~=~=~=~= PuTTY log 2021.02.04 15:51:49 =~=~=~=~=~=~=~=~=~=~=~=
sh running-config
!
! Configuration of VX9000 version 7.4.1.4-004R
!
!
version 2.7
!
!
client-identity Android-2-1
 dhcp 1 message-type request option 55 exact hexstring 0103061c21333a3b79
 dhcp 6 message-type request option 60 exact ascii "dhcpcd 4.0.1"
 dhcp-match-message-type request
!
client-identity Android-2-2
 dhcp 1 message-type request option 55 exact hexstring 01792103061c333a3b
 dhcp 6 message-type request option 60 exact ascii "dhcpcd 4.0.15"
 dhcp-match-message-type request
!
client-identity Android-2-3
 dhcp 3 message-type request option 55 exact hexstring 01792103061c333a3b
 dhcp 6 message-type request option 60 exact ascii "dhcpcd 4.0.15"
 dhcp 1 message-type request option-codes exact hexstring 353d32393c37
 dhcp 2 message-type request option-codes exact hexstring 353d3236393c37
 dhcp 10 message-type request option-codes exact hexstring 353d3236393c0c37
 dhcp-match-message-type request
!
client-identity Android-2-3-x
 dhcp 10 message-type request option 55 exact hexstring 01792103060f1c333a3b77
 dhcp 11 message-type request option 55 exact hexstring 01792103060f1c2c333a3b77
 dhcp 12 message-type request option 60 exact ascii "dhcpcd 4.0.15"
 dhcp-match-message-type request
!
client-identity Android-3
 dhcp 4 message-type request option 55 exact hexstring 012103061c333a3b
 dhcp 5 message-type request option 60 starts-with ascii dhcpcd-5.2.10
 dhcp 6 message-type request option-codes exact hexstring 3532393c0c37
 dhcp 7 message-type request option-codes exact hexstring 35393c0c37
 dhcp 8 message-type request option-codes exact hexstring 353236393c0c37
 dhcp-match-message-type request
!
client-identity Android-4
 dhcp 8 message-type request option 55 exact hexstring 012103061c333a3b
 dhcp 9 message-type request option 60 starts-with ascii dhcpcd-5.2.10
 dhcp 10 message-type request option 60 starts-with ascii dhcpcd-5.2.10:Linux-3
--More--         dhcp-match-message-type request
!
client-identity Android-4-1-X
 dhcp 1 message-type request option 55 exact hexstring 012103060f1c333a3b
 dhcp 2 message-type request option 60 exact ascii dhcpcd-5.2.10
 dhcp-match-message-type request
!
client-identity Android-6-0-X
 dhcp 1 message-type request option 55 exact hexstring 0103060f1a1c333a3b
 dhcp 2 message-type request option 60 starts-with ascii android-dhcp-6.0
 dhcp-match-message-type request
!
client-identity Android-7-X
 dhcp 1 message-type request option 60 contains ascii android-dhcp-7
 dhcp-match-message-type request
!
client-identity Android-8-X
 dhcp 1 message-type request option 60 contains ascii android-dhcp-8
 dhcp-match-message-type request
!
client-identity Android-9-X
 dhcp 1 message-type request option 55 starts-with hexstring 0103060f1a1c333a3b
 dhcp 2 message-type request option 60 contains ascii android-dhcp-9
 dhcp-match-message-type request
!
client-identity Android-X
 dhcp 1 message-type request option 55 exact hexstring 012103060f1c333a3b
 dhcp 2 message-type request option 60 exact ascii dhcpcd-5.5.6
 dhcp-match-message-type request
!
client-identity Blackberry
 dhcp 2 message-type request option 55 exact hexstring 011c02030f060c
 dhcp 1 message-type request option 60 contains ascii \"BlackBerry\ OS\"
 dhcp-match-message-type request
!
client-identity Chrome-OS-chromebook
 dhcp 1 message-type request option 55 exact hexstring 01792103060c0f1a1c33363a3b77fc
 dhcp-match-message-type request
!
client-identity Galaxy-A5
 dhcp 4 message-type request option 55 exact hexstring 0103060f1a1c333a3b2b
 dhcp 6 message-type request option 60 exact ascii android-dhcp-8.0.0
 dhcp 1 message-type request option-codes exact hexstring 353d32393c0c37
--More--         dhcp-match-message-type request
!
client-identity Galaxy-Note
 dhcp 8 message-type request option 55 exact hexstring 012103061c333a3b
 dhcp 9 message-type request option 60 exact ascii dhcpcd-5.2.10:Linux-3.0.15-N7000DDLP8-CL551076:armv7l:SMDK4210
 dhcp-match-message-type request
!
client-identity Galaxy-Note8
 dhcp 4 message-type request option 55 exact hexstring 0103060f1a1c333a3b2b
 dhcp 6 message-type request option 60 exact ascii android-dhcp-9
 dhcp 1 message-type request option-codes exact hexstring 353d32393c0c37
 dhcp-match-message-type request
!
client-identity Galaxy-S8
 dhcp 4 message-type request option 55 exact hexstring 0103060f1a1c333a3b2b
 dhcp 5 message-type request option 57 exact hexstring 05dc
 dhcp 6 message-type request option 60 exact ascii android-dhcp-9
 dhcp 1 message-type request option-codes exact hexstring 353d32393c0c37
 dhcp-match-message-type request
!
client-identity Galaxy-Tab
 dhcp 8 message-type request option 55 exact hexstring 012103061c333a3b
 dhcp 9 message-type request option 60 exact ascii dhcpcd-5.2.10:Linux-2.6.36.3:armv7l:p3
 dhcp 10 message-type request option-codes exact hexstring 353d3236393c0c37
 dhcp 11 message-type request option-codes exact hexstring 353d32393c0c37
 dhcp-match-message-type request
!
client-identity Google-Android
 dhcp 1 message-type request option 55 exact hexstring 012103060f1a1c333a3b
 dhcp 2 message-type request option 60 exact ascii dhcpcd-5.5.6\"
 dhcp-match-message-type request
!
client-identity Google-Pixel
 dhcp 4 message-type request option 55 exact hexstring 0103060f1a1c333a3b2b
 dhcp-match-message-type request
!
client-identity HTC-Android
 dhcp 1 message-type request option 55 exact hexstring 017921031c333a3b
 dhcp-match-message-type request
!
client-identity Mac-OS-9
 dhcp 3 message-type request option 55 exact hexstring 0103060f212a2c2d2e2f4546474a4e4f
 dhcp-match-message-type request
--More--         !
client-identity Mac-OS-X
 dhcp 3 message-type request option 55 starts-with hexstring 0103060f775ffc2c2e
 dhcp-match-message-type request
!
client-identity Motorola-Android
 dhcp 1 message-type request option 55 starts-with hexstring 012103060f1c2c333a3b
 dhcp-match-message-type request
!
client-identity Motorola-XOOM
 dhcp 9 message-type request option 55 exact hexstring 012103061c333a3b
 dhcp 10 message-type request option 60 exact ascii dhcpcd-5.2.10:Linux-2.6.36.3-00042-g3c1a41e:armv7l:stingray
 dhcp 11 message-type request option-codes exact hexstring 3532393c0c37
 dhcp 12 message-type request option-codes exact hexstring 35393c0c37
 dhcp 13 message-type request option-codes exact hexstring 353236393c0c37
 dhcp-match-message-type request
!
client-identity Sony-Ericsson-Android
 dhcp 1 message-type request option 55 exact hexstring 0103060c0f1c21333a3b7779
 dhcp-match-message-type request
!
client-identity Windows-10
 dhcp 1 message-type request option 55 exact hexstring 0103060f1f212b2c2e2f7779f9fc
 dhcp 5 message-type request option 60 exact ascii "MSFT 5.0"
 dhcp-match-message-type request
!
client-identity Windows-10-Mobile
 dhcp 1 message-type request option 55 exact hexstring 0103060f1f212b2c2e2f79f9fc
 dhcp 5 message-type request option 60 exact ascii "MSFT 5.0"
 dhcp-match-message-type request
!
client-identity Windows-7
 dhcp 2 message-type request option 55 exact hexstring 010f03062c2e2f1f2179f92b
 dhcp 9 message-type request option 60 exact ascii "MSFT 5.0"
 dhcp-match-message-type request
!
client-identity Windows-8
 dhcp 1 message-type request option 55 exact hexstring 010f03062c2e2f1f2179f9fc2b
 dhcp 5 message-type request option 60 exact ascii "MSFT 5.0"
 dhcp-match-message-type request
!
client-identity Windows-Phone-7-5
 dhcp 11 message-type request option 55 exact hexstring 0103060f2c2e2f
--More--         dhcp 12 message-type request option-codes exact hexstring 3536323d37
 dhcp-match-message-type request
!
client-identity Windows-XP
 dhcp 4 message-type request option 55 exact hexstring 010f03062c2e2f1f21f92b
 dhcp 5 message-type request option 60 exact ascii "MSFT 5.0"
 dhcp-match-message-type request
!
client-identity iPhone-iPad
 dhcp 4 message-type request option 55 exact hexstring 017903060f77fc
 dhcp 10 message-type request option 55 exact hexstring 0103060f7277fc
 dhcp 1 message-type request option-codes exact hexstring 3537393d32330c
 dhcp 2 message-type request option-codes exact hexstring 3537393d32360c
 dhcp 3 message-type request option-codes exact hexstring 3537393d3233
 dhcp 6 message-type request option-codes exact hexstring 3537393d330c
 dhcp-match-message-type request
!
client-identity-group block
 client-identity Android-X precedence 1
 client-identity Google-Pixel precedence 2
 client-identity Android-7-X precedence 3
 client-identity iPhone-iPad precedence 4
 load default-fingerprints
!
client-identity-group default
 load default-fingerprints
!
ip access-list BROADCAST-MULTICAST-CONTROL
 permit tcp any any rule-precedence 10 rule-description "permit all TCP traffic"
 permit udp any eq 67 any eq dhcpc rule-precedence 11 rule-description "permit DHCP replies"
 deny udp any range 137 138 any range 137 138 rule-precedence 20 rule-description "deny windows netbios"
 deny ip any 224.0.0.0/4 rule-precedence 21 rule-description "deny IP multicast"
 deny ip any host 255.255.255.255 rule-precedence 22 rule-description "deny IP local broadcast"
 permit ip any any rule-precedence 100 rule-description "permit all IP traffic"
!
ip access-list denymobile
 deny ip any any rule-precedence 10 
!
mac access-list PERMIT-ARP-AND-IPv4
 permit any any type ip rule-precedence 10 rule-description "permit all IPv4 traffic"
 permit any any type arp rule-precedence 20 rule-description "permit all ARP traffic"
!
mac access-list Top-Exec
--More--         permit host CE-E7-87-A2-EA-D5 any type ip log rule-precedence 10 
 permit host CE-E7-87-A2-EA-D5 any type arp log rule-precedence 20 
 permit host 5E-43-C9-CF-76-8E any type ip log rule-precedence 30 
 permit host 5E-43-C9-CF-76-8E any type arp log rule-precedence 40 
 deny any any type ip log rule-precedence 50 
 deny any any type arp log rule-precedence 60 
!
ip snmp-access-list default
 permit any
!
firewall-policy Progility_Security
 no ip dos smurf
 no ip dos twinge
 no ip dos invalid-protocol
 no ip dos router-advt
 no ip dos router-solicit
 no ip dos option-route
 no ip dos ascend
 no ip dos chargen
 no ip dos fraggle
 no ip dos snork
 no ip dos ftp-bounce
 no ip dos tcp-intercept
 no ip dos broadcast-multicast-icmp
 no ip dos land
 no ip dos tcp-xmas-scan
 no ip dos tcp-null-scan
 no ip dos winnuke
 no ip dos tcp-fin-scan
 no ip dos udp-short-hdr
 no ip dos tcp-post-syn
 no ip dos tcphdrfrag
 no ip dos ip-ttl-zero
 no ip dos ipspoof
 no ip dos tcp-bad-sequence
 no ip dos tcp-sequence-past-window
 no ip-mac conflict
 no ip-mac routing conflict
 dhcp-offer-convert
 no ipv6 strict-ext-hdr-check 
 no ipv6 unknown-options 
 no ipv6 duplicate-options 
 no ipv6 option strict-hao-opt-check
--More--         no ipv6 option strict-padding
 no stateful-packet-inspection-l2
 no ipv6-mac conflict
 no ipv6-mac routing conflict
!
firewall-policy default
 no ip dos tcp-sequence-past-window
!
role-policy BlockMobile
 user-role Mobile precedence 1
  ssid exact ProgilityTech
  client-identity Android-X
  client-identity Google-Pixel
  client-identity Android-7-X
  client-identity iPhone-iPad
  use mac-access-list in Top-Exec precedence 10
!
!
mint-policy global-default
!
meshpoint-qos-policy default
!
wlan-qos-policy default
 qos trust dscp
 qos trust wmm
!
radio-qos-policy default
!
aaa-policy Internal-AAA
 authentication server 1 onboard controller
!
aaa-policy Progility-AAA
 authentication server 1 host 172.22.97.151 secret 0 Siemens123$
 authentication server 1 proxy-mode through-controller
!
dns-whitelist Guest_Internal
 permit captiveportal.progilitytech.com 
!
dns-whitelist Progility-Guest
 permit 10.1.0.1 
!
captive-portal Progility-Guest-External
 access-type no-auth
--More--         server host 10.1.0.1
 server mode centralized
 terms-agreement
 webpage-location external
 webpage external login https://10.1.0.1:8443/auth.html
 webpage external welcome https://10.1.0.1:8443/auth.html
 webpage external fail https://10.1.0.1:8443/auth.html
 webpage external agreement https://10.1.0.1:8443/auth.html
 webpage external acknowledgement https://10.1.0.1:8443/auth.html
 webpage external registration https://10.1.0.1:8443/auth.html
 webpage external no-service https://10.1.0.1:8443/auth.html
 use dns-whitelist Progility-Guest
 webpage internal registration field city type text enable label "City" placeholder "Enter City"
 webpage internal registration field street type text enable label "Address" placeholder "123 Any Street"
 webpage internal registration field name type text enable label "Full Name" placeholder "Enter First Name, Last Name"
 webpage internal registration field zip type number enable label "Zip" placeholder "Zip"
 webpage internal registration field via-sms type checkbox enable title "SMS Preferred"
 webpage internal registration field mobile type number enable label "Mobile" placeholder "Mobile Number with Country code"
 webpage internal registration field age-range type dropdown-menu enable label "Age Range" title "Age Range"
 webpage internal registration field email type e-address enable mandatory label "Email" placeholder "you@domain.com"
 webpage internal registration field via-email type checkbox enable title "Email Preferred"
!
captive-portal Progility_Guest_Internal
 access-type registration
 server host captiveportal.progilitytech.com
 terms-agreement
 webpage internal org-name Progility Technologies Private Limited
 webpage internal org-signature Progility Technologies Private Limited. All Rights Reserved.
 webpage internal login main-logo progility.png
 webpage internal login small-logo progility.png
 webpage internal welcome main-logo progility.png
 webpage internal welcome small-logo progility.png
 webpage internal fail main-logo progility.png
 webpage internal fail small-logo progility.png
 webpage internal agreement main-logo progility.png
 webpage internal agreement small-logo progility.png
 webpage internal acknowledgement main-logo progility.png
 webpage internal acknowledgement small-logo progility.png
 webpage internal registration main-logo progility.png
 webpage internal registration small-logo progility.png
 webpage internal no-service main-logo progility.png
 webpage internal no-service small-logo progility.png
 use aaa-policy Internal-AAA
--More--         use dns-whitelist Guest_Internal
 webpage-auto-upload
 bypass captive-portal-detection
 webpage internal registration field mobile type number enable label "Mobile" placeholder "Mobile Number with Country code"
 webpage internal registration field email type e-address enable mandatory label "Email" placeholder "you@domain.com"
 webpage internal registration field name type text enable label "Full Name" placeholder "Enter First Name, Last Name"
!
wlan WLAN-EAP
 description Employee
 ssid ProgilityTech
 vlan 100
 bridging-mode local
 encryption-type ccmp
 authentication-type eap
 no multi-band-operation
 no protected-mgmt-frames
 radius vlan-assignment
 use aaa-policy Progility-AAA
!
wlan guest_new
 description Guest
 ssid Progility_Guest
 vlan 2
 bridging-mode local
 encryption-type none
 authentication-type none
 no client-client-communication
 no multi-band-operation
 no protected-mgmt-frames
 use captive-portal Progility_Guest_Internal
 captive-portal-enforcement fall-back
 enforce-dhcp
 proxy-arp-mode strict
!
auto-provisioning-policy "Auto-Provisioning Policy"
 evaluate-always
 adopt anyap precedence 1 profile Progility-AP-Site rf-domain Progility-WING model-number AP310i-WR 
!
radius-group Guest
 policy vlan 2
!
radius-user-pool-policy Guest-Users
 user guest111 password 0 admin123@ group Guest
--More--         !
radius-server-policy RADIUS-Guest
 use radius-user-pool-policy Guest-Users
!
!
management-policy Progility-AP-Management
 telnet
 no http server
 no https server
 rest-server
 ssh
 user admin password 1 96cd23521397f8e3d9e9af6a59d6dc027591d559d5a57932e549500ebe67ccf5 role superuser access all
!
management-policy Progility-Management
 no telnet
 no http server
 https server
 rest-server
 ssh
 user admin password 1 96cd23521397f8e3d9e9af6a59d6dc027591d559d5a57932e549500ebe67ccf5 role superuser access all
!
management-policy default
 no telnet
 no http server
 https server
 rest-server
 ssh
 user admin password 1 6fc577b3aaf57af7f4efcfa3c92bbe4cebdca02ba7c188eaca817f50839ab251 role superuser access all
 snmp-server community 0 private rw
 snmp-server community 0 public ro
 snmp-server user snmptrap v3 encrypted des auth md5 0 admin123
 snmp-server user snmpmanager v3 encrypted des auth md5 0 admin123
 t5 snmp-server community public ro 192.168.0.1
 t5 snmp-server community private rw 192.168.0.1
!
ex3500-management-policy default
 snmp-server community public ro
 snmp-server community private rw
 snmp-server notify-filter 1 remote 127.0.0.1
 snmp-server view defaultview 1 included
!
ex3500-qos-class-map-policy default
!
--More--         ex3500-qos-policy-map default
!
database-policy default
!
profile vx9000 default-vx9000
 no autoinstall configuration
 no autoinstall firmware
 no device-upgrade auto
 crypto ikev1 policy ikev1-default 
  isakmp-proposal default encryption aes-256 group 2 hash sha 
 crypto ikev2 policy ikev2-default 
  isakmp-proposal default encryption aes-256 group 2 hash sha 
 crypto ipsec transform-set default esp-aes-256 esp-sha-hmac
 crypto ikev1 remote-vpn
 crypto ikev2 remote-vpn
 crypto auto-ipsec-secure
 crypto load-management
 crypto remote-vpn-client
 interface xge1
 interface xge2
 interface xge3
 interface xge4
 interface ge1
 interface ge2
 use firewall-policy Progility_Security
 use auto-provisioning-policy "Auto-Provisioning Policy"
 use captive-portal server Progility-Guest-External
 logging on
 no auto-learn staging-config
 service pm sys-restart
 router bgp
 adoption-mode controller
!
profile anyap Progility-AP-Site
 no autoinstall configuration
 no autoinstall firmware
 crypto ikev1 policy ikev1-default 
  isakmp-proposal default encryption aes-256 group 2 hash sha 
 crypto ikev2 policy ikev2-default 
  isakmp-proposal default encryption aes-256 group 2 hash sha 
 crypto ipsec transform-set default esp-aes-256 esp-sha-hmac
 crypto ikev1 remote-vpn
 crypto ikev2 remote-vpn
--More--         crypto auto-ipsec-secure
 crypto load-management
 crypto remote-vpn-client
 interface radio1
  wlan WLAN-EAP bss 1 primary
  wlan guest_new bss 2 primary
  ldpc
 interface radio2
  wlan WLAN-EAP bss 1 primary
  wlan guest_new bss 2 primary
  ldpc
  no 11axSupport
 interface radio3
 interface bluetooth1
  shutdown
  mode le-sensor
 interface up1
 interface ge1
  switchport mode trunk
  switchport trunk allowed vlan 2,100
  switchport trunk native vlan 100
 interface ge2
 interface fe1
 interface fe2
 interface fe3
 interface fe4
 interface vlan2
  description "Guest VLAN"
  ip address dhcp
 interface vlan100
  description "Employee VLAN"
  ip address dhcp
  ip dhcp client request options all
 interface wwan1
 interface pppoe1
 use management-policy Progility-AP-Management
 use firewall-policy Progility_Security
 use captive-portal server Progility_Guest_Internal
 use client-identity-group block
 no auto-learn staging-config
 service pm sys-restart
 router ospf
 adoption-mode controller
--More--         !
profile ap310 default-ap310
 no autoinstall configuration
 no autoinstall firmware
 crypto ikev1 policy ikev1-default 
  isakmp-proposal default encryption aes-256 group 2 hash sha 
 crypto ikev2 policy ikev2-default 
  isakmp-proposal default encryption aes-256 group 2 hash sha 
 crypto ipsec transform-set default esp-aes-256 esp-sha-hmac
 crypto ikev1 remote-vpn
 crypto ikev2 remote-vpn
 crypto auto-ipsec-secure
 crypto load-management
 crypto remote-vpn-client
 interface radio1
 interface radio2
 interface bluetooth1
  shutdown
  mode le-sensor
 interface ge1
 interface ge2
 interface pppoe1
 interface usb0
 use firewall-policy default
 service pm sys-restart
 router ospf
 adoption-mode controller
!
rf-domain Progility-WING
 location Kanjurmarg
 contact IThelpdesk
 timezone Asia/Calcutta
 country-code in
 ad-wips-wireless-mitigation disable
 ad-wips-wired-mitigation disable
 controller-managed
!
rf-domain default
 no country-code
 ad-wips-wireless-mitigation disable
 ad-wips-wired-mitigation disable
!
vx9000 00-0C-29-17-DC-B1
--More--         use profile default-vx9000
 use rf-domain Progility-WING
 hostname Progility-VX9000
 license AAP VX-DEFAULT-64AAP-LICENSE
 license ADSEC DEFAULT-ADV-SEC-LICENSE
 license VX 86a9e2aed84629369ba7cd3b660bee7d49004f7aed3fdce563ccb4abfb928117c258e2b8fe1249f2
 location Kanjurmarg
 contact ithelpdesk
 timezone Asia/Colombo
 country-code in
 use database-policy default
 ip name-server 172.22.97.151
 ip name-server 172.22.97.152
 ip name-server 172.22.97.153
 ip domain-name progilitytech.com
 ip default-gateway 172.22.97.129
 use radius-server-policy RADIUS-Guest
 interface ge1
  switchport mode trunk
  switchport trunk allowed vlan 2,100,102
  switchport trunk native vlan 102
 interface ge2
  shutdown
  switchport mode trunk
  switchport trunk allowed vlan 2,102
  switchport trunk native vlan 102
 interface vlan1
  ip address dhcp
 interface vlan2
  ip address dhcp
  no shutdown
 interface vlan102
  description Management-VLAN
  ip address 172.22.97.149/25
 use management-policy Progility-Management
 use auto-provisioning-policy "Auto-Provisioning Policy"
 ip dns-server-forward
!
ap310 20-9E-F7-76-A5-AF
 use profile Progility-AP-Site
 use rf-domain Progility-WING
 hostname Kanjur-10th-AP1
!
--More--         ap310 20-9E-F7-76-A5-B4
 use profile Progility-AP-Site
 use rf-domain Progility-WING
 hostname Kanjur-10th-AP2
!
ap310 20-9E-F7-76-A5-B9
 use profile Progility-AP-Site
 use rf-domain Progility-WING
 hostname Kanjur-9th-AP1
!
ap310 20-9E-F7-76-A7-67
 use profile Progility-AP-Site
 use rf-domain Progility-WING
 hostname Delhi-AP1
!
ap310 20-9E-F7-76-A8-02
 use profile Progility-AP-Site
 use rf-domain Progility-WING
 hostname Delhi-AP2
!
ap310 20-9E-F7-76-A8-07
 use profile Progility-AP-Site
 use rf-domain Progility-WING
 hostname Ahmedabad-AP1
!
ap310 20-9E-F7-76-A8-0C
 use profile Progility-AP-Site
 use rf-domain Progility-WING
 hostname Hyderabad-AP1
!
ap310 20-9E-F7-76-A8-16
 use profile Progility-AP-Site
 use rf-domain Progility-WING
 hostname Kolkata-AP1
!
ap310 20-9E-F7-76-A8-25
 use profile Progility-AP-Site
 use rf-domain Progility-WING
 hostname Kolkata-AP2
!
ap310 20-9E-F7-76-A8-34
 use profile Progility-AP-Site
 use rf-domain Progility-WING
--More--         hostname Mahape-AP1
 use client-identity-group block
 use role-policy BlockMobile
!
ap310 20-9E-F7-76-A8-3E
 use profile Progility-AP-Site
 use rf-domain Progility-WING
 hostname Mahape-AP2
 use client-identity-group block
 use role-policy BlockMobile
!
ap310 20-9E-F7-76-A8-43
 use profile Progility-AP-Site
 use rf-domain Progility-WING
 hostname Pune-AP1
!
ap310 20-9E-F7-76-A8-6B
 use profile Progility-AP-Site
 use rf-domain Progility-WING
 hostname Kanjur-9th-AP2
!
ap310 20-9E-F7-76-A8-98
 use profile Progility-AP-Site
 use rf-domain Progility-WING
 hostname Chennai-AP1
!
ap310 20-9E-F7-76-A9-4C
 use profile Progility-AP-Site
 use rf-domain Progility-WING
 hostname Bangalore-AP1
!
ap310 20-9E-F7-76-AC-03
 use profile Progility-AP-Site
 use rf-domain Progility-WING
 hostname Bangalore-AP2
!
!
end
Progility-VX9000#  

Userlevel 5

Hi Shubha,

Please post the running config from your controller, that would be easiest way to figure out what's missing. 

You can use "show run" command and paste the output here.

 

Regards,

Ovais

Reply