<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: 10.11 HTTP Redirection at AP in ExtremeWireless (Identifi)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-identifi/10-11-http-redirection-at-ap/m-p/51479#M5500</link>
    <description>Andre&lt;BR /&gt;
&lt;BR /&gt;
My understanding is that the wlan service must be of type FFECP (see the manual pages in my first post.)&lt;BR /&gt;
&lt;BR /&gt;
If it is not, and the identity/shared secret fields are not complete, the AP will not redirect.&lt;BR /&gt;
&lt;BR /&gt;
I would recommend attaching your configs to a case and we will take a look at it, I have it working in the lab on this code, in a wireless trace I see the AP sending http redirect.&lt;BR /&gt;
&lt;BR /&gt;
-Gareth</description>
    <pubDate>Fri, 12 Aug 2016 20:35:00 GMT</pubDate>
    <dc:creator>Gareth_Mitchell</dc:creator>
    <dc:date>2016-08-12T20:35:00Z</dc:date>
    <item>
      <title>10.11 HTTP Redirection at AP</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/10-11-http-redirection-at-ap/m-p/51476#M5497</link>
      <description>Hi Guys&lt;BR /&gt;
&lt;BR /&gt;
So I am playing with the new HTTP redirection at the AP (Bridge@AP).&lt;BR /&gt;
&lt;BR /&gt;
For my test I would like to redirect users to the NAC portal page using a Bridge at AP.&lt;BR /&gt;
Not sure what I am doing wrong here:&lt;BR /&gt;
 &lt;BR /&gt;
I have enabled HTTP Redirection globally:&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="9d06f8421b624d83b9a37b498cdf53db_RackMultipart20160805-73557-4n39zv-1_inline.jpg"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/4400i7ACA811AB822CF86/image-size/large?v=v2&amp;amp;px=999" role="button" title="9d06f8421b624d83b9a37b498cdf53db_RackMultipart20160805-73557-4n39zv-1_inline.jpg" alt="9d06f8421b624d83b9a37b498cdf53db_RackMultipart20160805-73557-4n39zv-1_inline.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
I have created a redirection role with the following rules:&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="9d06f8421b624d83b9a37b498cdf53db_RackMultipart20160805-112574-htozkb-2_inline.jpg"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/4084i0B3FA07D18E65AAC/image-size/large?v=v2&amp;amp;px=999" role="button" title="9d06f8421b624d83b9a37b498cdf53db_RackMultipart20160805-112574-htozkb-2_inline.jpg" alt="9d06f8421b624d83b9a37b498cdf53db_RackMultipart20160805-112574-htozkb-2_inline.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="9d06f8421b624d83b9a37b498cdf53db_RackMultipart20160805-122662-p3fm1s-3_inline.jpg"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/2107iBDE2A87C463F4235/image-size/large?v=v2&amp;amp;px=999" role="button" title="9d06f8421b624d83b9a37b498cdf53db_RackMultipart20160805-122662-p3fm1s-3_inline.jpg" alt="9d06f8421b624d83b9a37b498cdf53db_RackMultipart20160805-122662-p3fm1s-3_inline.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
The user connect and receives an IP, but is never redirected.&lt;BR /&gt;
If I browse to the "Redirection URL" I do get the NAC Portal Page:&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="9d06f8421b624d83b9a37b498cdf53db_RackMultipart20160805-69387-ii3vla-4_inline.jpg"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/5968i119C61B590E1970C/image-size/large?v=v2&amp;amp;px=999" role="button" title="9d06f8421b624d83b9a37b498cdf53db_RackMultipart20160805-69387-ii3vla-4_inline.jpg" alt="9d06f8421b624d83b9a37b498cdf53db_RackMultipart20160805-69387-ii3vla-4_inline.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
Looking at the note at the bottom of the "Redirection URL"&lt;BR /&gt;
&lt;I&gt;&lt;B&gt;Note:&lt;/B&gt;&lt;/I&gt;&lt;B&gt;&lt;I&gt; token=&lt;I&gt;&amp;amp;dest=&lt;ORIGINAL_TARGET_URL&gt;&lt;/ORIGINAL_TARGET_URL&gt;&lt;/I&gt;&lt;/I&gt;&lt;/B&gt;&lt;I&gt;&lt;BR /&gt;
&lt;B&gt;&lt;I&gt;&amp;amp;hwcip=&lt;HWC_IP&gt;&amp;amp;hwcport=&lt;HWC_PORT&gt;&lt;/HWC_PORT&gt;&lt;/HWC_IP&gt;&lt;/I&gt;&lt;/B&gt;&lt;BR /&gt;
&lt;B&gt;&lt;I&gt;will be APPENDED to the redirection URL&lt;/I&gt;&lt;/B&gt;&lt;BR /&gt;
&lt;BR /&gt;
This might be the problem....&lt;BR /&gt;
&lt;BR /&gt;
Any idea??&lt;BR /&gt;
&lt;BR /&gt;
&lt;/I&gt;</description>
      <pubDate>Fri, 05 Aug 2016 20:34:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/10-11-http-redirection-at-ap/m-p/51476#M5497</guid>
      <dc:creator>Andre_Brits_Kan</dc:creator>
      <dc:date>2016-08-05T20:34:00Z</dc:date>
    </item>
    <item>
      <title>RE: 10.11 HTTP Redirection at AP</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/10-11-http-redirection-at-ap/m-p/51477#M5498</link>
      <description>Andre&lt;BR /&gt;
&lt;BR /&gt;
Do you have your portal type set to firewall friendly and the mandatory fields filled in, see page 178 in the user guide?&lt;BR /&gt;
&lt;BR /&gt;
I also recommend checking that DNS is working (ping &lt;A href="http://www.extremenetworks.com" target="_blank" rel="nofollow noreferrer noopener"&gt;www.extremenetworks.com&lt;/A&gt; and make sure that you resolve an IP.)&lt;BR /&gt;
&lt;BR /&gt;
• Configure the Captive Portal to be External Firewall Friendly. Configure the following parameters on the ECP:&lt;BR /&gt;
• The Identity and Shared Secret fields are required and must match the values used when you&lt;BR /&gt;
configured the captive portal.&lt;BR /&gt;
• When configuring the Allow policy for the ECP, The IP/subnet value specified on the Filter&lt;BR /&gt;
Rule Definition dialog, must match the Redirection URL value specified on the FFECP&lt;BR /&gt;
Configure dialog.&lt;BR /&gt;
• Select an option for Send Successful Login To.&lt;BR /&gt;
&lt;BR /&gt;
-Gareth&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Tue, 09 Aug 2016 19:44:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/10-11-http-redirection-at-ap/m-p/51477#M5498</guid>
      <dc:creator>Gareth_Mitchell</dc:creator>
      <dc:date>2016-08-09T19:44:00Z</dc:date>
    </item>
    <item>
      <title>RE: 10.11 HTTP Redirection at AP</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/10-11-http-redirection-at-ap/m-p/51478#M5499</link>
      <description>Hi Gareth    The FFECP only applies to routed or b@ewc topologies.  With new redirect options should allow you to redirect traffic with a Bridge at AP topology.    I have tried to set this and the controller then warns you that it only applies to routed and B@EWC topologies.    Enhanced Access Points (AP38XX/39XX) to directly support redirection and Firewall Friendly External Captive  Portal (FFECP) for distributed topologies.    Thx</description>
      <pubDate>Fri, 12 Aug 2016 20:35:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/10-11-http-redirection-at-ap/m-p/51478#M5499</guid>
      <dc:creator>Andre_Brits_Kan</dc:creator>
      <dc:date>2016-08-12T20:35:00Z</dc:date>
    </item>
    <item>
      <title>RE: 10.11 HTTP Redirection at AP</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/10-11-http-redirection-at-ap/m-p/51479#M5500</link>
      <description>Andre&lt;BR /&gt;
&lt;BR /&gt;
My understanding is that the wlan service must be of type FFECP (see the manual pages in my first post.)&lt;BR /&gt;
&lt;BR /&gt;
If it is not, and the identity/shared secret fields are not complete, the AP will not redirect.&lt;BR /&gt;
&lt;BR /&gt;
I would recommend attaching your configs to a case and we will take a look at it, I have it working in the lab on this code, in a wireless trace I see the AP sending http redirect.&lt;BR /&gt;
&lt;BR /&gt;
-Gareth</description>
      <pubDate>Fri, 12 Aug 2016 20:35:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/10-11-http-redirection-at-ap/m-p/51479#M5500</guid>
      <dc:creator>Gareth_Mitchell</dc:creator>
      <dc:date>2016-08-12T20:35:00Z</dc:date>
    </item>
    <item>
      <title>RE: 10.11 HTTP Redirection at AP</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/10-11-http-redirection-at-ap/m-p/51480#M5501</link>
      <description>Hi,    Been in the process of setting this up myself but been struggling also to get the redirect working. (Think it might be having the redirect firewall rule set to the NAC address instead of 0.0.0.0 as above, as you would traditionally do - will test and post back)    Would it be possible to provide the detail of an exact working configuration that redirects to NAC Captive Portal - the above details 90% of it but not sure how accurate it is and some bits are missing like if FFECP was required, and its elements.    Are the settings above, all the firewall entries exactly how they should be?    Did this require FFECP in the end to work? What was entered for the mandatory fields, like 'identity' for example (perhaps wireless controller hostname?)    I'm running on code 10.34.x    Many thanks.</description>
      <pubDate>Thu, 21 Sep 2017 23:01:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/10-11-http-redirection-at-ap/m-p/51480#M5501</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2017-09-21T23:01:00Z</dc:date>
    </item>
    <item>
      <title>RE: 10.11 HTTP Redirection at AP</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/10-11-http-redirection-at-ap/m-p/51481#M5502</link>
      <description>Have it working, screenshots of the configuration below. I did end up using FFECP but I didn't need to fill in feilds except the URL.&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="68f44acc7b294b1dbb3ffdcda3fc9e7d_RackMultipart20170922-10231-awsfxj-Role_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/1823iD75BE24A48796FF7/image-size/large?v=v2&amp;amp;px=999" role="button" title="68f44acc7b294b1dbb3ffdcda3fc9e7d_RackMultipart20170922-10231-awsfxj-Role_inline.png" alt="68f44acc7b294b1dbb3ffdcda3fc9e7d_RackMultipart20170922-10231-awsfxj-Role_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="68f44acc7b294b1dbb3ffdcda3fc9e7d_RackMultipart20170922-101466-1s2xkw8-Rule_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/2315iC7CB45826D6589DF/image-size/large?v=v2&amp;amp;px=999" role="button" title="68f44acc7b294b1dbb3ffdcda3fc9e7d_RackMultipart20170922-101466-1s2xkw8-Rule_inline.png" alt="68f44acc7b294b1dbb3ffdcda3fc9e7d_RackMultipart20170922-101466-1s2xkw8-Rule_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="68f44acc7b294b1dbb3ffdcda3fc9e7d_RackMultipart20170922-120594-zc4rtt-RuleRedirect_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/4145iD1B7A9E35AC4B5E9/image-size/large?v=v2&amp;amp;px=999" role="button" title="68f44acc7b294b1dbb3ffdcda3fc9e7d_RackMultipart20170922-120594-zc4rtt-RuleRedirect_inline.png" alt="68f44acc7b294b1dbb3ffdcda3fc9e7d_RackMultipart20170922-120594-zc4rtt-RuleRedirect_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="68f44acc7b294b1dbb3ffdcda3fc9e7d_RackMultipart20170922-51830-12lgl94-WLAN_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/1302iD60101BE99033FBD/image-size/large?v=v2&amp;amp;px=999" role="button" title="68f44acc7b294b1dbb3ffdcda3fc9e7d_RackMultipart20170922-51830-12lgl94-WLAN_inline.png" alt="68f44acc7b294b1dbb3ffdcda3fc9e7d_RackMultipart20170922-51830-12lgl94-WLAN_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="68f44acc7b294b1dbb3ffdcda3fc9e7d_RackMultipart20170922-9481-1x3qffw-FFECP_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/2000iF02771A96F14170C/image-size/large?v=v2&amp;amp;px=999" role="button" title="68f44acc7b294b1dbb3ffdcda3fc9e7d_RackMultipart20170922-9481-1x3qffw-FFECP_inline.png" alt="68f44acc7b294b1dbb3ffdcda3fc9e7d_RackMultipart20170922-9481-1x3qffw-FFECP_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
Mistakes I made to avoid:&lt;BR /&gt;
&lt;UL&gt; 
&lt;LI&gt;Make sure redirect rule is set to 0.0.0.0/0 for HTTP and HTTPS, and not NAC IP (As Above) 
&lt;/LI&gt;&lt;LI&gt;Make sure you enter NAC IP address in, otherwise you get an 'Internal Error' when redirected (As Above) 
&lt;/LI&gt;&lt;LI&gt;You don't need to fill out any fields in FFECP config other than URL (As Above) 
&lt;/LI&gt;&lt;LI&gt;IP 10.199.0.120 is NAC 
&lt;/LI&gt;&lt;LI&gt;IP 10.114.15.101/32 can be removed, this is a mistake. This was a hangup when originally configured for Bridge@EWC&lt;/LI&gt;&lt;/UL&gt;Thanks.&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Fri, 22 Sep 2017 18:16:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/10-11-http-redirection-at-ap/m-p/51481#M5502</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2017-09-22T18:16:00Z</dc:date>
    </item>
  </channel>
</rss>

