<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: How to config Wing to use Cisco ISE guestportal, redirect-URL in wing doesn't work in ExtremeWireless (WiNG)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-config-wing-to-use-cisco-ise-guestportal-redirect-url-in/m-p/18416#M791</link>
    <description>so in your AP profile... try:                  service  radius dynamic-authorization additional-port &lt;BR /&gt;
&lt;BR /&gt;
Cisco ISE: is typically 1700 i believe.. &lt;BR /&gt;
&lt;BR /&gt;</description>
    <pubDate>Tue, 17 Apr 2018 23:43:00 GMT</pubDate>
    <dc:creator>Peter_Miller</dc:creator>
    <dc:date>2018-04-17T23:43:00Z</dc:date>
    <item>
      <title>How to config Wing to use Cisco ISE guestportal, redirect-URL in wing doesn't work</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-config-wing-to-use-cisco-ise-guestportal-redirect-url-in/m-p/18412#M787</link>
      <description>I have set up an SSID which using the ISE as the radius server proxy through wireless controller. My goal is to use the hotspot and GuestPortal in the ISE&lt;BR /&gt;
Everything is fine in the ISE. The ISE returns the radius respons with and valid redirect-URL.&lt;BR /&gt;
Access-Accept&lt;BR /&gt;
The respons comes on standard radius port 1812. &lt;BR /&gt;
But i have expected to see any trafic on CoA port 3799!!&lt;BR /&gt;
I have struggling a lot, many hours seeking info about how to integrate ISE and WING. &lt;BR /&gt;
Having read all availble documents and videos, tried every suggestions. No success.&lt;BR /&gt;
&lt;BR /&gt;
My main problem is why is not the client redirected to the supplied URL?&lt;BR /&gt;
&lt;BR /&gt;
It works fine with Aruba's CCPM, hotspot and sponsored guest.&lt;BR /&gt;
Isn't it possible to use Cisco ISE with Wing, have any succeded in the task??&lt;BR /&gt;
&lt;BR /&gt;
I am running Wing v.5.8.6 and using AP7532 and NX7510 and ISE v.2.3&lt;BR /&gt;
&lt;BR /&gt;
Screeshoot of Radius respons from ISE&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="dd52b165c7d4419eb37b3eae2209c643_RackMultipart20180323-43661-13bqopx-RadiusRespons_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/5524iBEDDC751AB6976B0/image-size/large?v=v2&amp;amp;px=999" role="button" title="dd52b165c7d4419eb37b3eae2209c643_RackMultipart20180323-43661-13bqopx-RadiusRespons_inline.png" alt="dd52b165c7d4419eb37b3eae2209c643_RackMultipart20180323-43661-13bqopx-RadiusRespons_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Fri, 23 Mar 2018 14:48:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-config-wing-to-use-cisco-ise-guestportal-redirect-url-in/m-p/18412#M787</guid>
      <dc:creator>Roger_Jansson</dc:creator>
      <dc:date>2018-03-23T14:48:00Z</dc:date>
    </item>
    <item>
      <title>RE: How to config Wing to use Cisco ISE guestportal, redirect-URL in wing doesn't work</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-config-wing-to-use-cisco-ise-guestportal-redirect-url-in/m-p/18413#M788</link>
      <description>please, can you post the wing configuration?</description>
      <pubDate>Fri, 23 Mar 2018 14:51:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-config-wing-to-use-cisco-ise-guestportal-redirect-url-in/m-p/18413#M788</guid>
      <dc:creator>Andrew_Blomley</dc:creator>
      <dc:date>2018-03-23T14:51:00Z</dc:date>
    </item>
    <item>
      <title>RE: How to config Wing to use Cisco ISE guestportal, redirect-URL in wing doesn't work</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-config-wing-to-use-cisco-ise-guestportal-redirect-url-in/m-p/18414#M789</link>
      <description>Your configuration maybe will help. Do you configure the DNS whitelist to give the user access to your captive portal site?</description>
      <pubDate>Mon, 26 Mar 2018 11:53:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-config-wing-to-use-cisco-ise-guestportal-redirect-url-in/m-p/18414#M789</guid>
      <dc:creator>Timo1</dc:creator>
      <dc:date>2018-03-26T11:53:00Z</dc:date>
    </item>
    <item>
      <title>RE: How to config Wing to use Cisco ISE guestportal, redirect-URL in wing doesn't work</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-config-wing-to-use-cisco-ise-guestportal-redirect-url-in/m-p/18415#M790</link>
      <description>More info about the problem configuration.....&lt;BR /&gt;
&lt;BR /&gt;
I don't get the webpages on the captiveportal presented on the client.&lt;BR /&gt;
The captive portal status for authentication is redirected in Wing GUI console.&lt;BR /&gt;
No redirection is done to the url inte radius repons.&lt;BR /&gt;
&lt;BR /&gt;
The DNSwhitelist have all all ip's included.&lt;BR /&gt;
&lt;BR /&gt;
Have tried to extract the importent from the config.&lt;BR /&gt;
See attached text  .&lt;BR /&gt;
&lt;BR /&gt;
My ISE have ip 10.241.1.61 and controller has 10.2.50.71.&lt;BR /&gt;
&lt;BR /&gt;
If there is any who have succeded with the ISE integration please send me or publish an copy of the config regarding the WLAN, CaptivePortal and AAA-policy because  i am not fully sure how to its should be configurated to work.&lt;BR /&gt;
&lt;BR /&gt;
-----------------------------------------------------&lt;BR /&gt;
Extracted configuration....&lt;BR /&gt;
&lt;BR /&gt;
aaa-policy ISE_TEST&lt;BR /&gt;
 authentication server 1 host 10.241.1.61 secret 0 ??&lt;BR /&gt;
 authentication server 1 proxy-mode through-controller&lt;BR /&gt;
 accounting server 1 host 10.241.1.61 secret 0 ???&lt;BR /&gt;
 accounting server 1 proxy-mode through-controller&lt;BR /&gt;
 mac-address-format pair-hyphen case lower attributes all&lt;BR /&gt;
 accounting type start-interim-stop&lt;BR /&gt;
 attribute cisco-vsa audit-session-id&lt;BR /&gt;
 attribute chargeable-user-identity&lt;BR /&gt;
 attribute location-information include-always&lt;BR /&gt;
 attribute framed-ip-address&lt;BR /&gt;
!&lt;BR /&gt;
dns-whitelist ISE&lt;BR /&gt;
 permit 10.2.50.71 &lt;BR /&gt;
 permit 10.241.1.61 &lt;BR /&gt;
 permit accessise.karlskoga.se &lt;BR /&gt;
 permit play.google.com &lt;BR /&gt;
 permit 10.2.1.6 &lt;BR /&gt;
 permit 10.2.1.5 &lt;BR /&gt;
 permit 10.129.6.4 &lt;BR /&gt;
 permit 10.163.0.5 &lt;BR /&gt;
 permit 10.129.6.1 &lt;BR /&gt;
!&lt;BR /&gt;
captive-portal ISE_TEST&lt;BR /&gt;
 access-time 15&lt;BR /&gt;
 connection-mode https&lt;BR /&gt;
 server host accessise.karlskoga.se&lt;BR /&gt;
 server mode centralized&lt;BR /&gt;
 webpage-location external&lt;BR /&gt;
 webpage external login https://accessise.karlskoga.se:port/portal/gateway?sessionId=SessionIdValue&amp;amp;portal=f0ae43f0-7159-11e7-a355-005056aba474&amp;amp;daysToExpiry=value&amp;amp;action=cwa&lt;BR /&gt;
 webpage external welcome &lt;A href="http://www.karlskoga.se" target="_blank" rel="nofollow noreferrer noopener"&gt;http://www.karlskoga.se&lt;/A&gt;&lt;BR /&gt;
 webpage external fail &lt;A href="https://10.241.1.61:8443/portal/PortalSetup.action?portal=f0ae43f0-7159-11e7-a355-005056aba474" target="_blank" rel="nofollow noreferrer noopener"&gt;https://10.241.1.61:8443/portal/PortalSetup.action?portal=f0ae43f0-7159-11e7-a355-005056aba474&lt;/A&gt;&lt;BR /&gt;
 webpage external agreement &lt;A href="https://accessise.karlskoga.se:8443/portal/PortalSetup.action?portal=f0ae43f0-7159-11e7-a355-005056aba474" target="_blank" rel="nofollow noreferrer noopener"&gt;https://accessise.karlskoga.se:8443/portal/PortalSetup.action?portal=f0ae43f0-7159-11e7-a355-005056a...&lt;/A&gt;&lt;BR /&gt;
 webpage external acknowledgement &lt;A href="https://10.241.1.61:8443/portal/PortalSetup.action?portal=f0ae43f0-7159-11e7-a355-005056aba474" target="_blank" rel="nofollow noreferrer noopener"&gt;https://10.241.1.61:8443/portal/PortalSetup.action?portal=f0ae43f0-7159-11e7-a355-005056aba474&lt;/A&gt;&lt;BR /&gt;
 webpage external registration &lt;A href="https://10.241.1.61:8443/portal/PortalSetup.action?portal=f0ae43f0-7159-11e7-a355-005056aba474" target="_blank" rel="nofollow noreferrer noopener"&gt;https://10.241.1.61:8443/portal/PortalSetup.action?portal=f0ae43f0-7159-11e7-a355-005056aba474&lt;/A&gt;&lt;BR /&gt;
 webpage external no-service &lt;A href="https://10.241.1.61:8443/portal/PortalSetup.action?portal=f0ae43f0-7159-11e7-a355-005056aba474" target="_blank" rel="nofollow noreferrer noopener"&gt;https://10.241.1.61:8443/portal/PortalSetup.action?portal=f0ae43f0-7159-11e7-a355-005056aba474&lt;/A&gt;&lt;BR /&gt;
 accounting radius&lt;BR /&gt;
 use aaa-policy ISE_TEST&lt;BR /&gt;
 use dns-whitelist ISE&lt;BR /&gt;
 webpage internal registration field city type text enable label "City" placeholder "Enter City"&lt;BR /&gt;
 webpage internal registration field street type text enable label "Address" placeholder "123 Any Street"&lt;BR /&gt;
 webpage internal registration field name type text enable label "Full Name" placeholder "Enter First Name, Last Name"&lt;BR /&gt;
 webpage internal registration field zip type number enable label "Zip" placeholder "Zip"&lt;BR /&gt;
 webpage internal registration field via-sms type checkbox enable title "SMS Preferred"&lt;BR /&gt;
 webpage internal registration field mobile type number enable label "Mobile" placeholder "Mobile Number with Country code"&lt;BR /&gt;
 webpage internal registration field age-range type dropdown-menu enable label "Age Range" title "Age Range"&lt;BR /&gt;
 webpage internal registration field email type e-address enable mandatory label "Email" placeholder "you@domain.com"&lt;BR /&gt;
 webpage internal registration field via-email type checkbox enable title "Email Preferred"&lt;BR /&gt;
!&lt;BR /&gt;
wlan ISE-resticted&lt;BR /&gt;
 description Test Cisco ISE&lt;BR /&gt;
 ssid ISE1&lt;BR /&gt;
 vlan 1&lt;BR /&gt;
 bridging-mode local&lt;BR /&gt;
 encryption-type none&lt;BR /&gt;
 authentication-type mac&lt;BR /&gt;
 radius nas-identifier ISERestricted&lt;BR /&gt;
 no fast-bss-transition over-ds&lt;BR /&gt;
 wpa-wpa2 psk 0 ????&lt;BR /&gt;
 wpa-wpa2 exclude-wpa2-tkip&lt;BR /&gt;
 wpa-wpa2 use-sha256-akm&lt;BR /&gt;
 radius vlan-assignment&lt;BR /&gt;
 radius dynamic-authorization&lt;BR /&gt;
 accounting radius&lt;BR /&gt;
 wing-extensions ap-attributes-information&lt;BR /&gt;
 wing-extensions ap-attributes-information include-hostname&lt;BR /&gt;
 wing-extensions coverage-hole-detection 11k-clients&lt;BR /&gt;
 use aaa-policy ISE_TEST&lt;BR /&gt;
 use captive-portal ISE_TEST&lt;BR /&gt;
 captive-portal-enforcement&lt;BR /&gt;
!&lt;BR /&gt;
profile nx75xx ProfileNOC_NX7510-1&lt;BR /&gt;
 mint link force ip 10.2.200.1 level 2 cost 50&lt;BR /&gt;
 mint link ip 10.2.50.71 level 2&lt;BR /&gt;
 mint link ip 10.2.50.72 level 2&lt;BR /&gt;
 mint tunnel-across-extended-vlan&lt;BR /&gt;
 no legacy-auto-update ap650&lt;BR /&gt;
 ip name-server 10.2.1.5&lt;BR /&gt;
 ip name-server 10.2.1.6&lt;BR /&gt;
 ip domain-name karlskoga.se&lt;BR /&gt;
 ip default-gateway 10.2.3.1&lt;BR /&gt;
 ip route 10.128.0.0/10 10.163.0.1&lt;BR /&gt;
 ip route 10.220.56.0/24 10.163.0.1&lt;BR /&gt;
 no autoinstall configuration&lt;BR /&gt;
 no autoinstall firmware&lt;BR /&gt;
 device-upgrade auto ap7532&lt;BR /&gt;
 crypto ikev1 policy ikev1-default &lt;BR /&gt;
  isakmp-proposal default encryption aes-256 group 2 hash sha &lt;BR /&gt;
 crypto ikev2 policy ikev2-default &lt;BR /&gt;
  isakmp-proposal default encryption aes-256 group 2 hash sha &lt;BR /&gt;
 crypto ipsec transform-set default esp-aes-256 esp-sha-hmac&lt;BR /&gt;
 crypto ikev1 remote-vpn&lt;BR /&gt;
 crypto ikev2 remote-vpn&lt;BR /&gt;
 crypto auto-ipsec-secure&lt;BR /&gt;
  groupid KgaSec psk 0 Gregak88&lt;BR /&gt;
 crypto load-management&lt;BR /&gt;
 crypto remote-vpn-client&lt;BR /&gt;
 interface xge1&lt;BR /&gt;
 interface xge2&lt;BR /&gt;
 interface ge1&lt;BR /&gt;
  description MgmtNet&lt;BR /&gt;
 interface ge2&lt;BR /&gt;
  description "trunk if1"&lt;BR /&gt;
  switchport mode trunk&lt;BR /&gt;
  switchport trunk native vlan 130&lt;BR /&gt;
  switchport trunk native tagged&lt;BR /&gt;
  switchport trunk allowed vlan 130,138,147,1066&lt;BR /&gt;
  channel-group 1&lt;BR /&gt;
 interface ge3&lt;BR /&gt;
  description "trunk if2"&lt;BR /&gt;
  switchport mode trunk&lt;BR /&gt;
  switchport trunk native vlan 130&lt;BR /&gt;
  switchport trunk native tagged&lt;BR /&gt;
  switchport trunk allowed vlan 130,138,147,1066&lt;BR /&gt;
  channel-group 1&lt;BR /&gt;
 interface ge4&lt;BR /&gt;
  description "trunk if3"&lt;BR /&gt;
  switchport mode trunk&lt;BR /&gt;
  switchport trunk native vlan 130&lt;BR /&gt;
  switchport trunk native tagged&lt;BR /&gt;
  switchport trunk allowed vlan 130,138,147,1066&lt;BR /&gt;
  channel-group 1&lt;BR /&gt;
 interface ge5&lt;BR /&gt;
  description "trunk if4"&lt;BR /&gt;
  switchport mode trunk&lt;BR /&gt;
  switchport trunk native vlan 130&lt;BR /&gt;
  switchport trunk native tagged&lt;BR /&gt;
  switchport trunk allowed vlan 130,138,147,1066&lt;BR /&gt;
  channel-group 1&lt;BR /&gt;
 interface ge6&lt;BR /&gt;
 interface ge7&lt;BR /&gt;
 interface ge8&lt;BR /&gt;
 interface ge9&lt;BR /&gt;
 interface ge10&lt;BR /&gt;
 interface port-channel1&lt;BR /&gt;
  description "WiFi trunk"&lt;BR /&gt;
  switchport mode trunk&lt;BR /&gt;
  switchport trunk native vlan 130&lt;BR /&gt;
  switchport trunk native tagged&lt;BR /&gt;
  switchport trunk allowed vlan 130,138,147,1066&lt;BR /&gt;
  port-channel load-balance src-dst-mac&lt;BR /&gt;
 interface vlan1&lt;BR /&gt;
  description MgmtNet&lt;BR /&gt;
  ip address 172.30.200.70/16&lt;BR /&gt;
  no ipv6 address autoconfig&lt;BR /&gt;
  no ipv6 accept ra&lt;BR /&gt;
  no ipv6 redirects&lt;BR /&gt;
 interface vlan130&lt;BR /&gt;
  description Srvnet&lt;BR /&gt;
  ip address 10.2.50.70/16&lt;BR /&gt;
  no ipv6 address autoconfig&lt;BR /&gt;
  no ipv6 accept ra&lt;BR /&gt;
  no ipv6 redirects&lt;BR /&gt;
 interface vlan138&lt;BR /&gt;
  description KomnetWiFi&lt;BR /&gt;
  ip address 10.118.4.11/22&lt;BR /&gt;
  no ipv6 address autoconfig&lt;BR /&gt;
  no ipv6 accept ra&lt;BR /&gt;
  no ipv6 redirects&lt;BR /&gt;
 interface vlan147&lt;BR /&gt;
  description EdunetWiFi&lt;BR /&gt;
  ip address 10.163.0.5/20&lt;BR /&gt;
  ip nat outside&lt;BR /&gt;
  no ipv6 address autoconfig&lt;BR /&gt;
  no ipv6 accept ra&lt;BR /&gt;
  no ipv6 redirects&lt;BR /&gt;
 interface vlan199&lt;BR /&gt;
  description KonfigNet&lt;BR /&gt;
  ip address 192.168.208.1/20&lt;BR /&gt;
  ip nat inside&lt;BR /&gt;
  no ipv6 address autoconfig&lt;BR /&gt;
  no ipv6 accept ra&lt;BR /&gt;
  no ipv6 redirects&lt;BR /&gt;
 interface vlan1066&lt;BR /&gt;
  description "KgaGuestNet Firstspot"&lt;BR /&gt;
  ip address 192.168.16.3/20&lt;BR /&gt;
  no ipv6 address autoconfig&lt;BR /&gt;
  no ipv6 accept ra&lt;BR /&gt;
  no ipv6 redirects&lt;BR /&gt;
 interface vlan1072&lt;BR /&gt;
  description "local ElevZon"&lt;BR /&gt;
  ip address 192.168.80.2/22&lt;BR /&gt;
  no ipv6 address autoconfig&lt;BR /&gt;
  no ipv6 accept ra&lt;BR /&gt;
  no ipv6 redirects&lt;BR /&gt;
 use event-system-policy defaultKGA&lt;BR /&gt;
 use guest-management Komnet-smtp&lt;BR /&gt;
 use dhcp-server-policy NOC-Kga&lt;BR /&gt;
 use firewall-policy NOC&lt;BR /&gt;
 use auto-provisioning-policy NOC-KGA&lt;BR /&gt;
 use captive-portal server CPPM&lt;BR /&gt;
 use captive-portal server ElevNet&lt;BR /&gt;
 use captive-portal server ElevNetKga&lt;BR /&gt;
 use captive-portal server GuestNet-CP&lt;BR /&gt;
 use captive-portal server ISE&lt;BR /&gt;
 use captive-portal server NetLoan2&lt;BR /&gt;
 use captive-portal server Netloan&lt;BR /&gt;
 ntp server ntp2.karlskoga.se version 3 &lt;BR /&gt;
 use client-identity-group MobileDevices&lt;BR /&gt;
 use role-policy Basic&lt;BR /&gt;
 cluster name NX7510-1&lt;BR /&gt;
 cluster member ip 10.2.50.71 level 2&lt;BR /&gt;
 cluster member ip 10.2.50.72 level 2&lt;BR /&gt;
 email-notification host 10.2.100.71 sender noc-nx7510@karlskoga.se port 25&lt;BR /&gt;
 email-notification recipient admin1@karlskoga.se&lt;BR /&gt;
 logging on&lt;BR /&gt;
 logging host 10.2.100.122 &lt;BR /&gt;
 controller host 10.2.200.1 pool 1 level 2&lt;BR /&gt;
 service pm sys-restart&lt;BR /&gt;
 use routing-policy NX7510-1&lt;BR /&gt;
 router ospf&lt;BR /&gt;
 router bgp&lt;BR /&gt;
 l2tpv3 tunnel vlan1066&lt;BR /&gt;
  peer 1 hostname any router-id any &lt;BR /&gt;
  session vlan1066 pseudowire-id 1066 traffic-source vlan 1066&lt;BR /&gt;
  establishment-criteria cluster-master&lt;BR /&gt;
 dpi&lt;BR /&gt;
 dpi metadata voice-video&lt;BR /&gt;
 dpi metadata http&lt;BR /&gt;
 dpi metadata ssl&lt;BR /&gt;
 dpi logging on&lt;BR /&gt;
&lt;BR /&gt;
 &lt;BR /&gt;
 nx75xx 84-24-8D-7F-4C-70&lt;BR /&gt;
 use profile ProfileNOC_NX7510-1&lt;BR /&gt;
 use rf-domain NOC&lt;BR /&gt;
 hostname KgaDH1-nx7510-1A&lt;BR /&gt;
 license AAP ??????????????????&lt;BR /&gt;
 trustpoint radius-ca-ldaps wctrl4a&lt;BR /&gt;
 trustpoint radius-server-ldaps karlskoga-se&lt;BR /&gt;
 rsa-key ssh karlskoga-rsa-key&lt;BR /&gt;
 service radius dynamic-authorization additional-port 3599&lt;BR /&gt;
 trustpoint https karlskoga-se&lt;BR /&gt;
 interface vlan1&lt;BR /&gt;
  ip address 172.30.200.71/16&lt;BR /&gt;
 interface vlan130&lt;BR /&gt;
  ip address 10.2.50.71/16&lt;BR /&gt;
 use captive-portal server ElevNet&lt;BR /&gt;
 use captive-portal server ElevNetKga&lt;BR /&gt;
 cluster member ip 10.2.50.72 level 2&lt;BR /&gt;
 cluster master-priority 255&lt;BR /&gt;
 cluster force-configured-state&lt;BR /&gt;
 cluster force-configured-state-delay 120&lt;BR /&gt;
 !&lt;BR /&gt;
&lt;BR /&gt;
 profile ap7532 NOC-Komnet-1-ap7532&lt;BR /&gt;
 bridge vlan 1066&lt;BR /&gt;
  bridging-mode tunnel&lt;BR /&gt;
  ip igmp snooping&lt;BR /&gt;
  ip igmp snooping querier&lt;BR /&gt;
  ipv6 mld snooping&lt;BR /&gt;
  ipv6 mld snooping querier&lt;BR /&gt;
 ip name-server 10.2.1.5&lt;BR /&gt;
 ip name-server 10.2.1.6&lt;BR /&gt;
 ip domain-name komnet.karlskoga.se&lt;BR /&gt;
 ip route 10.11.0.0/16 10.16.0.1&lt;BR /&gt;
 ip route 10.2.0.0/16 10.16.0.1&lt;BR /&gt;
 ip default-gateway priority static-route 50&lt;BR /&gt;
 autoinstall configuration&lt;BR /&gt;
 autoinstall firmware&lt;BR /&gt;
 no led&lt;BR /&gt;
 crypto ikev1 policy ikev1-default &lt;BR /&gt;
  isakmp-proposal default encryption aes-256 group 2 hash sha &lt;BR /&gt;
 crypto ikev2 policy ikev2-default &lt;BR /&gt;
  isakmp-proposal default encryption aes-256 group 2 hash sha &lt;BR /&gt;
 crypto ipsec transform-set default esp-aes-256 esp-sha-hmac&lt;BR /&gt;
 crypto ikev1 remote-vpn&lt;BR /&gt;
 crypto ikev2 remote-vpn&lt;BR /&gt;
 crypto auto-ipsec-secure&lt;BR /&gt;
 crypto load-management&lt;BR /&gt;
 crypto remote-vpn-client&lt;BR /&gt;
 interface radio1&lt;BR /&gt;
  data-rates custom basic-12 basic-24 18 36 48 54 mcs-1s mcs-2s mcs-3s&lt;BR /&gt;
  wlan KgaGuestNet bss 1 primary&lt;BR /&gt;
  wlan Komnet-TLS bss 2 primary&lt;BR /&gt;
  wlan Kga-Personal bss 3 primary&lt;BR /&gt;
 interface radio2&lt;BR /&gt;
  data-rates custom basic-12 basic-24 18 36 48 54 mcs-1s mcs-2s mcs-3s&lt;BR /&gt;
  wlan KgaNet2 bss 2 primary&lt;BR /&gt;
  wlan KgaNet bss 3 primary&lt;BR /&gt;
  wlan Komnet-TLS bss 4 primary&lt;BR /&gt;
 interface ge1&lt;BR /&gt;
  switchport mode trunk&lt;BR /&gt;
  switchport trunk native vlan 1&lt;BR /&gt;
  no switchport trunk native tagged&lt;BR /&gt;
  switchport trunk allowed vlan 1,200,400&lt;BR /&gt;
 interface vlan1&lt;BR /&gt;
  ip address dhcp&lt;BR /&gt;
  ip address zeroconf secondary&lt;BR /&gt;
  no ipv6 address autoconfig&lt;BR /&gt;
  no ipv6 accept ra&lt;BR /&gt;
  no ipv6 redirects&lt;BR /&gt;
 interface vlan199&lt;BR /&gt;
  description KonfigNet&lt;BR /&gt;
  ip address 192.168.208.1/20&lt;BR /&gt;
  ip nat inside&lt;BR /&gt;
  no ipv6 address autoconfig&lt;BR /&gt;
  no ipv6 accept ra&lt;BR /&gt;
  no ipv6 redirects&lt;BR /&gt;
 interface vlan200&lt;BR /&gt;
  description EduNetWifi&lt;BR /&gt;
  ip address dhcp&lt;BR /&gt;
  ip dhcp client request options all&lt;BR /&gt;
  use ip-access-list in NAT-KonfigNet-AP&lt;BR /&gt;
  ip nat outside&lt;BR /&gt;
  no ipv6 address autoconfig&lt;BR /&gt;
  no ipv6 accept ra&lt;BR /&gt;
  no ipv6 redirects&lt;BR /&gt;
 interface vlan400&lt;BR /&gt;
  description ControllVLAN&lt;BR /&gt;
 interface vlan1072&lt;BR /&gt;
  description PreElevInternet&lt;BR /&gt;
  ip address 192.168.80.2/22&lt;BR /&gt;
  ip nat inside&lt;BR /&gt;
  no ipv6 address autoconfig&lt;BR /&gt;
  no ipv6 accept ra&lt;BR /&gt;
  no ipv6 redirects&lt;BR /&gt;
 interface pppoe1&lt;BR /&gt;
 use event-system-policy defaultKGA&lt;BR /&gt;
 use management-policy AP&lt;BR /&gt;
 use dhcp-server-policy Komnet-AP7532&lt;BR /&gt;
 use firewall-policy Standard&lt;BR /&gt;
 use auto-provisioning-policy NOC-KGA&lt;BR /&gt;
 use captive-portal server ElevNet&lt;BR /&gt;
 use captive-portal server ElevNetKga&lt;BR /&gt;
 ntp server ntp2.karlskoga.se version 3 &lt;BR /&gt;
 use client-identity-group MobileDevices&lt;BR /&gt;
 use role-policy Basic&lt;BR /&gt;
 ip dns-server-forward&lt;BR /&gt;
 email-notification host 10.2.100.71 sender noc-1-ap7532@karlskoga.se port 25&lt;BR /&gt;
 email-notification recipient admin1@karlskoga.se&lt;BR /&gt;
 logging on&lt;BR /&gt;
 logging host 10.2.100.122 &lt;BR /&gt;
 controller host 10.2.50.71 pool 1 level 2&lt;BR /&gt;
 ip nat inside source list NAT-GuestNet-AP precedence 20 interface vlan200 overload&lt;BR /&gt;
 ip nat inside source list NAT-KonfigNet-AP precedence 10 interface vlan200 overload&lt;BR /&gt;
 service pm sys-restart&lt;BR /&gt;
 use routing-policy Komnet-ap7532&lt;BR /&gt;
 router ospf&lt;BR /&gt;
 l2tpv3 tunnel vlan1066&lt;BR /&gt;
  peer 1 ip-address 10.2.50.71 hostname KgaDH1-nx7510-1A router-id any &lt;BR /&gt;
  peer 2 ip-address 10.2.50.72 hostname KgaDH1-nx7510-1B router-id any &lt;BR /&gt;
  session vlan1066 pseudowire-id 1066 traffic-source vlan 1066&lt;BR /&gt;
  establishment-criteria rf-domain-manager&lt;BR /&gt;
 l2tpv3 inter-tunnel-bridging&lt;BR /&gt;
 dpi&lt;BR /&gt;
 dpi metadata voice-video&lt;BR /&gt;
 dpi metadata http&lt;BR /&gt;
 dpi metadata ssl&lt;BR /&gt;
 dpi logging on&lt;BR /&gt;
 !&lt;BR /&gt;
&lt;BR /&gt;
 &lt;BR /&gt;
 ap7532 74-67-F7-00-87-C4&lt;BR /&gt;
 use profile NOC-Komnet-1-ap7532&lt;BR /&gt;
 use rf-domain 40-SKFALL&lt;BR /&gt;
 hostname SKFALL2FC-ITv2b&lt;BR /&gt;
 interface radio1&lt;BR /&gt;
  channel 9&lt;BR /&gt;
  wlan KgaGuestNet bss 1 primary&lt;BR /&gt;
  wlan Komnet-TLS bss 2 primary&lt;BR /&gt;
  wlan Kga-Personal bss 3 primary&lt;BR /&gt;
  wlan ElevNetWebAuth bss 4 primary&lt;BR /&gt;
  wlan EduXtra bss 5 primary&lt;BR /&gt;
  wlan CPPM bss 7 primary&lt;BR /&gt;
 interface radio2&lt;BR /&gt;
  wlan EduNet-noMac bss 1 primary&lt;BR /&gt;
  wlan KonfigNet bss 2 primary&lt;BR /&gt;
  wlan KgaNet bss 3 primary&lt;BR /&gt;
  wlan Komnet-TLS bss 4 primary&lt;BR /&gt;
  wlan ISE-resticted bss 5 primary&lt;BR /&gt;
  wlan EduXtra bss 6 primary&lt;BR /&gt;
  wlan ISE0-Open bss 7 primary&lt;BR /&gt;
  wlan TestGuestSSID bss 8 primary&lt;BR /&gt;
  wlan CPPM bss 9 primary&lt;BR /&gt;
 use captive-portal server ElevNet&lt;BR /&gt;
 use captive-portal server ElevNetKga&lt;BR /&gt;
 use captive-portal server HotSpot-Public&lt;BR /&gt;
 use captive-portal server ISE&lt;BR /&gt;
 use captive-portal server ISE_TEST&lt;BR /&gt;
 use captive-portal server NetLoan2&lt;BR /&gt;
 use captive-portal server Netloan&lt;BR /&gt;
 !&lt;BR /&gt;
&lt;BR /&gt;
/Roger</description>
      <pubDate>Tue, 27 Mar 2018 16:50:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-config-wing-to-use-cisco-ise-guestportal-redirect-url-in/m-p/18415#M790</guid>
      <dc:creator>Roger_Jansson</dc:creator>
      <dc:date>2018-03-27T16:50:00Z</dc:date>
    </item>
    <item>
      <title>RE: How to config Wing to use Cisco ISE guestportal, redirect-URL in wing doesn't work</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-config-wing-to-use-cisco-ise-guestportal-redirect-url-in/m-p/18416#M791</link>
      <description>so in your AP profile... try:                  service  radius dynamic-authorization additional-port &lt;BR /&gt;
&lt;BR /&gt;
Cisco ISE: is typically 1700 i believe.. &lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Tue, 17 Apr 2018 23:43:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-config-wing-to-use-cisco-ise-guestportal-redirect-url-in/m-p/18416#M791</guid>
      <dc:creator>Peter_Miller</dc:creator>
      <dc:date>2018-04-17T23:43:00Z</dc:date>
    </item>
    <item>
      <title>RE: How to config Wing to use Cisco ISE guestportal, redirect-URL in wing doesn't work</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-config-wing-to-use-cisco-ise-guestportal-redirect-url-in/m-p/18417#M792</link>
      <description>&lt;P&gt;Hallo Roger,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Were you able to solve this, and can you share your solution?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;</description>
      <pubDate>Fri, 26 Feb 2021 21:21:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-config-wing-to-use-cisco-ise-guestportal-redirect-url-in/m-p/18417#M792</guid>
      <dc:creator>DimiO</dc:creator>
      <dc:date>2021-02-26T21:21:00Z</dc:date>
    </item>
  </channel>
</rss>

