cancel
Showing results for 
Search instead for 
Did you mean: 

Control and XIQ-C: Setting Up Redirect URL for CWA?

Control and XIQ-C: Setting Up Redirect URL for CWA?

ttichi
New Contributor

Hello, Community,
I am currently struggling with configuring a CWA (Captive Portal) setup using XIQ-C and Control, and I could really use some help.

Requirements:

XIQ-C :E1120 10.10.02
XIQ-SE&control :24.7.11.22 

1. Clients connect to the SSID using EAP-TLS authentication.
2. After that, they are redirected to the Captive Portal.
3. On the portal, they sign in using the "Sign in with Microsoft" button.


However, with my current configuration, clients are not being redirected to the Captive Portal after completing EAP-TLS authentication.
When I tested the radiusd in Control, EAP-TLS completes successfully, but the Access-Accept packet does not include parameters like a redirect URL.

Looking at the End-Systems tab:

Under [Authorization], it shows:
「Filter-Id='Enterasys:version=1:policy=Unregistered', Login-LAT-Port='0'.」
スクリーンショット 2025-01-16 114417.png
For [Engine] -> [RADIUS Attributes to send], I haven’t manually configured anything, but [Extreme IdentiFi Wireless] is selected (this seems to be the default setting).

I understand that Login-LAT-Port='0' is a parameter interpreted by XIQ-C and is assigned to users who haven’t fully authenticated yet.
The policy=Unregistered setting is associated with a redirect service, which is enabled.
ACE_Policy_Domain.png
From my understanding, this should result in the client being redirected to the Captive Portal, but it is not working as expected.

3 REPLIES 3

ttichi
New Contributor

hi James-san

Upon checking, I found that a similar configuration is also present in the rules on XIQ-C.
I believe this configuration was pushed via policy enforcement from XIQ-SE/Control, which manages XIQ-C.
Or is it necessary to create a separate rule for proper interpretation in this case?
As far as I remember, if a rule is created within XIQ-C, it gets overwritten when enforced by SE.
Even in this case, should I create the rule on the XIQ-C side?

James_A
Valued Contributor

The XIQ-C documentation (p154 of the second link) says that there's a hidden role generated on XIQ-C, maybe check that it looks OK. It's slightly different to how it was done on Identifi which is what I had experience with.

GTM-P2G8KFN