Wireless Access

 View Only
Expand all | Collapse all

AOS10: Cloud Guest issue - securelogin.hpe.com not being resolved (captured/redirected?)

This thread has been viewed 99 times
  • 1.  AOS10: Cloud Guest issue - securelogin.hpe.com not being resolved (captured/redirected?)

    Posted Feb 18, 2025 06:43 AM

    Hi all

    Weird issue. Have a AOS 10 group (10.7.0.2) in Central that runs a Guest SSID with Cloud Guest captive portal. It has been working as expected when users register their phonenumber to recieve a verification code. It still does, but once the code is entered and we press Verify, we get a "unresolved error" and no redirection is done of the client to our company homepage.

    The browser says its "securelogin.hpe.com" that is unresolvable. The guest login is actually completed and internet is available - the users are just confused as it seems to error out.

    Seems like the APs are not catching the DNS request for securelogin. 

    Any idea´s?



  • 2.  RE: AOS10: Cloud Guest issue - securelogin.hpe.com not being resolved (captured/redirected?)

    Posted Feb 18, 2025 01:43 PM

    Downgraded to 10.7.0.1 where it used to work, and that fixed the issue. So it seems there is a captive portal (Cloud Guest) flaw in 10.7.0.2 that does not completes the redirection for clients (and thus informs the guestdevice of its authentication succes) after the user has successfully entered the verification code (we use SMS verification required)




  • 3.  RE: AOS10: Cloud Guest issue - securelogin.hpe.com not being resolved (captured/redirected?)

    Posted Feb 18, 2025 04:03 PM

    Is the authentication completing?  When the redirect fails, can the device browse to some other page that is manually specified?



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 4.  RE: AOS10: Cloud Guest issue - securelogin.hpe.com not being resolved (captured/redirected?)

    Posted Feb 18, 2025 04:15 PM
    Edited by Keyser Mar 07, 2025 06:34 AM
    Authentication actually completes in the backend, and the client Mac-address is put in the cache for mac-auth. But the client is not notified due to the NXDOMAIN on securelogin.hpe.com, and windows/iphone then drops the connection to the SSID as it assumes it's not working.
    However, if I reconnect the device to the SSID I'm immediately auth'ed from mac-caching (no captive portal) and can browse fully as an authenticated guest.





  • 5.  RE: AOS10: Cloud Guest issue - securelogin.hpe.com not being resolved (captured/redirected?)

    Posted Feb 18, 2025 04:28 PM

    That's what I was needing to hear, thank you.

    Have you opened a case on this subject yet?



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 6.  RE: AOS10: Cloud Guest issue - securelogin.hpe.com not being resolved (captured/redirected?)

    Posted Feb 18, 2025 04:42 PM
    Edited by Keyser Mar 07, 2025 06:34 AM
    Nope - have way to many tickets open with support on dead 503 APs, other bugs and Central issues as it is. So I'll have to leave it as is for now.






  • 7.  RE: AOS10: Cloud Guest issue - securelogin.hpe.com not being resolved (captured/redirected?)

    Posted Mar 07, 2025 06:34 AM

    Hmmm, the issues has just reappered on 10.7.0.1 today, so it seems it something that happens after a while on 10.7.x for us. 

    Wondering if it could be tied to a specific AP model  or its a general issue.

    I guess I have to open a ticket now.... :-(




  • 8.  RE: AOS10: Cloud Guest issue - securelogin.hpe.com not being resolved (captured/redirected?)

    Posted Mar 07, 2025 09:30 AM

    securelogin.hpe.com is being intercepted by the DNS engine on the AP. Some commands that can be useful

    show captive-portal-domains
    show cert all > search for "Current Web UI Server Certificate". This should be securelogin.hpe.com

    Did you check the certificate usage settings in the AP group? Check the Captive portal certificate. 



    ------------------------------
    Willem Bargeman
    Systems Engineer Aruba
    ACEX #125
    ------------------------------



  • 9.  RE: AOS10: Cloud Guest issue - securelogin.hpe.com not being resolved (captured/redirected?)

    Posted Mar 07, 2025 10:11 AM

    Yeah checked all that. They are running with the default certificates and also works flawlessly for the first couple of days or weeks. Then it stops intercepting the DNS request. Then I have to reboot the AP's to get I going again




  • 10.  RE: AOS10: Cloud Guest issue - securelogin.hpe.com not being resolved (captured/redirected?)

    Posted Mar 07, 2025 11:41 AM

    That is very much something that TAC needs to look at.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 11.  RE: AOS10: Cloud Guest issue - securelogin.hpe.com not being resolved (captured/redirected?)

    Posted Mar 07, 2025 11:48 AM

    I have created a ticket, but I doubt I'll be able to follow through as I'm never onsite and have a hard time working with support on tickets that is not 100% reproducible every time.

    I will upgrade to 10.7.1.1 tonight to see if the Guest SSID connection fix in that firmware might solve the issue for us.




  • 12.  RE: AOS10: Cloud Guest issue - securelogin.hpe.com not being resolved (captured/redirected?)

    Posted Mar 31, 2025 06:41 AM

    Hi, I have guests complaining for the same issue but with email link verification. With sms OTP code everything looks fine.

    Just tried to upgrade to 10.7.1.1 and issue still persists. Opened a case this morning, I will update topic here




  • 13.  RE: AOS10: Cloud Guest issue - securelogin.hpe.com not being resolved (captured/redirected?)
    Best Answer

    Posted Mar 31, 2025 06:57 AM

    I created a ticket also, and it turned out to be a port opening towards Central (TCP 2083) that was missing in our setup. That caused the AP's to be unable to reach cloud guest radius on TCP 2083 and meant DNS redirection became non functional after a while. 




  • 14.  RE: AOS10: Cloud Guest issue - securelogin.hpe.com not being resolved (captured/redirected?)

    Posted Mar 31, 2025 07:17 AM

    Good to know, and now is working fine in your environment? Just checked but port TCP/2083 seems to be opened looking at my EdgeConnect logs for this morning




  • 15.  RE: AOS10: Cloud Guest issue - securelogin.hpe.com not being resolved (captured/redirected?)

    Posted Mar 31, 2025 11:22 AM

    "show radius-servers", make sure that the Cloud Guest servers are showing RadSec enabled and port 2083 or 443.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 16.  RE: AOS10: Cloud Guest issue - securelogin.hpe.com not being resolved (captured/redirected?)

    Posted Mar 31, 2025 11:32 AM

    Hi Chulcher,

    yes I checked from an AP and it seems fine:

    Thanks




  • 17.  RE: AOS10: Cloud Guest issue - securelogin.hpe.com not being resolved (captured/redirected?)

    Posted Mar 31, 2025 11:42 AM

    Just to double check, what about "show radius status"?



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 18.  RE: AOS10: Cloud Guest issue - securelogin.hpe.com not being resolved (captured/redirected?)

    Posted Mar 31, 2025 12:55 PM
    Edited by Gian911 Mar 31, 2025 02:08 PM

    The one on port 2083 is in "connected" status




  • 19.  RE: AOS10: Cloud Guest issue - securelogin.hpe.com not being resolved (captured/redirected?)

    Posted Aug 14, 2025 02:09 PM

    This was my issue. We were migrating from internal Captive Portal Guest being served from on-prem ClearPass. Had a certificate specified for them and update to the the "aruba_default". All things are working with succes!!

    -------------------------------------------