Security

 View Only
Expand all | Collapse all

Wireless users keep looping back to Captive Portal page.

This thread has been viewed 42 times
  • 1.  Wireless users keep looping back to Captive Portal page.

    Posted Apr 02, 2025 09:29 AM

    Hello, I have question regarding the Clearpass Captive Portal.

    Wifi users at one of our sites aren't connecting to the internet after logging into the Captive Portal, they keep looping back to the Captive Portal page.

    If they Click on the SSID a second time however, they do connect to the internet. The same thing happens on both iPhones and Windows laptops (we didn't have any androids to test).

    We tried putting the Google.com URL in the default internet page, but it hasn't made any difference. We've checked the Registration page but can't see what might be causing it. 

    Has anyone seen this before?

    Many thanks

    PB



  • 2.  RE: Wireless users keep looping back to Captive Portal page.

    Posted Apr 02, 2025 10:19 AM

    What type of APs are used? In most cases the post to the AP/controller portal is not successful. Is the right address configured in the ClearPass guest page?

    Do you see any errors in the access tracker for the device/user?



    ------------------------------
    Willem Bargeman
    Systems Engineer Aruba
    ACEX #125
    ------------------------------



  • 3.  RE: Wireless users keep looping back to Captive Portal page.

    Posted Apr 02, 2025 11:51 AM

    Hi Willem,

    we're using AP505s. It's a new SSID but most of the configs were copied from one at another site, which is working fine. At first, users weren't even being re-directed to the Captive Portal so we checked the  Clearpass and Central and fixed that. The correct addresses are on the CP registration page.

    We disabled the 'Enhanced Open' function on Central and added the https to the SSID's  Pre-authentication role. The Access Tracker shows the users being re-directed to the Captive Portal and it looks ok but they keep looping back to it. We checked the 'Delay Login' timer and it's set to '0' so we're not sure why it's happening.




  • 4.  RE: Wireless users keep looping back to Captive Portal page.

    Posted Apr 02, 2025 02:29 PM

    Is this an InstantAP or AOS10 setup? Are the RADIUS servers configured in the AP configuration and are the AP IP addresses added to ClearPass? Please also check for any error in the ClearPass Event Viewer.



    ------------------------------
    Willem Bargeman
    Systems Engineer Aruba
    ACEX #125
    ------------------------------



  • 5.  RE: Wireless users keep looping back to Captive Portal page.

    Posted Apr 03, 2025 06:44 AM

    Hi Willem,

    it's an AOS8 setup. I have access to the Central UI but I need to arrange remote access to the Clearpass. I am going to check the Event viewer as you suggested and do a sanity check on the certificates. I'll post an update in here.

    Many thanks




  • 6.  RE: Wireless users keep looping back to Captive Portal page.

    Posted Apr 03, 2025 05:57 AM

    Hi @Burnside

    Check the certificates for affected side. You can also look into Clearpass logs under Guest / Administration / Support / Application Log for clues.

     Best, Gorazd



    ------------------------------
    Gorazd Kikelj
    MVP Guru 2025
    ------------------------------



  • 7.  RE: Wireless users keep looping back to Captive Portal page.

    Posted Apr 03, 2025 06:47 AM

    Thanks Gorzard,

    getting the logs is one I haven't done yet. I'm also going to check everything on the Clearpass again, including the certificates and addresses because I might have missed something.

    I'll keep you updated.

    Many thanks

    Paul




  • 8.  RE: Wireless users keep looping back to Captive Portal page.

    Posted Apr 03, 2025 06:52 AM

    Hi @Burnside

    Please also check certificates on APs. In many cases the problem lies there.

    Best, Gorazd



    ------------------------------
    Gorazd Kikelj
    MVP Guru 2025
    ------------------------------



  • 9.  RE: Wireless users keep looping back to Captive Portal page.

    Posted Apr 07, 2025 05:26 AM

    Hi @Burnside,

    did I get it right: on the first connection the users can successfully authenticate in the captive portal, but after logging in they return to the login page. On the second connection, there is no captive portal redirection and the users have immediate access to the Internet?

    In this case you need to check the role mapping and enforcement in ClearPass. 

    It looks like on the first WLAN connection, ClearPass enables MAC address caching for the endpoint, but sends an Aruba user role to the controller that does not exist there or was misspelled. This is the User Authentication Service. The user remains in the preauthenticated role and returns to the captive portal. For the second WLAN connection, the MAC address authentication service is matched. The client is authenticated by MAC address caching, here ClearPass sends correct postauthenticated role and the user gets Internet access.



    ------------------------------
    Regards,

    Waldemar
    ACCX # 1377, ACEP, ACX - Network Security
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 10.  RE: Wireless users keep looping back to Captive Portal page.

    Posted Apr 07, 2025 05:43 AM

    Hi Waldemar,

    yes that's correct, the users keep looping back to the Captive Portal page instead of connecting to the internet (after logging in). Weirdly however, if they click on the SSID a second time - it does connect to the internet.

    We are still having the issue but i have a remote call with them this afternoon to look at the Clearpass.  I'll check the Role Mapping as you suggested because I didn't do that last time and that could well be the issue. I'll get back to you and let you know how it goes later on today.

    Many thanks

    Burnside




  • 11.  RE: Wireless users keep looping back to Captive Portal page.

    Posted Apr 08, 2025 06:14 AM

    Hi Waldemar,

    just a quick update for you. The problem is still ongoing but TAC support have had a look at it. They checked the Clearpass configs, including the Role mapping and the Central VC's configs but couldn't identify the cause. They've taken a packet capture and I'll provide an update once I have something.

    Many thanks for your help.




  • 12.  RE: Wireless users keep looping back to Captive Portal page.

    Posted Apr 08, 2025 07:24 AM

    Hi Burnside, I see.
    Can you check the Aruba user roles in the WLAN?
    First WLAN connection, the client gets stuck in the captive portal.

    Which Aruba user role does the client have after the first WLAN connection? 
    Which Aruba user role does ClearPass send? Does this Aruba user role exist in the WLAN controller? Controllers interpret the role name case-sensitively.

    Second WLAN connection, the client receives Internet access immediately, without redirection to the captive portal.
    Which Aruba user role does the client have after the second WLAN connection?
    Which Aruba user role does ClearPass send?



    ------------------------------
    Regards,

    Waldemar
    ACCX # 1377, ACEP, ACX - Network Security
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------