Hi Burnside, I see.
Can you check the Aruba user roles in the WLAN?
First WLAN connection, the client gets stuck in the captive portal.
Which Aruba user role does the client have after the first WLAN connection?
Which Aruba user role does ClearPass send? Does this Aruba user role exist in the WLAN controller? Controllers interpret the role name case-sensitively.
Second WLAN connection, the client receives Internet access immediately, without redirection to the captive portal.
Which Aruba user role does the client have after the second WLAN connection?
Which Aruba user role does ClearPass send?
------------------------------
Regards,
Waldemar
ACCX # 1377, ACEP, ACX - Network Security
If you find my answer useful, consider giving kudos and/or mark as solution
------------------------------
Original Message:
Sent: Apr 08, 2025 06:13 AM
From: Burnside
Subject: Wireless users keep looping back to Captive Portal page.
Hi Waldemar,
just a quick update for you. The problem is still ongoing but TAC support have had a look at it. They checked the Clearpass configs, including the Role mapping and the Central VC's configs but couldn't identify the cause. They've taken a packet capture and I'll provide an update once I have something.
Many thanks for your help.
Original Message:
Sent: Apr 07, 2025 05:25 AM
From: Lord
Subject: Wireless users keep looping back to Captive Portal page.
Hi @Burnside,
did I get it right: on the first connection the users can successfully authenticate in the captive portal, but after logging in they return to the login page. On the second connection, there is no captive portal redirection and the users have immediate access to the Internet?
In this case you need to check the role mapping and enforcement in ClearPass.
It looks like on the first WLAN connection, ClearPass enables MAC address caching for the endpoint, but sends an Aruba user role to the controller that does not exist there or was misspelled. This is the User Authentication Service. The user remains in the preauthenticated role and returns to the captive portal. For the second WLAN connection, the MAC address authentication service is matched. The client is authenticated by MAC address caching, here ClearPass sends correct postauthenticated role and the user gets Internet access.
------------------------------
Regards,
Waldemar
ACCX # 1377, ACEP, ACX - Network Security
If you find my answer useful, consider giving kudos and/or mark as solution
Original Message:
Sent: Apr 03, 2025 06:51 AM
From: GorazdKikelj
Subject: Wireless users keep looping back to Captive Portal page.
Hi @Burnside
Please also check certificates on APs. In many cases the problem lies there.
Best, Gorazd
------------------------------
Gorazd Kikelj
MVP Guru 2025
Original Message:
Sent: Apr 03, 2025 06:47 AM
From: Burnside
Subject: Wireless users keep looping back to Captive Portal page.
Thanks Gorzard,
getting the logs is one I haven't done yet. I'm also going to check everything on the Clearpass again, including the certificates and addresses because I might have missed something.
I'll keep you updated.
Many thanks
Paul
Original Message:
Sent: Apr 03, 2025 05:57 AM
From: GorazdKikelj
Subject: Wireless users keep looping back to Captive Portal page.
Hi @Burnside
Check the certificates for affected side. You can also look into Clearpass logs under Guest / Administration / Support / Application Log for clues.
Best, Gorazd
------------------------------
Gorazd Kikelj
MVP Guru 2025
Original Message:
Sent: Apr 02, 2025 09:28 AM
From: Burnside
Subject: Wireless users keep looping back to Captive Portal page.
Hello, I have question regarding the Clearpass Captive Portal.
Wifi users at one of our sites aren't connecting to the internet after logging into the Captive Portal, they keep looping back to the Captive Portal page.
If they Click on the SSID a second time however, they do connect to the internet. The same thing happens on both iPhones and Windows laptops (we didn't have any androids to test).
We tried putting the Google.com URL in the default internet page, but it hasn't made any difference. We've checked the Registration page but can't see what might be causing it.
Has anyone seen this before?
Many thanks
PB