Cisco ISE Guest Portals with Ruckus SmartZone

Ruckus SmartZone 7.0 and later support a new RADIUS VSA (Vendor Specific Attribute) for dynamic URL redirection. This means that Cisco ISE can integrate with SmartZone Controllers just like Cisco WLCs and Meraki APs. 

The ISE built-in RuckusWireless NAD profile must be duplicated and modified to use Ruckus-External-Url VSA for the $URL variable. ISE will dynamically insert the PSN FQDN and portal port number during authorization. Ruckus also supports pushing an ACL name via RADIUS from the standard RADIUS Filter-ID attribute. SmartZone also now supports CoA for URL redirection once the client successfully logs into the ISE portal.

Ruckus-EXTERNAL-URL VSA


Filter-ID ACL

Once the NAD profile is modified and applied to the NAD definition for a Ruckus Controller, the ISE guest rules can be built out just like you normally would for any Cisco NAD. 

On the Ruckus SZ side, the ACL must be configured to allow DHCP, DNS, and access to the ISE nodes. An open/OWE SSID with MAC filtering should be configured with no captive portal, web-auth, or WISPr options. RADIUS responses will provide the portal URL. 

Map the ACL to a Firewall Profile and map the Firewall Profile to the WLAN. Create a User Traffic Profile Mapping and type the Group Attribute Value (GAV) to match exactly the filter-id attribute being sent from ISE in the authorization profile.


Comments

Popular posts from this blog

Fix Cisco ISE Messaging Service

ClearPass MPSK per Device Type with Profiling

Cisco Designated VIP 2024