Case Study: The Portal Page Cannot Be Displayed Because DNS Packets from STAs Are Not Permitted in the AC Authentication-Free Rule Profile
Symptom
In a Portal authentication scenario, the Portal authentication page is not displayed after a STA connects to the WLAN. As a result, the STA cannot access the WLAN.
Relevant Alarms and Logs
None
Cause Analysis
The DNS is not bypassed. As a result, the Portal page fails to be redirected and cannot be displayed.
Procedure
- After the IP address of the Portal page is directly entered in the browser of the STA, the Portal authentication page is displayed.
- Run the display current-configuration command on the AC to check whether basic configurations related to Portal authentication are correct.
- On the AP, check whether the Portal URL pushed by the AP is correct.
<AP> debug portal all <AP> terminal debugging <AP> terminal monitor
The command output does not contain HTTP or HTTPS packets that trigger Portal redirection.
- Run the display wsrv portal free-rule command in the diagnostic view of the AP to check the Portal authentication-free rule on the AP. The command output shows that DNS packets are not permitted.
- Check whether the authentication-free rule for Portal authentication users is configured on the AC. The command output shows that no rule is configured.
[AC] display free-rule-template configuration name test free-rule-template name test Total 0 free-rule(s)
- Configure the authentication-free rule profile on the AC to permit DNS packets from STAs.
[AC] free-rule-template name test [AC-free-rule-f1] free-rule 10 destination ip x.x.x.x mask 255.255.255.255