LAPN600 captive portal 401 errors

I have the following configuration:

  • (2) LAPN600 APs with 3 ESSID configured, one of which is a captive portal.
  • ANNUAL has the latest firmware and has been configured with this version of the firmware.
  • The captive portal is on vlan 100and firewall rules allow access to ports 80 and 443 on the address of vlan native 1 to the captive portal landing page.

I discovered a problem where the user receives an "unauthorized 401 - Access denied" error immediately after the connection, trying to load the captive portal landing page.  This happens on all types of devices (Windows, Andorid, iOS).

I don't think that it's a firewall rule because it is able to load the page with the error 401.  There seems to be an internal bug in the AP, rejecting clients without any apparent reason.  This happens on the two Access Points in the building.  I made a screenshot of the error packets and see that the device performs a normal redirect:

597 54.008251 10.1.100.146 10.1.0.3 627 GET HTTP /portal/signup.cgi?client_mac=ccfa00e9a571&sessionid=128e2d1284&url=http://connectivitycheck.gstatic.com/generate_204 HTTP/1.1

and a 401(k) is returned:

602 54.021614 10.1.0.3 10.1.100.146 66 HTTP HTTP/1.1 401 Unauthorized (text/html)

When I roam between access points, I have to authenticate again to launch page which should, however, about 50% of the time when I roam, I get this 401 when you try to load the page of launch of the new access point.

Any help is appreciated.

Thank you!

I recommend that the captive portal be on VLAN1 there is a known issue with having it on a default VLAN.

Tags: Linksys Products

Similar Questions

  • Need help, troubleshooting a LAN hotel (captive portal)

    This problem is not specific to Firefox, but I'm trying to see how I can use Firefox debugging features to solve a network problem. I stay in a hotel in China that uses a so-called "captive portal" to authenticate individuals before using the network. (This means that his first action navigation is redirected to the web page of the hotel for entering login information - as is often done in cafes, etc.). Using my own laptop, the redirect works if I use wifi and fails if I use the network cable (Firefox and IE both give the same result). I want my PC to work in both cases (and, in fact, it worked the day before by using a network cable to another location in the same hotel chain, which also uses what seems to be the same system of redirection). The hotel staff showed me that a PC provided by the hotel will work with the cable. So from their point of view, something is wrong with my PC, and from my point of view, something is wrong with their network. I need to know who he is.

    I enabled HTTP logging in Firefox on my PC. I noticed a cycle of GET requests where a URL has been hardcoded URL several times (so ':' becomes '% 3A', which becomes 'a 253% ', then '% 25253A', etc.). For GET requests get longer before reaching a limit, I guess... the end result being an error '400' ('bad request'). Because their servers are initially redirects, I can only assume they have a bug causing this repetitive URL encoding. But, mysteriously, the PC provided by the hotel does not have the problem (and neither does my PC when using wifi). As far as I know, Firefox and IE both fail in case of failure, and both are successful in the case of success, then I do not suspect the browser.

    My goal is to fix my system (if that is where the fault lies) or show the hotel staff which is the fault in their network (by demonstrating that the fault can occur even without my PC being involved). Effort on the PC provided by the hotel of troubleshooting is limited by the fact that, once authentication succeeds, I can't induce it expires, so I can't experiment a lot with the mechanism of redirection using this PC. Any ideas?

    Try this: go to your Control Panel then network and sharing Center then click on change settings card on the left side. Right click on your Ethernet-> properties, and then select internet protocol version 4-> properties and click on obtain an ip address automatically and obtain dns server automatically.

  • How can I set up an automatic connection with the captive portals on iOS?

    My public library has a system called Wi - Fi Spot, which requires that employers use their library card number and pin code to connect. They enter this information the first time they connect, and expect that the BONE will retain this information for the next time, they connect. This isn't. I understand that this WiFi configuration uses what is called a captive portal as a front end of connection. My question is, how do I configure the operating system to maintain login information?

    You have activated and completed Autofill? Settings > safari > AutoFill >

    How about you try settings > safari > passwords and by adding an entry for the portal. Assuming of course he has a static URL.

    If you read this manual for iOS Apple's Safari, it seems that Safari will respond to an offer/suggestion by a Web site, but does not have to remember a username or password otherwise. I guess the "when prompted" is a reaction of Safari to a website, not the other way around.

    I also would not assume that their portal invites you to register a user name. As I understand it in web programming, it is not a given.

    FWIW, my library has a similar sign in the program installation, but with their check boxes to remember my user name and PIN code. He worked for 4 weeks and then resets. When asked, they say it's a safety thing.

  • Comcast has a new IO program to solve the problems. It displays a 401 error code and will not install

    Comcast is offering a new PROGRAM to solve the problems of internet connection called.  My computer it does not open.  An said Comcast error code 401 error code.  Does anyone have an idea why it won't work?

    What internet connection problems that you think you are EasySolve of Comcast could correct?

    Related...

    http://www.broadbandreports.com/forum/r27178355-Comcast-EasySolve-

  • [SPA3102] SIP recording every hour with the 401 error and directly 12 OK

    Location: INET-ADSL modem in bridge mode-SPA3102.
    Problem: not really, everything seems to work, can dial in and out.
    But...
    Because I'm curious, I have a logserver of installation and checked what happened every hour of registration.

    What I see in the syslog hourly the 3102 made re - enroll by the SIP provider, but first I think 401 Unauthorized een 12 error and measured, I see an OK message.

    Seems weird to me.

    The same thing happens when I compose, firstly a 401 that OK.

    Can someone explain why the first attempt gives an error and how to avoid this?

    Some details of syslog:

    I replaced a text in the syslog:

    x.x.x.x is real My outside IP address.
    yyyyyyyyy = my local phone number including the area code, such as 31201234567, 31 = NL, 20 = codeZone for Amsterdam
    username = username by my SIP provider

    message 1:
    REGISTER SIP:SIP.poivy.com SIP/2.0
    Via: SIP/2.0/UDP x.x.x.x:5060; direction = z9hG4bK-2283ef7b
    From: + 31yyyyyyyyy ; tag = c85fff819484d288o0
    To: + 31yyyyyyyyy
    Call ID: [email protected]

    CSeq: 6104 REGISTRY
    Max-Forwards: 70
    Authorization: Digest username = "username", realm = "sip.poivy.com", nonce = "1663445546", uri = "sip:sip.poivy.com", algorithm = MD5 response = "c8c5b94c384559bb490b59b72be1c674"
    Contact: + 31yyyyyyyyy ; expires = 3600
    User-Agent: Linksys/SPA3102-3.3.6(GW)
    Content-Length: 0
    Allow: ACK, BYE, CANCEL, INFO, INVITE, NOTIFICATION OPTIONS, see
    Support: x-sipura

    Message 2:
    SIP/2.0 401 Unauthorized
    Via: SIP/2.0/UDP x.x.x.x:5060; direction = z9hG4bK-2283ef7b
    From: + 31yyyyyyyyy ; tag = c85fff819484d288o0
    To: + 31yyyyyyyyy
    Contact: sip:x.x.x.x:5060
    Call ID: [email protected]
    CSeq: 6104 REGISTRY
    Server: (very nice Sip Registrar/Proxy Server)
    Allow: ACK, BYE, CANCEL, INVITE, REGISTER, OPTIONS, INFO, MESSAGE
    WWW-Authenticate: Digest realm = "sip.poivy.com", nonce = "1667015687", algorithm = MD5
    Content-Length: 0

    Message 3:
    REGISTER SIP:SIP.poivy.com SIP/2.0
    Via: SIP/2.0/UDP x.x.x.x:5060; direction = z9hG4bK-4d7052c
    From: + 31yyyyyyyyy ; tag = c85fff819484d288o0
    To: + 31yyyyyyyyy
    Call ID: [email protected]

    CSeq: 6105 REGISTRY
    Max-Forwards: 70
    Authorization: Digest username = "username", realm = "sip.poivy.com", nonce = "1667015687", uri = "sip:sip.poivy.com", algorithm = MD5 response = "46f2176652c0ad8d27f8d3ad1cf72c24"
    Contact: + 31yyyyyyyyy ; expires = 3600
    User-Agent: Linksys/SPA3102-3.3.6(GW)
    Content-Length: 0
    Allow: ACK, BYE, CANCEL, INFO, INVITE, NOTIFICATION OPTIONS, see
    Support: x-sipura

    Message 4:
    SIP/2.0 200 Ok
    Via: SIP/2.0/UDP x.x.x.x:5060; direction = z9hG4bK-4d7052c
    From: + 31yyyyyyyyy ; tag = c85fff819484d288o0
    To: + 31yyyyyyyyy
    Contact: + 31yyyyyyyyy ; expires = 3600
    Call ID: [email protected]

    CSeq: 6105 REGISTRY
    Server: (very nice Sip Registrar/Proxy Server)
    Allow: ACK, BYE, CANCEL, INVITE, REGISTER, OPTIONS, INFO, MESSAGE
    Content-Length: 0

    @hw: thank you for your tip and your right on the spot!

    Never, ever, thought of this way of "logging" in a system and use delberatley an error response. With your tip, I thought that allows to read the RFC and found RFC 3665. This RFC describes the Protocol SIP basic call flow. And there he was, almost at the beginning of the real story on page 5! The protocol uses a command register which gives a message of 401 error back just to be sure to avoid security problems "man in the middle" (if I understand correctly). He present a challenge and you the answer to a totalizer new order including your answer on the challenge. Which will lead to an OK return the message.

    To resume: nothing weird, it is as expected. My curiosity is frankly satisfied. Another day with what I've learned something. Thank you.

  • Over the Air (OTA) authentication .htaccess .htpasswd 401 error

    Hello

    I have a signed application for Blackberry build against v4.7 OS and OS v4.2.

    I've successfully installed on a site to download OTA (file .jad + individual .cod files).

    User can download and install via the web link.

    The problem is I'm trying to set up basic with .htaccess authentication so that users are required to enter a username and password defined on server in .htpasswd or equivalent. It works on the emulator with MDS and on at least one device (a Verizon Wireless Tower).

    I can't make it work on phone my client or my Verizon Wireless Storm.  It fails with "error 401: Unauthorized Access."   I have full access, to the server and all newspapers.

    My .htaccess file is:

    AuthUserFile 
    AuthGroupFile /dev/null
    AuthName 
    AuthType Basic
    
    AddType text/vnd.sun.j2me.app-descriptior jad
    AddType application/java-archive jar
    AddType application/vnd.rim.cod cod
    
    
    require valid-user
    
    

    Issues related to the:

    1 .htaccess is located in a parent directory of real .jad and .cod files.  I think it's ok.  I tried putting the .jad and .cod with no change .htaccess files.  Is this ok for .htaccess in a directory parent?

    2. is it possible to change the basis of Digest authentication?

    3. why 401 error, I checked several times passwords?

    4. is there anything else I should try in the above .htaccess file?

    Please notify.

    -Sincerely, David

    They use the Internet browser on the BlackBerry Internet Service.

    When you use the Internet browser requests can pass through a number of different servers.  This means that the request to download your JAD file, and individual files of COD could come from different servers in the pool.  But as authentication would receive only with the first request therefore a 401(k) for the following applications.  There are two ways you can work around this problem.

    1. password protect your JAD file and leave the COD files without protection.

    2 use a HTTPS connection.  This translates all connections you through the same server.

  • Captive portal AP541-N?

    Hello

    I was reading a lot of previus discussions, but I still understand if I can do it!

    I don't know that "HTTP redirect" can be used to send to the external web site, but I can use that authentication?

    If it is not possible, can I use this access point in some controller?

    Thanks in advance.

    .

    Hello

    I also wanted to add that compared to the WAP121 and the WAP321 that only the WAP321 takes in charge the captive portal and not the WAP121 but they cluster always between them well when you run a certain firmware (do not know if they are released with a newer firmware that already has cluster option or not). Links to the form below if you would like more information on these products. So if you were wanting to buy an AP for the captive portal the WAP321 would be the way to go.

    WAP121: http://www.cisco.com/en/US/prod/collateral/wireless/ps5678/ps12236/ps12250/c78-697404_data_sheet.html

    WAP321: http://www.cisco.com/en/US/prod/collateral/wireless/ps5678/ps12237/ps12249/c78-697406_data_sheet.html

    Hope that helps out.

    Thank you
    Clayton Sill

  • WAP321 - captive portal in 2 VLAN different

    Hello

    I have a Wap321 installed in my network.  IP: 192.168.0.36 - VLAN 1

    If I'm in the local network, I don't have any problem to use the wireless.

    I just added a guest VLAN for people who need to connect Internet, without access to the network. So I install a second SSID and label with vlan 50. I can access the Internet.  But if I want to active the captive portal, I can't access it because the address is in the VLAN 1 (or 192.168.0.36).

    How can I configure my Wap321 having the captive portal in the VLAN 50, and not in the VLAN 1?

    Thank you

    Alex

    Hi Alexander,.

    For interVlan on ISA5510 setting, yes the same security settings is the first step to enable this function runs. This article will help you configure InterVlan routing.

    https://supportforums.Cisco.com/thread/2035882

  • WAP321 captive portal - impossible to set up the guest network connection

    Hello community.

    I use two WAP321 with the latest Firmware (1.0.6.2) in a cluster.

    Both are connected to a switch SG300-10 (FW: 1.4.1.3) in Mode of L3.

    The switch is connected to a router RV130 (FW: 1.0.2.7).

    The router has Inter-VLAN-routing active and static routes for my VLANS configured.

    To one of the Interfaces of the router is a connected DNS/DHCP server that manages the resolution of names and the dynamic distribution of IP4 for my network.

    In my network, I have different VLAN for customers, management, server, test and the WLAN clients.

    So far so good.

    I have install on the WAP321 cluster, an intern (VAP0) and a guest WLAN (VAP1) using the Setup Wizard.

    Delivery of DHCP and DNS lookups are ok for two wireless LANs.

    Settings WAP VLAN and IP4 address are:

    -untagged VLAN: enabled

    -untagged VLAN ID: e.g. 3

    -Management VLAN ID: the same without tag VLAN ID

    -IPv4 parameters are static in the ip range of the VLAN untagged

    -DNS server are set to manual for a server in VLAN 4 and to 8.8.8.8

    My problem is that I can connect to the WLAN comments but I never get the captive portal login screen.

    The First-Instance Association captive portal is set to VAP1.

    The Configuration of the Instance in captivity 'Vérification' is located in the local.

    A group and users are configured.

    The customer obtain an IP address in the host IP address range VLAN and can search names and IPS, e.g. www.cisco.com.

    If I try to open a Web site, and then I get the message that the server did not respond.

    Impatience on your part.

    Best regards

    Rainer.

    That's great. I'm glad to hear that.

    Eric Moyers

  • Captive portal RV120W?

    Hi all

    Not sure if I'm posting this in the right way/area so sorry if I'm wrong.

    Anyone know if there is anyway to run the captive portal on Cisco RV120W?

    I have multi sites and launch it on the RV180W to one and have a site with RV120W and would like to mirror the site of 180.

    Any help would be much appreciated.

    Thank you.

    Captive portal is not supported on RV120W or RV220W.

  • captive portal url that refers to a domain name

    in a pilot project, during the setup of initial installation ISE, I configured a local domain. After installation, I then changed to use a domain name business resolved by the DNS server in the company, but even if the console accepts the new domain and the ISE GUI shows the new correct FQDN, I have problem with captive portal page resolution because the redirect url created automatically by the ISE for the CWA are still called the ISE with the old domain used in the initial configuration thus creating a problem to resolve the url.

    The only reason I can think, present at the client cert is always composed the old FULL domain name. As we changed the domain name, you must generate a new certificate and install it on the ISE so that CN must match the new FULL domain name.

    Jatin kone
    -Does the rate of useful messages-

  • Captive portal AnyConnect

    Is there a way to disable this feature?

    I have a client with only a single IP address. Port 443 SSL for a web server, so Anyconnect SSL is now listening on a different port.

    When we changed the port and updated the profile of the customer, the customer think that now he is a captive portal inbetween and requires the user to authenticate first via web. This works very well but is now add this extra step to the process connection.

    I don't understand why Anyconnect (knowledge of the profile that the VPN client is on a different port) is still visibly looking to 443.

    Here, any help would be appreciated.

    You specify the port in the profile but if you change the port you must specify this in the client too.  By default, client AnyConnec will go to 443: here's an example.

  • 401 error after you deploy for stand-alone WLS

    I use JDev 12.1.3 on Windows 7 Pro

    My app has been migrated to 10g, 11 g to 12 c. He had a guarantee of manufacture which has been replaced by ADF security.

    I have it on my integrated WLS but after deployment to standalone WLS I get 401 - error not allowed after connection through OAM.

    I checked the server logs and don't see any error. The sys admin looks at some other newspapers but nothing concrete yet.

    The app has 26 roles of the company and my login has 5 assigned roles. Some business roles have been defined as Active Directory groups. I tried to check if the roles are case sensitive, but who has not found in textbooks again. Ad groups do not match the case of the roles defined in jazn-"Data.xml".

    Any suggestions on what and where to look is greatly appreciated.

    One suggestion is to remove all business roles and try to make it work with a single role. I intend to try this.

    Thanks in advance!

    Dave

    We found that the question. Business roles are case-sensitive. Windows administrator define groups of ads as of breaks. Jazn-"Data.xml", I made the business roles are all uppercase. Evolution of business roles jazn-data to match fixed the issue ad groups.

  • You receive a 401 error when I try to visit a web site.

    OK, so I got 401 erro on a site that I love, my tone brother must have made "make me crazy", invites order because he went to the high guest it was calculated, any help on the release of this site. I already checked my Systems32 file host and nothing up there. Any help, everything is greatly appreciated.

    original title: error 401, need help

    Hello Forev4r, game

    What internet browser do you use?
    Do all other programs that use the internet work?
    The simplest solution I try everything first is a system restore to before you think that something has changed:
  • 9.4 - default schema Portal installation error must be dbo

    I want to install Cisco Service Portal 9.4 and get the error "prior database Test Failed - the default schema must be 'dbo.

    I checked SQL server and the RCUser has a default schema of dbo.  This is a new installation of SQL server standard edition on a separate server.  Where should I look for the default schema?

    Hello Michael,

    I hope that you have defined RCUser as dbowner according to your 3rd image. "The database role membership for:"

    same as Datamart.

Maybe you are looking for

  • Photosmart HP 6520: Print spooler

    I was able to print from my phone (Samsung Galaxy s7) without problem on several different HP using the card of HP printers in. In the last three weeks, I get the message that has not stopped the print spooler. I took the plug stop, off, reinstalled,

  • Need help with the AMD Radeon HD M 8750 + HD 8000 Series Dual Graphics

    I recently bought the 15z-j000 ENVY and updated with the AMD Radeon HD M 8750 + HD 8000 Series Dual Graphics. I wanted the dedicated HD 8750 M for games and whatnot. When I opened first to the top of my new laptop, I did a clean install of Windows 8

  • Acer Iconia W700 - slight delay in contact after inactive for more than 5 seconds

    I upgraded the OS 8 Win provided with the tablet to Win 8 Pro and since then, I have a slight delay in recognition touch screen after the Tablet is idle for more than 5 or more seconds. As a result, I have to type something twice before it responds.

  • updates Windows vista failed

    I tried assistance from microsoft support about my updates failed. SOME are major, some are recommended. I can't get an answer from someone. I consulted with HP, the manufacturer, but they no longer support Vista either. I'm at my wits end. Someone p

  • installation of unknown device causing vista freeze

    For these last days, I get this notification in windows vista: ---------------------------------------------------------------------------------------------------- NEW HARDWARE FOUND WINDOWS NEEDS TO INSTALL DRIVER SOFTWARE FOR YOUR UNKNOWN DEVICE *