What you'll need
- Admin access to your Cisco Catalyst 9800 Wireless LAN Controller (WLC)
- If using the recommended setup: admin access to Cisco Identity Services Engine (ISE), plus network connectivity from MyWiFi's servers to your ISE server on port 9060 (HTTPS) — this normally means a site-to-site VPN or an ISE node placed in a DMZ, since ISE is not internet-facing in most deployments
- A dedicated ISE Sponsor account with REST API access — your regular ISE admin login will not work for this integration
- If you'd rather skip ISE entirely, a simpler (but less capable) setup is available directly on the WLC — see step 5
Steps
- Recommended: with ISE. On the WLC, create an open guest SSID with MAC Authentication Bypass (MAB) enabled, and configure ISE as its RADIUS server for both authentication and accounting. In ISE, add the WLC as a Network Access Device and enable Change of Authorization (CoA) — this is what lets ISE grant a guest internet access after they finish the MyWiFi login screen.
- In ISE, create an Authorization Profile with Web Redirection set to Centralized Web Auth, pointing at your MyWiFi portal URL, along with a Redirect ACL on the WLC that allows DNS/DHCP and blocks direct access to ISE while allowing general web traffic through.
- In ISE, create a dedicated internal user (for example,
mywifi-sponsor) and add it to a Sponsor Group with "Allow REST API" turned on — do not use a standard ISE admin account, Cisco's ISE design blocks admin credentials from creating or approving guest accounts. Note the sponsor portal's ID, which you'll need in a later step. - Confirm MyWiFi's servers can reach your ISE server on port 9060 over HTTPS. Since ISE is rarely exposed to the internet directly, this usually requires a VPN tunnel or placing an ISE node in a DMZ — plan for this ahead of time, as it's typically the biggest blocker to getting this integration live.
- Alternative: WLC only, no ISE. If you don't have ISE, the WLC can run local web authentication instead, where guest credentials are validated by the WLC itself rather than by MyWiFi. This is simpler to set up but captures less guest data and skips MyWiFi's login/analytics features — most customers should use the ISE-based setup above if ISE is available.
- In the MyWiFi dashboard, go to Devices and click Add Device.
- Select the Location, name the device, and under Select Your Hardware choose Cisco Catalyst 9800 / ISE.
- Enter your connection details as prompted — for the ISE-based setup, your ISE server address, the sponsor account credentials from step 3, and the sponsor portal ID — and save.
Best practice: confirm CoA is fully working end to end (WLC configured as a CoA recipient, and CoA traffic not blocked by a firewall) before going live — if CoA can't reach the WLC, guests will complete the MyWiFi login screen successfully but never actually get internet access, which is a confusing failure mode to debug after the fact.
Comments
Please sign in to leave a comment.