Add the Redirect Step to the Workflow

This section describes how to create a redirect step to the enrollment workflow to allow Cloudpath to accept an inbound connection request from the WLC, redirect the user to an Cloudpath-managed captive portal, and provide the onboarding process.
  1. Navigate to Configuration > Workflow.
  2. Select your passthrough workflow configuration.
  3. In the workflow, insert the redirect step.
    Note: In this example, the redirect occurs after the user accepts the AUP. However, the redirect step can be placed anywhere in the enrollment workflow.
  4. The workflow plug-in selection page opens.
  5. Click Redirect the User.
  6. Select Use a new redirect and click Next. The Create Redirect page opens.

    Create Redirect

  7. Enter the Reference information for the Cisco WLAN passthrough.
  8. Enter the Redirect URL in this format:
    ${switch_url}?buttonClicked=4&redirect_url=https://<redirect_website>/enroll/<your_Account>/Production/submit-redirect
    Note: The first part of this URL (${switch_url}?buttonClicked=4&redirect_url)takes the inbound request from the WLC and opens the firewall. The second part of this URL (https://<redirect_website>/enroll/<your_Account>/Production/submit-redirect)points the user to the Cloudpath captive portal.
  9. Leave Use POST unchecked.
    Note: Cisco WLAN Controllers allow both Get and POST for the URL call, but we recommend using Get.
  10. Check the Allow Continuation box. If this is left unchecked, the submit-redirect call is ignored.
  11. If needed, configure Filters & Restrictions to control when this redirect is utilized.
    By default the redirect is applied to all users. However, you can specify a filter such that the redirect is applied only to enrollments matching the filter.
  12. Save the workflow.

In this workflow example, the WLC passes the user to the Cloudpath captive portal, to accept the AUP. The Cisco WLAN redirect opens the firewall so that the client can access Cloudpath for the onboarding process. If the user selects the guest enrollment path, the device is moved to the Guest - Internet Only: network and given a short-term guest client certificate.

Completed Enrollment Workflow with Redirect Step