<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D50Z00008C3jZdSAJOkta Classic EngineSingle Sign-OnAnswered2025-12-14T09:00:23.000Z2016-05-27T04:01:41.000Z2018-11-09T00:21:03.000Z
IWA with Guest Wifi Network
Hi,

 

We have come across a problem in a few different Okta setups now where they have IWA configured.  If the guest wifi network gets NATed through the same external IP as the internal network, then laptops will not be able to log into Okta.  Mobile devices are fine becasue Okta can detact them and not redirect.  Laptops on the internal wifi are fine as they can reach the IWA agents.  The problem is for partners who are trying to reach Okta protected applications while on site and there for using the wifi.

 

I've had a couple of ideas on how to fix this but none of them are 100% desirable.  Does anyone have any better ideas?  I'm sure there are better ways of doing this.

 

Thanks,

Tom

lkcfn, j5v7c, and 4 others like this.
  • j5v7c (j5v7c)

    This is a very good question as we have the same type setup and issue
  • Parth Swadas (Customer)

    We have similar issue. Since guests are connected to external network, they never reach internal IWA server.

     

    /Parth
  • MikeS.77767 (Customer)

    Posting to say same issue here. It would be nice to have the ability in app authentication policies to say "if User/group=x, then athenicate via=loginpage, IWA, or etc..)
  • svpz0 (svpz0)

    We have the exact same issue and so far do not have any good way to address this. We had to turn off desktop SSO because of issues with our guest networks. I wish Okta would give this issue more attention.
  • hv0kl (hv0kl)

    We have this problem too.  Over 100 locations now need a different IP for our guest wifi - and some can only have one.  I'd like to see the public DNS for our IWA server point back to Okta. A cookie could be dropped on the browser before redirect and if there when they end up back at Okta, it could tell them what's going on. (customer/destination, etc)
  • BradB.13033 (Customer)

    Adding to the thread.  100 sites, 100 internal LAN's that work great.  100 guest wifi's SSIDs that route out through the same Public IP.  They cannot authenticate to the IWA and it times out.  Maybe a timeout of 5 seconds, would say, I clearly can't connect to IWA, let's authenticate as off-net with MFA.
  • jermm (jermm)

    I have the same problem, I've solved with the solution 2 (

    Have the DNS on the guest network direct https://desktopsso/iwa to another web server that redirects to https://company.okta.com/login/default - needs split DNS and a web server to maintain) but it's not the best and I hope that Okta will improve the javascript logic in order to handle case like this
  • BradB.13033 (Customer)

    We received a "by design" response. Our solution was to add static 2+ (5 is standard) static IPs to each out our circuits. Given we have 100+ circuits across the United States it was a little bit of a project on the ISP side of things.

    Once those IPs were issued and our main WAN1 IP was updated, we simply took a second public IP and NATed (through the Virtual IP Config) the Public traffic policy through it. That was the easy part.

     

    Now, our LAN/Private wifi traffic NATs through 1 public ip that is is on the Okta list and the Public traffic NATs through 1 ip that is NOT on the Okta list.

     

    Hope this helps.

    Expand Post
10 of 13
This question is closed.
Loading
IWA with Guest Wifi Network