Security

Reply
Contributor II
Posts: 43
Registered: ‎07-01-2013

Some Androids disconnect after 2 minutes when behind Captive Portal

[ Edited ]

Hi all,

 

I've encountered an interesting behavior that apparently has existed for some Android devices since 4.3 (Jelly Bean). The issue is that some handsets, such as a Samsung Galaxy S5 from Verizon with stock ROM and Android 4.4 KitKat, will disconnect from an SSID if it is behind a captive portal for more than two minutes.

 

This introduces a significant complication in our ClearPass Onboard process, in which we are using the guest SSID to allow employees to Onboard. The use must connect, launch a browser, hit the captive portal, follow the link to Onboard, pass through our SSO provider (which uses dual factor authentication, making the process even longer), and obtain the certificates and network profile from the QuickConnect app within 2 minutes lest the client automatically disconnects.

 

I was wondering if anyone knows of anyway of tricking the device to think it is not behind a captive portal. This only seems to affect some handsets; a Samsung Galaxy S3 from Virgin Mobile running stock ROM and Android 4.4 (KitKat) did not experience the problem.

 

We are open to most suggestions, however one requirement from our security team is that we don't use PEAP for authentication, thus single-SSID Onboarding is not an option. Additinally, we are already using the "landing.php" workaround and have some sites whitelisted on the captive portal profile (adding more is an option if that might fix it).

 

Obviously this is also a problem for guests who self-register for a guest account.

 

We are running AOS 6.4.2.x and ClearPass 6.4.x.

 

Thanks for any suggestions,

Tim

Tim Haynie, ACMX #508, ACDX #384, ACCP, CWSP, CCNP R/S, CCNP Wireless, CCNA Security, CCDA, Aruba Partner Ambassador
Guru Elite
Posts: 7,837
Registered: ‎09-08-2010

Re: Some Androids disconnects after 2 minutes behind Captive Portal

Try allowing http access to clients3.Google.com

This will prevent the captive network assistant from popping up but will allow the browser to continue to pass traffic. 


Thanks, 
Tim

Tim Cappalli | Aruba ClearPass TME
@timcappalli | ACMX #367 / ACCX #480 / ACEAP / CWSP
Search Airheads
Showing results for 
Search instead for 
Did you mean: