Security

 View Only
last person joined: 18 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Guest self-registration for macbook

This thread has been viewed 32 times
  • 1.  Guest self-registration for macbook

    Posted Dec 06, 2021 02:55 AM
    Hi
    anyone has this issue with macbook connecting to network on wired but does not automatically open browser and re-direct to CPPM Self-registration guest page? Note: The guest self registration works fine on BYOD windows 10.

    BYOD Macbook, connect to wired it does not work, but if I manually key in the full self register URL it works fine as I can register an account. another note is that the BYOD macbook works fine on WIFI Guest network. When connect to WIFI Guest, it will immediately popup browser and to self register URL.

    Appreciate any advise on this.
    Thanks

    ------------------------------
    Daniel Kweh
    ------------------------------


  • 2.  RE: Guest self-registration for macbook

    MVP GURU
    Posted Dec 06, 2021 06:42 AM
    Are you issuing the same initial role on wired and wireless? Have you checked that DNS works in both scenarios?

    Can the device resolve captive.apple.com in the initial role?

    ------------------------------
    Dustin Burns
    Lead Mobility Engineer @WEI

    ACCX 1271| ACMX 509| ACSP | ACDA | MVP Guru 2021
    If my post was useful accept solution and/or give kudos
    ------------------------------



  • 3.  RE: Guest self-registration for macbook

    Posted Dec 06, 2021 08:15 AM
    Thank you for your response.
    I think they are on the same role as mentioned, currently the automated self-redirection guest registration works well on Windows machine (Wired and wireless)  but not on Macbook. 


    ------------------------------
    Daniel Kweh
    ------------------------------



  • 4.  RE: Guest self-registration for macbook

    MVP GURU
    Posted Dec 06, 2021 06:45 AM
    Also, have you seen this?

    https://poweruser.blog/macos-catalina-wifi-issue-captive-portal-broken-45610cc016b5


    ------------------------------
    Dustin Burns
    Lead Mobility Engineer @WEI

    ACCX 1271| ACMX 509| ACSP | ACDA | MVP Guru 2021
    If my post was useful accept solution and/or give kudos
    ------------------------------



  • 5.  RE: Guest self-registration for macbook

    Posted Dec 06, 2021 08:19 AM
    Thanks for your response. The issue is on wired to the captive portal. On WIFI, it works fine.

    ------------------------------
    Daniel Kweh
    ------------------------------



  • 6.  RE: Guest self-registration for macbook

    EMPLOYEE
    Posted Dec 06, 2021 08:53 AM
    If, from the wired when you should be automatically redirected, can you try to open your browser to http://captive.apple.com/

    Are you redirected to the captive portal at that point?

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 7.  RE: Guest self-registration for macbook

    Posted Dec 07, 2021 08:18 AM
    Thanks for the response. I will try that once I am back office again.

    ------------------------------
    Daniel Kweh
    ------------------------------



  • 8.  RE: Guest self-registration for macbook

    Posted Dec 12, 2021 11:51 PM
    Hi Herman
    I just tried typing captive.apple.com and it works fine for macbook. I can see it immediately redirect to CPPM self registration page. but if i key in any other URL like www.google.com or www.yahoo.com it does not redirect.
    Would you be able to advise? I have log a case with HPE support and for weeks, they are still asking for information.

    ------------------------------
    Daniel Kweh
    ------------------------------



  • 9.  RE: Guest self-registration for macbook

    EMPLOYEE
    Posted Dec 13, 2021 05:20 AM
    Two things. First, your observation confirms what I have seen at a few places that macOS does not do captive portal checks on the wired (just on the wireless). There is unfortunately not so much you can do.

    Then for google.com and yahoo.com you hit the HSTS problem that I wrote a blog around a few years ago. Also, that is not something that helps or solves the issue.

    While I have not really investigated, I read some rumors that indicate that some vendors started to implement RFC-7710, that adds the captive portal URL in the DHCP messages. This was one of the suggestions in my blog, but I never tried it after. You may try and see if that helps...

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 10.  RE: Guest self-registration for macbook

    MVP EXPERT
    Posted Dec 14, 2021 03:27 AM
    Didn’t know about RFC 7710 sounds really useful . However seems like it might be replaced by


    draft-ietf-capport-rfc7710bis-08



    Which uses a different attribute option. 114 instead of 160 due to a clash.

    Problem is apparently andorid11 beta , iOS 14 and Big Sur started using option 160 where’s draft-ietf-capport-rfc7710bis-08 specified option 114 due to a clash.


    A




  • 11.  RE: Guest self-registration for macbook

    MVP EXPERT
    Posted Dec 14, 2021 03:36 AM
    o.k. cancel that, think apple are using option 114
    A




  • 12.  RE: Guest self-registration for macbook

    Posted Dec 15, 2021 05:53 AM
    Thank you for the advise. it is really helpful. I will explore using the dhcp option 114. Thanks

    ------------------------------
    Daniel Kweh
    ------------------------------



  • 13.  RE: Guest self-registration for macbook

    EMPLOYEE
    Posted Dec 17, 2021 09:14 AM
    Please report back your findings... I'm starting to be curious if this works as designed.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 14.  RE: Guest self-registration for macbook

    Posted Dec 19, 2021 10:35 PM
    Hi just tested the option114 on the dhcp option and still the same. the Macbook Safari does not redirect when I key in any URL.
    I was online with HPE Engineer today and he enable (redirection VLAN) IP interface on the edge switch and the macbook redirection on safari works.

    Thank you all for the good advise.

    ------------------------------
    Daniel Kweh
    ------------------------------