Wireless Access

 View Only
last person joined: 14 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

iPhone Private Address and Mobility Controller

This thread has been viewed 38 times
  • 1.  iPhone Private Address and Mobility Controller

    MVP
    Posted May 30, 2021 01:03 PM
    Hi,

    I have iPhone users in my wireless network running ArubaOS 8.6 where they cannot connect to the SSID when the "Private Address" option is enabled on their phone WiFi settings. When disabled they can join without any issues. Because of this users are complaining that they cannot connect to the network. What exactly does private address provide and how is Aruba mobility controller treating this?. Is there any setting that can be changed in the controller?

    Thanks,

    ------------------------------
    Ajin Skariah
    ------------------------------


  • 2.  RE: iPhone Private Address and Mobility Controller

    Posted May 30, 2021 02:15 PM
    Private Address sets a 'random' mac-address on the iPhone. So you would need some typ of mac-filtering on your controller or radius-server that prevents them from joining the network with private address turned on.

    ------------------------------
    Christoffer Starck
    ------------------------------



  • 3.  RE: iPhone Private Address and Mobility Controller

    MVP
    Posted May 30, 2021 02:23 PM
    I haven't set any filtering now and the users cannot join the network with private address enabled. Where is this setting in the controller?

    ------------------------------
    Ajin Skariah
    ------------------------------



  • 4.  RE: iPhone Private Address and Mobility Controller

    Posted May 30, 2021 02:29 PM
    What type of security do you have on the SSID that the clients are trying to connect to? WPA-Enterprise, PSK, Open ?

    ------------------------------
    Christoffer Starck
    ------------------------------



  • 5.  RE: iPhone Private Address and Mobility Controller

    MVP
    Posted May 30, 2021 02:39 PM
    WPA2 Personal


  • 6.  RE: iPhone Private Address and Mobility Controller

    Posted May 31, 2021 08:41 AM
    You should begin with checking out the AAA-profile on the virtual ap profile for that network. You will find the profiles under "Configuration -> System -> Profiles".

    ------------------------------
    Christoffer Starck
    ------------------------------



  • 7.  RE: iPhone Private Address and Mobility Controller

    EMPLOYEE
    Posted May 31, 2021 09:28 AM
    By default, there should not be any limitations to support randomized MAC for a WPA2 Personal network, unless you configured something like MAC Filtering, MPSK, or external authentication. Randomized MAC addresses are not so much different from static MAC.

    If you don't have such settings, it may be best to work with your Aruba partner or Aruba Support to get investigated what is going on.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 8.  RE: iPhone Private Address and Mobility Controller

    Posted Jun 01, 2021 10:46 AM
    Curious whether WPA2 Enterprise (or WPA3 Enterprise) would by default have any prohibition against the private MAC address feature of these iPhones. (We get a fair number of users saying their iPhones don't automatically maintain a connection to our enterprise .1x SSID, but the Guest SSID seems to reconnect more easily.)





  • 9.  RE: iPhone Private Address and Mobility Controller

    MVP EXPERT
    Posted Jun 01, 2021 12:10 PM
    Hi,

    Running wpa3-enterprise here on an Aruba Instant ( 8.8) , my iphone/mac book air both connect using TLS ( iOS 14.6, macOS 11.4) works just fine




  • 10.  RE: iPhone Private Address and Mobility Controller

    MVP
    Posted Jun 04, 2021 09:56 AM
    Did you check if the mac addresses of the troubled users have their "random mac address" blacklisted on the controllers? When the iPhone mac randomization feature first came out (forget exactly what version) there were bugs causing the phones to send bad ARP replies that contained invalid mac info, causing controllers to blacklist that mac addresses (and hence cause the iPhones to not be able to connect to any APs). But if you toggled off the random mac (going back to the burnt-in 'real' mac), the phone would connect fine because that mac address wasn't blacklisted.

    So spot check a few of the 'random' mac addresses in your blacklist database. If you find some, you will have to clear them, and also make sure those iPhone users update their iOS to the latest versions. If I remember correctly, iOS version 14.2 corrected the bad ARP reply issues (thus resolving the blacklisting issue).