Higher Education

last person joined: 8 days ago 

Got questions on how to enable mobility in education? Submit them here!
Expand all | Collapse all

iOS 7 - Captive Portal

This thread has been viewed 4 times
  • 1.  iOS 7 - Captive Portal

    EMPLOYEE
    Posted Sep 18, 2013 12:02 PM

    Looks like they changed the behavior of the captive network assistant check. If you have captive network assistant bypass turned on, you'll likely need to update your netdests.


    There are two new destinations that it checks for:

     

    www.appleiphonecell.com

    captive.apple.com

     

     

     



  • 2.  RE: iOS 7 - Captive Portal

    Posted Sep 18, 2013 12:35 PM

    Tim,

    I already have my certificate authority whitelisted to allow OCSP. What are the symptoms for the users if these destinations aren't whitelisted? Does Apple require additional destinations (in addition to the two you specified)?

    Thanks,

    Brad

     



  • 3.  RE: iOS 7 - Captive Portal

    EMPLOYEE
    Posted Sep 18, 2013 01:03 PM

    Brad,

     

    This isn't a certificate issue. It has to do with the captive network assistant and "faking" it out to think its connected while still being able to redirect to Onboard and other initial captive portals.



  • 4.  RE: iOS 7 - Captive Portal

    Posted Sep 18, 2013 01:18 PM

    If you are running ClearPass, they've issued an iOS 7 Captive Network Assistant fix; I first noticed it after applying Patch 1 to 6.2 if you are using the .../landing.php/... page method.



  • 5.  RE: iOS 7 - Captive Portal

    EMPLOYEE
    Posted Sep 19, 2013 07:25 AM

    And we are also adding this same logic to Instant and AOS on the controllers.  Apple's CNA is more "complex" and whitelisting a few specific URLs will no longer be sufficient.  They are rotating a few more URLs out there to figure this out.  However, our solutions will keep Guest registrations working.



  • 6.  RE: iOS 7 - Captive Portal

    Posted Nov 21, 2013 08:39 AM

    If whitelisting the URLs is not the best method any more, what is appropriate?  I am using the landing page trick, but my iOS 7 devices are still hitting the CNA, even with the iOS7 CP patch.  I would assume the landing page method only works if the device is attempting to access apple.com?  So what am I missing?



  • 7.  RE: iOS 7 - Captive Portal

    EMPLOYEE
    Posted Nov 21, 2013 08:43 AM

    There is also an option in the captive portal profile:

     

    captive-portal-bypass.PNG



  • 8.  RE: iOS 7 - Captive Portal

    Posted Nov 21, 2013 08:55 AM

    What version is required for this?  I heard it was in 6.2 but I don't have it as an option.  I'm on 6.2.1.3.



  • 9.  RE: iOS 7 - Captive Portal

    Posted Nov 21, 2013 09:03 AM
    I have it on 6.3.1.1 but I don't have it in 6.2.1.2


  • 10.  RE: iOS 7 - Captive Portal

    EMPLOYEE
    Posted Nov 21, 2013 09:04 AM
    6.3.x


  • 11.  RE: iOS 7 - Captive Portal

    Posted Nov 21, 2013 09:36 AM

    Thanks for the info.

     

    Anyone aware of the complete list of Apple FQDNs that iOS7 is attempting to hit?  I heard there are up to 5.



  • 12.  RE: iOS 7 - Captive Portal

    Posted Nov 22, 2013 11:53 AM

    i found this list online:

    captive.apple.com
    ibook.info
    appleiphonecell.com
    airport.us
    thinkdifferent.us
    itools.info

     

    such a shame apple doesnt just publish it, why doing this and not informing your users. also equally silly you cant just disable CNA.

     

    apperently they also use a certain user agent string to identify these requests. i hope aruba doesn't just allow request from that user agent to go through because then there is a nice way through your captive portal.

     

    also: why post this in the education forum, it is something that affects everyone in my opinion.



  • 13.  RE: iOS 7 - Captive Portal

    Posted Nov 22, 2013 03:05 PM

    Thanks Boneyard.  TAC just the same list of FQDNs, but of course, they said they're subject to change.  Bad move on Apple's part - I agree.



  • 14.  RE: iOS 7 - Captive Portal

    Posted Dec 13, 2013 01:43 PM

    @boneyard wrote:

    i found this list online:

    captive.apple.com
    ibook.info
    appleiphonecell.com
    airport.us
    thinkdifferent.us
    itools.info



    Is allowing port 80 to  these destinations sufficient or do more holes need to ne

     



  • 15.  RE: iOS 7 - Captive Portal

    Posted Sep 18, 2013 01:18 PM

    Tim,

    What does the user experience if the captive network assistant (I'm assuming this is a component of the Apple device) is not faked out to think it's connected?

    Thanks,

    Brad