Security

 View Only
last person joined: 19 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Aruba Central Cloud Guest captive portal issue with Autopilot

This thread has been viewed 35 times
  • 1.  Aruba Central Cloud Guest captive portal issue with Autopilot

    Posted Dec 08, 2023 09:48 AM

    Hi everybody,

    I would like to know if there are any known issues with the Aruba Central Cloud Guest Captive Portal, during an Intune Autopilot setup -using a Windows 11 23H2 notebook).

    In the Autopilot setup page I see the network in the list. I can connect to it and  a browser app pops up which automatically directs me to the splash page.
    But the page doesn't show anything (is blanco / completely white).

    I tried testing with the default splash page and with a custom splash page, but no success.


    Troubleshooting Autopilot I was able to open the Microsoft Edge browser and the captive portal opened without issues.
    This indicates that the issue is limited to the specifiek browser-app that Autopilot automatically opens when I connect to the network.
    This particular app shows a very limited GUI, only showing the URL, a forward and back button, a refresh button and a close button.

    I already contacted Microsoft about this, but while waiting for an answer I turned to the AP itself.

    The AP I use, runs on firmware version 8.11.2.0_87947.
    Might this be the cause of some incompatibility?
    I've read AOS 10 is more suited for Guest networks and access management.
    Would you suggest upgrading to 10.5.0.1_88128 ?


    Has anybody expecienced the same issue? Can you please share how it was resolved?

    Thanks!



  • 2.  RE: Aruba Central Cloud Guest captive portal issue with Autopilot

    EMPLOYEE
    Posted Dec 08, 2023 11:43 AM

    I don't have experience with this, but it looks like the Autopilot browser does not run any Javascript and does not render the guest page for that reason.

    Cloud Guest requires JavaScript on the client to be enabled.

    Please reach out to Aruba Support so they can validate this assumption and possibly report to engineering, as the use-case sounds valid to me (but also to be cinfirmed by TAC).

    Last week at HPE Discover with Atmosphere in Barcelona, I had a conversation with a customer trying to do the same, Autopilot through a Guest Captive Portal, I shared the idea that allowing the Autopilot/Intune/EntraID URLs through your captive portal may work as well. Not tested, and it may not be desired to allow traffic to a number of services without login, but it may be worth trying.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 3.  RE: Aruba Central Cloud Guest captive portal issue with Autopilot

    EMPLOYEE
    Posted Dec 08, 2023 11:46 AM

    David ~ please open a TAC case around this to get it resolved quickly.  

    Historically, mini browsers are limited in their ability to do a number of things, for example Google will no longer allow authentication from any mini-browser agent (including Android).  As these issues are identified we try to adjust the system to accommodate the behavior as much as possible.  I suspect that this is a new agent that we have not yet worked with that is failing to properly render the content we are providing.  We then just need to be able to make the adjustments based on the mini-browser to properly work with your devices.




  • 4.  RE: Aruba Central Cloud Guest captive portal issue with Autopilot

    Posted Dec 08, 2023 05:51 PM

    Please let me know if you have any luck with TAC.  We had the same issue with some e-readers's mini browsers and TAC certainly was not quick.  They did some packet captures, and when they found out that it was not a network issue but a web page rendering issue TAC was not particularly interested in in resolving the issue or even sending anything to development.   Which is what I hoped they would do.  Honestly the Cloud Guest Captive Portal is somewhat remedial I don't think there is much focus on doing any improvement or development of the feature. 

     

    We ended up having to create an additional bandwidth restricted SSID without the guest portal to accommodate those users.  Fast enough to download books but slow enough that guest users would not be motivated to bypass the normal guest SSID.

     

     






  • 5.  RE: Aruba Central Cloud Guest captive portal issue with Autopilot

    Posted Dec 14, 2023 10:08 AM

    Case 5378474261 was logged. 
    I'll keep you updated on the progress.

    At this point Microsoft hasn't been great of a help, though I suspect there is a misunderstanding on their side.
    I showed a Microsoft engineer what happens and got a reply from one of his colleagues, claiming the mini browser app that starts, is some form of Aruba application, not related to Microsoft Autopilot.

    As far as I'm aware, the only thing I configure in the Aruba Clearpass, to get the Cloud Portal working, is how the website / splash page looks like (and ofcourse the SSID, with its settings)
    .
    I've send them a video of the steps I go through, what exactly happens - and asked them to review it too.




  • 6.  RE: Aruba Central Cloud Guest captive portal issue with Autopilot

    Posted Feb 23, 2024 05:36 AM

    I'm sorry for the late update, but I would like to inform you that the HPE Aruba engineers deployed a fix 03/02 that solved the problem!

    Some notes from the engineering ticket.

    • The mini-browser ("Edge component") is using a "WebView/3.0" (you can see this in the HTTP User-Agent) and it is clearly an older version of Edge:
    • Mozilla/5.0 (Windows NT 10.0; Win64; x64; WebView/3.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.22631
    • Edge 12–18 are considered "legacy" browsers.  The current version is 120.

    I did contact Microsoft about the findings and they have forwarded it to their internal teams.




  • 7.  RE: Aruba Central Cloud Guest captive portal issue with Autopilot

    Posted Mar 12, 2024 04:41 AM

    Hi, what ArubaOS-version fixed the problem?

    BR
    //Tomas




  • 8.  RE: Aruba Central Cloud Guest captive portal issue with Autopilot

    EMPLOYEE
    Posted Mar 12, 2024 07:57 AM

    I'd think this is a fix in Cloud Guest, not in ArubaOS. From the above by DavidB, it looks like the fix was deployed a month ago.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 9.  RE: Aruba Central Cloud Guest captive portal issue with Autopilot

    Posted Mar 13, 2024 05:15 AM

    Aha, ok. Thx, i will test it then :)