Security

 View Only
last person joined: 18 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

iPhone Users not getting Captive Portal redirect when connecting to Guest

This thread has been viewed 55 times
  • 1.  iPhone Users not getting Captive Portal redirect when connecting to Guest

    Posted 17 days ago

    Hi,

    iPhone users on their personal phone that are connecting to our Guest Wi-Fi are not getting redirected to the Captive Portal automatically. All other devices are. Guest users can put in the link manually, and all works fine there, but they just won't get the automatic redirect when they connect to the guest SSID.



  • 2.  RE: iPhone Users not getting Captive Portal redirect when connecting to Guest

    EMPLOYEE
    Posted 17 days ago

    What happens when one of those devices connects to the network?  What is the result of the redirect?



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 3.  RE: iPhone Users not getting Captive Portal redirect when connecting to Guest

    Posted 17 days ago

    They are denied access to the internet, but their phone still pulls a DHCP IP. They simply don't get the Captive Portal page like they should, where they go through the process to authenticate their Guest User account and MAC




  • 4.  RE: iPhone Users not getting Captive Portal redirect when connecting to Guest

    EMPLOYEE
    Posted 17 days ago

    They have the proper role for captive portal enforcement?  What error is shown in the browser?



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 5.  RE: iPhone Users not getting Captive Portal redirect when connecting to Guest

    Posted 17 days ago

    They have the proper role. It is only iPhone users that are having the issue.

    No error is shown in the browser. They just do not get the splash page/Captive Portal redirect.




  • 6.  RE: iPhone Users not getting Captive Portal redirect when connecting to Guest

    EMPLOYEE
    Posted 17 days ago

    This was working for your iPhone users at some point?  What was changed?



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 7.  RE: iPhone Users not getting Captive Portal redirect when connecting to Guest

    Posted 17 days ago

    @chulcher

    No, it was never working. We used a PSK before for Guest Users and only recently moved to using Clearpass for Guest authentication via Captive Portal.

    @su_A_ve

    Issue has been present since the beginning. It affects all iOS versions that we have attempted with. We have not upgraded CPPM in a bit, as we are on 6.9.7.131609




  • 8.  RE: iPhone Users not getting Captive Portal redirect when connecting to Guest

    Posted 17 days ago
    Is this a new issue or new installation? Does it affect different iOS versions or all of them? Has it happened after CPPM update/upgrade?

    --
    °(((=((===°°°(((================================================





  • 9.  RE: iPhone Users not getting Captive Portal redirect when connecting to Guest

    Posted 17 days ago
    We also had the problem with a customer about half a year ago that the iPhones were not redirected to the captive portal.
    It turned out that the iPhones had not queried the DNS server assigned via DHCP, but a public DNS.
    The iPhones could not resolve the FQDN to the captive portal, which was the reason for the misbehavior.
     
    You can show all client connections in the wlan controller with "show datapath session table <client-ip>".
    Check which DNS server is being queried.
    If an external DNS server is queried, you can redirect all DSN queries to the internal DNS server in the preauth-role.


    ------------------------------
    Regards,

    Waldemar
    ACCX # 1377, ACEP, ACX - Network Security
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------