Aruba Apps

 View Only
last person joined: 7 days ago 

The HPE Aruba Networking Apps board is designed to address questions, comments, and feature requests for all HPE Aruba Networking mobile Apps
Expand all | Collapse all

Whatsapp problem on enterprise network

This thread has been viewed 37 times
  • 1.  Whatsapp problem on enterprise network

    Posted Apr 11, 2023 12:33 PM
    Hello,

    I have a WhatsApp problem on my network. When using our Guest Wifi, we have whatsapp which stays on the connecting state. We need to wait a few minutes before we are able to send and receive messages and calls. I checked the firewall, there is no drop or block on any whatsapp application. There are no particular settings applied on the application as well. 
    Does anyone have any idea please about what could be the root cause of this problem ?

    Thank you, 


  • 2.  RE: Whatsapp problem on enterprise network

    EMPLOYEE
    Posted Apr 12, 2023 04:25 AM

    Is your Guest WiFi Aruba based? Instant? Controller? What firmware versions?
    What Aruba role are your guests in? How does that role look like?
    Do you have other networks on the same environment? Do you see the same issue there?

    The description 'need to wait a few minutes' suggests that client traffic is dropped (somewhere), and after a timeout Whatsapp tries another method that works. You may need to open up more than just port 80 & 443.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 3.  RE: Whatsapp problem on enterprise network

    Posted Apr 12, 2023 06:16 AM

    Hello, 

    We are using controller based wifi-guest, and the firmware is 6.5.4.23. 



    Yes, we have the issue with two SSIDs using the same subnet.




  • 4.  RE: Whatsapp problem on enterprise network

    EMPLOYEE
    Posted Apr 12, 2023 08:22 AM

    And the role guest is what is actually assigned to the user? Have you verified?
    With 'show datapath session table <ip address>' you can see what traffic is passed/blocked. There may be more needed than just port 80/443 for Whatsapp to work happily. I also see that you should disable SSL inspection on your firewall as well for that traffic, in case you have that enabled.
    If on the other SSID there is an authenticated role, or other role with allow any traffic, there may be something else.
    It may be good to open a TAC case or work with your Aruba partner to do some further testing.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 5.  RE: Whatsapp problem on enterprise network

    MVP EXPERT
    Posted Apr 15, 2023 05:54 PM

    The user-role "guest" is a default role uses in the controller and only allow basic ports like http,https,dns,dhcp. Whatsapp use more than this basic ports.

    Whatsapp uses TCP 443 (HTTPS) to pass the majority of the connection traffic but it also uses TCP 80 (HTTP). If voice is used, then ports 4244, 5222, 5223, 5228,50318, 59234 & 5242 are used.

    UDP Ports: 34784, 45395, 50318, 59234.

    To figure out if the issue is in the wlan controller firewall our your external firewall you can do the following:
    - go to the wlan controller where the wifi client is active
    - show user-table, look for the client, client-ip, client-mac and assigned role (guest).
    - show datapath session table | incl "client-ip" and look for denied traffic (D flags).

    Other approach can be to create a test SSID with same vlan but with the default role "authenticated", the authenticated role have a "any any permit ACL".

    I willn't advise to use a "permit any any" ACL, but can help you to figure out if the issue is the client role/acl in the wlan controller our your external firewall.

    Based on my experience your guest role (which is default) have to less access for the watchapp application. 

    I will recommend to not change the default role "guest", but create a new role with a customized ACL policy and bound that you your SSID configution. If the user-role is derived from your radius server you must keep in mind you probably have to setup that to.

    Hope this help.



    ------------------------------
    Marcel Koedijk | MVP Expert 2023 | ACEP | ACMP | ACCP | ACDP | Ekahau ECSE | Not an HPE Employee | Opinions are my own
    ------------------------------



  • 6.  RE: Whatsapp problem on enterprise network

    Posted Apr 28, 2023 03:37 PM

    Hello Marcel, 

    I created an ACL that includes all TCP and UDP ports that you have mentioned, applied it to the guest user role and we could connect to Whatsapp without any delays. 

    Thank you very much for your help. Thanks to you, I resolved a persisting problem for years before my arrival at the company.

    Best regards, 

    Yassir LAMDERHRI




  • 7.  RE: Whatsapp problem on enterprise network

    MVP EXPERT
    Posted Apr 29, 2023 09:33 AM

    Hi Yassir,

    Glad to hear i can help solving your issue, feel free to accept my post a as a solution or giving kudos.
    Best practice is to not change the factory available roles but just copy them and at your own ACL rules.



    ------------------------------
    Marcel Koedijk | MVP Expert 2023 | ACEP | ACMP | ACCP | ACDP | Ekahau ECSE | Not an HPE Employee | Opinions are my own
    ------------------------------



  • 8.  RE: Whatsapp problem on enterprise network

    MVP
    Posted Apr 28, 2023 02:25 PM

    Hi,

    At one of our end customers, we had a deny all X.0.0.0 / 8 on the end of the access-list set for the certain User-Role, which caused the issue. After we have added the correct addressing, (example x.y.0.0/16 and x.z.0.0/16) whatsapp was working like a charm :)



    ------------------------------
    Shpat | MVP 2021 | ACEP | ACMP | ACCP | ACDP |
    ------------------------------