<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WSA blocking smartphones before authentication in Web Security</title>
    <link>https://community.cisco.com/t5/web-security/wsa-blocking-smartphones-before-authentication/m-p/3700886#M8014</link>
    <description>I would agree with Sakun here, since displaying the pop up to enter authentication is depends on the application capabilities. Not all application have the capabilities to do this (internet browser such as chrome, firefox, safari, IE can definitely do this).&lt;BR /&gt;&lt;BR /&gt;When you check in the WSA accesslogs, you should find logs that would have TCP_DENIED/407 or TCP_DENIED/401 for that traffic, which indicating WSA is requesting for authentication to move forward and when WSA does not get response on that request, it will display the block page advising authentication required.</description>
    <pubDate>Wed, 05 Sep 2018 02:51:17 GMT</pubDate>
    <dc:creator>Handy Putra</dc:creator>
    <dc:date>2018-09-05T02:51:17Z</dc:date>
    <item>
      <title>WSA blocking smartphones before authentication</title>
      <link>https://community.cisco.com/t5/web-security/wsa-blocking-smartphones-before-authentication/m-p/3697064#M7996</link>
      <description>&lt;P&gt;Hello there,&lt;BR /&gt;we are deploying WSA and it's working, but when someone access the wifi using an smartphone, and try to access the internet, the access is blocked.&lt;/P&gt;
&lt;P&gt;The user connects to the WiFi, then the smartphone detects that doesnt have internet access (because the user arent authenticated on WSA yet) and open its pseudo browser (kind of a popup), warning the user that he should authenticate.&lt;BR /&gt;But when the user clicks on that warning WSA send the block page "access not authenticated", instead of ask for authentication.&lt;/P&gt;
&lt;P&gt;How we could correct this behavior?&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Aug 2018 15:06:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-blocking-smartphones-before-authentication/m-p/3697064#M7996</guid>
      <dc:creator>andre.ortega</dc:creator>
      <dc:date>2018-08-29T15:06:51Z</dc:date>
    </item>
    <item>
      <title>Re: WSA blocking smartphones before authentication</title>
      <link>https://community.cisco.com/t5/web-security/wsa-blocking-smartphones-before-authentication/m-p/3697299#M8000</link>
      <description>&lt;P&gt;how is this user authenticated&amp;nbsp; from smart phone ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;WSA configured of single sign on capabilities ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Look at the access log, it will give you some idea, why this is failing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;go to command level&lt;/P&gt;
&lt;P&gt;grep&amp;nbsp;&lt;/P&gt;
&lt;P&gt;option 1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Aug 2018 19:22:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-blocking-smartphones-before-authentication/m-p/3697299#M8000</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2018-08-29T19:22:03Z</dc:date>
    </item>
    <item>
      <title>Re: WSA blocking smartphones before authentication</title>
      <link>https://community.cisco.com/t5/web-security/wsa-blocking-smartphones-before-authentication/m-p/3697321#M8001</link>
      <description>&lt;P&gt;If user opens a browser, like Chrome, it (the browser) shows a popup then user can authenticate.&lt;/P&gt;
&lt;P&gt;The problem is when the smartphone shows automaticaly that "pseudo browser", you know? It is an warning on the top of the phone's screen. In this case, if the user clicks, it shows wsa's block page.&lt;/P&gt;
&lt;P&gt;That is the problem. It should shows the popup so user can log in, or at least, it should say "open a browser".&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Single sign on doesn't apply to users that are not logged in domain...&lt;BR /&gt;There was nothing on access log that could help.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Aug 2018 20:01:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-blocking-smartphones-before-authentication/m-p/3697321#M8001</guid>
      <dc:creator>andre.ortega</dc:creator>
      <dc:date>2018-08-29T20:01:22Z</dc:date>
    </item>
    <item>
      <title>Re: WSA blocking smartphones before authentication</title>
      <link>https://community.cisco.com/t5/web-security/wsa-blocking-smartphones-before-authentication/m-p/3697556#M8003</link>
      <description>&lt;P&gt;Coming back to basic information to understand the setup.&lt;/P&gt;
&lt;P&gt;it would be nice to explain your setup to understand better.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;how is WSA allow user to access internet, what basis ? any user can use your WSA and browse internet, how are you redirecting traffic to WSA, WCCP or proxy config ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If no log shown means it by passing proxy, what kind of rules setup for these kind of devices.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Aug 2018 04:52:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-blocking-smartphones-before-authentication/m-p/3697556#M8003</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2018-08-30T04:52:13Z</dc:date>
    </item>
    <item>
      <title>Re: WSA blocking smartphones before authentication</title>
      <link>https://community.cisco.com/t5/web-security/wsa-blocking-smartphones-before-authentication/m-p/3697851#M8006</link>
      <description>&lt;P&gt;We are redirecting all traffic (http and https) through PBR.&lt;/P&gt;
&lt;P&gt;All users from AD are allowed. There is logs, but it just says "blocked non authenticated access".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't know if I made myself clear... but it works if user open a browser on the smartphone and try to access some webpage. In this case the browser shows a popup and then user can log in.&lt;BR /&gt;The problem is when the user try to log in using that "fake browser", built in the SO.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your help balaji.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Aug 2018 12:24:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-blocking-smartphones-before-authentication/m-p/3697851#M8006</guid>
      <dc:creator>andre.ortega</dc:creator>
      <dc:date>2018-08-30T12:24:40Z</dc:date>
    </item>
    <item>
      <title>Re: WSA blocking smartphones before authentication</title>
      <link>https://community.cisco.com/t5/web-security/wsa-blocking-smartphones-before-authentication/m-p/3698045#M8007</link>
      <description>&lt;P&gt;&lt;div class="lia-vid-container video-embed-center"&gt;&lt;div id="lia-vid-R4cHgzZzE6P8qNTBVC_es4CGRK00eIG_w720h1280r145" class="lia-video-brightcove-player-container"&gt;&lt;video-js data-video-id="6064654412001" data-account="6058004235001" data-player="default" data-embed="default" class="vjs-fluid" controls="" data-application-id="" style="width: 100%; height: 100%;"&gt;&lt;/video-js&gt;&lt;/div&gt;&lt;script src="https://players.brightcove.net/6058004235001/default_default/index.min.js"&gt;&lt;/script&gt;&lt;script&gt;(function() {  var wrapper = document.getElementById('lia-vid-R4cHgzZzE6P8qNTBVC_es4CGRK00eIG_w720h1280r145');  var videoEl = wrapper ? wrapper.querySelector('video-js') : null;  if (videoEl) {     if (window.videojs) {       window.videojs(videoEl).ready(function() {         this.on('loadedmetadata', function() {           this.el().querySelectorAll('.vjs-load-progress div[data-start]').forEach(function(bar) {             bar.setAttribute('role', 'presentation');             bar.setAttribute('aria-hidden', 'true');           });         });       });     }  }})();&lt;/script&gt;&lt;a class="video-embed-link" href="https://community.cisco.com/t5/video/gallerypage/video-id/R4cHgzZzE6P8qNTBVC_es4CGRK00eIG_"&gt;(view in My Videos)&lt;/a&gt;&lt;/div&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;See the behavior.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Aug 2018 20:53:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-blocking-smartphones-before-authentication/m-p/3698045#M8007</guid>
      <dc:creator>andre.ortega</dc:creator>
      <dc:date>2018-08-31T20:53:03Z</dc:date>
    </item>
    <item>
      <title>Re: WSA blocking smartphones before authentication</title>
      <link>https://community.cisco.com/t5/web-security/wsa-blocking-smartphones-before-authentication/m-p/3698165#M8009</link>
      <description>&lt;P&gt;As per the video since it is not English not able to understand.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;what is the IP&amp;nbsp; : 10.91.16.117&lt;/P&gt;
&lt;P&gt;is that your proxy URL : &lt;A href="http://proxy.insper.local" target="_blank"&gt;http://proxy.insper.local&lt;/A&gt; ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Aug 2018 18:59:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-blocking-smartphones-before-authentication/m-p/3698165#M8009</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2018-08-30T18:59:11Z</dc:date>
    </item>
    <item>
      <title>Re: WSA blocking smartphones before authentication</title>
      <link>https://community.cisco.com/t5/web-security/wsa-blocking-smartphones-before-authentication/m-p/3698988#M8010</link>
      <description>&lt;P&gt;I changed the video, if you can, please edit your post to represent the right content.&lt;/P&gt;
&lt;P&gt;Basicaly the IP 10.123.45.102 (new video) is the client IP.&lt;/P&gt;
&lt;P&gt;wsa.lab.added.com.br is the WSA hostname.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Aug 2018 20:56:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-blocking-smartphones-before-authentication/m-p/3698988#M8010</guid>
      <dc:creator>andre.ortega</dc:creator>
      <dc:date>2018-08-31T20:56:16Z</dc:date>
    </item>
    <item>
      <title>Re: WSA blocking smartphones before authentication</title>
      <link>https://community.cisco.com/t5/web-security/wsa-blocking-smartphones-before-authentication/m-p/3700135#M8013</link>
      <description>I believe is not all the application and OS level service supports authentication and would need direct Internet access or transparent redirection with no authentication. Or there is an app called Microsoft Authenticator, maybe try that, that might help.</description>
      <pubDate>Tue, 04 Sep 2018 06:52:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-blocking-smartphones-before-authentication/m-p/3700135#M8013</guid>
      <dc:creator>Sakun Sharma</dc:creator>
      <dc:date>2018-09-04T06:52:49Z</dc:date>
    </item>
    <item>
      <title>Re: WSA blocking smartphones before authentication</title>
      <link>https://community.cisco.com/t5/web-security/wsa-blocking-smartphones-before-authentication/m-p/3700886#M8014</link>
      <description>I would agree with Sakun here, since displaying the pop up to enter authentication is depends on the application capabilities. Not all application have the capabilities to do this (internet browser such as chrome, firefox, safari, IE can definitely do this).&lt;BR /&gt;&lt;BR /&gt;When you check in the WSA accesslogs, you should find logs that would have TCP_DENIED/407 or TCP_DENIED/401 for that traffic, which indicating WSA is requesting for authentication to move forward and when WSA does not get response on that request, it will display the block page advising authentication required.</description>
      <pubDate>Wed, 05 Sep 2018 02:51:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-blocking-smartphones-before-authentication/m-p/3700886#M8014</guid>
      <dc:creator>Handy Putra</dc:creator>
      <dc:date>2018-09-05T02:51:17Z</dc:date>
    </item>
  </channel>
</rss>

