<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE BYOD ANDROID ACL FOR GOOGLE PLAY in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-byod-android-acl-for-google-play/m-p/2980098#M37834</link>
    <description>&lt;P style="margin-bottom: 7.5pt;"&gt;&lt;SPAN style="font-size: 12.0pt; color: #58585b;"&gt;Hi,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin-bottom: 7.5pt;"&gt;&lt;SPAN style="font-size: 12.0pt; color: #58585b;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin-bottom: 7.5pt;"&gt;&lt;SPAN style="font-size: 12.0pt; color: #58585b;"&gt;Is there anyone out there who has an ACL (DNS and IP) that works for google play access during the BYOD flow for Android.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin-bottom: 7.5pt;"&gt;&lt;SPAN style="font-size: 12.0pt; color: #58585b;"&gt;I am located in Europe and there doesn’t seem to be any example that works.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 07:10:50 GMT</pubDate>
    <dc:creator>Simon Parlsjo</dc:creator>
    <dc:date>2019-03-11T07:10:50Z</dc:date>
    <item>
      <title>ISE BYOD ANDROID ACL FOR GOOGLE PLAY</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-android-acl-for-google-play/m-p/2980098#M37834</link>
      <description>&lt;P style="margin-bottom: 7.5pt;"&gt;&lt;SPAN style="font-size: 12.0pt; color: #58585b;"&gt;Hi,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin-bottom: 7.5pt;"&gt;&lt;SPAN style="font-size: 12.0pt; color: #58585b;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin-bottom: 7.5pt;"&gt;&lt;SPAN style="font-size: 12.0pt; color: #58585b;"&gt;Is there anyone out there who has an ACL (DNS and IP) that works for google play access during the BYOD flow for Android.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin-bottom: 7.5pt;"&gt;&lt;SPAN style="font-size: 12.0pt; color: #58585b;"&gt;I am located in Europe and there doesn’t seem to be any example that works.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:10:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-android-acl-for-google-play/m-p/2980098#M37834</guid>
      <dc:creator>Simon Parlsjo</dc:creator>
      <dc:date>2019-03-11T07:10:50Z</dc:date>
    </item>
    <item>
      <title>Hello Simon-</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-android-acl-for-google-play/m-p/2980099#M37835</link>
      <description>&lt;P&gt;Hello Simon-&lt;/P&gt;
&lt;P&gt;What does your ACL look like?&lt;/P&gt;
&lt;P&gt;There are a couple of easy ways you can do this:&lt;/P&gt;
&lt;P&gt;1. If you are running version 7.6 and later then you can use DNS based ACL entries. That way a single entry can permit the google play store&lt;/P&gt;
&lt;P&gt;2. If #1 is not an option then you can make the provisioning ACL for google play less restrictive. For instance, my regular provisioning ACL is pretty locked down, but the one for Android blocks all of my internal networks (except ISE servers and DNS) and then permits all Internet access.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope this helps!&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2016 17:24:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-android-acl-for-google-play/m-p/2980099#M37835</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2016-10-25T17:24:35Z</dc:date>
    </item>
    <item>
      <title>HI,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-android-acl-for-google-play/m-p/2980100#M37836</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have tried with a lot of diffrent URLs and IP ranges. Currently i'm trying with the following:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;DNS&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="tab-stops: list 36.0pt;"&gt;&lt;SPAN style="font-size: 12.0pt; font-family: 'Times New Roman',serif;"&gt;Android.clients.google.*.*&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="tab-stops: list 36.0pt;"&gt;&lt;SPAN style="font-size: 12.0pt; font-family: 'Times New Roman',serif;"&gt;&lt;A href="http://Www.googleapis.com"&gt;Www.googleapis.&lt;SPAN style="color: windowtext; text-decoration: none; text-underline: none;"&gt;*.*&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="tab-stops: list 36.0pt;"&gt;&lt;SPAN style="font-size: 12.0pt; font-family: 'Times New Roman',serif;"&gt;Play.google.*.*&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="tab-stops: list 36.0pt;"&gt;&lt;SPAN style="font-size: 12.0pt; font-family: 'Times New Roman',serif;"&gt;Ggpht.com.*.*&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="tab-stops: list 36.0pt;"&gt;&lt;SPAN style="font-size: 12.0pt; font-family: 'Times New Roman',serif;"&gt;Android.pool.ntp.*.*&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="tab-stops: list 36.0pt;"&gt;&lt;SPAN style="font-size: 12.0pt; font-family: 'Times New Roman',serif;"&gt;Market.android.*.*&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="tab-stops: list 36.0pt;"&gt;&lt;SPAN style="font-size: 12.0pt; font-family: 'Times New Roman',serif;"&gt;Mtalk.google.*.*&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="tab-stops: list 36.0pt;"&gt;&lt;SPAN style="font-size: 12.0pt; font-family: 'Times New Roman',serif;"&gt;*.android.clients.google.*.*&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="tab-stops: list 36.0pt;"&gt;&lt;SPAN style="font-size: 12.0pt; font-family: 'Times New Roman',serif;"&gt;*.*.android.clients.google.*.*&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="tab-stops: list 36.0pt;"&gt;&lt;SPAN style="font-size: 12.0pt; font-family: 'Times New Roman',serif;"&gt;*.gstatic.*.* (for bypassing internet check on Android - Disables mini-browser pop-up)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; font-family: 'Times New Roman',serif;"&gt;IP&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="tab-stops: list 36.0pt;"&gt;&lt;SPAN style="font-size: 12.0pt; font-family: 'Times New Roman',serif;"&gt;74.125.0.0/16&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="tab-stops: list 36.0pt;"&gt;&lt;SPAN style="font-size: 12.0pt; font-family: 'Times New Roman',serif;"&gt;173.194.0.0/16&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="tab-stops: list 36.0pt;"&gt;&lt;SPAN style="font-size: 12.0pt; font-family: 'Times New Roman',serif;"&gt;173.227.0.0/16&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="tab-stops: list 36.0pt;"&gt;&lt;SPAN style="font-size: 12.0pt; font-family: 'Times New Roman',serif;"&gt;206.111.0.0/16&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="tab-stops: list 36.0pt;"&gt;&lt;SPAN style="font-size: 12.0pt; font-family: 'Times New Roman',serif;"&gt;203.42.0.x/16&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="tab-stops: list 36.0pt;"&gt;&lt;SPAN style="font-size: 12.0pt; font-family: 'Times New Roman',serif;"&gt;8.35.0.0/16&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; font-family: 'Times New Roman',serif;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; font-family: 'Times New Roman',serif;"&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2016 06:38:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-android-acl-for-google-play/m-p/2980100#M37836</guid>
      <dc:creator>Simon Parlsjo</dc:creator>
      <dc:date>2016-10-26T06:38:16Z</dc:date>
    </item>
    <item>
      <title>So what happens when you try</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-android-acl-for-google-play/m-p/2980101#M37837</link>
      <description>&lt;P&gt;So what happens when you try to run through the BYOD flow?&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2016 16:21:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-android-acl-for-google-play/m-p/2980101#M37837</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2016-10-26T16:21:41Z</dc:date>
    </item>
    <item>
      <title>Also, be aware that not all</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-android-acl-for-google-play/m-p/2980102#M37838</link>
      <description>&lt;P&gt;Also, be aware that not all AP's support DNS ACL's, and that before 8.2 it's my experience that DNS ACL's were a bit buggy. You might wan't to make sure DNS Snooping is actually being activated in the AP, and the WLC is recieving host/ip records from the AP's when you are doing the DNS lookup from your clients.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2016 16:40:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-android-acl-for-google-play/m-p/2980102#M37838</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2016-10-26T16:40:33Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-android-acl-for-google-play/m-p/2980103#M37839</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I accentliy marked this as answered. Is there a way to undo this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With the ACL above I am not even able to access google play.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also tried with the following and then I can go all the way to download. But when I tap the link to start the download it is stuck in Downloading state.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;play.google.com&lt;/P&gt;
&lt;P&gt;google.co&lt;/P&gt;
&lt;P&gt;store.google.com&lt;/P&gt;
&lt;P&gt;.googleapis.com&lt;/P&gt;
&lt;P&gt;gstaic.com&lt;/P&gt;
&lt;P&gt;accounts.youtube.com&lt;/P&gt;
&lt;P&gt;dns.cisco.com&lt;/P&gt;
&lt;P&gt;.appspot.com&lt;/P&gt;
&lt;P&gt;ggpht.com&lt;/P&gt;
&lt;P&gt;market.android.com&lt;/P&gt;
&lt;P&gt;android.pool.ntp.org&lt;/P&gt;
&lt;P&gt;google-analytics.com&lt;/P&gt;
&lt;P&gt;.googleusercontext.com&lt;/P&gt;</description>
      <pubDate>Thu, 27 Oct 2016 07:10:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-android-acl-for-google-play/m-p/2980103#M37839</guid>
      <dc:creator>Simon Parlsjo</dc:creator>
      <dc:date>2016-10-27T07:10:03Z</dc:date>
    </item>
    <item>
      <title>Hi Simon, I have the same</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-android-acl-for-google-play/m-p/2980104#M37840</link>
      <description>&lt;P&gt;Hi Simon, I have the same issue we also tried to monitor the traffic in our firewall and put those IP addresses in the ACL or even put different DNS-based entries in the ACL.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Do you have now the fix for this? Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jan 2017 04:58:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-android-acl-for-google-play/m-p/2980104#M37840</guid>
      <dc:creator>fatalXerror</dc:creator>
      <dc:date>2017-01-18T04:58:57Z</dc:date>
    </item>
    <item>
      <title>Re: Hi</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-android-acl-for-google-play/m-p/3826357#M37841</link>
      <description>&lt;P&gt;Having the same issue as you SImon, it seems to be stuck at the downloading state and not progressing further. Did you happen to find a solution for this?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 15:03:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-android-acl-for-google-play/m-p/3826357#M37841</guid>
      <dc:creator>mumanika</dc:creator>
      <dc:date>2019-03-26T15:03:05Z</dc:date>
    </item>
  </channel>
</rss>

