<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: BYOD broken with ANDROID 10 - Wireless Randomised MAC in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/byod-broken-with-android-10-wireless-randomised-mac/m-p/4009322#M454670</link>
    <description>&lt;P&gt;First, disabling the ISE policy authorisation condition &lt;STRONG&gt;MAC_in_SAN&lt;/STRONG&gt; is not an option. This is part of the security and the only way to check the identity of the client device.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a fix for a Dual SSID BYOD solution, it's not pretty but it does work on my OnePlus Android. Here is a summary of the process.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;H1&gt;Devices that currently use a BYOD service.&lt;/H1&gt;&lt;P&gt;Devices that currently use a BYOD service (with certificates) but have or want to upgrade to Android 10 will have to re-on-board.&lt;/P&gt;&lt;P&gt;The following menu options may be different on different Android devices but the principle is the same.&lt;/P&gt;&lt;H2&gt;Before you re-on-board&lt;/H2&gt;&lt;OL&gt;&lt;LI&gt;Forget both the Open and 802.1X SSID networks on your android device.&lt;/LI&gt;&lt;LI&gt;Remove the network user credentials.&lt;/LI&gt;&lt;LI&gt;On the phone: &lt;STRONG&gt;Settings -&amp;gt; Security -&amp;gt; Advanced -&amp;gt; Encryption -&amp;gt; Clear Credentials&lt;/STRONG&gt;.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;EM&gt;It is recommended to restart the device.&lt;/EM&gt;&lt;/P&gt;&lt;H1&gt;To on-board with Android 10&lt;/H1&gt;&lt;OL&gt;&lt;LI&gt;Connect to 802.1X SSID. It will fail to connect but should then show as a &lt;STRONG&gt;Saved&lt;/STRONG&gt; network which should allow you to change its configuration. Configure it to “Use device MAC” (probably under Advanced -&amp;gt; Privicy option).&lt;/LI&gt;&lt;LI&gt;Connect to Open SSID and configure it to “Use device MAC”&lt;/LI&gt;&lt;LI&gt;Now disconnect then re-connect to the Open SSID to ensure it now uses the device MAC (perhaps try connecting and disconnecting to another SSID) and proceed with the on-boarding process.&lt;/LI&gt;&lt;LI&gt;Manually configure the 802.1X SSID with EAP Method (TLS), Certificates (CA and User) and Identity (AD username)&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Hope this helps others.&lt;/P&gt;</description>
    <pubDate>Fri, 10 Jan 2020 10:16:43 GMT</pubDate>
    <dc:creator>Scott Gillies</dc:creator>
    <dc:date>2020-01-10T10:16:43Z</dc:date>
    <item>
      <title>BYOD broken with ANDROID 10 - Wireless Randomised MAC</title>
      <link>https://community.cisco.com/t5/network-access-control/byod-broken-with-android-10-wireless-randomised-mac/m-p/4008000#M454668</link>
      <description>&lt;P&gt;I have just upgraded my OnePlus 6 to Android 10. It has broken my EAPTLS BYOD service because it now automatically uses Randomised MAC when connecting to wireless networks.&lt;/P&gt;&lt;P&gt;My ISE authorisation policy includes the condition "MAC_in_SAN" which my device now fails on. Remove the condition and it works.&lt;/P&gt;&lt;P&gt;Now you can actually configure it to "Use device MAC" but the default is "Use randomised MAC (default)" &lt;FONT size="4" color="#FF0000"&gt;&lt;STRONG&gt;BUT&lt;/STRONG&gt; &lt;/FONT&gt;To add insult to injury the upgrade has also changed my device Wireless MAC address which also breaks the "MAC_in_SAN" policy condition.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do Cisco have any guidance on this?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2022 07:25:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/byod-broken-with-android-10-wireless-randomised-mac/m-p/4008000#M454668</guid>
      <dc:creator>Scott Gillies</dc:creator>
      <dc:date>2022-03-10T07:25:53Z</dc:date>
    </item>
    <item>
      <title>Re: BYOD broken with ANDROID 10 - Wireless Randomised MAC</title>
      <link>https://community.cisco.com/t5/network-access-control/byod-broken-with-android-10-wireless-randomised-mac/m-p/4008252#M454669</link>
      <description>&lt;P&gt;That is correct, with Android 10 BYOD registered and MAC-in-SAN condition will not work. What you have is what we recommend. &lt;A href="https://community.cisco.com/t5/security-documents/ise-byod-endpoint-notes/ta-p/3857246#toc-hId--1243681234" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-byod-endpoint-notes/ta-p/3857246#toc-hId--1243681234&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2020 16:35:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/byod-broken-with-android-10-wireless-randomised-mac/m-p/4008252#M454669</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2020-01-08T16:35:41Z</dc:date>
    </item>
    <item>
      <title>Re: BYOD broken with ANDROID 10 - Wireless Randomised MAC</title>
      <link>https://community.cisco.com/t5/network-access-control/byod-broken-with-android-10-wireless-randomised-mac/m-p/4009322#M454670</link>
      <description>&lt;P&gt;First, disabling the ISE policy authorisation condition &lt;STRONG&gt;MAC_in_SAN&lt;/STRONG&gt; is not an option. This is part of the security and the only way to check the identity of the client device.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a fix for a Dual SSID BYOD solution, it's not pretty but it does work on my OnePlus Android. Here is a summary of the process.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;H1&gt;Devices that currently use a BYOD service.&lt;/H1&gt;&lt;P&gt;Devices that currently use a BYOD service (with certificates) but have or want to upgrade to Android 10 will have to re-on-board.&lt;/P&gt;&lt;P&gt;The following menu options may be different on different Android devices but the principle is the same.&lt;/P&gt;&lt;H2&gt;Before you re-on-board&lt;/H2&gt;&lt;OL&gt;&lt;LI&gt;Forget both the Open and 802.1X SSID networks on your android device.&lt;/LI&gt;&lt;LI&gt;Remove the network user credentials.&lt;/LI&gt;&lt;LI&gt;On the phone: &lt;STRONG&gt;Settings -&amp;gt; Security -&amp;gt; Advanced -&amp;gt; Encryption -&amp;gt; Clear Credentials&lt;/STRONG&gt;.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;EM&gt;It is recommended to restart the device.&lt;/EM&gt;&lt;/P&gt;&lt;H1&gt;To on-board with Android 10&lt;/H1&gt;&lt;OL&gt;&lt;LI&gt;Connect to 802.1X SSID. It will fail to connect but should then show as a &lt;STRONG&gt;Saved&lt;/STRONG&gt; network which should allow you to change its configuration. Configure it to “Use device MAC” (probably under Advanced -&amp;gt; Privicy option).&lt;/LI&gt;&lt;LI&gt;Connect to Open SSID and configure it to “Use device MAC”&lt;/LI&gt;&lt;LI&gt;Now disconnect then re-connect to the Open SSID to ensure it now uses the device MAC (perhaps try connecting and disconnecting to another SSID) and proceed with the on-boarding process.&lt;/LI&gt;&lt;LI&gt;Manually configure the 802.1X SSID with EAP Method (TLS), Certificates (CA and User) and Identity (AD username)&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Hope this helps others.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2020 10:16:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/byod-broken-with-android-10-wireless-randomised-mac/m-p/4009322#M454670</guid>
      <dc:creator>Scott Gillies</dc:creator>
      <dc:date>2020-01-10T10:16:43Z</dc:date>
    </item>
    <item>
      <title>Re: BYOD broken with ANDROID 10 - Wireless Randomised MAC</title>
      <link>https://community.cisco.com/t5/network-access-control/byod-broken-with-android-10-wireless-randomised-mac/m-p/4009668#M454671</link>
      <description>&lt;P&gt;The randomized mac should be a setting in the wireless/advanced. Can't you just turn it off?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2020 20:20:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/byod-broken-with-android-10-wireless-randomised-mac/m-p/4009668#M454671</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2020-01-10T20:20:00Z</dc:date>
    </item>
  </channel>
</rss>

