<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issues with ISE hotspot and self registration portals with apple devices in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/issues-with-ise-hotspot-and-self-registration-portals-with-apple/m-p/3776058#M486472</link>
    <description>Yes likely the Apple Captive network assistant is not liking the self signed cert.&lt;BR /&gt;&lt;BR /&gt;I recommend reviewing the guest guide under http:://cs.co/ise-guest&amp;lt;&amp;gt;&lt;BR /&gt;&lt;BR /&gt;And also enabling captive portal bypass on the controller to suppress the CNA so the regular browser is used&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-5/config-guide/b_cg85/wlan_security.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-5/config-guide/b_cg85/wlan_security.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Look for Captive Portal Bypass&lt;BR /&gt;&lt;BR /&gt;Information About Captive Bypassing&lt;BR /&gt;&lt;BR /&gt;Long term you will want to allow users to have a seamless flow and disabling it&lt;BR /&gt;</description>
    <pubDate>Wed, 09 Jan 2019 13:47:43 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2019-01-09T13:47:43Z</dc:date>
    <item>
      <title>Issues with ISE hotspot and self registration portals with apple devices</title>
      <link>https://community.cisco.com/t5/network-access-control/issues-with-ise-hotspot-and-self-registration-portals-with-apple/m-p/3775980#M486469</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have configured ISE 2.4 to create wifi hotspots and self registration access. We user a WLC 2504 controller software version 8.5.&lt;/P&gt;
&lt;P&gt;Everything works fine with windows devices and android devices which get correctly redirected to ISE portal pages. However, with the iphone we get errors. The phone connects to the ssid but then gives an error as below:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Error Opening Page - "Hotspot login cannot open the page because the server cannot be found". I believe this is trying to go to captive.apple.com. My redirect ACL on the WLC allows access to DNS and also to the ISE server. Do I need to add access to captive.apple.com in the ACL?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Another point is that the ise server has a certificate signed by a CA that is not a publicly trusted CA. I have added the root CA to my trusted certs on the iphone but still the same issue. I have also enabled &lt;STRONG&gt;web-auth captive-bypass &lt;/STRONG&gt;and rebooted the WLC but still the same issues.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help would be great.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance&lt;/P&gt;
&lt;P&gt;Nick&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2019 12:23:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issues-with-ise-hotspot-and-self-registration-portals-with-apple/m-p/3775980#M486469</guid>
      <dc:creator>n-russell-biggie</dc:creator>
      <dc:date>2019-01-09T12:23:42Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with ISE hotspot and self registration portals with apple devices</title>
      <link>https://community.cisco.com/t5/network-access-control/issues-with-ise-hotspot-and-self-registration-portals-with-apple/m-p/3776058#M486472</link>
      <description>Yes likely the Apple Captive network assistant is not liking the self signed cert.&lt;BR /&gt;&lt;BR /&gt;I recommend reviewing the guest guide under http:://cs.co/ise-guest&amp;lt;&amp;gt;&lt;BR /&gt;&lt;BR /&gt;And also enabling captive portal bypass on the controller to suppress the CNA so the regular browser is used&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-5/config-guide/b_cg85/wlan_security.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-5/config-guide/b_cg85/wlan_security.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Look for Captive Portal Bypass&lt;BR /&gt;&lt;BR /&gt;Information About Captive Bypassing&lt;BR /&gt;&lt;BR /&gt;Long term you will want to allow users to have a seamless flow and disabling it&lt;BR /&gt;</description>
      <pubDate>Wed, 09 Jan 2019 13:47:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issues-with-ise-hotspot-and-self-registration-portals-with-apple/m-p/3776058#M486472</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-01-09T13:47:43Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with ISE hotspot and self registration portals with apple devices</title>
      <link>https://community.cisco.com/t5/network-access-control/issues-with-ise-hotspot-and-self-registration-portals-with-apple/m-p/3776082#M486473</link>
      <description>&lt;P&gt;Many thanks Jason,&lt;/P&gt;
&lt;P&gt;I have enabled captive bypass on the WLC. I am able to get a step further, so obviously I do not get automatically redirected to ise, however when I open a browser I do get redirected to ISE but that is as far as I can get as it tells me there is an issue with he certificate. I do not get the option to trust or add the certificate for ISE so I get stuck here.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The domain name is xxxxxxx.local. I have read somewhere that iphones do not like a .local domain.&lt;/P&gt;
&lt;P&gt;Any other help would be great.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Nick&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2019 14:18:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issues-with-ise-hotspot-and-self-registration-portals-with-apple/m-p/3776082#M486473</guid>
      <dc:creator>n-russell-biggie</dc:creator>
      <dc:date>2019-01-09T14:18:55Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with ISE hotspot and self registration portals with apple devices</title>
      <link>https://community.cisco.com/t5/network-access-control/issues-with-ise-hotspot-and-self-registration-portals-with-apple/m-p/3776094#M486474</link>
      <description>Correct Apple doesn’t like that. Would recommend trying something else. We use a fake domain like securitydemo.net. And a well known cert, otherwise Apple devices won’t go through BYOD flow as well. This isn’t an ise issue. &lt;BR /&gt;</description>
      <pubDate>Wed, 09 Jan 2019 14:30:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issues-with-ise-hotspot-and-self-registration-portals-with-apple/m-p/3776094#M486474</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-01-09T14:30:43Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with ISE hotspot and self registration portals with apple devices</title>
      <link>https://community.cisco.com/t5/network-access-control/issues-with-ise-hotspot-and-self-registration-portals-with-apple/m-p/3776131#M486475</link>
      <description>&lt;P&gt;Thats great, thanks Jason. I will give this a try and let you know how I got on.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers&lt;/P&gt;
&lt;P&gt;Nick&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2019 14:56:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issues-with-ise-hotspot-and-self-registration-portals-with-apple/m-p/3776131#M486475</guid>
      <dc:creator>n-russell-biggie</dc:creator>
      <dc:date>2019-01-09T14:56:07Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with ISE hotspot and self registration portals with apple devices</title>
      <link>https://community.cisco.com/t5/network-access-control/issues-with-ise-hotspot-and-self-registration-portals-with-apple/m-p/3901741#M486476</link>
      <description>&lt;P&gt;Hi Russell, can I ask what the results of your testing were?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2019 21:41:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issues-with-ise-hotspot-and-self-registration-portals-with-apple/m-p/3901741#M486476</guid>
      <dc:creator>briankk1582</dc:creator>
      <dc:date>2019-08-01T21:41:06Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with ISE hotspot and self registration portals with apple devices</title>
      <link>https://community.cisco.com/t5/network-access-control/issues-with-ise-hotspot-and-self-registration-portals-with-apple/m-p/3911024#M486477</link>
      <description>thanks please let me know</description>
      <pubDate>Tue, 20 Aug 2019 17:24:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issues-with-ise-hotspot-and-self-registration-portals-with-apple/m-p/3911024#M486477</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-08-20T17:24:11Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with ISE hotspot and self registration portals with apple devices</title>
      <link>https://community.cisco.com/t5/network-access-control/issues-with-ise-hotspot-and-self-registration-portals-with-apple/m-p/3991938#M486478</link>
      <description>&lt;P&gt;Hi Jason,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i facing same issue, i try to change certificate selfsigned using xxx.com&lt;/P&gt;&lt;P&gt;the result, still same in apple device. " hotspot login cannot open the page because the server cannot be found "&lt;/P&gt;&lt;P&gt;i try to using browser its working normally.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is there any advice ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2019 09:30:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issues-with-ise-hotspot-and-self-registration-portals-with-apple/m-p/3991938#M486478</guid>
      <dc:creator>ganiabdullahgenderang</dc:creator>
      <dc:date>2019-12-02T09:30:45Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with ISE hotspot and self registration portals with apple devices</title>
      <link>https://community.cisco.com/t5/network-access-control/issues-with-ise-hotspot-and-self-registration-portals-with-apple/m-p/3992002#M486479</link>
      <description>Are you saying you’re using self signed certificate?&lt;BR /&gt;&lt;BR /&gt;Apple captive network browser assistant doesn’t like that likely&lt;BR /&gt;</description>
      <pubDate>Mon, 02 Dec 2019 11:43:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issues-with-ise-hotspot-and-self-registration-portals-with-apple/m-p/3992002#M486479</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-12-02T11:43:38Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with ISE hotspot and self registration portals with apple devices</title>
      <link>https://community.cisco.com/t5/network-access-control/issues-with-ise-hotspot-and-self-registration-portals-with-apple/m-p/3992090#M486480</link>
      <description>hi Jason,&lt;BR /&gt;&lt;BR /&gt;yes, i am using selfsigned certificate.&lt;BR /&gt;earlier everything running well.&lt;BR /&gt;and now apple device cannot using CNA.&lt;BR /&gt;&lt;BR /&gt;so, we need using public certificate ?&lt;BR /&gt;&lt;BR /&gt;thanks</description>
      <pubDate>Mon, 02 Dec 2019 14:15:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issues-with-ise-hotspot-and-self-registration-portals-with-apple/m-p/3992090#M486480</guid>
      <dc:creator>ganiabdullahgenderang</dc:creator>
      <dc:date>2019-12-02T14:15:19Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with ISE hotspot and self registration portals with apple devices</title>
      <link>https://community.cisco.com/t5/network-access-control/issues-with-ise-hotspot-and-self-registration-portals-with-apple/m-p/3992242#M486481</link>
      <description>that's correct, self-signed certificate is not supported in the guest flow for production as many browsers have issues with them&lt;BR /&gt;&lt;BR /&gt;check out guest guide&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-guest-access-prescriptive-deployment-guide/ta-p/3640475" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-guest-access-prescriptive-deployment-guide/ta-p/3640475&lt;/A&gt;&lt;BR /&gt;and certificate guide&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-documents/how-to-implement-digital-certificates-in-ise/ta-p/3630897" target="_blank"&gt;https://community.cisco.com/t5/security-documents/how-to-implement-digital-certificates-in-ise/ta-p/3630897&lt;/A&gt;</description>
      <pubDate>Mon, 02 Dec 2019 17:41:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issues-with-ise-hotspot-and-self-registration-portals-with-apple/m-p/3992242#M486481</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-12-02T17:41:31Z</dc:date>
    </item>
  </channel>
</rss>

