<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Android Devices unable to download BYOD profile in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/android-devices-unable-to-download-byod-profile/m-p/3700388#M527297</link>
    <description>&lt;P&gt;Hello &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/301947"&gt;@ciscoworlds&lt;/a&gt; - did you ever solve the issue with the Android BYOD onboarding not working?&lt;/P&gt;</description>
    <pubDate>Tue, 04 Sep 2018 13:43:38 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2018-09-04T13:43:38Z</dc:date>
    <item>
      <title>Android Devices unable to download BYOD profile</title>
      <link>https://community.cisco.com/t5/network-access-control/android-devices-unable-to-download-byod-profile/m-p/3598684#M527293</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ISE experts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm currently facing an issue with the BYOD provisioning for Android devices. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Background:&lt;/STRONG&gt; The supplicant policies have already been configured under the authorization policy in ISE. So far, the other devices are provisioning and onboarding without any issue. The Android devices are able to download the Cisco Network Setup Assistant however when trying to download the supplicant profile, an error message stating "&lt;STRONG&gt;Unable to detect Server. Please ensure your network access device is configured to redirect enroll.cisco.com to ISE"&lt;/STRONG&gt; On the NSP_GOOGLE_ACL, i have already permitted 72.163.0.0 but still the issue persists.&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;STRONG&gt;WLC&lt;/STRONG&gt; - 8.0.133&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;STRONG&gt;ISE&lt;/STRONG&gt; - 2.2 Patch 2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;Based on the Android workflow which was published in &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;STRONG&gt;Using Certificates for Differentiate Access &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;STRONG&gt;with Cisco Identity Services Engine&lt;/STRONG&gt;, the flow stopped as shown in the image below.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;IMG alt="Untitled-2.jpg" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/110815_Untitled-2.jpg" style="height: 332px; width: 620px;" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When checking the spw.log on the android device, it shows that the gateway is unreachable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: 'courier new', courier;"&gt;2017.08.29 10:27:16 ERROR:java.net.SocketTimeoutException: failed to connect to /10.8.12.1 (port 80) after 2000ms&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 10pt;"&gt;2017.08.29 10:27:16 ERROR:failed to connect to /10.8.12.1 (port 80) after 2000ms&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 10pt;"&gt;2017.08.29 10:27:19 ERROR:DiscoverAsynchTask&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 10pt;"&gt;2017.08.29 10:27:19 ERROR:java.net.SocketTimeoutException: failed to connect to enroll.cisco.com/72.163.1.80 (port 80) after 2000ms&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 10pt;"&gt;2017.08.29 10:27:19 ERROR:failed to connect to enroll.cisco.com/72.163.1.80 (port 80) after 2000ms&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 10pt;"&gt;2017.08.29 10:27:19 ERROR:Unable to discover ISE Server&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: 'courier new', courier;"&gt;2017.08.29 10:27:19 INFO:Internal system error.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to know if we are actually suppose to use the NSP-ACL-GOOGLE to download the supplicant profile and certificate.&lt;/P&gt;&lt;P&gt;Somehow if the device is on the CWA Redirection ACL , it's able to download the supplicant profile without any issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone experienced this issue before?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ryan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Aug 2017 02:46:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/android-devices-unable-to-download-byod-profile/m-p/3598684#M527293</guid>
      <dc:creator>ryan.chen</dc:creator>
      <dc:date>2017-08-29T02:46:48Z</dc:date>
    </item>
    <item>
      <title>Re: Android Devices unable to download BYOD profile</title>
      <link>https://community.cisco.com/t5/network-access-control/android-devices-unable-to-download-byod-profile/m-p/3598685#M527294</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: arial, helvetica, sans-serif;"&gt;Ryan, I would suggest removing the ACE permitting traffic to enroll.cisco.com or 72.163.0.0/16 from the NSP_GOOGLE_ACL. I know it sounds counter intuitive, but when it reads '&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; font-family: arial, helvetica, sans-serif;"&gt;Please ensure your network access device is configured to redirect enroll.cisco.com to ISE', it is asking you to configure the ACL so the traffic to enroll.cisco.com gets denied by the redirect ACL and gets redirected to the ISE per redirect process on the network device. By removing the line, you are letting the implicit deny take care of it. As you can see that is why the CWA ACL works as it is denying the traffic to the enroll.cisco.com. This is how client application like NSP or AnyConnect posture module finds the correct ISE node.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Aug 2017 15:16:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/android-devices-unable-to-download-byod-profile/m-p/3598685#M527294</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2017-08-29T15:16:54Z</dc:date>
    </item>
    <item>
      <title>Re: Android Devices unable to download BYOD profile</title>
      <link>https://community.cisco.com/t5/network-access-control/android-devices-unable-to-download-byod-profile/m-p/3598686#M527295</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Howon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your response. I've tried the following and I was able to obtain the supplicant profile from ISE after that. &lt;IMG src="https://community.cisco.com/legacyfs/online/emoticons/happy.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ryan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Aug 2017 02:53:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/android-devices-unable-to-download-byod-profile/m-p/3598686#M527295</guid>
      <dc:creator>ryan.chen</dc:creator>
      <dc:date>2017-08-30T02:53:55Z</dc:date>
    </item>
    <item>
      <title>Re: Android Devices unable to download BYOD profile</title>
      <link>https://community.cisco.com/t5/network-access-control/android-devices-unable-to-download-byod-profile/m-p/3598687#M527296</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I get the same &lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;"&lt;/SPAN&gt;&lt;STRONG style="font-size: 12px; font-family: arial; color: #3d3d3d;"&gt;Unable to detect Server. Please ensure your network access device is configured to redirect enroll.cisco.com to ISE"&lt;/STRONG&gt; message. But my ACL on WLC has already denied everything, including traffic to "enroll.cisco.com". &lt;/P&gt;&lt;P&gt;&lt;IMG alt="ise6.png" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/117829_ise6.png" style="height: 122px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I Also permitted every traffic between that network destined everywhere. So why do I get this message on my Android device?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jun 2018 09:52:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/android-devices-unable-to-download-byod-profile/m-p/3598687#M527296</guid>
      <dc:creator>ciscoworlds</dc:creator>
      <dc:date>2018-06-26T09:52:02Z</dc:date>
    </item>
    <item>
      <title>Re: Android Devices unable to download BYOD profile</title>
      <link>https://community.cisco.com/t5/network-access-control/android-devices-unable-to-download-byod-profile/m-p/3700388#M527297</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/301947"&gt;@ciscoworlds&lt;/a&gt; - did you ever solve the issue with the Android BYOD onboarding not working?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2018 13:43:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/android-devices-unable-to-download-byod-profile/m-p/3700388#M527297</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2018-09-04T13:43:38Z</dc:date>
    </item>
  </channel>
</rss>

