<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: BYOD Android DNS-based ACL in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/byod-android-dns-based-acl/m-p/3488779#M539750</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Keep in mind the AP only supports so many named based ACLs, not all of these might be needed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An alternative is to have a peap ssid where user is allowed Internet to download the app and when they try to access internal resources they are redirected to on boarding portal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or user grabs app from another network&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 02 Mar 2016 14:32:56 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2016-03-02T14:32:56Z</dc:date>
    <item>
      <title>BYOD Android DNS-based ACL</title>
      <link>https://community.cisco.com/t5/network-access-control/byod-android-dns-based-acl/m-p/3488773#M539743</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have many questions from the Customers how to configure ACLs on the WLC for Android clients to get access to the Play Market during BYOD onboarding (in order to download Network setup assistant).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately we don't have any document that specifies what should be configured. The Customers are complaining that IP addresses of Google services are changed very often, so they need to re-configure them all the time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we tried to add the following URLs to the Redirect ACL but still it didn't work for us:&lt;/P&gt;&lt;P&gt;accounts.google.com&lt;/P&gt;&lt;P&gt;googleapis.com&lt;/P&gt;&lt;P&gt;play.google.com&lt;/P&gt;&lt;P&gt;android.pool.ntp.org&lt;/P&gt;&lt;P&gt;market.android.com&lt;/P&gt;&lt;P&gt;support.google.com&lt;/P&gt;&lt;P&gt;ggpht.com&lt;/P&gt;&lt;P&gt;mtalk.google.com&lt;/P&gt;&lt;P&gt;android.clients.google.com&lt;/P&gt;&lt;P&gt;android.l.google.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do we have any official recommendations regarding it that we can share with the Customers?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Feb 2016 13:14:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/byod-android-dns-based-acl/m-p/3488773#M539743</guid>
      <dc:creator>anvolkov</dc:creator>
      <dc:date>2016-02-26T13:14:15Z</dc:date>
    </item>
    <item>
      <title>Re: BYOD Android DNS-based ACL</title>
      <link>https://community.cisco.com/t5/network-access-control/byod-android-dns-based-acl/m-p/3488774#M539745</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you see this site? It has an entry for it&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;https://communities.cisco.com/docs/DOC-64033?mobileredirect=true&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also are you using a supported version of the WLC? There have been issues with dns based acls on certain releases best to check with authors&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;https://supportforums.cisco.com/document/12481821/tac-recommended-aireos&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Feb 2016 14:02:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/byod-android-dns-based-acl/m-p/3488774#M539745</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2016-02-26T14:02:33Z</dc:date>
    </item>
    <item>
      <title>Re: BYOD Android DNS-based ACL</title>
      <link>https://community.cisco.com/t5/network-access-control/byod-android-dns-based-acl/m-p/3488775#M539746</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jason, thank you!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So we need to add both URLs and IP addresses to the ACL? Also i have doubts regarding IP addresses for different regions. Will they be the same?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;About URL with asterisk (*.google.com) - based on our experience, the asterisk as added automatically even if it's not visible in GUI, please refer to the screenshots:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/93521_pastedImage_0.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jive-image image-2" src="https://community.cisco.com/legacyfs/online/fusion/93522_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding WLC versions - we even tested special BU release of 8.0.120.x where CSCuv82513 was resolved. We'll try to modify the URLs once again and test. I'm not only sure about the IP addresses, as I mentioned above...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Feb 2016 14:36:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/byod-android-dns-based-acl/m-p/3488775#M539746</guid>
      <dc:creator>anvolkov</dc:creator>
      <dc:date>2016-02-26T14:36:49Z</dc:date>
    </item>
    <item>
      <title>Re: BYOD Android DNS-based ACL</title>
      <link>https://community.cisco.com/t5/network-access-control/byod-android-dns-based-acl/m-p/3488776#M539747</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From what I understand is you allow the names you want to open (you don’t also need to duplicate with Ips). So as long as you get the names correct then it should work fine. Also need to make sure you are using supported AP for the DNS based ACL feature.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Feb 2016 17:52:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/byod-android-dns-based-acl/m-p/3488776#M539747</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2016-02-26T17:52:58Z</dc:date>
    </item>
    <item>
      <title>Re: BYOD Android DNS-based ACL</title>
      <link>https://community.cisco.com/t5/network-access-control/byod-android-dns-based-acl/m-p/3488777#M539748</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would suggest to check with Cisco wireless platform teams, as DNS-based ACL might not have been supported in certain wireless deployment scenarios.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Feb 2016 21:02:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/byod-android-dns-based-acl/m-p/3488777#M539748</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2016-02-26T21:02:28Z</dc:date>
    </item>
    <item>
      <title>Re: BYOD Android DNS-based ACL</title>
      <link>https://community.cisco.com/t5/network-access-control/byod-android-dns-based-acl/m-p/3488778#M539749</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;Thank you for your responses. We did an additional test from the rooted android device. We see the DNS requests to the following URLs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Safebrowsing.googleapis.com&lt;/P&gt;&lt;P&gt;Play.googleapis.com&lt;/P&gt;&lt;P&gt;googleapis.l.google.com&lt;/P&gt;&lt;P&gt;android.clients.google.com&lt;/P&gt;&lt;P&gt;beacons.gvt2.com&lt;/P&gt;&lt;P&gt;beacons2.gvt2.com&lt;/P&gt;&lt;P&gt;beacons3.gvt2.com&lt;/P&gt;&lt;P&gt;beacons4.gvt2.com&lt;/P&gt;&lt;P&gt;accounts.google.com&lt;/P&gt;&lt;P&gt;clients2.google.com&lt;/P&gt;&lt;P&gt;clients.l.google.com&lt;/P&gt;&lt;P&gt;play.google.com&lt;/P&gt;&lt;P&gt;ww3.l.google.com&lt;/P&gt;&lt;P&gt;apis.google.com&lt;/P&gt;&lt;P&gt;gstaticadsl.l.google.com&lt;/P&gt;&lt;P&gt;oauth.googleusercontent.com&lt;/P&gt;&lt;P&gt;googlehosted.googleusercontent.com&lt;/P&gt;&lt;P&gt;ssl.gstatic.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we will try to re-configure ACL once again and if it doesn't work then we'll contact wireless team once again. Thank you!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Mar 2016 14:17:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/byod-android-dns-based-acl/m-p/3488778#M539749</guid>
      <dc:creator>anvolkov</dc:creator>
      <dc:date>2016-03-02T14:17:38Z</dc:date>
    </item>
    <item>
      <title>Re: BYOD Android DNS-based ACL</title>
      <link>https://community.cisco.com/t5/network-access-control/byod-android-dns-based-acl/m-p/3488779#M539750</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Keep in mind the AP only supports so many named based ACLs, not all of these might be needed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An alternative is to have a peap ssid where user is allowed Internet to download the app and when they try to access internal resources they are redirected to on boarding portal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or user grabs app from another network&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Mar 2016 14:32:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/byod-android-dns-based-acl/m-p/3488779#M539750</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2016-03-02T14:32:56Z</dc:date>
    </item>
    <item>
      <title>Re: BYOD Android DNS-based ACL</title>
      <link>https://community.cisco.com/t5/network-access-control/byod-android-dns-based-acl/m-p/3488780#M539751</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;did you get the ACL sorted in the end ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Or is [1] the best guess ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;[1] &lt;A href="https://community.cisco.com/thread/62901"&gt;BYOD What sites do I need to open to support Android Playstore Google?&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jul 2016 04:08:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/byod-android-dns-based-acl/m-p/3488780#M539751</guid>
      <dc:creator>stephane.delort1</dc:creator>
      <dc:date>2016-07-08T04:08:38Z</dc:date>
    </item>
  </channel>
</rss>

