<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Guest access - Redirection issue on ios16 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/guest-access-redirection-issue-on-ios16/m-p/4823500#M581435</link>
    <description>&lt;P&gt;But why are you exposing internal name space to guest users? Also not really a best practice to expose internal DNS server (most often also a domain controller) to untrusted guest endpoints. Why not deploy a dedicated ISE guest node in a protected DMZ on public name space. Or configure a second NIC on an ISE node to service guests with a public FQDN?&lt;/P&gt;</description>
    <pubDate>Fri, 28 Apr 2023 03:23:58 GMT</pubDate>
    <dc:creator>ahollifield</dc:creator>
    <dc:date>2023-04-28T03:23:58Z</dc:date>
    <item>
      <title>Guest access - Redirection issue on ios16</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-access-redirection-issue-on-ios16/m-p/4820958#M581364</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;We have an issue with ios16 where guest access is not working due to failures at the redirection phase.&amp;nbsp;This issue happens only with iPhone while it's working totally fine with Windows or Androids.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After some checking and troubleshooting we found that there is a behavior change starting from ios16 to use public DNS servers instead of the private ones. This is mentioned here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.arubanetworks.com/discussion/apple-ios-devices-not-open-captive-portal-login-page-automatically" target="_blank" rel="noopener"&gt;https://community.arubanetworks.com/discussion/apple-ios-devices-not-open-captive-portal-login-page-automatically&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://developer.apple.com/forums/thread/715416" target="_blank" rel="noopener"&gt;https://developer.apple.com/forums/thread/715416&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;We already had a case with Cisco TAC but they ended up recommending us to reach for Apple support since this is an iPhone issue and ask for a fix but this seems like a dead end to me.&amp;nbsp;&lt;BR /&gt;I was wondering if anyone else faced this issue? and the recommended way to fix it?&lt;BR /&gt;&lt;BR /&gt;Best regards,&lt;BR /&gt;Tariq&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 06:44:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-access-redirection-issue-on-ios16/m-p/4820958#M581364</guid>
      <dc:creator>Tariq Mahmoud</dc:creator>
      <dc:date>2023-04-25T06:44:23Z</dc:date>
    </item>
    <item>
      <title>Re: Guest access - Redirection issue on ios16</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-access-redirection-issue-on-ios16/m-p/4821617#M581377</link>
      <description>&lt;P&gt;Why not just allow DNS to any server?&amp;nbsp; Or am I misunderstanding something here?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 22:42:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-access-redirection-issue-on-ios16/m-p/4821617#M581377</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2023-04-25T22:42:14Z</dc:date>
    </item>
    <item>
      <title>Re: Guest access - Redirection issue on ios16</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-access-redirection-issue-on-ios16/m-p/4821715#M581381</link>
      <description>Hi, can u explain further how the DNS bug is impacting your redirection. In&lt;BR /&gt;theory you shouldn't set internal and external DNS in your dhcp options.&lt;BR /&gt;Only point to internet DNS with HA and that is set to DNS forwarder.&lt;BR /&gt;</description>
      <pubDate>Wed, 26 Apr 2023 01:42:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-access-redirection-issue-on-ios16/m-p/4821715#M581381</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2023-04-26T01:42:59Z</dc:date>
    </item>
    <item>
      <title>Re: Guest access - Redirection issue on ios16</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-access-redirection-issue-on-ios16/m-p/4822260#M581389</link>
      <description>&lt;P&gt;DNS traffic is already allowed in the redirect ACL if that's what you are asking for. However, if endpoints want to reach ISE captive portal, they should query the internal DNS so that they can reach ISE. &lt;BR /&gt;What we have seen with ios16 is that it ignores the local DNS and always go for the public DNS server and captive.apple.com and hence have no idea about the captive portal of our ISE setup.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2023 14:20:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-access-redirection-issue-on-ios16/m-p/4822260#M581389</guid>
      <dc:creator>Tariq Mahmoud</dc:creator>
      <dc:date>2023-04-26T14:20:27Z</dc:date>
    </item>
    <item>
      <title>Re: Guest access - Redirection issue on ios16</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-access-redirection-issue-on-ios16/m-p/4823500#M581435</link>
      <description>&lt;P&gt;But why are you exposing internal name space to guest users? Also not really a best practice to expose internal DNS server (most often also a domain controller) to untrusted guest endpoints. Why not deploy a dedicated ISE guest node in a protected DMZ on public name space. Or configure a second NIC on an ISE node to service guests with a public FQDN?&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2023 03:23:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-access-redirection-issue-on-ios16/m-p/4823500#M581435</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2023-04-28T03:23:58Z</dc:date>
    </item>
    <item>
      <title>Re: Guest access - Redirection issue on ios16</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-access-redirection-issue-on-ios16/m-p/4824182#M581437</link>
      <description>&lt;P&gt;personally, I just added ISE to our external DNS but with the internal IP address so they get to the portal. Our guest is behind a firewall, but can be allowed to talk to out ISE servers on the ports for the portals.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2023 13:41:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-access-redirection-issue-on-ios16/m-p/4824182#M581437</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2023-04-28T13:41:22Z</dc:date>
    </item>
    <item>
      <title>Re: Guest access - Redirection issue on ios16</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-access-redirection-issue-on-ios16/m-p/4897975#M583249</link>
      <description>&lt;P&gt;We have restarted the wireless controller and after that the issue got fixed. We haven't seen the issue again for a while now and all works fine.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2023 01:14:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-access-redirection-issue-on-ios16/m-p/4897975#M583249</guid>
      <dc:creator>Tariq Mahmoud</dc:creator>
      <dc:date>2023-08-03T01:14:41Z</dc:date>
    </item>
    <item>
      <title>Re: Guest access - Redirection issue on ios16</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-access-redirection-issue-on-ios16/m-p/4898970#M583295</link>
      <description>&lt;P&gt;What was your controller and ISE version?&lt;/P&gt;</description>
      <pubDate>Fri, 04 Aug 2023 19:02:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-access-redirection-issue-on-ios16/m-p/4898970#M583295</guid>
      <dc:creator>hakheman</dc:creator>
      <dc:date>2023-08-04T19:02:31Z</dc:date>
    </item>
    <item>
      <title>Re: Guest access - Redirection issue on ios16</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-access-redirection-issue-on-ios16/m-p/4899614#M583301</link>
      <description>&lt;P&gt;WLC is 8.10 (foreign/anchor setup) and ISE is 3.1.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Based on my observations, it could be that the configurations were not active for some reason. What I did was configuring the SSID from scratch, then reloaded the WLC and after that all worked fine on iphone.&lt;/P&gt;</description>
      <pubDate>Sun, 06 Aug 2023 12:33:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-access-redirection-issue-on-ios16/m-p/4899614#M583301</guid>
      <dc:creator>Tariq Mahmoud</dc:creator>
      <dc:date>2023-08-06T12:33:15Z</dc:date>
    </item>
  </channel>
</rss>

