<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Android users not getting redirected to ISE captive portal in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/android-users-not-getting-redirected-to-ise-captive-portal/m-p/4829326#M255480</link>
    <description>&lt;P&gt;Packet capture on the Checkpoint and the Anchor WLC show the following multiple entries indicating that the android is not replying ARP broadcast from Checkpoint&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="arp request.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/183899i661E5208EA316931/image-size/large?v=v2&amp;amp;px=999" role="button" title="arp request.PNG" alt="arp request.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;172.16.157.252 is the DHCP IP assigned to the android &amp;amp;&amp;nbsp;172.16.157.3 is the Checkpoint gateway.&lt;/P&gt;&lt;P&gt;Show arp command on Checkpoint, which eventually times out as there is no response from the android.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="incomplete arp.PNG" style="width: 924px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/183901iD03B625BA3DB69BD/image-size/large?v=v2&amp;amp;px=999" role="button" title="incomplete arp.PNG" alt="incomplete arp.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 05 May 2023 14:16:00 GMT</pubDate>
    <dc:creator>tmnetsec</dc:creator>
    <dc:date>2023-05-05T14:16:00Z</dc:date>
    <item>
      <title>Android users not getting redirected to ISE captive portal</title>
      <link>https://community.cisco.com/t5/wireless/android-users-not-getting-redirected-to-ise-captive-portal/m-p/4829134#M255463</link>
      <description>&lt;P&gt;We have recently deployed a wireless guest CWA solution that involves 9800 WLCs, ISE and Checkpoint firewalls. Our topology is&lt;/P&gt;&lt;P&gt;Guest VLAN 100 -&amp;gt;AP-&amp;gt;Primary WLC&amp;lt;via mobility&amp;gt;Anchor WLC&amp;lt;&amp;gt;Checkpoint Int4.100 (VLAN interface)&lt;/P&gt;&lt;P&gt;ISE&amp;lt;&amp;gt;Checkpoint Int5&lt;/P&gt;&lt;P&gt;Android users are getting a dhcp IP but are not getting redirected to the ISE portal for guest registration. The issue observed is that the Checkpoint sends a broadcast requesting the IP of the android mac address and does not get a response back from the android. The arp entry on the Checkpoint shows as 'Incomplete' and is eventually removed from the arp cache as the android does not respond to this request. Disabling randomized mac address feature on the android sometimes helps and the user gets the ISE portal, but this is not always the case.&lt;/P&gt;&lt;P&gt;The ISE logs show that it issues the redirect ACL and an essential license is consumed. The guest vlan DHCP scope was configured on the anchor WLC and was later moved to the Checkpoint but the issue persisted.&lt;/P&gt;&lt;P&gt;Other devices like Apple devices, laptops, etc get the captive portal and can connect fine. Out of ideas at the moment.&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2023 09:52:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/android-users-not-getting-redirected-to-ise-captive-portal/m-p/4829134#M255463</guid>
      <dc:creator>tmnetsec</dc:creator>
      <dc:date>2023-05-05T09:52:07Z</dc:date>
    </item>
    <item>
      <title>Re: Android users not getting redirected to ISE captive portal</title>
      <link>https://community.cisco.com/t5/wireless/android-users-not-getting-redirected-to-ise-captive-portal/m-p/4829326#M255480</link>
      <description>&lt;P&gt;Packet capture on the Checkpoint and the Anchor WLC show the following multiple entries indicating that the android is not replying ARP broadcast from Checkpoint&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="arp request.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/183899i661E5208EA316931/image-size/large?v=v2&amp;amp;px=999" role="button" title="arp request.PNG" alt="arp request.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;172.16.157.252 is the DHCP IP assigned to the android &amp;amp;&amp;nbsp;172.16.157.3 is the Checkpoint gateway.&lt;/P&gt;&lt;P&gt;Show arp command on Checkpoint, which eventually times out as there is no response from the android.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="incomplete arp.PNG" style="width: 924px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/183901iD03B625BA3DB69BD/image-size/large?v=v2&amp;amp;px=999" role="button" title="incomplete arp.PNG" alt="incomplete arp.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2023 14:16:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/android-users-not-getting-redirected-to-ise-captive-portal/m-p/4829326#M255480</guid>
      <dc:creator>tmnetsec</dc:creator>
      <dc:date>2023-05-05T14:16:00Z</dc:date>
    </item>
    <item>
      <title>Re: Android users not getting redirected to ISE captive portal</title>
      <link>https://community.cisco.com/t5/wireless/android-users-not-getting-redirected-to-ise-captive-portal/m-p/4829383#M255486</link>
      <description>&lt;P&gt;What model of 9800?&lt;BR /&gt;What version of software?&lt;/P&gt;
&lt;P&gt;Have you looked at the ARP proxy feature?&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-3/config-guide/b_wl_17_3_cg/m_arp_proxy.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-3/config-guide/b_wl_17_3_cg/m_arp_proxy.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2023 15:27:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/android-users-not-getting-redirected-to-ise-captive-portal/m-p/4829383#M255486</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2023-05-05T15:27:47Z</dc:date>
    </item>
    <item>
      <title>Re: Android users not getting redirected to ISE captive portal</title>
      <link>https://community.cisco.com/t5/wireless/android-users-not-getting-redirected-to-ise-captive-portal/m-p/4829391#M255488</link>
      <description>&lt;P&gt;Foreign WLC is 9800-40 and Anchor WLC is 9800-L. Both running 17.3.6&lt;/P&gt;&lt;P&gt;Yes, I have the arp proxy feature enabled.&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2023 15:40:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/android-users-not-getting-redirected-to-ise-captive-portal/m-p/4829391#M255488</guid>
      <dc:creator>tmnetsec</dc:creator>
      <dc:date>2023-05-05T15:40:04Z</dc:date>
    </item>
    <item>
      <title>Re: Android users not getting redirected to ISE captive portal</title>
      <link>https://community.cisco.com/t5/wireless/android-users-not-getting-redirected-to-ise-captive-portal/m-p/4829419#M255490</link>
      <description>&lt;P&gt;I should also have asked what model of AP?&lt;/P&gt;
&lt;P&gt;- The wave 2 AP bugs (see Leo's list below) are mostly supposed to be resolved in 17.3.6.&amp;nbsp; Do you also have all the 17.3.6 APSP's installed (if not you should)?&amp;nbsp; &amp;nbsp;17.3.7 (which includes all the APSP fixes) is also out now but ...&lt;BR /&gt;- I'm a bit dubious about all the strange problems like this which people report in 17.3.&amp;nbsp; We never used it - we couldn't go live till 17.6 (needs features which only came after 17.3) and have been on that and 17.9 since and quite stable.&amp;nbsp; 17.3 is now approaching end of life so it might be a good idea to start planning upgrade to 17.6.5 or 17.9.3 anyway and if you're lucky it might even resolve your issue otherwise I think you're heading for a TAC case.&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2023 16:25:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/android-users-not-getting-redirected-to-ise-captive-portal/m-p/4829419#M255490</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2023-05-05T16:25:59Z</dc:date>
    </item>
    <item>
      <title>Re: Android users not getting redirected to ISE captive portal</title>
      <link>https://community.cisco.com/t5/wireless/android-users-not-getting-redirected-to-ise-captive-portal/m-p/4831549#M255601</link>
      <description>&lt;P&gt;Hi Richard - The AP's are 9130AXE running the&amp;nbsp;&lt;SPAN&gt;17.3.6.76 code.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 08:12:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/android-users-not-getting-redirected-to-ise-captive-portal/m-p/4831549#M255601</guid>
      <dc:creator>tmnetsec</dc:creator>
      <dc:date>2023-05-09T08:12:19Z</dc:date>
    </item>
    <item>
      <title>Re: Android users not getting redirected to ISE captive portal</title>
      <link>https://community.cisco.com/t5/wireless/android-users-not-getting-redirected-to-ise-captive-portal/m-p/4831554#M255602</link>
      <description>&lt;P&gt;I have found a workaround. From the android phone's chrome browser, if I manually type the IP address of the Checkpoint (gateway IP), the Checkpoint learns the mac address of the android and then the ISE's portal page opens up in a new window.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thinking this could be the android phones as the Apple and Windows device can connect without any issues. But the same android phone works in public cafes, hotels, etc without any issues.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just an FYI, the Checkpoint gateways are running R81.10 with the latest JHF.&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 08:24:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/android-users-not-getting-redirected-to-ise-captive-portal/m-p/4831554#M255602</guid>
      <dc:creator>tmnetsec</dc:creator>
      <dc:date>2023-05-09T08:24:07Z</dc:date>
    </item>
    <item>
      <title>Re: Android users not getting redirected to ISE captive portal</title>
      <link>https://community.cisco.com/t5/wireless/android-users-not-getting-redirected-to-ise-captive-portal/m-p/4832737#M255682</link>
      <description>&lt;P&gt;Do the WLCs forward the broadcast via the capwap tunnel towards the APs/wireless clients? Packet captures on the anchor and foreign WLC show that the broadcast is received from the Checkpoint but I cannot tell whether the broadcast is being forwarded towards the AP and wireless clients.&lt;/P&gt;&lt;P&gt;Is there any way I can do a capture on the AP to see the arp broadcast? Cant find any software which does packet captures on android.&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2023 16:15:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/android-users-not-getting-redirected-to-ise-captive-portal/m-p/4832737#M255682</guid>
      <dc:creator>tmnetsec</dc:creator>
      <dc:date>2023-05-10T16:15:56Z</dc:date>
    </item>
    <item>
      <title>Re: Android users not getting redirected to ISE captive portal</title>
      <link>https://community.cisco.com/t5/wireless/android-users-not-getting-redirected-to-ise-captive-portal/m-p/4867188#M257766</link>
      <description>&lt;P&gt;We have similar problem (android, widows,..), client does not receive DNS replays from DNS server, so no any web authentication page is open. As initial workarround we enabled "passive client" for the involved Policy. Cisco is working on a solution.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jul 2023 17:03:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/android-users-not-getting-redirected-to-ise-captive-portal/m-p/4867188#M257766</guid>
      <dc:creator>SPCNET soluciones de negocio electronico</dc:creator>
      <dc:date>2023-07-04T17:03:04Z</dc:date>
    </item>
    <item>
      <title>Re: Android users not getting redirected to ISE captive portal</title>
      <link>https://community.cisco.com/t5/wireless/android-users-not-getting-redirected-to-ise-captive-portal/m-p/4954738#M262645</link>
      <description>&lt;P&gt;Did you find any solution other then typing the IP address ? We have the exact same situation with Checkpoint Gateway and no redirect to ISE Guestportal only for Android devices.&lt;/P&gt;&lt;P&gt;BR and Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2023 07:05:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/android-users-not-getting-redirected-to-ise-captive-portal/m-p/4954738#M262645</guid>
      <dc:creator>klausi</dc:creator>
      <dc:date>2023-11-07T07:05:42Z</dc:date>
    </item>
  </channel>
</rss>

