<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Android devices can't access wifi webauth 1.1.1.1/login.html in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/android-devices-can-t-access-wifi-webauth-1-1-1-1-login-html/m-p/5230985#M278349</link>
    <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/213535-wlc-virtual-ip-address-1-1-1-1.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/213535-wlc-virtual-ip-address-1-1-1-1.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;We already explained in the answers below but here goes again...&amp;nbsp; You could use any of the private subnets listed in the guide above but for your certificate to work 100% with modern devices you need a fully qualified domain name (FQDN) eg: &lt;STRONG&gt;mywlc.companyname.com&lt;/STRONG&gt;, which correctly matches the name on your certificate.&amp;nbsp; Your DNS for that FQDN needs to resolve to the virtual IP address you choose to configure.&amp;nbsp; It might be difficult for you to do that with a private IP.&amp;nbsp; In that case you need to use a registered public internet address.&amp;nbsp; Talk to your Internet Service Provider about how to get a public IP (some provide with the internet connection already).&amp;nbsp; Once you have that setup your redirect needs to use the FQDN not the IP address.&amp;nbsp; The requirement for the IP to be "unrouteable" just means you do not want anybody who is not a WLC client or on the internet to be able to reach it, so if you use a public IP then make sure to filter any internet traffic to that destination.&amp;nbsp; Only your wireless clients should ever be using that IP which will be intercepted by the WLC.&lt;/P&gt;
&lt;P&gt;A convenient side effect of this is that if you have multiple WLCs you can use the same FQDN and IP address on every WLC because it is always intercepted on the WLC so it becomes an anycast address.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisa.gov/news-events/news/understanding-website-certificates" target="_blank"&gt;https://www.cisa.gov/news-events/news/understanding-website-certificates&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://venafi.com/blog/how-does-browser-trust-certificate/" target="_blank"&gt;https://venafi.com/blog/how-does-browser-trust-certificate/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 01 Dec 2024 13:19:33 GMT</pubDate>
    <dc:creator>Rich R</dc:creator>
    <dc:date>2024-12-01T13:19:33Z</dc:date>
    <item>
      <title>Android devices can't access wifi webauth 1.1.1.1/login.html</title>
      <link>https://community.cisco.com/t5/wireless/android-devices-can-t-access-wifi-webauth-1-1-1-1-login-html/m-p/5216099#M277010</link>
      <description>&lt;P&gt;&lt;FONT size="4"&gt;Hi there;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;FONT size="4"&gt;Actually, I have wireless and I set the wifi access by web authatciin 1.1.1.1/login.html by username and password..&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="4"&gt;&lt;STRONG&gt;&lt;FONT color="#3366FF"&gt;All devices can access to wifi except android devices when try's connect, we faced this message&lt;/FONT&gt;:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="4"&gt;&lt;STRONG&gt;&lt;FONT color="#FF6600"&gt;- The message of error err_ssl_version_or_cipher_mismatch &lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="4"&gt;&lt;U&gt;&lt;EM&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;How can we solve that? Thanks&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/EM&gt;&lt;/U&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2024 10:56:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/android-devices-can-t-access-wifi-webauth-1-1-1-1-login-html/m-p/5216099#M277010</guid>
      <dc:creator>sulimanalassiry</dc:creator>
      <dc:date>2024-10-28T10:56:46Z</dc:date>
    </item>
    <item>
      <title>Re: Android devices can't access wifi webauth 1.1.1.1/login.html</title>
      <link>https://community.cisco.com/t5/wireless/android-devices-can-t-access-wifi-webauth-1-1-1-1-login-html/m-p/5216116#M277011</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Could you start by no longer using&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;1.1.1&lt;/STRONG&gt;.&lt;STRONG&gt;1&lt;/STRONG&gt;&lt;/FONT&gt; for web authentication (and or redirect) , because these days the address is owned by &lt;STRONG&gt;Cloudfare&lt;/STRONG&gt; and that might result in side effects such as you are seeing&amp;nbsp; , &lt;U&gt;&lt;FONT color="#008000"&gt;&lt;EM&gt;use a (real) private address instead ,&lt;/EM&gt;&lt;/FONT&gt;&lt;/U&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;M.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2024 11:34:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/android-devices-can-t-access-wifi-webauth-1-1-1-1-login-html/m-p/5216116#M277011</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-10-28T11:34:30Z</dc:date>
    </item>
    <item>
      <title>Re: Android devices can't access wifi webauth 1.1.1.1/login.html</title>
      <link>https://community.cisco.com/t5/wireless/android-devices-can-t-access-wifi-webauth-1-1-1-1-login-html/m-p/5216478#M277047</link>
      <description>&lt;P&gt;If your doing Local Web Auth make sure you have a publicly signed certificate on the WLC&lt;/P&gt;&lt;P&gt;also as stated do not use 1.1.1.1 as the virtual IP&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2024 22:20:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/android-devices-can-t-access-wifi-webauth-1-1-1-1-login-html/m-p/5216478#M277047</guid>
      <dc:creator>Haydn Andrews</dc:creator>
      <dc:date>2024-10-28T22:20:53Z</dc:date>
    </item>
    <item>
      <title>Re: Android devices can't access wifi webauth 1.1.1.1/login.html</title>
      <link>https://community.cisco.com/t5/wireless/android-devices-can-t-access-wifi-webauth-1-1-1-1-login-html/m-p/5216654#M277065</link>
      <description>&lt;P&gt;Also what model of WLC are you using and what version of software?&lt;BR /&gt;See the TAC recommended link below for TAC recommended software versions.&lt;/P&gt;
&lt;P&gt;Your redirect URL should be using a DNS resolved FQDN with matching publicly signed certificate (as Haydn has highlighted) because most modern browsers and OS will not trust IP based URL and self-signed certificates.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Oct 2024 09:32:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/android-devices-can-t-access-wifi-webauth-1-1-1-1-login-html/m-p/5216654#M277065</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2024-10-29T09:32:30Z</dc:date>
    </item>
    <item>
      <title>Re: Android devices can't access wifi webauth 1.1.1.1/login.html</title>
      <link>https://community.cisco.com/t5/wireless/android-devices-can-t-access-wifi-webauth-1-1-1-1-login-html/m-p/5230920#M278331</link>
      <description>&lt;P&gt;Thanks much for comment; but how do "&lt;SPAN&gt;&lt;U&gt;&lt;FONT color="#008000"&gt;&lt;EM&gt;use a (real) private address instead ,&lt;/EM&gt;&lt;/FONT&gt;&lt;/U&gt;&lt;/SPAN&gt;"?&lt;/P&gt;&lt;P&gt;What these steps for configure that?.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 01 Dec 2024 08:15:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/android-devices-can-t-access-wifi-webauth-1-1-1-1-login-html/m-p/5230920#M278331</guid>
      <dc:creator>sulimanalassiry</dc:creator>
      <dc:date>2024-12-01T08:15:09Z</dc:date>
    </item>
    <item>
      <title>Re: Android devices can't access wifi webauth 1.1.1.1/login.html</title>
      <link>https://community.cisco.com/t5/wireless/android-devices-can-t-access-wifi-webauth-1-1-1-1-login-html/m-p/5230948#M278344</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;- Checkout :&amp;nbsp;&lt;A href="https://community.cisco.com/t5/wireless/setting-management-interface-wlc-7-4-121-0/m-p/2557362/highlight/true#M116897" target="_blank"&gt;https://community.cisco.com/t5/wireless/setting-management-interface-wlc-7-4-121-0/m-p/2557362/highlight/true#M116897&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Sun, 01 Dec 2024 10:44:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/android-devices-can-t-access-wifi-webauth-1-1-1-1-login-html/m-p/5230948#M278344</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-12-01T10:44:47Z</dc:date>
    </item>
    <item>
      <title>Re: Android devices can't access wifi webauth 1.1.1.1/login.html</title>
      <link>https://community.cisco.com/t5/wireless/android-devices-can-t-access-wifi-webauth-1-1-1-1-login-html/m-p/5230985#M278349</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/213535-wlc-virtual-ip-address-1-1-1-1.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/213535-wlc-virtual-ip-address-1-1-1-1.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;We already explained in the answers below but here goes again...&amp;nbsp; You could use any of the private subnets listed in the guide above but for your certificate to work 100% with modern devices you need a fully qualified domain name (FQDN) eg: &lt;STRONG&gt;mywlc.companyname.com&lt;/STRONG&gt;, which correctly matches the name on your certificate.&amp;nbsp; Your DNS for that FQDN needs to resolve to the virtual IP address you choose to configure.&amp;nbsp; It might be difficult for you to do that with a private IP.&amp;nbsp; In that case you need to use a registered public internet address.&amp;nbsp; Talk to your Internet Service Provider about how to get a public IP (some provide with the internet connection already).&amp;nbsp; Once you have that setup your redirect needs to use the FQDN not the IP address.&amp;nbsp; The requirement for the IP to be "unrouteable" just means you do not want anybody who is not a WLC client or on the internet to be able to reach it, so if you use a public IP then make sure to filter any internet traffic to that destination.&amp;nbsp; Only your wireless clients should ever be using that IP which will be intercepted by the WLC.&lt;/P&gt;
&lt;P&gt;A convenient side effect of this is that if you have multiple WLCs you can use the same FQDN and IP address on every WLC because it is always intercepted on the WLC so it becomes an anycast address.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisa.gov/news-events/news/understanding-website-certificates" target="_blank"&gt;https://www.cisa.gov/news-events/news/understanding-website-certificates&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://venafi.com/blog/how-does-browser-trust-certificate/" target="_blank"&gt;https://venafi.com/blog/how-does-browser-trust-certificate/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 01 Dec 2024 13:19:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/android-devices-can-t-access-wifi-webauth-1-1-1-1-login-html/m-p/5230985#M278349</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2024-12-01T13:19:33Z</dc:date>
    </item>
    <item>
      <title>Re: Android devices can't access wifi webauth 1.1.1.1/login.html</title>
      <link>https://community.cisco.com/t5/wireless/android-devices-can-t-access-wifi-webauth-1-1-1-1-login-html/m-p/5231052#M278360</link>
      <description>&lt;P&gt;he error "err_ssl_version_or_cipher_mismatch" on Android devices indicates an incompatibility with the SSL/TLS protocol versions and cipher suites. To resolve this:&lt;/P&gt;&lt;P&gt;Update Android Device Firmware: Ensure the latest firmware is installed.&lt;BR /&gt;Configure Web Authentication Server: Enable TLS 1.2 and 1.3, use strong cipher suites, and verify the CA certificate.&lt;BR /&gt;Android Device Network Settings: Clear network settings, forget the Wi-Fi network, and reconnect.&lt;BR /&gt;Additionally, check firewall rules, DNS settings, and browser settings.&lt;/P&gt;</description>
      <pubDate>Sun, 01 Dec 2024 20:42:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/android-devices-can-t-access-wifi-webauth-1-1-1-1-login-html/m-p/5231052#M278360</guid>
      <dc:creator>nnemrmaika</dc:creator>
      <dc:date>2024-12-01T20:42:52Z</dc:date>
    </item>
  </channel>
</rss>

