<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: iOS IP Conflicts in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517595#M306818</link>
    <description>&lt;P&gt;Hey everyone, MX Support Specialist chiming in here.&lt;/P&gt;&lt;P&gt;We opened up a case with Apple this morning, because it looks like iOS devices with this feature enabled are doing something a little weird with ARP requests:&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-09-24 at 9.48.15 AM.png" style="width: 999px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/269668i36CB25DB35B15BD4/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;If you look at frame 548 in that packet capture screenshot, you can see that it's an ARP response sourced from one MAC address, but saying that the IP in question belongs to a completely &lt;EM&gt;different&lt;/EM&gt; MAC address.&lt;/P&gt;&lt;P&gt;Then, later on, in 964, you see it respond again, but this time it says the IP, correctly, belongs to the same MAC as what's seen in the Ethernet source address.&lt;/P&gt;&lt;P&gt;It's this disparity that's causing these duplicate IP alerts, because MX's rely on ARP mappings to verify that two devices aren't trying to both use the same IP address.&lt;/P&gt;&lt;P&gt;Once we have a better idea on how they plan to address this, I'll be sure to share what updates I can provide here.&lt;/P&gt;</description>
    <pubDate>Thu, 24 Sep 2020 19:56:43 GMT</pubDate>
    <dc:creator>alexapie</dc:creator>
    <dc:date>2020-09-24T19:56:43Z</dc:date>
    <item>
      <title>iOS IP Conflicts</title>
      <link>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517589#M306812</link>
      <description>&lt;P&gt;I have multiple sites sending alerts for IP conflicts recently. It is only iPhones, and only on our wireless. I have SSIDs and a VLAN setup dedicated just to mobile phones, and the MX running as DHCP server for that VLAN. This was not an issue until two or three weeks ago but we are getting two to three alerts for different sites almost every day. Anyone have any idea where to start looking on how to fix this? Is this another iOS bug?&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2020 17:55:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517589#M306812</guid>
      <dc:creator>TimBisel</dc:creator>
      <dc:date>2020-09-24T17:55:16Z</dc:date>
    </item>
    <item>
      <title>Re: iOS IP Conflicts</title>
      <link>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517590#M306813</link>
      <description>&lt;P&gt;Check network settings. iOS made an update that randomizes MAC addresses. &lt;/P&gt;&lt;P&gt;&lt;A href="https://community.meraki.com/t5/Wireless-LAN/MAC-Randomization-using-IOS14-and-Android-10-and-above/m-p/98354" target="_blank"&gt;https://community.meraki.com/t5/Wireless-LAN/MAC-Randomization-using-IOS14-and-Android-10-and-above/m-p/98354&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2020 18:09:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517590#M306813</guid>
      <dc:creator>kYutobi</dc:creator>
      <dc:date>2020-09-24T18:09:57Z</dc:date>
    </item>
    <item>
      <title>Re: iOS IP Conflicts</title>
      <link>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517591#M306814</link>
      <description>&lt;P&gt;iOS 14 makes randomizes MAC addresses default.  You have some options.  You can turn that feature off in network settings on the devices, you can disable the annoying alerts from Meraki Dashboard.  You can try a shorter DHCP lease time.&lt;/P&gt;&lt;P&gt;There are probably other options too.  It is not an Apple bug or specific to Apple though. AFAIK, Android and Windows, etc. do this also, but may not be enabled at default.  Since Apple prides itself on their privacy and security posture it makes sense they turned it on at default.  &lt;/P&gt;&lt;P&gt;I know I am drifting off topic, but ultimately this is a "good thing" because MAC addresses are way too easy to connect to a person and that means good &lt;EM&gt;and&lt;/EM&gt; bad actors can track you too easily and without your permission so it needs to stop somehow..&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2020 18:17:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517591#M306814</guid>
      <dc:creator>Brandon Svec</dc:creator>
      <dc:date>2020-09-24T18:17:18Z</dc:date>
    </item>
    <item>
      <title>Re: iOS IP Conflicts</title>
      <link>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517592#M306815</link>
      <description>&lt;P&gt;On Sept 1, Apple released the 13.7 update that pertains to Covid tracing. My guess, since it's only started happening in the last couple weeks and only to iPhones, is the update is intent on trying to keep the same IP address for continuity of tracking. We all know how that goes when it comes to DHCP requests.&lt;/P&gt;&lt;P&gt;ETA- iOS 14 is only a week old, so while the randomized MAC address might be the issue, it wouldn't have started a couple weeks ago.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2020 18:20:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517592#M306815</guid>
      <dc:creator>Asavoy</dc:creator>
      <dc:date>2020-09-24T18:20:26Z</dc:date>
    </item>
    <item>
      <title>Re: iOS IP Conflicts</title>
      <link>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517593#M306816</link>
      <description>&lt;P&gt;This is from Apple and what is causing this issue.&lt;/P&gt;&lt;H1 id="toc-hId-481742036"&gt;Use private Wi-Fi addresses in iOS 14, iPadOS 14, and watchOS 7&lt;/H1&gt;&lt;DIV class="intro"&gt;&lt;P&gt;To further protect your privacy, your iPhone, iPad, iPod touch, or Apple Watch can use a different MAC address with each Wi-Fi network.&lt;/P&gt;&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;P&gt;To communicate with a Wi-Fi network, a device must identify itself to the network using a unique network address called a media access control (MAC) address. If the device always uses the same Wi-Fi MAC address across all networks, network operators and other network observers can more easily relate that address to the device's network activity and location over time. This allows a kind of user tracking or profiling, and it applies to all devices on all Wi-Fi networks.&lt;/P&gt;&lt;P&gt;To reduce this privacy risk, iOS 14, iPadOS 14, and watchOS 7 use a different MAC address for each Wi-Fi network. This unique, static MAC address is your device's private Wi-Fi address for that network only.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 24 Sep 2020 18:49:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517593#M306816</guid>
      <dc:creator>Gryffindor1</dc:creator>
      <dc:date>2020-09-24T18:49:37Z</dc:date>
    </item>
    <item>
      <title>Re: iOS IP Conflicts</title>
      <link>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517594#M306817</link>
      <description>&lt;P&gt;Thanks - This is a big help.  We were wondering why we kept getting conflict alerts all of a sudden. &lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2020 18:55:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517594#M306817</guid>
      <dc:creator>wtesolutions</dc:creator>
      <dc:date>2020-09-24T18:55:24Z</dc:date>
    </item>
    <item>
      <title>Re: iOS IP Conflicts</title>
      <link>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517595#M306818</link>
      <description>&lt;P&gt;Hey everyone, MX Support Specialist chiming in here.&lt;/P&gt;&lt;P&gt;We opened up a case with Apple this morning, because it looks like iOS devices with this feature enabled are doing something a little weird with ARP requests:&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-09-24 at 9.48.15 AM.png" style="width: 999px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/269668i36CB25DB35B15BD4/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;If you look at frame 548 in that packet capture screenshot, you can see that it's an ARP response sourced from one MAC address, but saying that the IP in question belongs to a completely &lt;EM&gt;different&lt;/EM&gt; MAC address.&lt;/P&gt;&lt;P&gt;Then, later on, in 964, you see it respond again, but this time it says the IP, correctly, belongs to the same MAC as what's seen in the Ethernet source address.&lt;/P&gt;&lt;P&gt;It's this disparity that's causing these duplicate IP alerts, because MX's rely on ARP mappings to verify that two devices aren't trying to both use the same IP address.&lt;/P&gt;&lt;P&gt;Once we have a better idea on how they plan to address this, I'll be sure to share what updates I can provide here.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2020 19:56:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517595#M306818</guid>
      <dc:creator>alexapie</dc:creator>
      <dc:date>2020-09-24T19:56:43Z</dc:date>
    </item>
    <item>
      <title>Re: iOS IP Conflicts</title>
      <link>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517596#M306819</link>
      <description>&lt;P&gt;Thanks &lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/180"&gt;@alexapie&lt;/A&gt; Good to know.  Subscribing to and bookmarking this post now..&lt;/P&gt;&lt;P&gt;Not totally off topic, but I read about a change to the way iOS 14 handles DNS today.  You might be interested: &lt;A href="https://mailman.nanog.org/pipermail/nanog/2020-September/209823.html" target="_blank" rel="nofollow noopener noreferrer"&gt;https://mailman.nanog.org/pipermail/nanog/2020-September/209823.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Best.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2020 20:12:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517596#M306819</guid>
      <dc:creator>Brandon Svec</dc:creator>
      <dc:date>2020-09-24T20:12:52Z</dc:date>
    </item>
    <item>
      <title>Re: iOS IP Conflicts</title>
      <link>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517597#M306820</link>
      <description>&lt;P&gt;&lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/180"&gt;@alexapie&lt;/A&gt; I believe this is the way Apple handles Bonjour sleep proxying, but recently it seems to have extended to more devices than just Apple TVs and HomePods that respond to ARPs on behalf of a sleeping client. It seems like if a client wants to go into deep sleep, it picks another awake client to answer on behalf of its IP. &lt;/P&gt;</description>
      <pubDate>Sun, 27 Sep 2020 17:11:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517597#M306820</guid>
      <dc:creator>JohnD3</dc:creator>
      <dc:date>2020-09-27T17:11:13Z</dc:date>
    </item>
    <item>
      <title>Re: iOS IP Conflicts</title>
      <link>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517598#M306821</link>
      <description>&lt;P&gt;Took DHCP leases down to an hour, still getting these stupid alerts.  Dont want to disable the alerts, but we currently do not have MDM. So looks like I am going to be losing alerting for this... Fun.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:26:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517598#M306821</guid>
      <dc:creator>TimBisel</dc:creator>
      <dc:date>2020-09-28T12:26:29Z</dc:date>
    </item>
    <item>
      <title>Re: iOS IP Conflicts</title>
      <link>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517599#M306822</link>
      <description>&lt;P&gt;I notice Apple released an update in the last day or two. I just installed it and the notes referenced a bug fix that might help the phone get on a wifi network. Anyone know if this fixed our problem?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2020 22:10:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517599#M306822</guid>
      <dc:creator>Odysseycommunity</dc:creator>
      <dc:date>2020-10-01T22:10:32Z</dc:date>
    </item>
    <item>
      <title>Re: iOS IP Conflicts</title>
      <link>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517600#M306823</link>
      <description>&lt;P&gt;Unfortunately, we tested iOS 14.0.1 this morning, and still noticed the same bug; we submitted our findings to Apple today, so hopefully that means we'll have some kind of update to share on this soon.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2020 22:13:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517600#M306823</guid>
      <dc:creator>alexapie</dc:creator>
      <dc:date>2020-10-01T22:13:21Z</dc:date>
    </item>
    <item>
      <title>Re: iOS IP Conflicts</title>
      <link>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517601#M306824</link>
      <description>&lt;P&gt;Apple's currently investigating our report, and isn't asking for any new data. As before, once I have more to share, I will do so.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Oct 2020 15:26:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517601#M306824</guid>
      <dc:creator>alexapie</dc:creator>
      <dc:date>2020-10-06T15:26:33Z</dc:date>
    </item>
    <item>
      <title>Re: iOS IP Conflicts</title>
      <link>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517602#M306825</link>
      <description>&lt;P&gt;For those that are using Microsoft Intune to manage devices - and  have a configuration profile that is pushing the SSID/Login information from Intune via MDM - there is now an option in the configuration that allows for "Disable MAC address Randomization" - or as was previously suggested, you can ask your users to set that on their devices as suggested by apple: &lt;A href="https://support.apple.com/en-us/HT211227" target="_blank" rel="nofollow noopener noreferrer"&gt;https://support.apple.com/en-us/HT211227&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2020 14:51:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517602#M306825</guid>
      <dc:creator>stefbauer</dc:creator>
      <dc:date>2020-10-07T14:51:40Z</dc:date>
    </item>
    <item>
      <title>Re: iOS IP Conflicts</title>
      <link>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517603#M306826</link>
      <description>&lt;P&gt;Thanks for following up &lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/180"&gt;@alexapie&lt;/A&gt;! Replying to this thread so that I can follow it and add my voice to the choir - this has been an issue for us as well. Hopeful for a resolution!&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 18:52:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517603#M306826</guid>
      <dc:creator>J-Edge</dc:creator>
      <dc:date>2020-10-13T18:52:26Z</dc:date>
    </item>
    <item>
      <title>Re: iOS IP Conflicts</title>
      <link>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517604#M306827</link>
      <description>&lt;P&gt;Please be aware that the ability to disable MAC randomization via MDM profile may also be subject to an Apple side bug.&lt;/P&gt;&lt;P&gt;If the option to disable MAC randomization is selected, the user still has the ability to re-enable it within the UI. Meraki has also sent feedback for this issue as well.&lt;/P&gt;&lt;P&gt;This behavior is observable via profiles created directly within Apple Configurator which suggests that this may only be resolved through a future iOS update.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2020 20:26:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517604#M306827</guid>
      <dc:creator>Daltross</dc:creator>
      <dc:date>2020-10-14T20:26:13Z</dc:date>
    </item>
    <item>
      <title>Re: iOS IP Conflicts</title>
      <link>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517605#M306828</link>
      <description>&lt;P&gt;This is creating issues. Some of the suggestions do not really work. If i have a guest network using meraki dhcp i can not disable random mac via MDM. Any way to adjust alerts so we can get ip conflict alerts based on dhcp scopes &lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 19:30:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517605#M306828</guid>
      <dc:creator>ryan@abs-solutions.com</dc:creator>
      <dc:date>2020-10-19T19:30:57Z</dc:date>
    </item>
    <item>
      <title>Re: iOS IP Conflicts</title>
      <link>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517606#M306829</link>
      <description>&lt;P&gt;I dont think there is a way to limit the alerts on a per-scope or VLAN. I think that might end up being the Meraki work around though. Seems like Android is going to do a similar thing. &lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 19:33:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517606#M306829</guid>
      <dc:creator>TimBisel</dc:creator>
      <dc:date>2020-10-19T19:33:54Z</dc:date>
    </item>
    <item>
      <title>Re: iOS IP Conflicts</title>
      <link>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517607#M306830</link>
      <description>&lt;P&gt;Hey everyone,&lt;/P&gt;&lt;P&gt;So we're clear here, you should &lt;U&gt;not&lt;/U&gt; need to be implementing any workarounds for this based on what is expected behavior on Apple's (and hopefully Android's) part - we're trying to test a new release from Apple that should hopefully have this resolved.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2020 15:04:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517607#M306830</guid>
      <dc:creator>alexapie</dc:creator>
      <dc:date>2020-10-20T15:04:39Z</dc:date>
    </item>
    <item>
      <title>Re: iOS IP Conflicts</title>
      <link>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517608#M306831</link>
      <description>&lt;P&gt;I’m seeing this behaviour even when MAC randomisation (Private Address setting on the iOS device) is Disabled.&lt;/P&gt;&lt;P&gt;Hopefully Apple has a fix soon.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Oct 2020 08:56:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ios-ip-conflicts/m-p/5517608#M306831</guid>
      <dc:creator>shaun.oliver</dc:creator>
      <dc:date>2020-10-21T08:56:25Z</dc:date>
    </item>
  </channel>
</rss>

