cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
8729
Views
7
Helpful
18
Replies

"Your browser is currently unsupported" BYOD portal - ISE 2.4 U14

phake
Level 1
Level 1

We've been noticing that any new iOS device trying to use and enroll in our BYOD portal/setup, they're getting: "Your browser is currently unsupported". 
I'm fairly confident it's any device that's upgraded to iOS 15, 15.1, 15.2. It was working on several older test iPhones last week. 
I have: 

Version: 2.4.0.357
Installed Patches: 5,8,9,14

Any thoughts on how to get this running again?

1 Accepted Solution

Accepted Solutions

This community is not TAC and we cannot comment on or escalate TAC cases. You'll need to work with TAC and escalate if needed via their processes. The TAC engineer will need to work with the software developers to determine if a workaround/fix can be developed.

I can say that I tested my iPad running iOS 15.2 with the BYOD flow in ISE 3.0 p4. With the Captive Network Assistant Bypass feature disabled on my BYOD provisioning SSID (WLC AireOS 8.5), I saw the same "Your browser is currently unsupported" message from the BYOD Portal.

I enabled the CNA Bypass feature on the SSID, and I was able to complete the BYOD enrollment successfully.

View solution in original post

18 Replies 18

Greg Gibbs
Cisco Employee
Cisco Employee

The Cisco supported OS versions are updated by the Posture Update packages. If you have not done so already, I would suggest getting the last online update via the Administration > System > Settings > Posture > Updates page. I believe the current 'Cisco supported OS version' should be 63.0.0.0.

If you have already updated to the current version, you might need to open a TAC case.

Greg,

Thanks for this!
I checked and we're at the latest, Cisco supported OS version 63.0.0.0.

 

Last successful update on 2021/11/15 15:10:52.

Just strange that all iOS devices stopped working after iOS v15.

Greg,

We found this article:
BYOD portal - Your browser is currently unsupported - Cisco Community

Looks like it has to do with the WLC and the Captive Portal.

I noticed this is the case for any device over iOS 15.x. How is Cisco solving this issue? There has got to be a large amount of customers having this issue right now. No one is going to figure out how to go to Safari, and then go to a non-cached website to activate the redirect portal.
Do we have to detect the version of the device? Can we just skip that part? 

If this is related to the Apple CNA, this is not the first time Apple has made changes to their CNA that end up breaking portal flows. Cisco has no involvement or control over Apple software development, so this typically involves development effort to identify and implement a workaround, which takes time. If you have not already done so, please open a TAC case to investigate further and track this potential issue and any potential in-flight enhancements.

A common practice to avoid these potential CNA issues with portal-based flows is to use one of the methods to bypass the CNA documented here. Leveraging these bypass methods does involve training the users to open a browser on their device, which is typically included in the communication plan to the end users when enabling/enhancing end-user services like BYOD. Doing so, however, helps mitigate future potential issues with portal-based flows breaking due to vendors changing something with their CNA.

phake
Level 1
Level 1

Greg,

 

Sorry, but this isn't a solution. What is Cisco actually doing to fix this issue. Apple did something post iOS 15.1 to break the captive portal redirect. What is Cisco doing to fix it?


Open a TAC case to investigate further and track this potential issue and any potential in-flight enhancements.

I do have a case open. SR 692538402. Zero progress has been made. 

This community is not TAC and we cannot comment on or escalate TAC cases. You'll need to work with TAC and escalate if needed via their processes. The TAC engineer will need to work with the software developers to determine if a workaround/fix can be developed.

I can say that I tested my iPad running iOS 15.2 with the BYOD flow in ISE 3.0 p4. With the Captive Network Assistant Bypass feature disabled on my BYOD provisioning SSID (WLC AireOS 8.5), I saw the same "Your browser is currently unsupported" message from the BYOD Portal.

I enabled the CNA Bypass feature on the SSID, and I was able to complete the BYOD enrollment successfully.

Just an update for anyone else interested in this topic. I tested the same ISE BYOD flow in ISE 3.0 p4 using the 9800-CL WLC (17.3.4c) and found a similar issue with the Apple CNA portal on my iPad running 15.2.

I created a webauth parameter map to enable Captive Bypass Portal on my BYOD SSID (single-SSID flow) as per the Configuration Guide and was able to complete the BYOD enrollment successfully.


@Greg Gibbs wrote:

 

I created a webauth parameter map to enable Captive Bypass Portal on my BYOD SSID (single-SSID flow) as per the Configuration Guide and was able to complete the BYOD enrollment successfully.


Hi Greg could you please possibly expand on this and how it can achieve a work-around solution to the problem? Does it mean the Guest users can still be automatically redirected upon joining vs. having to open a page? 

Hi Phake,

Do you have any updates from Cisco wrt to your case?

Thanks

DerpaNet
Level 1
Level 1

Also seeing this on a 3.1-patch3 environment and 2.6-patch10

At least on the 3.1 environment I can get around this by hitting the Retry button, waiting for it to time-out, after which the SSID connects without the BYOD work-flow. 

Seeing this as well on 3.1.0.518 patch 3.  Captive portal bypass is not working in my environment; possibly because I am using a Meraki cloud controller instead of Cisco WLC.

This thread is from 2.4.  I would suggest creating a new one for your issue.