cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4049
Views
0
Helpful
9
Replies

Does iPhone support Cisco NAC v4.7.2 and above?

Hi There

I have Cisco NAC enabled in my environment. It's all working fine with Windows O/S, MAC O/S and Linux O/S? I was just wondering, is Cisco NAC supported on IPhones example in in-band mode using web agent?

Regards,

Ram

+6012-2918870

Warm regards,
Ramraj Sivagnanam Sivajanam
9 Replies 9

Hi There

In Cisco's website, it states that the Cisco NAC Appliance recognizes IPhone iOS as "Macintosh All" and supports basic web login only if Safari browser is used. Cisco has released a patch update for Cisco NAC Appliance Release 4.7(2) CASs that provides web login (no persistent or temporal Agents) support for Apple iPads. See caveat CSCtf60530.

I tried it myself earlier today, and it doesn't work? Is there any additional steps required for this?

Regards,

ram

+6-0122918870

Warm regards,
Ramraj Sivagnanam Sivajanam

Hi Everyone

Yes, Cisco NAC do support IPhone IOS, but you'll need to install JAVA, which cannot happen unless you jailbreak the IPhone. How do you recommend your clients to jailbreak their IPhone. That's illegal in many countries. Hence, when Cisco say Cisco NAC do support IPhone IOS, they also need to mention about JAILBREAK as well :-(

Warm regards,
Ramraj Sivagnanam Sivajanam

Hi Ramraj,

It sounds like the user page is configured incorrectly - under the general tab for the MAC_ALL page, please make sure the "use web client" options are not checked.  After that, the client should not be required to use Java to login.

Thanks,

Lauren

Hi Lauren Sullivan

I don't have that option checked, as shown below

Device Management > Clean Access

Certified Devices General Setup Network Scanner Clean Access Agent Updates
      Web Login   ·  Agent Login 
User Role
Operating System 
Use 'ALL' settings for the MAC OS family if no version-specific settings are specified


   Show Network Scanner User Agreement page to web login users
  Enable pop-up scan vulnerability reports from User Agreement page
  Require users to be certified at every login
  Exempt certified devices from web login requirement by adding to MAC filters
  Block/Quarantine users with vulnerabilities in role:
       Show quarantined users User Agreement Page of:

            
Warm regards,
Ramraj Sivagnanam Sivajanam

Hi Ramraj,

That's the settings for the web agent, not the web client - annoyingly similar names, but totally different things

For the web client, it's under Adminstration > User Pages > edit the page for MAC_ALL, and it's under the General tab.

Thanks,

Lauren

Hi Lauren Sullivan

Thank you for your prompt and kind assistance. Shown below are my present settings under Administration > User Pages > EDIT > General

Use web client to detect client MAC address and Operating System.
Use web client to release and renew IP address when necessary (OOB).
(Helps OOB client acquire new IP address after authentication without bouncing the switch port)
Install DHCP Refresh tool into Linux/MacOS system directory.
(Avoids root/admin password prompt to refresh the IP address for Linux/MacOS clients when the web client is used to perform DHCP release and renew)


Hence, do I uncheck the first item only?

Warm regards,
Ramraj Sivagnanam Sivajanam

Hi Lauren Sullivan

I have disable all the 3 options listed below and it's slightly better now, but when it prompts me to download the Cisco NAC agent, I get an error, "Safari cannot download the file". I believe this could be because my iPhone has not been jailbreak yet, hence I can't download? Conclusion, can I say, if you don't jailbreak your iPhone, this means iPhone cannot be used with Cisco NAC?

Use web client to detect client MAC address and Operating System.
Use web client to release and renew IP address when necessary (OOB).
(Helps OOB client acquire new IP address after authentication without bouncing the switch port)
Install DHCP Refresh tool into Linux/MacOS system directory.
(Avoids root/admin password prompt to refresh the IP address for Linux/MacOS clients when the web client is used to perform DHCP release and renew)

Warm regards,
Ramraj Sivagnanam Sivajanam

Hi Ramraj,

Ah - let me clarify a bit more.  You can do web authentication (no posture assessment) with iPhones (or most other mobile devices), but can't install the NAC agent or NAC web agent.

Are you able to see the user page on the iPhone now and authenticate, and then getting that agent prompt?  If so, it sounds like you have the agent required for all OSs for that user role.  So, under Clean Access > General Setup > Agent login, choose the user role, and then choose MAC_ALL as the OS.  You'll want to uncheck "use ALL settings for the Mac OS X family" and then make sure "require use of agent" and "require use of Cisco NAC web agent" are both unchecked.  If you are using the Mac agent for your OS X users, please make sure to then set the OS to MAC_OSX and check "require use of agent" there.

Thanks,

Lauren

Hi Lauren Sullivan

Yes, I have uncheck "use ALL settings for the Mac OS X family" and then make sure "require use of agent" and "require use of Cisco NAC web agent" are both unchecked.

Currently, when I use my iPhone to login into the NAC, i still see the page asking me to download the agent. WHen I click on the continue button, it hangs there. This behaviour is similar to Windows based Mobile Phones as well. What should I do? Please kindly advice.

Yes, I do have MAC OS workstations in my network. I do have the Use 'MAC_ALL' settings for this OS version set for this, as shown below? Perhaps, I should change set the OS to MAC_OSX and check "require use of agent" ONLY.

Certified Devices General Setup Network Scanner Clean Access Agent Updates
      Web Login   ·  Agent Login 
User Role
Operating System 
Use 'MAC_ALL' settings for this OS version


   Require use of Agent (for Windows & Macintosh OSX only)
        Agent Download Page Message (or URL):
       

  Require use of Cisco NAC Web Agent (for Windows 7/2000/XP/Vista only)
        Cisco NAC Web Agent Launch Page Message (or URL):
       

  Allow restricted network access in case user cannot use NAC Agent or Cisco NAC Web Agent

Warm regards,
Ramraj Sivagnanam Sivajanam
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card