cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
11004
Views
5
Helpful
7
Replies

iPhone devices not connecting to guest network

ManuelSilva2168
Level 1
Level 1

We are seen an issue where iPhone devices are not able to connect to guest wireless network. when the iPhone tries to connect to the guest network we are getting "error opening page. Hotspot login cannot open the page because the server cannot be found" This was previously not an issue and no config changes have been done. iPhone is getting DHCP ip address and DNS ip address. 

 

We have seen this issue on different versions of IOS 14.4 and 14.6 

 

Android devices connect just fine to the guest network and get the splash pg automatically. Windows computers are also able to connect to the guest network with no issues. 

 

manual workarounds to get iPhone connected to the guest network work but this is not a scalable fix. ( manual solutions include, changing dns settings to manual -> add dns servers. 

Turn WiFi OFF and Turn ON Again

Go to iOS settings, then WiFi and turn WiFi OFF.
Go to iOS settings, then Cellular and turn Cellular Data OFF.
Go to iOS settings, then WiFi and turn WiFi ON.
Connect to the Guest WiFi signal and complete log in process.
Go to iOS settings, then Cellular and turn Cellular Data ON.

 

we are using a third party trusted certificate for our guest network, not a self signed cert. something about webauth/captive active portal redirect on IOS seems to be the problem. 

1 Accepted Solution

Accepted Solutions

ManuelSilva2168
Level 1
Level 1

Quick update

 

Our Guest network DHCP scope dns settings had our internal dns servers on top (prefer) and google dns servers at the bottom (least prefer). We removed google DNS and this seem to have fix the issue for now. iPhones are now getting the guest splash page automatically. 

 

Not sure why google dns entries were being prefer over our internal dns servers for the guest network. 

View solution in original post

7 Replies 7

balaji.bandi
Hall of Fame
Hall of Fame

how about OLD iPhone before 14.X  IOS ? is that works ? you need to capture full  Logs to see what is wrong here ?

 

When i had same issue Last time i did one test, configure iphone with static IP with DNS, it works as expected - can you do that test.

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Unfortunately, we do not have an old iphone with a version lower than 14.6 at the moment. We will try to see if we can find one. We can manually add the dns servers to the guest wifi setting on the client's iPhone and this works/brings up the splash pg. However, we are trying to figure out why this is happening and find a scalable solution for our end users. We are hoping to get the splash pg to come up automatically on iPhones. 

 

Seems to be related to this problem.

Version 7.2.110.0 or higher of the Cisco WLC contains a feature that bypasses the CNA feature on Apple devices. This feature is only available in the command-line interface (CLI).

config network web-auth captive-bypass enable

Reboot the controller for this feature to take effect. The next time a device logs onto the wireless network, the user must manually open a browswer to be redirected to the captive portal.

https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/116041-solution-apple-osx-00.html

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Rps-Cheers | If it solves your problem, please mark as answer. Thanks !

Thanks, this seems like a good workaround. We are hoping to find a solution where the splash pg comes up automatically. Not sure what change on the IOS side that screw things up. At the end we might have to go with this and test this workaround.

ManuelSilva2168
Level 1
Level 1

Quick update

 

Our Guest network DHCP scope dns settings had our internal dns servers on top (prefer) and google dns servers at the bottom (least prefer). We removed google DNS and this seem to have fix the issue for now. iPhones are now getting the guest splash page automatically. 

 

Not sure why google dns entries were being prefer over our internal dns servers for the guest network. 

Looks like your corporate URL Local one, so you need to have your Local DNS resolve Lookup prefer to redirect you the page was Locally defined and hosted, google DNS can only resolved FQDN -  make sense, thank you for the feedback

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Leo Laohoo
Hall of Fame
Hall of Fame

@ManuelSilva2168 wrote:

manual solutions include, changing dns settings to manual -> add dns servers


That's a DNS issue.  Check the DHCP scope settings for the DNS used and try using IP address of the DNS server.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card