cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1727
Views
15
Helpful
5
Replies

manage/monitoring 9800 WLAN Controller with apple ios device

Michael Fees
Level 1
Level 1

We can't configure/manage/monitor our C9800-L-F-K9 16.12.04a with an iPhone or iPad. (iOS Version 13 or 14) and the web management page of the controller.

(Access local via wireless - no cloud configuration)


With browser (Safari, Chrome, Firefox on iphone or iPad) we can https connect via IP address or name,
but we see every wireless count, AP count and client count with number "0".
See attached picture.


Has anyone else the same problem?
To use a remote desktop from iPhone to see the web monitoring page of the wlan controller is no alternative solution.
SW version 17.3.4 (and below)

Thanks in advance.

1 Accepted Solution

Accepted Solutions

So that likely confirms my suspicion that it's the self-signed cert causing the problem.

If you want to use those consumer grade devices to manage your enterprise network (remember Apple is super strict on security and getting stricter with every release) then you'll need to get a 'real' cert for your WLC.  I'll be very surprised if that does not solve the problem.  Otherwise get yourself a windows tablet where you can easily make the self=signed cert work.

You might also want to think about updating your 9800 code version.

 

If you want to prove it either way then you'll need to use browser trace with your iPad/iPhone USB paired to a MAC to see exactly what the browser objects to.  I expect you'll see it refusing the TLS cert when trying to load those components embedded in the page.  You'd also see that with a packet capture on the WLC (client device would simply reset the TCP connection after receiving the server cert).

https://www.browserstack.com/guide/how-to-debug-on-iphone

 

View solution in original post

5 Replies 5

Rich R
VIP
VIP

Your screenshot doesn't show the full browser screen with address bar - specifically are you using https?

And if you are using https then are using using a valid public SSL certificate rather than a default self-signed cert?

Based on the limited info you've provided that would be the most likely problem in my opinion.

So you don't have anything other than iPhones or iPads?  No Windows PCs?

I wouldn't recommend managing your network from those devices anyway.

Hi rrudling,
Thank's for your answer.

It is https with IOS Self-Signed SSL Certificate (from Cisco/from the controller itself).
When I go through the floors in our company and I get a phone call with wireless problems, I have to check the wireless controller. (Most time without a laptop or a computer). My iPhone is with me walking through the campus.

Access to wireless controller web management  site is with https://foo.contoso.com (as example).
The logon screen is displayed and I can login with an administrative user.
The Dashboard is displayed (like on the computer) but all counters for Wireless LANs, Access Points, Clients, Rogues and Interferers are displayed with a "0" (zero). No error. Only instead of the correct count like 3 Wireless LANs, 300 Clients: on iphone and iPad the digits are "0". (no error, no dash).

That's very strange. 

Also if I try different browsers on my iPhone and also if I try to "show desktop website" or "show mobile website" in Safari - everytime no error, just the "0".

Same if I select "Monitoring - Wireless - Clients" 
Total Clients in Network: 0
Same if I select "Monitoring - Wireless - AP Statistics"  
Number of AP(s): 0

No HTTP-Error, no error message.

On regular Windows computers (with firefox, edge, chrome, ie, safari) everything fine. The counts are correct.

Michael




So that likely confirms my suspicion that it's the self-signed cert causing the problem.

If you want to use those consumer grade devices to manage your enterprise network (remember Apple is super strict on security and getting stricter with every release) then you'll need to get a 'real' cert for your WLC.  I'll be very surprised if that does not solve the problem.  Otherwise get yourself a windows tablet where you can easily make the self=signed cert work.

You might also want to think about updating your 9800 code version.

 

If you want to prove it either way then you'll need to use browser trace with your iPad/iPhone USB paired to a MAC to see exactly what the browser objects to.  I expect you'll see it refusing the TLS cert when trying to load those components embedded in the page.  You'd also see that with a packet capture on the WLC (client device would simply reset the TCP connection after receiving the server cert).

https://www.browserstack.com/guide/how-to-debug-on-iphone

 

Hi rrudling.
Thank you very much. it works.
I used our wildcard certificate (pfx) and worked with the following manual

https://community.cisco.com/t5/wireless-mobility-documents/wildcard-certificate-installation-on-wlc-wireless-lan-controller/ta-p/3143484
on WLC go to Configuration - Security - PKI Management
Add Certificate
Import PKCS12 Certificate
Upload the "All-certs.p12" and enter the password which I used in OpenSSL (the same password for installing pfx).

next step: 
Adminstration - Management - HTTP/HTTPS/Netconf and change
"HTTP Trust Point Configuration" and select "Trust Points" to "All-certs.p12"

Than it works.
Thanks a lot.



Review Cisco Networking for a $25 gift card