Wireless Access

 View Only
  • 1.  Guest Captive Portal on IOS

    Posted Jun 06, 2025 05:08 AM

    Hi everyone,

    I have Clearpass Guest configured and working with Laptops/Android.

    I have AOS 10 APS, they tunnel their traffic towards a controller, and then on towards clearpass for authenication, as mention this all works without fault on every device I have tried apart from IOS,

    i have the captive portal signed with a public CA, and i also have a signed cert on the AP and the same common name configure within Clearpass for after the authnicate has complete.

    does anyone one know what speific requirement Apple has to which i need to configure in order for it to display the portal ? 

    I don't get a popup the device just connects to the SSID with an IP, but tells me there is no internet connectivity. 

    TIA

    Mike 



  • 2.  RE: Guest Captive Portal on IOS

    Posted Jun 11, 2025 04:48 AM
    Edited by Herman Robers Jun 18, 2025 12:47 PM

    The captive portal certificate should (also) be on the gateway, and it needs to be 'chained', so all intermediate certificates should be included.

    Another thing is that for Apple there is an option 'CNA bypass' to prevent the automatic popup, maybe that's enabled on the gateway or ClearPass.

    What you may try is to open Safari or another browser, when connected, then manually go to something like: http://1.2.3.4/ and see if that's redirected... (note http, not https); and maybe you see certificate warnings or other indication what's wrong. I think there is a (reduced) list of trusted root CAs for captive portal on IOS; check if your CA is supported.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 3.  RE: Guest Captive Portal on IOS

    Posted Jun 18, 2025 05:06 AM

    Hi Herman,

    Thanks for your response, apologies for the delay in responding.

    You mentioned that the captive portal cert should be on the gateway, i have been stuggling to upload the the cert via central as i get an error when trying to add it and via the gateways GUI i get a message that i cannot add due to the gateway being controller by ASP. but wouldn't not having the cert on the gateway stop the laptops/andriod devices from working? As currently they all work fine, without the cert on the gateway.

    I have opened Safari and used 1.1.1.1 and the captive portal appears and there is no cert issues displayed all works as expected i just don't get the inital portal 'pop up' when i first connect to the Guest SSID. I have also checked the CNA bypass it is unticked on both the gateway and Clearpass. 

    Any other ideas? 

    this is the error it get on Central when i try to added the cert to the gateway.




  • 4.  RE: Guest Captive Portal on IOS

    Posted Jun 18, 2025 12:55 PM

    I got corrected on that point; with AOS10 apparently the certificate only needs to be on the AP. And you are right that if it works for non IOS devices, it can't really be the certificate being on the wrong device.

    What IOS is expected to do is check https://captive.apple.com/hotspot-detect.html and if it's redirected, it should pop up the captive portal, if it shows just the text 'Success', it assumes it's on a functional network. You could check that URL manually, if there is indeed a redirect happening. Otherwise, try switching off cellular data (or enable flight mode); see if that improves things. This may be something to work on with TAC.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 5.  RE: Guest Captive Portal on IOS
    Best Answer

    Posted Jun 23, 2025 06:15 AM

    After much troubleshooting, i have found out why the captive was not displaying on IOS.

    If you have AOS10 APs, within Aruba Central and under the Guest SSID you need to edit Captive Portal Profile and then switch 'Server Offload' on.

     




  • 6.  RE: Guest Captive Portal on IOS

    Posted Jun 24, 2025 05:31 AM

    interesting. The definition for this as per the user guide is

    Server Offload-Turn on the toggle switch to enable the server offload feature. The server offload feature ensures that the non-browser client applications are not unnecessarily redirected to the external captive portal server, thereby reducing the load on the external captive portal server.



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 7.  RE: Guest Captive Portal on IOS

    Posted Jun 24, 2025 06:26 AM

    Few weeks ago I've seen the same issue. Reason was that the captive portal contains some public sources (like external java script). 

    Adding this destination to the bypass / allowlist was solving this issue. Not sure why the server offload features also helps to solve this.



    ------------------------------
    Willem Bargeman
    Systems Engineer Aruba
    ACEX #125
    ------------------------------