ebelshaw Posted October 6, 2017 Posted October 6, 2017 Morning, Not sure if this is the correct section to post in? Since our Apple users have upgraded to iOS11 they can no longer connect to our BYOD network, (Sophos UTM) They can connect, put in password, they get a DHCP address then it instantly drops out. Has anyone else seen this and have any ideas? Thanks
trinity_teign Posted October 6, 2017 Posted October 6, 2017 We are having the exact same issue although our wireless is Unifi rather than Sophos. Unifi support suggested turning off the wifi assist option in settings but hasn't made any difference.
TronXP Posted October 6, 2017 Posted October 6, 2017 Do you guys use Security Certificates? If so Apple introduced a new a new Option in Settings>General>About>Certificate Trust Settings You have to make sure the root certificate is enabled as well as installed...
Brimstone Posted October 6, 2017 Posted October 6, 2017 Morning, Not sure if this is the correct section to post in? Since our Apple users have upgraded to iOS11 they can no longer connect to our BYOD network, (Sophos UTM) They can connect, put in password, they get a DHCP address then it instantly drops out. Has anyone else seen this and have any ideas? Thanks Get them to forget the network, then reconnect with password etc should solve this.
chrispounds Posted October 6, 2017 Posted October 6, 2017 Hi, We also have this issue, we pre-configure some of our iPads with Wi-Fi credentials via Meraki. Also using UTM. This also drops out, but only with certain types of connection, this one in particular is used with a RADIUS server. Will be interesting if anyone comes up with a fix for this, the forget network / reconnect doesn't solve it for us.
ebelshaw Posted October 9, 2017 Author Posted October 9, 2017 I have tried forgetting network etc and it hasn't made any difference. We have 2 networks one for insternal use and it works fine on there, it is only our BYOD which is affected. Tron dont think we use certificates on our wifi.
trinity_teign Posted October 10, 2017 Posted October 10, 2017 Just managed to get this working.... sort of! On a phone running ios 11.0.2 I went into the wifi settings for our wireless network by pressing the blue information circle next to the SSID Changed the DNS settings to manual and entered 8.8.8.8 which is googles DNS. Then pressed join this network which it did and stayed connected. Whilst connected I went back into the wifi settings by pressing the blue information circle and changed it back to automatic. I am now able to switch the wifi on/off, forget/join the network without any issues! Tried the above by entering our internal DNS server and it wouldn't work. Really strange, not sure where to go from here! Would be interested to see if anyone else can get the above working on their devices.
Fazza Posted October 10, 2017 Posted October 10, 2017 I think it's to do with SSL certificates - if you dont have one or dont have the right one then connecting to things like this doesnt work. Since upgrading to IOS11 I cannot for example join our WiFi nor that of "The Cloud" free WiFi you see in a lot of shopping centres as on the Captive Portal Page they dont use SSLs - you only get one once you've been authenticated on the CPP.
ebelshaw Posted October 10, 2017 Author Posted October 10, 2017 Trinity Thanks for the info, just tried it on my phone and it has worked for me too. Put in Googles DNS, connected and then removed setting. My phone has now stayed connected and it is letting me hit our Authentication page and now browse! Not sure how to go forward with this? Can't really ask users to do this??
AlanD Posted October 10, 2017 Posted October 10, 2017 . Tron dont think we use certificates on our wifi. WHAT???? !!!!! you MUST get your wireless users to install a certificate - and block all traffic from devices without a certificate - otherwise you are seriously in breech of government "prevent" requirements. Remember, its NOT sufficient to "block" unsuitable web sites - you must "monitor" access - and be able to identify those staff/students at risk - or radicalisation, violence, sexual grooming or whatever. And it may well be that simply blocking access would not enable you to track such risks. So you can't have a connection like you would at home - with a shared WPA code that staff (or students) use to join wireless and away they go. Either users need to identify themselves individually by using an enterprise wireless logon using a radius server (which if you are using Sophos should be easy...) or you need a captive portal (if for example you have shared devices connecting to wireless) - which is a pain - because users need to use web before using an app...and you need to set a timeout so the next user will not be using the first user's authentication. If you don't use a certificate on the device you won't be able to monitor or block any of the https traffic which will be completely invisible. (Actually - that's not quite true- because you could be using a DNS or IP filter.... but it wouldn't be a very robust method) 2
ebelshaw Posted October 11, 2017 Author Posted October 11, 2017 Morning Alan, Once users connect to our BYOD, they are presented with a Sophos Login page to authenticate with their AD credentials. So no one can get on without been authenticated, then we can monitor what website they are visiting. With Sophos you can get a really detailed report so think we are pretty well covered. We have daily reports setup to flag anything extreme \ pornographic etc.
pcstru Posted October 11, 2017 Posted October 11, 2017 Remember, its NOT sufficient to "block" unsuitable web sites - you must "monitor" access - and be able to identify those staff/students at risk - or radicalisation, violence, sexual grooming or whatever. And it may well be that simply blocking access would not enable you to track such risks. Sorry, but I can't parse that. "It is not Sufficient to Block" suggests that you should block and do something else. If the something else is monitoring, then in order to monitor, you would have to leave the site unblocked. It cannot be right that we leave such sites unblocked so that we can monitor who is looking at the content.
AlanD Posted October 11, 2017 Posted October 11, 2017 Despite having said it - I largely agree with you, at least to the extent that the worst of such material needs to be blocked. And of course - you might ask "what is the point of blocking it - if they access anything they like via 3G/4G on their phones which now seem to come with download limits and speeds that would be difficult to match with a leased line shared between users". But the fact remains that the requirement is "monitoring" and "protecting" and if doesn't always mean blocking everything. Indeed as they get older we are required to have age related accessibility/blocking - and you might have to decide whether to block an increasing number of really useful but unmoderated sites like Pinterest....
pcstru Posted October 11, 2017 Posted October 11, 2017 Despite having said it - I largely agree with you, at least to the extent that the worst of such material needs to be blocked. And of course - you might ask "what is the point of blocking it - if they access anything they like via 3G/4G on their phones which now seem to come with download limits and speeds that would be difficult to match with a leased line shared between users". The key difference between a user owned device using 4G and that device using our network is that when we are providing a connectivity service, we have a duty of care involved. Do we have a duty of care to someone using their own equipment and their own connectivity? If we do, I'd be interested what makes that so. But the fact remains that the requirement is "monitoring" and "protecting" and if doesn't always mean blocking everything. Indeed as they get older we are required to have age related accessibility/blocking - and you might have to decide whether to block an increasing number of really useful but unmoderated sites like Pinterest.... I agree. Here we have a little committee that can deal with any difficult blocking decisions but that is a different issue than allowing access to extremist content specifically so it can be monitored - which is what you seemed to be saying.
AlanD Posted October 11, 2017 Posted October 11, 2017 Morning Alan, Once users connect to our BYOD, they are presented with a Sophos Login page to authenticate with their AD credentials. So no one can get on without been authenticated, then we can monitor what website they are visiting. With Sophos you can get a really detailed report so think we are pretty well covered. We have daily reports setup to flag anything extreme \ pornographic etc. ...but if they don't have a certificate which they have installed in their device - regardless of whether they logged in to Sophos - the traffic would essentially be invisible to sophos because it would not see any of the websites or details of any web searches - because they are hidden by ssl encryption....so the only thing you would see is the good stuff...
ebelshaw Posted October 12, 2017 Author Posted October 12, 2017 Hi Alan, We scan HTTPS traffic so we can see\log what users are googling. Threads gone a bit off topic, anyone had any progress with ios11 and their wifi netowrks?
ebelshaw Posted October 17, 2017 Author Posted October 17, 2017 I have updated my phone to 11.0.3 and still no joy. I have logged a call with Sophos to see if thay can give me any ideas.
ebelshaw Posted October 18, 2017 Author Posted October 18, 2017 Info from sophos: As discussed on call, there is already a bug created with us for the behavior where Browser Based authentication on the firewall for iOS11 updated devices are failing to connect. This is to be resolved in the next version v9.504 and so please wait for the version and you can revert the configuration to the original settings. For the meantime please change the settings so that the policies are applied as per the IP address / Network instead of the users as a temporary workaround. Further, as there is no other workaround available for now, we will go ahead and close this case.
trinity_teign Posted October 19, 2017 Posted October 19, 2017 Thanks for the update ebelshaw. We are moving to a Sophos firewall and filter next week so will be asking about this. Having spent some time over the last few days looking at this, my suspicion was that there is an issue with the firewall/filter.
ebelshaw Posted November 8, 2017 Author Posted November 8, 2017 Think I have had a break through this morning. 2 more updates have come from Sophos, but have not fixed this issue. I have found in Sophos you can change what authentication method to use. Using 'browser' produces the issue, if this is changed to 'Active Directory SSO' it has fixed the problem. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now