ISE BYOD with Android device

hi
i deployed ISE for BYOD and its working fine for windows and Apple devices. the issue is with android. sometimes i can register the devices in MY DEVICES portal and ISE will redirect me to download the network assistant tool. and sometimes it refuses to register the devices and its showing this error for some devices "unsupported operating system type encountered" and showing this error for the others "We are unable to determine access privileges in order to access the netwotk. Please contact your administrator"
does anyone know how to solve this issue?
thanks in advance.

Ok, so the obvious things for the first part of the problem are;
Is the Android Client using a supported OS? Check here;
http://www.cisco.com/en/US/docs/security/ise/1.1.1/compatibility/ise_sdt.html#wp80321
Are you using the latest Supplicant Provisioning plugins in ISE? And are you using the latest version of ISE?
Do the failing Clients have anything in common? Same hardware, OS Version, etc?
The second issue, where  you get "We are unable to determine access privileges in order to access the netwotk. Please contact your administrator" is typically caused by one of three things.  Either your Client has been idle for too long and the session has timed out, the ISE hasn't been able to Profile your device yet (and so doesn't know how to provision it), or you haven't configured ISE with an Android Supplicant Provisioning config.
Finally, I've had that last problem before, albeit on a different handset, I missed some ports/protocols/hosts on my ACL

Similar Messages

  • ISE integration with Mobile Device Management ( MDM ) help required

    Dear Techies,
         Am here bring to your notice an different issue and no much resources to support even in PEC or Cisco Document.
         We are conduction a Proof Of Concept (PoC) on  Secure Bring Your Own Device ( BYOD ) using Cisco ISE and gonna test all the scenarios like Wired, Wireless and VPN user access.
    Setup Brief :
    =========
          Our Setup has  ISE VM acting as Admin, Monitor and Profiling Device, we have NAC 3315 physical Appliance as Inline posture Device, Wireless LAN controller, Access point and the Identity source as Microsof Active Directory
         Having Plans to Integrate Mobile Device Management ( MDM ) and Citrix VDI setup also.
    Activity Brief:
    =========
         As of now we have tested the Wired Scenario Authentication and authorization for guest users and gonna carry out the profiling and posture.
    Clarifications Required
    ================
    Wired Scenario - Require some configuration / steps on how to carryout posture for the guest wired users i.e. LAPTOP.
    Wireless Scenario
    MDM can be integrated to ISE ? 
    How the MDM can be integrated to Cisco ISE configuration or Guide to show the same?
    What is the demarcation between MDM and ISE ( i.e. What is the role of ISE and MDM on Mobile Devices ) ?
    If MDM is available so then when the control of ISE ends, does MDM do management or ISE will do management of the devices ?
    Is MDM will do client provisioning or ISE should do ?
    Is MDM send or update patches of Mobile Devices ?
    As of now these are the scenarios, kindly revert if any good documents to show this or share your expertise on the Integration Part.
    Thanks for Reading...
    Arun

    I would like to avail your valuable inputs to understand on the  Client provisioning part for the Mobile Devices/ Laptop. I understand  from your reply that MDM integration is not available in the current  release ISE 1.1 - That is correct.
    Kindly let me know your views or any documents on the following scenarios with the current release in mind
    1. User  with Mobile devices connecting to Wireless  ( both Employee  and Guest ) , How the Flow differs for the Employee and Guest.  How the  client provisioning is done ( i.e. Like Posturing  or Compliance Check  ).
    The posturing and compliance check is done based on the user authentication information (i.e. AD memberOf vs Guest user) combined with the users endpoint (windows, mac osx, or a mobile device), ISE then has a few decisions to make based on the authorization policies. For example, if a Domain User coming from a Windows 7 machine joins the network, then can either use the nac agent, or the web agent. Then you can scan for registry settings, file settings, program requirements, hotfix compliance...and the list goes on. If the user fails a check then you can either assign an acl for the user so they only have guest access, or you can place them into a remediation vlan the options are entirely up to the requirements and however the solution is implemented.
    2. User  with Laptop  connecting to Wireless  ( both Employee  and Guest ). How the client provisioning is done ( i.e. Like Posturing   or Compliance Check ).
    Guests are usually redirected to the guest portal which they authenticate and their user group falls within the Guest container that is on the ISE internal database, that is usually coupled with an authorization profile that grants them internet access. For the client provisioning, that is usually done based on the operating system, via profiling (dhcp, and user agent string., netmap...etc) and can be fine tuned for all laptops or to a specific set of users based on their group membership.
    3. What are advantages of having ISE also in  place for Mobile devices, since most of the Mobile related tasks ( like  Authentication, Authorization, Profiling and  Posture ) are carried out  by MDM. I am checking for the significant advantage of having ISE for  Client network having only Mobile devices. Kindly clarify.
    Currently the advantage of Cisco ISE is that it supports profiling within wireless and really fits well within a network that has mostly Cisco products since they are all part of of the Borderless security initiative being driven on the backend. The product teams for wireless, wired, security (vpn..etc) and ISE are pretty close in building their solutions so that you can get connected with any device any where (sorry for the sales pitch). The latests wireless code is improving and is going to have support similar to the ios sensor for wired devices where dhcp, cdp, and other attributes can be sent in the radius packet for better profiling decisions. With integration for an MDM platform coming soon, and also support for TACACS rumored (have to verify with your account rep) you have options that really stand out from a unit that only supports MDM. Cisco ISE also comes with a wireless product ID so that makes the budget work when it comes to deploying ISE if you arent looking for enforcement on your wired devices.
    4. Do you recommend 802.1X Authentication to use for the Employee and Contractor? The Guest user  authentication as Open ?
    For internal users and vendors the best option by far is dot1x, almost all operating systems are capable of performing dot1x and the 1.1.1 MR has a piece now that can provision the supplicant for the users, by using scep to enroll certificates or configure peap settings.
    There is a feature within the guest portal that allows you to statically assign guests into endpoint group, that feature is called device registration web authentication. It seems like an open network but uses mac filtering to assign these devices to an endpoint without requiring users to enter any credentials. They are presented with an AUP page, once they accept their mac address is mapped to the endpoint group
    5. How can we ensure the Encryption of traffic from the Guest user to the NAD ( Network Access devices ) ?
    This may be a wireless question but I am sure the encryption is done using AES and using dot1x as the key management here is a brief background for this - http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a00807f42e9.shtml#L2
    You can also use the anyconnect client which can provide macsec which is layer 2 encryption for wired - http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/qa_c67-622477_ns1049_Networking_Solutions_Q_and_A.html
    6. We are also looking for VDI  ( Citrix, VMware ) solution for the  client  ( both Employee and Guest ) , how ISE can play a role in  securing the VDI environment.
    For most thin clients you can perform dot1x authentication on the device itself, however that is something the manufacturer will have to support. This is a little gray for me.
    7. Is that any integration required  with Citrix or VMware. How the  VDI can be offered based on the User  role ( i.e. Employee, Contractor or Guest ), since Guest database is  available only with ISE, how the checks are made from the VDI  environment.
    IN ISE there is an identity sequence which can authenticate users in AD first, if the user is not found then it can look in the internal database.
    Our solution demands  MDM in the integrated  solution, As on today ISE cant be integrated with MDM. so what kind of  solution we can propose to have MDM and Cisco ISE .Do the clients now  enter the network should have already installed the MDM agent (or) any  other way of pushing the same to the Client.
    Today there is no integration between the devices, the last release time I heard was December for this feature. However it would be best to confirm with your Cisco Account rep on this issue.
    Thanks,
    Tarik Admani
    *Please rate helpful posts*

  • Issue with Android devices - cannot connect to Fac...

    Good morning.
    I have an issue with android phones and a tablet not being able to connect to Facebook etc on our home wifi.  Everything works on other wifi and the signal strength is good.
    Did get it to work for an hour after a pin reset, but that did not last.
    An hour on the phone to BT help yesterday, set the channel to 2.4ghz but that made no difference and no more ideas from BT it seems.
    Was told by the BT man not to do a pin reset as it wears out the router, apparently.
    Any help greatly appreciated.
    Thanks.
    Solved!
    Go to Solution.

    do you have parental controls active?  if so turn off
    If you like a post, or want to say thanks for a helpful answer, please click on the Ratings star on the left-hand side of the post.
    If someone answers your question correctly please let other members know by clicking on ’Mark as Accepted Solution’.

  • Ical not properly syncing with android device google calendar?

    I have my iCal and my gmail account linked with for the calendars and address book. When I create an event with a specific time of day I can log on to google calendar from the internet and see the event exactly as I created it. When I look on my android phone which is also synced with google calendar it shows the event as all day no matter what I do in iCal. Any suggestions on what to do/ideas on why this is happening?

    Thanks for posting this, JW --- I was about to post something similar because I'd entered some events for 11/7 last week in Entourage 2008 and noticed they were syncing an hour later on the iPhone and it was driving me crazy as I was thinking they would correct themselves (in iCal) once the time changed.
    They didn't so I ended up deleting them off the phone and they managed to sync correctly from Entourage. Then I made some mods and noticed they had advanced up one hour again.
    Maybe some DST patch is needed because technology probably still thinks time changes the last Saturday in October as I'm sure no one has thought to adjust this in programming?
    I guess we have to wait and see....

  • Officejet 150 mobile printer with iPad/ iPhone and Android devices.

    Hi All,
    The Officejet 150 mobile printer won't work with IOS devices like iPhone or IPad over bluetooth connection.
    But can work with android devices. You can download the printshare app and print via bluetooth connection
    Happy printing
    Click on the "Thumbs up"button on the left to say "Thanks"
    Please mark the post that solves your problem as "Accepted Solution"
    (Although I am employed by HP, I am speaking for myself and not for HP)

    Hi,
    I'm happy to announce that there is now an additional solution for mobile printing using the HP NFC/Wireless 1200w Mobile Print Accessory (HP Part Number: E5K46A) that will work on a number of HP Printing devices, please see the link: http://h20195.www2.hp.com/v2/GetPDF.aspx%2F4AA4-82​35ENW.pdf
    The only requirement is that you have the latest firmware revision installed on the device, this can also be powered directly from the devices USB port (in your case OfficeJet 150) via the USB cable.
    Regards
    Pedro
    Regards
    Pedro
    I do work for HP and my comments & advice are mine alone.

  • Problems with EA2700 and Android devices

    I enjoyed EA2700 for more than 3 months so far until I decided to change my cell phone to Galaxy S3.
    I have my router operating 2.4Ghz and 5Ghz simultaneously, providing perfect internet access to my two windows 7 laptops, mac mini and iPad. This is not the case when I try to hook my Galaxy S3 phone and Galaxy Tab 2 7.0. This two korean devices have a real problem using the router for internet. Both the tablet and the phone connect to the router and have strong signal, but there is no ping going through nor any other internet app works. The router is set to WPA2/WPA Mixed personal sec mode and auto channel. I even try to make it open, but even then the Android devices connect but don't have an internet access. In the same time the rest of the home pcs and mac work perfectly.
    I tried, for the two last days different approaches like upgrading the router firmware, installing the cloud and the smart wi-fi interface, removing the security and opening the network…. it didn't work! What I figure out so far that if I set a guess account the devices connect without problem and have internet, although I have to manually enter  the password for the guess account, which dialogue is provided through a web page you have to navigate to before attempting to use internet. I though the problem could be with the Samsung s3 and the tablet 2 7.0,  and had them several time reset to their factory settings.
    I tried connecting and old WRT 120N router and it worked fine!!!! just this EA2700 is still not usable with android devices running Android 4.0 OS.
    Has somebody experienced the similar problem please share the found solution, otherwise I have to change the EA2700 i guess.
    Solved!
    Go to Solution.

    @NO_SCREENNAME@ wrote:
    I enjoyed EA2700 for more than 3 months so far until I decided to change my cell phone to Galaxy S3.
    I have my router operating 2.4Ghz and 5Ghz simultaneously, providing perfect internet access to my two windows 7 laptops, mac mini and iPad. This is not the case when I try to hook my Galaxy S3 phone and Galaxy Tab 2 7.0. This two korean devices have a real problem using the router for internet. Both the tablet and the phone connect to the router and have strong signal, but there is no ping going through nor any other internet app works. The router is set to WPA2/WPA Mixed personal sec mode and auto channel. I even try to make it open, but even then the Android devices connect but don't have an internet access. In the same time the rest of the home pcs and mac work perfectly.
    I tried, for the two last days different approaches like upgrading the router firmware, installing the cloud and the smart wi-fi interface, removing the security and opening the network…. it didn't work! What I figure out so far that if I set a guess account the devices connect without problem and have internet, although I have to manually enter  the password for the guess account, which dialogue is provided through a web page you have to navigate to before attempting to use internet. I though the problem could be with the Samsung s3 and the tablet 2 7.0,  and had them several time reset to their factory settings.
    I tried connecting and old WRT 120N router and it worked fine!!!! just this EA2700 is still not usable with android devices running Android 4.0 OS.
    Has somebody experienced the similar problem please share the found solution, otherwise I have to change the EA2700 i guess.
    you may wanna try using Wireless B/G Only for network mode on 2.4GHz. check if your devices can connect to the network successfully. there was an issue with Android devices connecting to N networks before so this might be a fix. however, it will rate limit your connection speeds to 54Mbs at best.
    there's also a workaround you can try on the android devices. ensure wifi is set to enable at start up. turn off wifi and reboot the device. verify your connection status. since your devices have already connected to the network, they should reconnect to the network automatically. check if you can go online from there.

  • [SOLVED]Can't mount iPhone/Android devices.

    Hi,
    Since some update (can't tell exact update) I am unable to mount mobile devices on iOS or Android as a flash drive. It appears as "camera" in my "Available Devices" in KDE and when I try to open it with file manager, it appears blank.
    In journalctl I can see the reason, but don't know how to fix it:
    sep 11 12:32:14 laptop kernel: usb 1-1.2: new high-speed USB device number 11 using ehci-pci
    sep 11 12:32:14 laptop mtp-probe[20038]: checking bus 1, device 11: "/sys/devices/pci0000:00/0000:00:1a.0/usb1/1-1/1-1.2"
    sep 11 12:32:14 laptop mtp-probe[20038]: bus: 1, device: 11 was not an MTP device
    sep 11 12:32:14 laptop kernel: ipheth 1-1.2:4.2: Apple iPhone USB Ethernet device attached
    sep 11 12:32:14 laptop upowerd[2855]: usbmuxd_get_device_list: error opening socket!
    sep 11 12:32:14 laptop colord[709]: Device added: sysfs-Apple_Inc.-iPhone
    sep 11 12:32:14 laptop systemd[1]: Starting iOS USB Muxer...
    -- Subject: Unit usbmuxd.service has begun with start-up
    -- Defined-By: systemd
    -- Support: http://lists.freedesktop.org/mailman/listinfo/systemd-devel
    -- Unit usbmuxd.service has begun starting up.
    sep 11 12:32:14 laptop systemd[1]: Started iOS USB Muxer.
    -- Subject: Unit usbmuxd.service has finished start-up
    -- Defined-By: systemd
    -- Support: http://lists.freedesktop.org/mailman/listinfo/systemd-devel
    -- Unit usbmuxd.service has finished starting up.
    -- The start-up result is done.
    sep 11 12:32:14 laptop usbmuxd[20052]: [12:32:14.302][3] usbmuxd v1.0.8 starting up
    sep 11 12:32:14 laptop usbmuxd[20052]: [12:32:14.303][3] Successfully dropped privileges to 'usbmux'
    sep 11 12:32:14 laptop usbmuxd[20052]: [12:32:14.311][3] Connecting to new device on location 0x1000b as ID 1
    sep 11 12:32:14 laptop usbmuxd[20052]: [12:32:14.311][3] Initialization complete
    sep 11 12:32:14 laptop usbmuxd[20052]: [12:32:14.312][3] Connected to v1.0 device 1 on location 0x1000b with serial number bda1b89b56ff882835c0790ebe27d9e74e163cec
    sep 11 12:32:14 laptop systemd-sysctl[20064]: Duplicate assignment of kernel/sysrq in file '/usr/lib/sysctl.d/50-default.conf', ignoring.
    sep 11 12:32:14 laptop systemd-sysctl[20065]: Duplicate assignment of kernel/sysrq in file '/usr/lib/sysctl.d/50-default.conf', ignoring.
    sep 11 12:32:14 laptop systemd-udevd[20035]: renamed network interface eth0 to enp0s26u1u2c4i2
    sep 11 12:32:14 laptop NetworkManager[389]: <warn> failed to allocate link cache: (-10) Operation not supported
    sep 11 12:32:14 laptop NetworkManager[389]: <info> (enp0s26u1u2c4i2): carrier is OFF
    sep 11 12:32:14 laptop NetworkManager[389]: <info> (enp0s26u1u2c4i2): new Ethernet device (driver: 'ipheth' ifindex: 27)
    sep 11 12:32:14 laptop NetworkManager[389]: <info> (enp0s26u1u2c4i2): exported as /org/freedesktop/NetworkManager/Devices/5
    sep 11 12:32:14 laptop NetworkManager[389]: <info> (enp0s26u1u2c4i2): device state change: unmanaged -> unavailable (reason 'managed') [10 20 2]
    sep 11 12:32:14 laptop NetworkManager[389]: <info> (enp0s26u1u2c4i2): bringing up device.
    sep 11 12:32:14 laptop NetworkManager[389]: <info> (enp0s26u1u2c4i2): preparing device.
    sep 11 12:32:14 laptop NetworkManager[389]: <info> (enp0s26u1u2c4i2): deactivating device (reason 'managed') [2]
    sep 11 12:32:14 laptop NetworkManager[389]: <info> Added default wired connection 'Wired connection 3' for /sys/devices/pci0000:00/0000:00:1a.0/usb1/1-1/1-1....26u1u2c4i2
    sep 11 12:32:14 laptop kernel: IPv6: ADDRCONF(NETDEV_UP): enp0s26u1u2c4i2: link is not ready
    sep 11 12:32:17 laptop kernel: traps: iphone-set-info[20040] general protection ip:7fd151259e86 sp:7fff6197fdf0 error:0 in libimobiledevice.so.4.0.1[7fd15114e000+1a000]
    sep 11 12:32:17 laptop systemd-coredump[20067]: Process 20040 (iphone-set-info) dumped core.
    -- Subject: Process 20040 (iphone-set-info) dumped core
    -- Defined-By: systemd
    -- Support: http://lists.freedesktop.org/mailman/listinfo/systemd-devel
    -- Documentation: man:core(5)
    -- Process 20040 (iphone-set-info) crashed and dumped core.
    -- This usually indicates a programming error in the crashing program and
    -- should be reported to its vendor as a bug.
    I've tried to mount iOS device with ifuse, but it didn't work either.
    Any idea?
    Thanks in advance.
    Last edited by Zack7777 (2013-11-11 10:13:26)

    Thanks for the answers.
    ewaller wrote:That looks like it is trying to treat your iPhone as a network interface.  Have you turned on USB tethering on your phone?  What happens if you turn it off?
    It's always like this, no matter if I turn on or off tethering.
    mzneverdies, donniezazen,
    Ok, this seems to work with android devices but not with iOS. Also when I run detect while my iPhone is plugged in, device list is empty:
    $ mtp-detect
    Unable to open ~/.mtpz-data for reading, MTPZ disabled.libmtp version: 1.1.6
    Listing raw device(s)
    No raw devices found.
    Main goal is to return support of iOS.
    Last edited by Zack7777 (2013-09-12 07:56:34)

  • ISE BYOD Android : Impossible to launch "Network setup assistant"

    Hello
    The Byod procedure fails when launching "Network setup assistant"
    Error message  is: "This profile could not be downloaded, are-you connected to Guest Portal ?"
    WLC 5508  (VM) 7.5
    Wlan : Flexconnect
    Config : AP Flexconnect
    ISE 1.3
    Android 4.1.2
    Here are the step:
    1: Rule CWA : Redirect to Guest portal : OK
    2: Rule CWA : Redirect to device portal : OK
    3: Rule Android_dualSSID : Downloading "Network setup assistant" from Googleplay : OK
    4: Rule Android_dualSSID :  Launch "Network setup assistant 1.2.40"  : NOK
    Note : Profile "CWA_GooglePlay" = Redirect-ACL (NSP-ACL-Google)
    The NSP-ACL-Google looks like:
    (Taken from Flexconnect AP):
    Extended IP access list NSP-ACL-Google
        10 permit ip any host <IP ISE>
        20 permit ip host <IP ISE> any
        30 permit udp any range 0 65535 any eq domain
        40 permit udp any eq domain any range 0 65535
        50 permit ip any 74.128.0.0 0.0.255.255
        60 permit ip 74.128.0.0 0.0.255.255 any
        70 permit ip any 173.194.0.0 0.0.255.255
        80 permit ip 173.194.0.0 0.0.255.255 any
        90 permit ip any 206.111.0.0 0.0.255.255
        100 permit ip 206.111.0.0 0.0.255.255 any
        110 permit ip any 74.125.0.0 0.0.255.255
        120 permit ip 74.125.0.0 0.0.255.255 any
        130 permit ip any 208.117.224.0 0.0.0.255
        140 permit ip 208.117.224.0 0.0.0.255 any
        150 permit ip any 216.12.120.0 0.0.0.255
        160 permit ip 216.12.120.0 0.0.0.255 any
        170 deny ip any any
    Could you please help
    Michel Misonne

    Hello
    We use the one describe in "Cisco Unified Access (UA) and Bring Your Own
    Device (BYOD) CVD"
    I tried also with this one:
    Extended IP access list NSP-ACL-Google
        10 permit ip any host 10.35.124.195
        20 permit ip host 10.35.124.195 any
        30 permit ip any host 10.35.65.4
        40 permit ip host 10.35.65.4 any
        50 deny ip any 72.163.1.0 0.0.0.255
        60 permit ip any any
    10 : ISE
    20 : ISE
    30 : DNS
    40 : DNS
    50  :Enroll.cisco.com= 72.163.1.80  ( To redirect the Network setup assistant to ISE)
    (Enroll.cisco.com is the adresse that the Network setup assiatnt is tryiong to connect)
    Regards
    Michel

  • Problem with Afaria and LDAP user authentication in Android device

    Hi all,
    I have a server with Afaria 7 (SP4, hotfix3) installed. In this Afaria there is a tenant (system) without LDAP/AD integration working correctly. I need to have other tenant with LDAP integration in which the users must be authenticated.
    I know that for iOS devices is necessary reinstall the iphoneserver selecting "Afaria Server managed authentication" but at first I want to make run the Android devices. For this reason I don't do this yet.
    I follow the next steps:
    1-Create a new tenant
    2- Configure LDAP integration
    3-Create a inventory policy with authentication required
    4-Create a static group associated to the inventory policy
    5-Create a enrolment policy associated to the static group.
    When I launch the Afaria agent on the device, the user/password parameters are required. After fill the user/password parameters, the device connect to the server and then is show the message "user or password incorrects".
    I have seen the log and seem the problem is that Afaria can't authenticate this user.
    I validate that Afaria can "see" the LDAP users creating a user group that contains this user(JimenM99)
    The problem is autentication, because if I remove "autentication required" of the inventory policy, the device enrol correctly.
    Could you please help to solve this problem?
    Thanks in advance.  

    Hi all,
    I have a server with Afaria 7 (SP4, hotfix3) installed. In this Afaria there is a tenant (system) without LDAP/AD integration working correctly. I need to have other tenant with LDAP integration in which the users must be authenticated.
    I know that for iOS devices is necessary reinstall the iphoneserver selecting "Afaria Server managed authentication" but at first I want to make run the Android devices. For this reason I don't do this yet.
    I follow the next steps:
    1-Create a new tenant
    2- Configure LDAP integration
    3-Create a inventory policy with authentication required
    4-Create a static group associated to the inventory policy
    5-Create a enrolment policy associated to the static group.
    When I launch the Afaria agent on the device, the user/password parameters are required. After fill the user/password parameters, the device connect to the server and then is show the message "user or password incorrects".
    I have seen the log and seem the problem is that Afaria can't authenticate this user.
    I validate that Afaria can "see" the LDAP users creating a user group that contains this user(JimenM99)
    The problem is autentication, because if I remove "autentication required" of the inventory policy, the device enrol correctly.
    Could you please help to solve this problem?
    Thanks in advance.  

  • Using HH2 as WAP with Infinity and Android devices

    We have just had Infinity installed.
    Before Infinity I had two HH2s set up as waireless access points using the guide prodiced by Keith of this neighbourhood.  They conected back to the HH3 via two TP-Link powerlink units.  It all worked well.  I never got round to resetting the SSID to the same on all 3 hubs which meant as you moved from one side of the house to the other you have to choose a different router.
    BT set up Infinity today and it was working fine with my original setup however on the spur of the moment I decided I would change the SSID for all three hubs (two original HH2s and the new HH5).
    I started with HH5 and it worked fine.  I then worked my way around the other two HH2s and it seemed to work for a while and then suddenly when I was in the same room as the HH5 my Android tablet could not get the internet.  Logging into the IP address for the HH5 it showed that it was connected.  The blue linelight was on.  The internet radio in the cooking room was connected and working, presumably connected to the nearest HH2.
    I reset the wireless settings on the HH5 but still my tablet and my Android phone got the error page saying that there was no internet connection.  After diconnecting a couple of times I eventually got the Android tablet connecting to both the HH5 and to the common SSID now shared by the HH2s.  My phone wont connect at all.
    As a test I then connected my work laptop via a cable connection to a TP-Link and it worked fine.  I then connected it via the commn SSID (HH2 only) and the HH3 SSID and agin it works fine.  This thread is created on WiFi to the common SSID.
    Sorry for the long description.
    Two questions:
    1.  When setting the common SSID I used the same passkey for all three routers, was this the best way to do it?
    2.  Why has my Android phone lost connectivity and how do I recover it?
    PS 3rd question, why wont this forum accept the word "kit c hen"?
    PPS I've just checked on the settings within HH5 and the phone is showing as connected but to the 2.4GHz signal.

    There are a couple of different guides on my website, one of them is by Jarviser, so I don`t know which one you are using.
    If you make all the SSIDs the same, then Android devices tend to get confused, as they see the same SSID, but with a different BSSID (Wireless MAC address).
    This can cause them to fail to get a valid IP address, so you get no connectivity, this is a common issue with BT Wifi hotspots as well, when Android devices are used.
    It would be better to use slightly different SSIDS, and then allow the devices to automatically select the one that is in range.
    Make sure that the HH2s are on different channels, and make sure that smart wireless, and smart setup is disabled on the HH5.
    To answer your last question, its part of the spam protection that was implemented on this forum a while back.
    There are some useful help pages here, for BT Broadband customers only, on my personal website.
    BT Broadband customers - help with broadband, WiFi, networking, e-mail and phones.

  • I can't sync my mobile with laptop, and dialogue on android device gets stuck. Is this a bug?

    I use my Ee PC notebook as the "main device" and have successfully synced with my other laptop. When I try to sync with Android Phone however, I don't get a 3 x 4 digit code that I should enter in the dialogue pop-up on the main device.
    My Android also shows 3x4 dots where i´m supposed to enter the code. So, no code, and two empty 3x4 dot dialogue pop-ups.
    Worse, the dialoge pop-up on my Android device gets "stuck", It does not respond to the cancel button and won't go away when I use the arrow back-button on the device.

    Thank you for your reply. I tried to sync using the Sync key (by tapping "I don't have the device with me"), but again: the dialog pop-up on my android got stuck and I had to restart it.
    Now I have trouble to log the bug to file it. I suppose I have to log the Android activity, since that is the device I'm having trouble with (syncing two laptops worked fine). But I have no idea were to find "about:sync-log" on my droid phone :-S
    Hope you can help? Really appreciate it!

  • I have a MacBook Pro 15" laptop with Retina running OSX 10.8.5. It will not recognize that my android device (Samsung Galaxy Note3). I am using the standard USB that came out of the box to connect my device to my MAC. Deleted Kies 4 MAC. Help Pls!

    I have a MacBook Pro 15" laptop with Retina running OSX 10.8.5. It will not recognize that my android device (Samsung Galaxy Note3). I am using the standard USB that came out of the box to connect my device to my MAC. Deleted Kies 4 MAC. Help Pls!

    Dee002 wrote:
    MacBook's only have 2.0 USB ports.
    Wrong. 
    If you're not going to provide correct advice then don't repsond at all.
    http://www.apple.com/macbook-pro/specs-retina/

  • Flash Builder will not debug app with .ane on Android Device

    Hello ,
    I'm having a big issue with the overall stability of Flash Builder 4.7 on my Mac (OS X 10.7.5)
    I developped an extension on FB 4.6 for iOS and Android and it was  working good. In the meantime I updated to 4.7, and since then I keep on running in to lots of problems when debuggin or compiling.
    Now my extension needs to be extended, and suddenly the complete project stopped, because debugger refuses working on android devices.
    The error I get is:
    An internal error occurred during: "Launching MyAppWithExtension".
    java.lang.NullPointerException
    at com.adobe.flexbuilder.project.ui.utils.ANE.AppXMLFileANEExtensionHandler.retainExtensionIds(AppXMLFileANEExtensionHandler.java:309)
    at com.adobe.flexbuilder.project.ui.utils.ANE.ANEController.modifyAppXMLforPackaging(ANEController.java:360)
    at com.adobe.flexbuilder.project.ui.utils.ANE.ANEController.modifyAppXMLforPackaging(ANEController.java:326)
    at com.adobe.flexbuilder.project.ui.utils.ANE.AbstractANEPackageHandler.modifyAppXMLforPackaging(AbstractANEPackageHandler.java:86)
    at com.adobe.flexide.launching.multiplatform.launchhandlers.AbstractMultiPlatformLaunchHandler.handleANEPackagingDetails(AbstractMultiPlatformLaunchHandler.java:195)
    at com.adobe.flexide.launching.multiplatform.launchhandlers.AbstractMultiPlatformLaunchHandler.applyPackagingDetails(AbstractMultiPlatformLaunchHandler.java:168)
    at com.adobe.flexide.multiplatform.android.launching.ADBLaunchHandler.initialisePackager(ADBLaunchHandler.java:533)
    at com.adobe.flexide.multiplatform.android.launching.ADBLaunchHandler.doPackage(ADBLaunchHandler.java:409)
    at com.adobe.flexide.multiplatform.android.launching.ADBLaunchHandler.launch(ADBLaunchHandler.java:350)
    at com.adobe.flexide.launching.multiplatform.MultiPlatformLaunchDelegate.launch(MultiPlatformLaunchDelegate.java:184)
    at com.adobe.flexide.launching.AbstractFlexLaunchDelegate.launch(AbstractFlexLaunchDelegate.java:244)
    at com.adobe.flexide.launching.AbstractFlexLaunchDelegate.launch(AbstractFlexLaunchDelegate.java:134)
    at org.eclipse.debug.internal.core.LaunchConfiguration.launch(LaunchConfiguration.java:854)
    at org.eclipse.debug.internal.core.LaunchConfiguration.launch(LaunchConfiguration.java:703)
    at org.eclipse.debug.internal.ui.DebugUIPlugin.buildAndLaunch(DebugUIPlugin.java:928)
    at org.eclipse.debug.internal.ui.DebugUIPlugin$8.run(DebugUIPlugin.java:1132)
    at org.eclipse.core.internal.jobs.Worker.run(Worker.java:54)
    Session Data:
    eclipse.buildId=M20110909-1335
    java.version=1.6.0_51
    java.vendor=Apple Inc.
    BootLoader constants: OS=macosx, ARCH=x86_64, WS=cocoa, NL=en_US
    Framework arguments:  -keyring /Users/myusername/.eclipse_keyring -showlocation
    Command-line arguments:  -os macosx -ws cocoa -arch x86_64 -keyring /Users/myusername/.eclipse_keyring -consoleLog -showlocation
    This is a continuation of log file /Users/myusername/PathToMy/Workspaces/MyAppWithExtension/.metadata/.bak_0.log
    Created Time: 2013-07-24 11:43:14.053
    What I tried so far:
    - Creating new workspace
    - Running Flash Builder with -clean parameter at startup
    - Reinistalling Flash Builder using Adobe Clean Tool
    - Stripping all metadata from the project (keeping only the source files) and make a complete new project setup.
    All to no avail.
    There's a good chance, I have a problem in my .ane code, but how am I supposed to find out, if debugger isn't working?
    BTW, I can make an release build of the project, but it hangs after the splash screen. I don't know, if it's a build or coding error, though.
    Ironically, I convinced my my employer to update FB to 4.7 due to the advanced iOS debugging features, but now I already spent about 10 times more working hours in finding workarounds to debugging / compiling issues than these features will ever be able to save me.
    Maybe anybody here has an idea on how to solve this issue ?

    Ok, this is an old post but i still needed a couple of hours to find a solution, so here we go:
    - Most likely you have TWO executable build targets in your project (two mxml that you can launch). If so, go to the Project settings > Flex Applications and remove the one you don't need so you only have one.
    - My case was a bit complex though - i was using an ANE and Coldfucion server. In this case change the Output folder in the Project Properties > Flex Server > Output folder to something like "temp" instead of "C:..." generated by Flex Builder. The Android device gets confused by a "C:" reference but still can understand a local "temp" folder
    I hope i have saved your day

  • ISE deny access to Android devices

    I have a customer who likes to deny access to any Android devices on its guest service. (The network has an anchor WLC, the authentication is set as LWA)
    First I tried setting a simple AuthZ rule indicating "if Device-OS equals Android, then Deny Access"
    Also tried setting a profiled group. Any device belonging to this Android devices group must be denied.
    It appears the results were not consistent enough. On my first tests, a Galaxy smartphone was not allowed to pass after the AUP, but after some tries the user got access.
    I think something may be missing in the config, as it appears the ISE is not recognizing the Device-OS. Any device is added to the profiled group.
    Some idea to troubleshoot and fix this requirement?
    Regards

    I did a quick test enabling DHCP profiling on WLAN in the WLC. I couldn't did extensive tests because the DHCP appears to not working, so I needed to back. I don't understand why enabling this option affects the DHCP functionality ...
    Unfortunately I can't do extensive tests on productive network, so I would need to be sure about which parameters to change.
    In lab (not the same environment to test) I have seen the ISE is able to identify a Galaxy smartphone as Samsung Device (by RADIUS probe), I guess by the OUI Endpoint, and some minutes later as Android (by DHCP probe) ... So, I wonder if it is possible to define a priority or preference over which probe apply first ...
    In the ISE Endpoint details I found this
    User-Agent      Mozilla/5.0 (Linux; U; Android 2.3.6; es-us; GT-I9070 Build/GINGERBREAD) AppleWebKit/533.1 (KHTML, like Gecko) Version/4.0 Mobile Safari/533.1
    I guess here is where the ISE learns from the device is an Android, right?
    Regards ...

  • Cisco ISE integration with SMS passcode Device

    HI Experts,
    i have a scenario where the requirement is to integrate the ISE device with SMSpasscode device which will trigger the OTP to the mobile devices 
    Currently i have my authentication configured to work with the AD 
    When my VPN users connects  its authenticates against AD and the users get the access . 
    Now as per the new requirement once the user is authenticate against AD ,  the user should be prompted for the OTP password send to the users  using SMS passcode device 
    Anyone had worked on similar requirement please help me to resolve the issue .
    Thanks in advance 
    Angus

    Hi all
    I am working exactly for a month on this topic with no success.
    I need to integrate VASCO OTP solution. But VASCO do not support any external authentication backend for virtual/SMS token. Only passcode or local authentication.
    I need to implement an external authentication against LDAP somewhere...
    Gunnar, do CISCO clearly says it is not able to participate to such setup?
    So, my need would be to be able to insert in the flow an authentication in ISE against the LDAP.
    The flow is:
    WebApplication send login+password (LDAP) to ISE
    ISE checks the credentials and if it is OK forward the request to VASCO
    VASCO does not check for password but generate the OTP and send it via SMS
    VASCO replies with a access-challenge
    ISE forward the challenge to Web Application
    WebApplication send login+OTP response to ISE
    ISE forward to VASCO
    VASCO checks for OTP and replies to ISE with accept
    ISE forward to Web Application
    User is logged in...
    All the flow is working if the user enters a passcode
    I would like to implement a Identity source sequences where the user is checked again all the entries not the first match
    First LDAP then VASCO...

Maybe you are looking for

  • I have just updated my Mac but can't connect iPhone and Ipad

    Why cant I connect my iPhone and Ipad to my mac via bluetooth??

  • HT3235 How to connect or activate mini dvihdmi port on Mac pro 10.6x ?

    Why when I plug mini dvihdmicable adapter into the mini dvi port and then into my HDTV nothing happens? What am I not doing?

  • OEM 12.1.0.3 installation problem

    Hi, I want to install OEM 12c Release 3 (12.1.0.3) on my virtual machine/box. VM details: Windows Server standard 2007 service pack 2 Memory(RAM) :5 GB System Type : 64 bit. HDD free space : 9 GB Already 11g database is installed on this VM. Earlier

  • Code to print report not working

    Dear All, I have installed oracle 10g database and forms 10g on my laptop having o.s xp. when i call report from forms it gives following error- "REP-52266: The in-process Reports Server rep_aouni failed to start.oracle.reports.RWException: IDL:oracl

  • MATERIAL ON A SALES ORDER

    hi everyone, i have question if somebody can help me up In customizing i´ve made a modification in order to assign a control group to a plant for creating a sales order, because i couldnt do it. This messagge appers: THERE IS NO CONTROL GROUP(MASTER