Android and iOS enrollment fails with error message "Access to Company Network is not available".

book

Article ID: CTX428050

calendar_today

Updated On:

Description

  • After upgrading the ADC to 12.1-64.16, Android and iOS enrollment started failing.
  • MDM enrollment and profile installation succeeds, and then brought back to SH FTU screen with error message "Access to Company Network is not available".
  • Syslog error: "AAA Client Handler: Found extended error code: 589827"

Resolution

CLI Command:

set vpn sessionAction <Session_Action_Name> -useMIP NS -useIIP OFF

Where <Session_Action_Name> is the name of the Session Profile used for SecureHub 

GUI Option 

SecureHub Session Policy - typically the Profile starts with AC_OS_.... using XenMobile Wizard Profile naming conventions.

image.png

Problem Cause

Found the following in ADC trace:
image.png
image.png
image.png

Issue/Introduction

Requires an additional configuration: set vpn sessionAction -useMIP NS -useIIP OFF