[NetScaler-AAA] MAC address EPA scan on macOS 15 may fail

[NetScaler-AAA] MAC address EPA scan on macOS 15 may fail

book

Article ID: CTX691894

calendar_today

Updated On:

Description

If you have EPA policies to scan Gateway clients MAC address, it may fail after end users upgrading macOS to version 15. Log says, the MAC address predefined in EPA policy cannot be found. Log sample: 

[2024-09-26 15:54:30] Epa Failed
[2024-09-26 15:54:30] Case ID : 9fc30
[2024-09-26 15:54:30] Epa log msg - Access might have been denied because of following issues. Please retry after rectifying relevant issues.

 Machine's Mac address doesn't exist in predefined list.

Environment

Citrix is not responsible for and does not endorse or accept any responsibility for the contents or your use of these third party Web sites. Citrix is providing these links to you only as a convenience, and the inclusion of any link does not imply endorsement by Citrix of the linked Web site. It is your responsibility to take precautions to ensure that whatever Web site you use is free of viruses or other harmful items.

Resolution

Modify NetScaler EPA Action to fit the new MAC address or turn off Private Address on macOS. See: Use private Wi-Fi addresses on Apple devices - Turn this feature off or on for a network


Problem Cause

Apple turns on Private Address feature by default on macOS 15. The feature changes client's MAC address. For details, please see Apple article: About private Wi-Fi addresses and enterprise networks

Issue/Introduction

EPA MAC address scan issue on macOS