Same issues, check out my testing:
https://communities.cisco.com/message/293975#293975
Agreed, only way I could get this to work was to bypass CNA which my customer is not happy about...
Summary:
-2504 Running 8.3, MAB, AAA override and ISE NAC. I get the pop up, enter creds, and are redirected to the success page and it works fine on IOS, MACOS, Windows.
-Meraki MR34, MAB, ISE for Radius and "Use ISE for splash page". My IOS devices get the pop up, enter creds, and get a 400 Error. Works fine on Windows and MACOS.
So, I tried this:
-Meraki MR34, MAB, ISE for Radius and "Use ISE for splash page". Added 17.0.0.0/8 into the walled garden list (nslookup on apple.com), and the CNA browser did not pop up. I opened a browser manually (fail, default was https://www.google.com), went to a http (no s) site, my Splash page came up, enter creds, and logged in just fine.