We ran into this as well, still on 17.10, but, I was able to at least work around this issue for a small branch office. Create a policy group for IOS devices Create a L3 Firewall rule to allow 17.0.0.0/8 (apples subnet) Create a traffic shaping rule for subnet 17.248.190.0/24 (17.0.0.0/8 would also likely work) and set the DSCP tag to 46 (EF - Expedited forwarding) Tell IOS users to turn off "Private wi-fi addresses for the wifi network connected to" https://support.apple.com/en-us/HT211227 Move IOS users into correct policy group Again, workaround for a small office, so does not scale too well, this was done on a MX64W
... View more