We ran into this as well, still on 17.10, but, I was able to at least work around this issue for a small branch office. Create a policy group for IOS devices Create a L3 Firewall rule to allow (apples subnet) Create a traffic shaping rule for subnet ( would also likely work) and set the DSCP tag to 46 (EF - Expedited forwarding) Tell IOS users to turn off "Private wi-fi addresses for the wifi network connected to" https://support.apple.com/en-us/HT211227 Move IOS users into correct policy group Again, workaround for a small office, so does not scale too well, this was done on a MX64W
... View more