Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Blocked site get the "Network Authentication" page instead of "Blocked Request" page...

Hi,
I just figured out to set the XG Firewall to used it only with Web Filtering.
Now when I have hit on a blocked policy, I'm redirected to the Captive Portal and I get the Network Authenticaion to login.
But I want to get the " Blocked Request" page and not the Network Authenticaion page.
How do I accplish this?
TIA



This thread was automatically locked due to age.
Parents
  • Hi everybody,

    I had the same issue on our XG firewall with SFOS 17.5.3 MR-3. Since this thread is not marked as answered, here's my solution:

    I had to disable Prompt unauthenticated users to log in feature

    Additional I had to disable NTLM Authentication in the Device Access menue

  • Disabling NTLM Authentication is the only thing needed for this.

    Basically if you have NTLM on, it is assumed that all clients are NTLM capable so it will try to authenticate with NTLM.  If that fails then it displays captive portal.  This ends up bypassing the Block Page altogether.

    The "Prompt unauthenticated users of log in" controls whether the block page contains a link to log in (when the user is not authenticated).

     

    The purpose behind both of these is that many companies have configured it so that authenticated users have more privilege to view sites than unauthenticated.  So if they hit a block page they should try to authenticate because after that the policy is re-evaluated and they may no longer be blocked.

     

Reply
  • Disabling NTLM Authentication is the only thing needed for this.

    Basically if you have NTLM on, it is assumed that all clients are NTLM capable so it will try to authenticate with NTLM.  If that fails then it displays captive portal.  This ends up bypassing the Block Page altogether.

    The "Prompt unauthenticated users of log in" controls whether the block page contains a link to log in (when the user is not authenticated).

     

    The purpose behind both of these is that many companies have configured it so that authenticated users have more privilege to view sites than unauthenticated.  So if they hit a block page they should try to authenticate because after that the policy is re-evaluated and they may no longer be blocked.

     

Children
No Data