This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Your connection is not Private

Hi, 

purchased an XGS2100 to replace our SG230 for our Public WiFi connection.

The device is not on a domain and has its own internet connection. It is only used for members of the public to get access to the internet on their own  personal devices, mobiles, laptops and tablets etc. We have APX320 access points connected to the device. 

Using the default Web Policy with Source Any Zone Any Host, and Destination Wan Any host   Any Service

Have a hotspot set up with Terms and conditions front page sign in.

A user can connect to the Wifi, then a screen pops up.

SSL Certificate Not Trusted. The security certificate for this network is not from a trusted authority. We do not recommend that you connect to this network.

They can continue and accept the terms and conditions.

After that, a large number of webites show up with the Error, Your connection is not Private. Attackers  etc.  CERT-Authority-Invalid

Is it because their device doesnt have the SSL installed ? if so, how do I get their device to do this so they can acess the internet?

or is it the message we get when trying to access blocked sites and the Blocked site message doesnt show?

Thanks

Trev



This thread was automatically locked due to age.
Parents Reply Children
  • Hi Raphael

    Thanks for the reply, I will certainly look into all these points. 

    I do think a lot of them are blocked sites as more general sites are accessible.

    Is there any way around the certificate installation as a lot of our WiFi users are casual users and will not know how to install a certificate themselves.

    They are members of the public who attend short classes on a short term basis and others just come to use the public WiFi.

    Is there an auto install?

    We dont have this problem on our Sophos SG230 device and all blocked sites show the correct sophos message and users dont get the "Your connection is Not Privsate" message.

    regards

    Trev

  • You should consider excluding "external" devices from SSL-decryption.
    Depends on access rights to vulnerable resources.


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

  • Thank you. I will try that too.

    Users have no access to any resources on our system, The XGS2100 device is only used for them to access the internet and browse sites for personal use on their own devices or on tabkets in our Public access area.


    Currently all users get a message saying  "Could not verify server identity" "Appliance certificate not trusted"  Cancel or Connect.

    If they connect, they then see our Terms and conditions page to access the Public internet.  Is there anyway of not seeing this meesage?

    I have updated the Web access policy and now all general sites seem to be available. 

    thank you

    Trev

  • You need a trusted certificate for your "Terms and conditions page" too.


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

  • The only one I can select from the HotSpot Settings Page is the ApplianceCertificate, is there aother one I need to add or create somewhere?

  • You need to add/import a  trusted certificate


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

  • Hi, appreciate all the help given for this.

    Do you know where I can find instructions on how to "add/import a  trusted certificate"  please?

    Trev