Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Web authentication captive page

1. Login  with https://yourfirewall.domain.com:8090/httpclient.html 

2. After Successful login Close tab / or closed accidently 

3. Again open  https://yourfirewall.domain.com:8090/httpclient.html 

It shows Sign in form with username and password. This is very annoying behavior. When already session is established after sign in it should show logout / signout button instead of login page which will make user life easy. 

-- We have below settings

Sign out user --> When user is inactive 

( Here user is still active, so expected behavior is to show signout or logout button )



This thread was automatically locked due to age.
Parents Reply
  • Hi Michael thanks for the clarification it convincing. One more query. 

    If someone spoof IP which is already logged in.  Whether sophos having any mechanism to understand this ?  Session can be hijacked right ?

    Scenario is when you have L3 routing. Sophos will not get user MAC address.

    User <----> LAN  <----> L3 routing <----> Sophos <---> WAN

Children
  • The XG maintains a list of what user is logged into what IP address, it does not not use MAC address.
    Yes in theory spoofing where one computer appears as another (logged in) computer could occur.  However in practical terms it cannot because of the problems where two computers share the same IP address.  Moreover the impact is low.  The worst would be...  if you had a web policy that blocked Facebook but you knew that Jack down the hall had a different web policy that was allow all, you could spoof Jack's IP and not get blocked.  So you have issues of the wrong policy being applied and the wrong user appearing in reports, but you don't have any loss of security.  The reality is that most people who are bypassing web policy just use their phone connected directly to their cell phone company.