Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

TLS Inspection & Google Passkeys

I have TLS inspection setup on my main network running through a Sophos XG (20.0.2 MR-2) and am trying to setup Google Passkeys for G-Mail. 

The passkeys were setup using a different network connection, and they do work on another network. If I go through the G-Mail logon process it gets to the point of displaying the QR code which I scan on a mobile phone, at which point the browser give a "Something went wrong" error and G-Mail asks if I want to try again. 

If I turn TLS inspection off the logon process works using passkeys.

To get Passkey authentication working I suspect that I need to exclude one of the Google URLs from TLS inspection, but don't know which one. I don't want to exclude all Google services, including Gmail itself, from TLS - just the Passkey authentication process.

Has anyone got this working with TLS enabled?



Added TAGs
[edited by: Raphael Alganes at 9:52 AM (GMT -7) on 16 Oct 2024]
Parents Reply
  • I had to make a specific gmail rule for IPv6 traffic. IP4 traffic was handled by the existing mail rule.

    I had to use the IPv6 address of google and create my own IP address group because the current versions of XG v20 and v21 do not support IPv6 FQDNs. The rule only allows smtps.

    Ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

Children
No Data