Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Captive portal and HTTPS requests

hi,

I'm running a XG Firewall at home to test it for a bigger project. Now I have an issue with HTTPS requests which really drives me crazy!

I set up rules for users and clientless devices and every other connection will be dropped. If a device wants to connect to a website with http the captive portal is displayed and after the login the user gets redirected to the requested website. Works perfectly!

BUT if the user requests a httpS website the captive portal is not displayed. An error message comes up telling me that the certificate is invalid.

What am I doing wrong?
Is there a way to get the captive portal displayed even if the requested website is https?

I just want the redirect to be a http request.

Cheers,
Matthias



This thread was automatically locked due to age.
Parents
  • I have the same issue.

    We can't ask guest to install XG cert.

    Any suggestion on HTTPS redirect to captive portal?

  • Hi All,

    The certificate error is caused as HTTPS scanning is enabled in the FW rule to forward the hotspot client traffic to internet. Disable the HTTPS scan from the FW rule if certificates cannot be imported.

    There is a HTTPS redirect option available in the diagonostics> authentication> authentication service> captive portal > redirect HTTPS. Enable this option to redirect HTTPS connections securely to captive portal.

    Thanks

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

Reply
  • Hi All,

    The certificate error is caused as HTTPS scanning is enabled in the FW rule to forward the hotspot client traffic to internet. Disable the HTTPS scan from the FW rule if certificates cannot be imported.

    There is a HTTPS redirect option available in the diagonostics> authentication> authentication service> captive portal > redirect HTTPS. Enable this option to redirect HTTPS connections securely to captive portal.

    Thanks

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

Children