Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Captive portal and HTTPS requests

hi,

I'm running a XG Firewall at home to test it for a bigger project. Now I have an issue with HTTPS requests which really drives me crazy!

I set up rules for users and clientless devices and every other connection will be dropped. If a device wants to connect to a website with http the captive portal is displayed and after the login the user gets redirected to the requested website. Works perfectly!

BUT if the user requests a httpS website the captive portal is not displayed. An error message comes up telling me that the certificate is invalid.

What am I doing wrong?
Is there a way to get the captive portal displayed even if the requested website is https?

I just want the redirect to be a http request.

Cheers,
Matthias



This thread was automatically locked due to age.
Parents
  • I have the same issue.

    We can't ask guest to install XG cert.

    Any suggestion on HTTPS redirect to captive portal?

  • Hi All,

    The certificate error is caused as HTTPS scanning is enabled in the FW rule to forward the hotspot client traffic to internet. Disable the HTTPS scan from the FW rule if certificates cannot be imported.

    There is a HTTPS redirect option available in the diagonostics> authentication> authentication service> captive portal > redirect HTTPS. Enable this option to redirect HTTPS connections securely to captive portal.

    Thanks

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

  • No! You give me the wrong issue.

    I didn't enable HTTPS scan in all my rules.

    We are talking about Captive Portal for users to identify.

    Guests got certification error when they open the https website, and failed to redirect to Captive Portal.

    But open http website can redirect to Captive Portal well.

    HTTPS scan is not the issue!

  • Sachin,

    What Shunze is saying is correct. Same thing for me!

  • Hello Luk

    I was able to recreate this and getting the same behaviour. I was not able to get around this without trusting the appliance certificate. 

    The only other workaround I could figure out at the moment was using hotspot, I read earlier in the post that this is a hotspot, so if hotspot and password of the day, or vouchers are enabled, the hotspot captive portal is shown instantly (HTTP and HTTPS). 

    Hope it helps.

  • Varun,

    Thanks for your response. Can you track it internally and give us a response ? I am not using hotspot (only have 3 customers do it).

    This should work out of the box.

    Thanks

Reply Children