Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Captive portal and HTTPS requests

hi,

I'm running a XG Firewall at home to test it for a bigger project. Now I have an issue with HTTPS requests which really drives me crazy!

I set up rules for users and clientless devices and every other connection will be dropped. If a device wants to connect to a website with http the captive portal is displayed and after the login the user gets redirected to the requested website. Works perfectly!

BUT if the user requests a httpS website the captive portal is not displayed. An error message comes up telling me that the certificate is invalid.

What am I doing wrong?
Is there a way to get the captive portal displayed even if the requested website is https?

I just want the redirect to be a http request.

Cheers,
Matthias



This thread was automatically locked due to age.
Parents Reply
  • Guys, I don't do much firewalling these days but get to stay in plenty of hotels every week. I have a bad habit of using google.com for checking my internet connectivity. I can tell you from experience that whenever I use google.com which redirects to https://www.google.com, I never get any kind of authentication offering from the login system. Iphones usually work fine and you get an immediate login page as soon as you connect to a wifi network that needs authentication (hotspot functionality), however for all PCs etc, I always have to use non ssl website to get to the authentication page.

    I don't think 's comment about the issue being known to them means that there is an easy fix. I don't know why he wants to open a feature request on this[8-|]You cannot redirect ssl traffic to a third party without throwing a certificate error. How can you be sure that the website https://mybank.money  is really going to your bank if anyone can hijack your ssl traffic in the middle without any error in your browser? The only way for this to work is to install the certs that are trusted by the client but that is not practical in all cases. Using hotspot or similar where the user authenticates before going to any website is the only way.

    On a side note, I agree with . Sometimes its easy to tell the users to open a feature request. I think the most needed feature in XG was to change interface names because it becomes really confusing using port1, port2 etc when you have multiple networks connected to one appliance. We still don't have it in v16. XG gets a ding from everyone on the logging system since its inception. We still have to use cli to grep and tail different logs. Better feedback mechanism was promised during the beta https://community.sophos.com/products/xg-firewall/v16beta/f/sfos-v16-beta-issues-bugs/79949/beta-4-a-disappointment-with-the-limited-fixes-only-no-innovation/305034#305034 but never materialized. Kicking the ball down the road is not the answer to the question that really need a yes/no answer.

    Regards

    Bill

Children