Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG v18 captive portal appears after a few days with Match known users disabled

Hello! Hoping someone has seen this before and has found a solution.

I am running XG firewall home version SFOS 18.0.4 MR-4 on a home network. I have a basic LAN to WAN firewall rule with #Standard LAN Policy applied to it and Match known users unchecked. After a few days, anywhere between 2 and 16 days but never immediately, devices start losing internet connectivity and displaying the captive portal.

Restarting the firewall acts as a workaround until the captive portal appears again after a number of days. The connectivity issues and captive portal appearing all begin at the same time for every device on the network when this happens and there doesn't seem to be a clear reason why it happens when it does. I have Match known users unchecked with the assumption that checking it enables this kind of behaviour, and unchecking it means that the captive portal is never displayed. Am I correct in assuming this? Any ideas why the captive portal is appearing and why the timing seems to be random?



This thread was automatically locked due to age.
Parents
  • Hello Lewis,

    Thank you for contacting the Sophos Community.

    To answer your question, it’s correct.

    When the issue happens do you see in the Log Viewer if the traffic is taking the same Firewall rule as the one that doesn't have Match known users enabled?

    If you aren’t using authentication generally, try disabling globally under System >> Administration >> Device Access.

    Regards,

  • Hey,

    Disabling Client Authentication had no effect but disabling Captive Portal worked. Looking at the timings, the captive portal starts to appear when an AD user logs in to a workstation on the network. Any ideas what is causing this behaviour?

    Correction:

    1. Disabling captive portal removed the sign-in requests however traffic still gets blocked. 
  • Hello Lewis,

    Thank you for the feedback.

    Probably STAS authentication is enabled, Configure >> Authentication >> STAS 

    Regards,

Reply Children