Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

office365 is not working for unauthenticated users when enable captive portal for users

Hi,

i have XG with V18 MR5 Build 586. it is integrated with Active Directory. users/groups are imported in it. office 365 is being used by all users for emails and so on.

My Requirement is given below:
1. I need to block internet browsing for few users. but  for those user whose internet is blocked their office365(outlook/teams/sahrepoint) should keep working.
2. I need that for those user to whom internet is allowed,office365(outlook/teams/sahrepoint) should keep working,  when user open browser then if he need to do browsing then captive portal will appear and he will give his username and password of AD and he will start browsing according to policies

What i have done is given below:
1. Integrated AD with firewall and imported users
2. Created a DNS rules for name resolution and kept it on top, should i need to create this ???
3. I created firewall rule according to user/group, call appropriate user/group in that Firewall rule. i did not check the show captive portal to unauthenticated users.
4. Created  a web policy for office 365 url and make a firewall for office365 so that every user who is authenticated or not will get his emails. i kept this rule in
bottom, means this is the last rule.

The Challenge i am facing:
with above given Firewall rules, all users who are autenticated and who are not authenticated are able to get emails from office365
but user when open the browser then he did not get the captive portal page automatically. when i manually open like https://1.1.1.:8090 then page appears.
to overcome this when i check the checkbox show captive portal to unathenciated user  in firewall rule. then those user to whom i dont want to use internet did not get emails too and other users start getting captive portal and emails as well but these user only start getting email once authenticate on portal.

please advise how can i achive my requirement given above.

regards,



This thread was automatically locked due to age.
Parents
  • Hi,

    what is your primary dns, if XG you do not need a dns firewall rule.

    you will need seperate rules for those allowed to access the internet and those only allowed to access o365. I also assume you have them in different AD groups?
    ian

  • i created a DNS rule for any to any for everyone and keep it on top

    then create a rule for authenticated users. and called AD group in this rule.

    create  an office365 rule for any to any so that all users either authenticated or non authenticated should get emails. in this rule is did not call any users. it is simple network rule. 

    please guide me. 

  • That sounds okay except for the dns rule. Where does your dhcp server point to for dns?

    ian

  • my lan users are using Active directory as  a DNS server.

    The Challenge i am facing:
    with above given Firewall rules, all users who are autenticated and who are not authenticated are able to get emails from office365
    but user when open the browser then he did not get the captive portal page automatically. when i manually open like https://1.1.1.:8090 then page appears.
    to overcome this when i check the checkbox show captive portal to unathenciated user  in firewall rule. then those user to whom i dont want to use internet did not get emails too and other users start getting captive portal and emails as well but these user only start getting email once authenticate on portal.

  • Do you use the XG dns for any thing? How does the XG resolve requests from your ad?
    ian

Reply Children