Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG Firewall and BYOD WiFi on VLAN in a school

New install of XG Firewall in a UK school and I am really struggling to get the Capture Portal to work on IOS and Android devices.

  • It works for Windows devices, as soon as I connect to the network, a logon window appears (not the sophos one) and I can authenticate and browse the internet.
  • On IOS when connected to the WiFi it gets an IP on the correct VLAN, however the Capture Portal does not appear, it will only appear if we browse to it in safari or chrome. Once logged in, I can access the internet with no issues
  • Android pops up a certificate error page, again if I get to the portal by typing in the URL it works. I have purchased a globally signed certificate but still fails if HTTPS is on or off

Sophos support have spent most of the week on it, to finally tell me that I need to get a certificate for the IP address and not the URL, or install the client. The Client is not an option for over 1000 students and 90+ staff.

If I was to get another certificate, what do I need and which IP address do I use? Or is there a another solution?

I am desperate for a solution and under huge pressure to get this resolved ASAP.

Thanks



This thread was automatically locked due to age.
Parents
  • So essentially clients should do the redirect to the portal. But this can break, if the certificate of the website is not valid/trusted. Therefore you should make sure, the redirect of the Captive Portal is reachable and has a valid cert. You can decide in Admin settings, if you use a URL or a IP for this. 

  • Thanks for the reply, we do have a certificate for the URL, which has a green tick to say it is verified. It is also Globally signed by RapisSSL.

    When we browse internally to the URL via HTTPS on a windows device, IOS or Android it loads with no errors and the certificate is valid.

    The admins settings for the portal as below... 

Reply
  • Thanks for the reply, we do have a certificate for the URL, which has a green tick to say it is verified. It is also Globally signed by RapisSSL.

    When we browse internally to the URL via HTTPS on a windows device, IOS or Android it loads with no errors and the certificate is valid.

    The admins settings for the portal as below... 

Children