This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Clientless Access VPN - BUG

Hi,

I have an internal website that my external workers have been accessing via the portal (VPN > Clientless Access). As of yesterday my remote workers can't access pages correctly. I've restarted Sophos XG and the Server. I've noticed in the Log Viewer the following...

Log Comp: SSL VPN

Status: ALLOWED

Username: My Username

Message: Use "My Username" was allowed access of the HTTP resource http://images/logo.jpg

Is this correct? Does the IP address of the internal server need to be prefixed? Eg. http://10.12.44.10/images/logo.jpg

The portal website sometimes displays the page poorly or not at all and I can see the following source code...

The URL for this blank white page is  = https://myexternalip/userportal/CRSSL/http/ClientLogin.aspx

The source code for that page is...

"<!--#set var="TITLE" value="SSLVPN User Portal Error:"

--><!--#include virtual="include/top.html" -->


<!--#if expr="$REDIRECT_ERROR_NOTES" -->
<!--#include virtual="include/spacer.html" -->
<!--#echo encoding="none" var="REDIRECT_ERROR_NOTES" -->
<!--#endif -->"

Please can you help or throw any suggestions my way? Many thanks

EDIT: The first page kind of works. There's no neat formatting or styling. However I can see text. The URL displays the following...

https://externalip/userportal/CRSSL/http/10.12.44.10:8181

When I click any link, a white page appears and the URL changes to https://externalip/userportal/CRSSL/pagename.aspx

It's not prefixing the URL and therefore nothing is displaying correctly. Please can others check this to see if it's just me :)

Many thanks



This thread was automatically locked due to age.
Parents
  • Hi All,

    I want to update about the issues related to Clientless VPN access, there are two reported NC-ID associated to this issue.

    1. NC-13570 - This is resolved in v16.05 MR-5. The bookmarks didn't resolve properly which was caused due to "Restrict Web Applications". When it is ON, it will only allow URLs which have same domain as given in URL of bookmark. It won't allow sub domains which are used in that website. To allow this sub domains, user has to mention "Referred Domains" while creating bookmark. There was an issue in the match condition which is not fixed.
    2. NC-10370 - This issue is a known behavior and the NC-ID is closed. When the URLs are generated dynamically at client side(Web Browser), then the code is not possible to rewrite. If you feel that this is not technically correct then let us know why and I would also request you to push your support case and ask for answers from the development team.

    Thanks

  • I just checked out the known issues list.  Its unfortunate that little-to-no energy is being spent on this.  its a feature I was excited to use, it fills in a nice feature gap for our business.

     

    unfortunately, I have tried 3 different web-based bookmarks and one is rdp.  None of them work.

     

    I don't have time to sort out if they are rewriting urls, etc...I just know that they don't work.  one of them is simply a link to google for testing purposes.  it loads everything except the google logo.  

     

    but trying to use these to access internal resources such as our intranet, web interfaces for networking equipment, or web interface for an internally-hosted app all fail miserably.

     

    I have opened a case, but haven't heard from anyone yet to start working on it.

Reply
  • I just checked out the known issues list.  Its unfortunate that little-to-no energy is being spent on this.  its a feature I was excited to use, it fills in a nice feature gap for our business.

     

    unfortunately, I have tried 3 different web-based bookmarks and one is rdp.  None of them work.

     

    I don't have time to sort out if they are rewriting urls, etc...I just know that they don't work.  one of them is simply a link to google for testing purposes.  it loads everything except the google logo.  

     

    but trying to use these to access internal resources such as our intranet, web interfaces for networking equipment, or web interface for an internally-hosted app all fail miserably.

     

    I have opened a case, but haven't heard from anyone yet to start working on it.

Children
No Data