Technical Tip: How to troubleshoot HSTS captive portal error in Google Chrome
| Description | This article describes how to troubleshoot the HSTS error for the captive portal in Google Chrome. |
| Scope | FortiGate, Google Chrome. |
| Solution | HTTP strict transport security (HSTS) is a web security standard that forces browsers to connect to websites using HTTPS instead of HTTP. This HSTS helps to prevent man-in-the-middle attacks and other types of insecure access to websites. When a domain is enabled for HSTS, the browser will automatically redirect any HTTP request to HTTPS.
How is this HSTS causing issues with the FortiGate Captive portal:
MAIN_FW (setting) # show
After the above changes, download the 'Fortinet_CA_SSL' certificate from the FortiGate firewall and install it on all end-users PC.
Workaround:
Note: HSTS was implemented on Chrome's recent upgraded version and this is not a FortiGate issue. |

