Skip to main content
runab
New Member
August 18, 2024
Solved

/proxy/ issue over sslvpn webportal for http/https bookmark

  • August 18, 2024
  • 1 reply
  • 1692 views
 
We use sslvpn web portal to reach http/https server. We are not able to proceed after browser hits the url https://hostname-fortigate/proxy/xxxxxxx/https/login.microsoftonline.com/common/GetCredentialType?mkt=en-US

I did debug for sslvpn and following is the error:

[313:root:5dd]SSL established: TLSv1.3 TLS_AES_256_GCM_SHA384
[313:root:5dd]do_http_validate:442 method (POST) on uri (/proxy/xxxxxx/https/login.microsoftonline.com/common/GetCredentialType) not allowed.
[313:root:5dd]sslConnGotoNextState:309 error (last state: 1, closeOp: 0)
[313:root:5dd]Destroy sconn 0x7f0f70cae000, connSize=0. (root)
[313:root:5dd]SSL state:warning close notify ()
Best answer by runab

It started working when I set "set ssl-max-proto-ver tls1-2"

config vpn ssl setting

    set ssl-max-proto-ver tls1-2

    

But later I again changed to tls1-3. It still works. It was a bit strange.

1 reply

AEK
SuperUser
SuperUser
August 18, 2024

Did you configure a firewall rule that allows this access?

AEK
runab
runabAuthor
New Member
August 18, 2024

We allow traffic to login.microsoftonline.com. Before it hits this url, other url to login.microsoftonline.com works over sslvpn web portal.

runab
runabAuthor
New Member
August 19, 2024

I checked again I see traffic to login.microsoftonline.com. But when it comes to login.microsoftonline.com/common urls, it gets the error. And it does not allow for SSO to login.microsoftonline.com.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.