Skip to main content
runab
New Member
August 18, 2024
Solved

/proxy/ issue over sslvpn webportal for http/https bookmark

  • August 18, 2024
  • 5 replies
  • 1707 views
 
We use sslvpn web portal to reach http/https server. We are not able to proceed after browser hits the url https://hostname-fortigate/proxy/xxxxxxx/https/login.microsoftonline.com/common/GetCredentialType?mkt=en-US

I did debug for sslvpn and following is the error:

[313:root:5dd]SSL established: TLSv1.3 TLS_AES_256_GCM_SHA384
[313:root:5dd]do_http_validate:442 method (POST) on uri (/proxy/xxxxxx/https/login.microsoftonline.com/common/GetCredentialType) not allowed.
[313:root:5dd]sslConnGotoNextState:309 error (last state: 1, closeOp: 0)
[313:root:5dd]Destroy sconn 0x7f0f70cae000, connSize=0. (root)
[313:root:5dd]SSL state:warning close notify ()
Best answer by runab

It started working when I set "set ssl-max-proto-ver tls1-2"

config vpn ssl setting

    set ssl-max-proto-ver tls1-2

    

But later I again changed to tls1-3. It still works. It was a bit strange.

5 replies

AEK
SuperUser
SuperUser
August 18, 2024

Did you configure a firewall rule that allows this access?

AEK
runab
runabAuthor
New Member
August 18, 2024

We allow traffic to login.microsoftonline.com. Before it hits this url, other url to login.microsoftonline.com works over sslvpn web portal.

runab
runabAuthor
New Member
August 19, 2024

I checked again I see traffic to login.microsoftonline.com. But when it comes to login.microsoftonline.com/common urls, it gets the error. And it does not allow for SSO to login.microsoftonline.com.

Thought Leadership. Security Summit. Thursday, November 12th, PGA National Resort, Palm Beach Gardens, FL.
Thought Leadership. Security Summit. Thursday, October 8th. Disney's Grand Californian Hotel & SPA, Anaheim, CA.
Security Operations Summit: Modernize SecOps. Operate AI-Native.AMER: November 4 | 9:00 AM PST. India and SAARC: November 5 | 10:00 AM IST. EMEA: November 5 | 10:30 AM CET. APAC: November 5 | 11:00 AM SGT