Created on 
    
	
		
		
		10-01-2024
	
		
		12:01 AM
	
	
	
	
	
	
	
	
	
	
	
	
	
	
  Edited on 
    
	
		
		
		01-23-2025
	
		
		12:50 AM
	
	
	
	
	
	
	
	
	
	
	
	
	
	
 By  
				
		 Jean-Philippe_P
		
			Jean-Philippe_P
		
		
		
		
		
		
		
		
	
			 
		
| Description | This article describes how to troubleshoot the HSTS error for the captive portal in Google Chrome. | 
| Scope | FortiGate, Google Chrome. | 
| Solution | HTTP strict transport security (HSTS) is a web security standard that forces browsers to connect to websites using HTTPS instead of HTTP. This HSTS helps to prevent man-in-the-middle attacks and other types of insecure access to websites. When a domain is enabled for HSTS, the browser will automatically redirect any HTTP request to HTTPS. 
 How is this HSTS causing issues with the FortiGate Captive portal: 
 
 
 MAIN_FW (setting) # show  
 After the above changes, download the 'Fortinet_CA_SSL' certificate from the FortiGate firewall and install it on all end-users PC. 
 Workaround: 
 
 Note: HSTS was implemented on Chrome's recent upgraded version and this is not a FortiGate issue. | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.