Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ashik_k
New Contributor

Captive portal issue

Upload.jpgI am facing an issue with the captive portal after updating Google Chrome. I am attaching a screenshot for reference.

Help please for solving the issue.

Regards,
Ashik

Network Engineer
Network Engineer
11 REPLIES 11
AEK
SuperUser
SuperUser

Check if the certificate authority certificate you are signing with is installed on your browser.

Chrome > Settings > Security > Manage Certificates.

AEK
AEK
ashik_k
New Contributor

its already checked

Network Engineer
Network Engineer
ebilcari
Staff
Staff

As I know this page should use http since its function is just to check if the host has internet access. Check the browser if there is any settings or extension that force every site to use https.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
ashik_k

After that browser update we facing the issue. To get internet access, the authentication page needs to load. But right now, the authentication page is not loading, and instead, this error is appearing

Network Engineer
Network Engineer
ebilcari

Yes, usually this page is used by chrome to detect the lack of internet access and redirect to the portal page URL (the process happens in background and is not visible by the end user). This is done through http but it seems that after the upgrade something has change on chrome configuration/behavior. Maybe check if this option is now enabled:

 
 

chrome.PNG

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
ashik_k

its disabled, but issue not resolved.

Network Engineer
Network Engineer
pminarik
Staff
Staff

Well.. the error is pretty self-explanatory. The browser doesn't trust the CA that issued the server-certificate being presented.

 

I know you wrote that "it's already checked", but with all due respect I'd trust the browser's claim over yours.

 

1, On that error screen, click the red triangle and check what cert chain is being presented, up to the CA.

2, Inspect those certificates in details.

3, Compare the CA shown against the CA you're expecting to be used by the FortiGate for captive portals (by default controlled by config user settings > set auth-ca-cert).

[ corrections always welcome ]
Jagabandhu
New Contributor

Dear Ashik Jee,

I am still facing issues with the captive portal login page not redirecting properly through the Chrome browser. I reported this problem yesterday as well. The FortiGate technical team has informed me that the issue lies with the Chrome browser itself.

 

Could you please provide any updates or suggestions on how to resolve this issue? Your assistance would be greatly appreciated.

 

@fortigate Team,

Could you please confirm when the issue will be resolve.

 

 

Thank you.

Best regards,
Jagabandhu

+91-9439291306

sbabu
Staff
Staff

Hi @ashik_k 

The issue with the captive portal is due to the latest update on Google Chrome. When we open the browser the connectivity test will happen with google.com which is HSTS sites.

 

As a workaround, you can try accessing non-HSTS sites like example.com, yahoo.com to get a captive portal. Once you authenticate the internet works fine for users.

 

Regards,

Shaik Babu.

Shaik Babu
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors