I setup captive portal authentication on fortigate1000d and complete. There are windows and MacOSs on my office. all Windows and MacOSs could do authentication and complete well. but There was only one MacOS machine could not do authentication. which I login using chrome browser with captive portal. after I filled user and password and enter. I got error on chrome browser "ERR_EMPTY_RESPONSE"
after I tried from chrome then I tried on safari both cloud not do authentication
Dose anyone know how to fix this problem. I am not good with MacOS I familiar with windows more
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi,
my approach, not necessarily the best one, would probably be ..
- test with different user (just to rule out that user is not failing to auth)
- test original user on another workstation, or via 'diag test auth..' on FGT, just to test user is OK
- use flow debug + diag debug app fnbamd 7 .. to see that auth is going OK and passing through expected policy
- check policies, there might be unexpected policy matching
Above mentioned tests should tell you a bit more and show the way where to go next.
Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff
thank you xsilver.
I have tested with different user(on MacOS machine that has problem). result It can not do authentication.
I have tested original user on another workstation. result It can do authentication usually
I think Maybe It is a result of that machine because It has problem just only one machine.
I am not sure a machine owner is setup or configured wrong or some file(file system) of MacOS lose. so cause that machine can not do authentication.
so you have ruled out that user is NOT a problematic part. Workstation IS.
What are results of policy check and fnbamd app debug when user tries to auth from broken workstation ?
In general, what is difference between this broken and working workstation ?
Any differences in connection, assigned IP (range differs or so), OS updates, used browser and it's settings ?
It almost certainly is not a problem on FortiGate, but somehow incompatible config of FGT versus workstation.
Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.