<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic WLC 9800: detectportal.firefox and gstatic.com without HTTPS in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wlc-9800-detectportal-firefox-and-gstatic-com-without-https/m-p/4657570#M244514</link>
    <description>&lt;P&gt;Hello,&lt;BR /&gt;I'm using the Cisco Catalyst 9800-CL Wireless Controller, with Web Auth and captive portal. The captive portal is hosted on an external server, within my network, with https.&lt;/P&gt;&lt;P&gt;on some devices, when I try to access the internet, I am redirected to the captive portal, using https, as it should.&lt;BR /&gt;However, in some cases I am redirected to portals like detectportal.firefox and gstatic.com (depending on browser) , which use http (no security).&lt;BR /&gt;Is there any way to force the use of the correct portal, ie the portal with https?&lt;/P&gt;&lt;P&gt;Thank you in advance for your help&lt;/P&gt;</description>
    <pubDate>Tue, 26 Jul 2022 13:21:19 GMT</pubDate>
    <dc:creator>Bolivar</dc:creator>
    <dc:date>2022-07-26T13:21:19Z</dc:date>
    <item>
      <title>WLC 9800: detectportal.firefox and gstatic.com without HTTPS</title>
      <link>https://community.cisco.com/t5/wireless/wlc-9800-detectportal-firefox-and-gstatic-com-without-https/m-p/4657570#M244514</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;I'm using the Cisco Catalyst 9800-CL Wireless Controller, with Web Auth and captive portal. The captive portal is hosted on an external server, within my network, with https.&lt;/P&gt;&lt;P&gt;on some devices, when I try to access the internet, I am redirected to the captive portal, using https, as it should.&lt;BR /&gt;However, in some cases I am redirected to portals like detectportal.firefox and gstatic.com (depending on browser) , which use http (no security).&lt;BR /&gt;Is there any way to force the use of the correct portal, ie the portal with https?&lt;/P&gt;&lt;P&gt;Thank you in advance for your help&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 13:21:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-9800-detectportal-firefox-and-gstatic-com-without-https/m-p/4657570#M244514</guid>
      <dc:creator>Bolivar</dc:creator>
      <dc:date>2022-07-26T13:21:19Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 9800: detectportal.firefox and gstatic.com without HTTPS</title>
      <link>https://community.cisco.com/t5/wireless/wlc-9800-detectportal-firefox-and-gstatic-com-without-https/m-p/4657598#M244516</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- For starters have a&amp;nbsp;&lt;SPAN&gt;&amp;nbsp; r&lt;/SPAN&gt;eview the 9800-CL&amp;nbsp; configuration with the CLI command :&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#008000"&gt;show&amp;nbsp; tech&lt;STRONG&gt;&lt;U&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;wireless&lt;/U&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;, have the output &lt;STRONG&gt;analyzed&lt;/STRONG&gt; by&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://cway.cisco.com/tools/WirelessAnalyzer/" target="_blank" rel="noopener nofollow noreferrer" data-saferedirecturl="https://www.google.com/url?q=https://cway.cisco.com/tools/WirelessAnalyzer/&amp;amp;source=gmail&amp;amp;ust=1658930767336000&amp;amp;usg=AOvVaw33eA07Gq5hsb-7UR4xuchX"&gt;https://cway.cisco.com/&lt;WBR /&gt;tools/WirelessAnalyzer/&lt;/A&gt;&amp;nbsp; , please note do not use classical&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;show tech-support&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(short version) , use the command denoted in green for Wireless Analyzer&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 14:07:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-9800-detectportal-firefox-and-gstatic-com-without-https/m-p/4657598#M244516</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2022-07-26T14:07:08Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 9800: detectportal.firefox and gstatic.com without HTTPS</title>
      <link>https://community.cisco.com/t5/wireless/wlc-9800-detectportal-firefox-and-gstatic-com-without-https/m-p/4657668#M244526</link>
      <description>&lt;P&gt;Thanks for the tip. I found and fixed some bugs, as well as adjusting some best practice tips.&lt;BR /&gt;However, nothing related to the problem I'm facing&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 15:44:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-9800-detectportal-firefox-and-gstatic-com-without-https/m-p/4657668#M244526</guid>
      <dc:creator>Bolivar</dc:creator>
      <dc:date>2022-07-26T15:44:02Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 9800: detectportal.firefox and gstatic.com without HTTPS</title>
      <link>https://community.cisco.com/t5/wireless/wlc-9800-detectportal-firefox-and-gstatic-com-without-https/m-p/4657685#M244529</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;- Make sure the destination portal offers (secure) http&lt;U&gt;&lt;STRONG&gt;&lt;FONT color="#008000"&gt;s&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/U&gt;&amp;nbsp; access as default , and or disable&lt;FONT color="#FF0000"&gt; simple http&lt;/FONT&gt; access (&lt;EM&gt;if configured)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 16:19:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-9800-detectportal-firefox-and-gstatic-com-without-https/m-p/4657685#M244529</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2022-07-26T16:19:52Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 9800: detectportal.firefox and gstatic.com without HTTPS</title>
      <link>https://community.cisco.com/t5/wireless/wlc-9800-detectportal-firefox-and-gstatic-com-without-https/m-p/4657702#M244530</link>
      <description>&lt;P&gt;The external captive portal page is configured to operate with https. It is an apache server. That part is working without problems.&lt;/P&gt;&lt;P&gt;I noticed that the problem occurs in two cases:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;1st when the captive portal "default" (detectportal.firefox or gstatic.com) is opened in the browser, with http;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;2nd when the user tries to access a website with https, before authentication. In this case, the request is forwarded to Cisco's default captive portal, from wlc controller, without https.&lt;/P&gt;&lt;P&gt;When trying to access any website that uses http, I am correctly redirected to the secure captive portal (external with https)&lt;/P&gt;&lt;P&gt;Here at the institution, we have a WLC 5500 series, which works correctly for all cases. Besides the version, another difference is that the older wireless cisco controller is physical while the new one (wlc 9800) is virtualized (KVM).&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 17:01:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-9800-detectportal-firefox-and-gstatic-com-without-https/m-p/4657702#M244530</guid>
      <dc:creator>Bolivar</dc:creator>
      <dc:date>2022-07-26T17:01:37Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 9800: detectportal.firefox and gstatic.com without HTTPS</title>
      <link>https://community.cisco.com/t5/wireless/wlc-9800-detectportal-firefox-and-gstatic-com-without-https/m-p/4658691#M244573</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1355998"&gt;@Bolivar&lt;/a&gt;&amp;nbsp;please clarify?&lt;BR /&gt;You say it does NOT work for &lt;STRONG&gt;http&lt;/STRONG&gt; captive portal requests to&amp;nbsp;&lt;SPAN&gt;detectportal.firefox or gstatic.com but then you say "When trying to access any website that uses &lt;STRONG&gt;http&lt;/STRONG&gt;, &lt;STRONG&gt;I am correctly redirected&lt;/STRONG&gt; to the secure captive portal (external with https)" which contradicts that!&lt;BR /&gt;Is your apache server using a valid public certificate with matching fully qualified domain name?&lt;BR /&gt;Does your WLC also have a valid DNS name and cert installed?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Note that http URLs for captive portal detection and redirection are the ONLY way to reliably trigger a captive portal redirection without security/cert warnings or outright failure as some OS/browsers will now block invalid https redirects altogether without any warning.&amp;nbsp; That is the industry standard now, used by all major browsers and OS on all devices.&amp;nbsp; Trying to block that will break the service or at least make it a horrible experience for most users.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2022 16:48:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-9800-detectportal-firefox-and-gstatic-com-without-https/m-p/4658691#M244573</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2022-07-27T16:48:47Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 9800: detectportal.firefox and gstatic.com without HTTPS</title>
      <link>https://community.cisco.com/t5/wireless/wlc-9800-detectportal-firefox-and-gstatic-com-without-https/m-p/4658807#M244582</link>
      <description>&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;"Is your apache server using a valid public certificate with matching fully qualified domain name?"&lt;BR /&gt;Yes, the certificate was signed by the same CA of other services that we already use in the institution.&lt;/P&gt;&lt;P&gt;"Does your WLC also have a valid DNS name and cert installed?"&lt;BR /&gt;Yup. Registered in the institutional DNS server&lt;/P&gt;&lt;P&gt;When I try to access an http page, I am correctly redirected to the captive secure portal page. On the other hand, in some cases, where the access attempt (before authentication) is performed through a website with https (example: &lt;A href="https://www.google.com" target="_blank"&gt;https://www.google.com&lt;/A&gt;), I am redirected to detectportal.firefox or gstatic.com .&lt;/P&gt;&lt;P&gt;To work around this problem, I added a static page, which has the sole purpose of forcing redirection to another page with http. On the other hand, when being redirected to a non-secure page (with http) the WLC manages to redirect me to the correct captive portal (with https).&lt;/P&gt;&lt;P&gt;Here in Brazil, we call this type of procedure a "gambiarra". I believe in English it's "jerry-rig"&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2022 21:30:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-9800-detectportal-firefox-and-gstatic-com-without-https/m-p/4658807#M244582</guid>
      <dc:creator>Bolivar</dc:creator>
      <dc:date>2022-07-27T21:30:33Z</dc:date>
    </item>
  </channel>
</rss>

