Users can still connect to wifi after closing sign in splash page and not authenticating

Solved
Jason_A
Here to help

Users can still connect to wifi after closing sign in splash page and not authenticating

Hello everyone,

 

I want to apologize in advance for my ignorance, as I am not well versed in networking - our network admin left our company and I am just learning Meraki as I go to help.

 

Our current setup is that when connecting to our corp network, a splash page pops up and you authenticate using your OKTA credentials through our RADIUS server.  The issue we have found is that if you just close out the splash page pop up, you are still able to connect to the internet, albeit not able to connect to anything internally (seems to be giving you a form of guest access).

 

I have currently checked in Wireless -> Configure -> Access Control to see what is set:

 

  • Network Access - Open (no encryption) Any user can associate
  • Splash Page - Sign on with: "My radius server"
  • Failover policy -  If none of your RADIUS servers are reachable, should clients be allowed to use the network?
    • Deny Access

 

I noticed one section named "Captive Portal Strength" which states "The sign-on method you selected requires users to visit a splash page before having access to the network. You can choose how restricted they will be before completing this page."

 

Jason_A_0-1690315569673.png

 

Not sure if this should be set to "block all access until sign on is complete", or if this is even relevant to the issue.

 

Any help here would be greatly appreciated.

 

Thanks everyone!

 

1 Accepted Solution
ww
Kind of a big deal
Kind of a big deal

Almost all web traffic is https. So yes if you set it to allow non http you can still browse almost every website.

 

So you can set it to block and test again . In case you are using a external splash page you have to alow that url in the walled garden https://documentation.meraki.com/General_Administration/Cross-Platform_Content/Walled_Garden

View solution in original post

3 Replies 3
ww
Kind of a big deal
Kind of a big deal

Almost all web traffic is https. So yes if you set it to allow non http you can still browse almost every website.

 

So you can set it to block and test again . In case you are using a external splash page you have to alow that url in the walled garden https://documentation.meraki.com/General_Administration/Cross-Platform_Content/Walled_Garden

Jason_A
Here to help

Thank you very much!  I'm aware most traffic is through https, I was moreso just wondering if that setting was relevant to the issue we are having and could possibly help block that sign in flow problem.  Thanks again, I will try this and report back.

Jason_A
Here to help

This worked - thank you again for your help 🙂

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels