Community Record
15
Posts
9
Kudos
0
Solutions
Badges
Apr 2 2024
11:34 AM
2 Kudos
I appreciate it, thank you
... View more
Apr 2 2024
10:49 AM
Hi! Thanks for sharing Raphaell, would you be so kind as to create a support ticket and share that with me on this? Delays here are something I am looking into and driving an improvement process around. We definitely want this to take minutes and not hours.
... View more
Thank you for this response, this agrees with my understanding. Thanks again for taking the time to share/post this!
... View more
Based on our testing, chrome browsers do work. Basically the accepted solution by the google auth API is to permit/allow any full browser that is invoking the google auth process--which definitely includes chrome. please open a support ticket on this so we may track/address thank you
... View more
I hear you and am forwarding this request to our product teams, thank you for sharing it here. While we can do this, some elements of client tracking such as vendor/OS MAC randomization + persistence strategy can confound our efforts here.
... View more
Hi, that step 2 for Android is actually a vertical ellipses which is the droid UI for opening the 'settings' page on the captive portal page in question. We are adding in a line regarding "This also affects desktop users" quickly as well, thank you for the suggestion. Also since I'm here we're also going to be enabling our product support teams to disable this new pre-splash page on google auth SSIDs. We were trying to analyze the cost vs benefit of having the pre-splash page vs not, but after it has been enabled for a certain period of time the cons may begin to outweigh the benefits so we are enabling our support teams to be able to turn this feature off. But I agree with you that step may not be necessary if the instructions clearly explain the desktop user experience is highly similar.
... View more
Yes, any auth method you choose OTHER THAN Google auth will permit the prior /smooth / splash flow. You can pick any of our supported auth methods (Meraki Auth, Radius, various 3rd party, etc) Of course, you are free to deploy your own captive portal as you linked above, just be aware it isn't Meraki that is enforcing this auth requirement from a full browser, it is Google so make sure that you don't use the Google oauth API with your own token as you will end up in precisely the same place we and everyone else are.
... View more
Apologies for the erroneous statement above ("this only affects mobile users"), as it turns out during our testing this affects BOTH mobile and desktop and we are pushing the pre-splash page to ALL users now. Our official documentation on this topic is over here:->https://documentation.meraki.com/MR/MR_Splash_Page/Google_Sign-In I apologize for not being able to edit the original post in this thread!
... View more
This pre-splash page is being sent to both mobile AND desktop. As it turns out from testing, Mac desktop needs the pre-splash page just like mobile devices as do Chromebooks. Only windows users seem to default to a "full browser" , and this is surprisingly difficult to effect (isolate user agents for the desktops that work/dont work)
... View more
roOI, just wanted to double check: your users on a given SSID that is configured for ANY 3rd party auth (not just Google oAuth) is being redirected to the new pre-splash page we built specifically for this Google Auth change? Thank you, also if possible could you open a support ticket on this if true I would like to track/solve this.
... View more
Nov 9 2023
1:56 PM
Update on this topic: This error specifically is coming from Google, and we have a new way to handle this https://community.meraki.com/t5/Wireless-LAN/Upcoming-Changes-for-Meraki-Captive-Portal-Networks-Splash/m-p/212495#M29329
... View more
Nov 9 2023
1:55 PM
403_user_agent forbidden is coming from google. Please see --> https://community.meraki.com/t5/Wireless-LAN/Upcoming-Changes-for-Meraki-Captive-Portal-Networks-Splash/m-p/212495#M29329
... View more
Oct 18 2023
9:39 AM
if I'm not mistaken, this is egress from the user device/client, inbound from the SaaS/provider is untagged and so there may be some benefit* to tagging the traffic inbound. Apologies as I haven't read the support article on this topic. Also if I'm not mistaken per the QoS/design guide on WiFi, by the time the return traffic hits the AP, it is already considered 'too late' and flagging UP or DSCP/fastlane or other priority mechanism at that point is in fact too late. Anyways I love this topic and hope I am not spewing mis-information. 😄
... View more
October 17, 2023 Users of google authentication behind splash captive portals need to be aware of a change in service due to a new policy from Google. Until now, captive portals have redirected users (302 redirect) to a captive portal where authentication is optionally performed including Google Authentication, especially for .edu customers. In the near future, Google will be turning on enforcement of their new security posture which disallows the use of this method to redirect users to Google authentication. Google authentication may still be used, but users will have to open a full/regular browser rather than the embedded browser/websheet to satisfy Google's security requirements. For this reason we have created a new pre-splash informational page that gives the user instructions for how to perform this. This only applies to mobile users, desktop users can bypass this step as they authenticate in a full browser already. The new steps that a mobile user must do are now: 1.) Copy the URL provided with a 'tap here to copy the link' (URL is http://escapessl.com) 2.) Open a full browser, and copy this URL into the address field 3.) Login when prompted to Google If the customer is using a walled garden that includes captive.apple.net and *.gstatic.com/*.google.com (or whatever captive portal OS the user has points to), they don't need to do anything. Otherwise, users may also have to select the equivalent of 'Use this network when not connected to the internet' or equivalent. It is expected that Google will begin enforcement of this change starting towards the end of 2023. Please let us know if you have any questions or concerns, ~Joe Tansey Meraki Cloud Platform joetanse@cisco.com New instruction page
... View more
My Top Kudoed Posts
Subject | Kudos | Views |
---|---|---|
4 | 30487 | |
2 | 1432 | |
1 | 25189 | |
1 | 25190 | |
1 | 27239 |