How to troubleshoot a "Login failed - HTTPS User login not allowed from here" Error?

Description

This article provides troubleshooting steps to resolve the following error message: "HTTPS User login not allowed from here" or "HTTPS Administrator Login not allowed from here" depending on Users Group Membership.

       

Cause

The "HTTPS User login not allowed from here" or "HTTPS Administrator Login not allowed from here" error message may occur in the following scenarios:

Scenario 1: The error is displayed when attempting to manage the SonicWall appliance through a VPN tunnel.
Scenario 2: The SonicWall is configured to require users to authenticate with a username and password before accessing the Internet, a feature commonly referred to as User-Level Authentication (ULA).
Scenario 3: When managing the SonicWall from a computer on a wireless Zone. [Only applies to GEN6 firewalls]

 

Resolution for SonicOS 7.X

This release includes significant user interface changes and many new features that are different from the SonicOS 6.5 and earlier firmware. The below resolution is for customers using SonicOS 7.X firmware.

Scenario 1: The error is displayed when attempting to manage the SonicWall appliance through a VPN tunnel.

  • Login to SonicWall management Interface, Click Network | IPsec VPN | Rules and settings | Policies.
  • Edit the appropriate VPN policy, go to the Advanced tab.
  • Enable the HTTPS option under the User Login via this SA.
  • Save the changes.

 

Scenario 2: The SonicWall is configured to require users to authenticate with a username and password before accessing the Internet, a feature commonly referred to as User-Level Authentication (ULA).

  • Login to the SonicWall GUI.
  • Click Network on the top bar, navigate to System | Interfaces page, and edit the appropriate (e.g. X0 or LAN) Interface.
  • Enable the HTTPS under User Login.
  • Click OK to save the Changes.



Resolution for SonicOS 6.5

This release includes significant user interface changes and many new features that are different from the SonicOS 6.2 and earlier firmware. The below resolution is for customers using SonicOS 6.5 firmware.


Scenario 1: The error is displayed when attempting to manage the SonicWall appliance through a VPN tunnel.

  • Login to SonicWall management Interface, Click MANAGE on the top bar, navigate to the VPN | Base Settings page.
  • Edit the appropriate VPN policy, go to the Advanced tab.
  • Enable the HTTPS checkbox for enabling the User Login via this SA.
  • Click OK to save the changes.



Scenario 2: The SonicWall is configured to require users to authenticate with a username and password before accessing the Internet, a feature commonly referred to as User-Level Authentication (ULA).

  • Login to the SonicWall GUI.
  • Click MANAGE on the top bar, navigate to Network | Interfaces page, and edit the appropriate (e.g. X0 or LAN) Interface.
  • Enable the HTTPS checkbox for enabling the User Login.
  • Click OK to save the Changes

 

Scenario 3: Error while managing the SonicWall from a computer on a wireless Zone.

There are multiple ways to resolve this issue:

Disable WiFiSec Enforcement.

  • Navigate to the diag page after login to Sonicwall. Diag page can be accessed at <https://ip_address/diag.html>. Click INTERNAL SETTINGS.
  • Under Wireless Settings, Disable the checkbox for Legacy WiFiSec Enforcement Support, if it is enabled.
  • Click Accept to Save the changes and CLOSE to exit from the Internal Settings page.
    When WiFiSec enforcement is enabled, it is not possible to access the SonicWall for management from a wireless connection unless a tunnel is successfully established using Global VPN Client. The Login failed - HTTPS Administrator login not allowed from here error is shown in this situation.

Use Global VPN Client 

  • On the wireless computer, Use Global VPN Client to establish the IPSec VPN tunnel with the firewall, then access the SonicWall's LAN IP address for management. For more information on this refer to Group VPN Configuration

NOTE: With WiFiSec Enforcement Support disabled, access rules allowing traffic from the WLAN to the LAN may permit LAN access to all users on the WLAN. This action may not be recommended in some situations for security reasons. 

Related Articles

  • GVC 2FA Not Working on NSA 2700 (Gen7)
    Read More
  • Enforce Default Browser for SAML Authentication in NetExtender 10.3.4
    Read More
  • 第7世代TZ/NSaシリーズと旧世代TZ/SOHO/NSa製品との違い
    Read More
not finding your answers?