Captive Portal Support
The Skyhigh Client ensures uninterrupted network protection across both private and public networks by seamlessly adapting to network transitions. When a network change is detected, the Skyhigh Client temporarily enters fail-open mode to establish basic internet connectivity.
This behavior is particularly important when connecting to public Wi-Fi networks, such as those in airports, hotels, or cafés, that require captive portal authentication. Before authentication is completed, internet access is restricted, preventing the Skyhigh Client from establishing a connection with the Skyhigh Cloud Proxy. To allow the user to access the Captive Portal and complete authentication, the Skyhigh Client temporarily bypasses traffic inspection.
Once Captive Portal authentication is successfully completed and internet connectivity is restored, the Skyhigh Client automatically re-establishes its connection to the Skyhigh Cloud Proxy and resumes forwarding traffic for policy enforcement and inspection.
A temporary fail-open mechanism is therefore essential for captive portal support. In contrast, a strict fail-close policy would block all traffic during the authentication phase, preventing users from accessing captive portal pages and, consequently, from connecting to public Wi-Fi networks.
IMPORTANT: Skyhigh Security strongly recommends enabling the block traffic settings for stricter security posture. For more details, see Block Traffic Settings.
