We have a captive portal in identifi with a NON auth policy containing "Allow "rules pointing to Facebook and twitter services.
The facebook ones seems wo work just ok, however the twitter domains doesn work so well, even thou Facebook is more complex and twitter use just two domains "twitter.com" and "twimg.com" (and all those sub-domains).
The clients get stuck time after time on http calls to those domains, or receive certificate warnings...
attached a picture