<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Issues with Captive Portal / Continue URL Filtering Response page on 10.1.12 in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/issues-with-captive-portal-continue-url-filtering-response-page/m-p/585269#M3076</link>
    <description>&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;Upgraded 30 days ago to 10.1.12. &lt;BR /&gt;~14 days ago started getting complains from users that sites are broken - getting "site cannot be reached". &lt;BR /&gt;Sites that cannot be reached are site we specifically have "continue" action in our URL Filtering profile for &lt;BR /&gt;Changing "continue" to either "alert" or "allow" fixes the issue &lt;BR /&gt;Tested verting our "continue" Response Page back to Palo predefined default - issue persists when action is "continue" &lt;BR /&gt;Broken sites show a redirect to :6080 &lt;BR /&gt;Traffic logs show 6080 traffic aged-out &lt;BR /&gt;Session log shows active captive-portal sessions for that traffic &lt;BR /&gt;Issue appears to be worsening (started w/ 1 particular site, more and more reports, another firewall affected, ...)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;Any one experience this? Palo TAC says other customers are complaining about similar issue, feels like a PanOS bug but they will not commit to that yet.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&lt;SPAN&gt;EDIT:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;also worth noting - I see the Captive Portal service is not healthy on this problem firewall. I tried restarting it, but no difference - &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;gt; debug software restart process l3-service&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;gt; show system software status | match l3svc&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Process&amp;nbsp; l3svc&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; stopping&amp;nbsp;&amp;nbsp; (pid: -1) - User Stop&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&lt;SPAN&gt;Judging by the fact that the browser shows :6080 when "site cannot be reached", I have a hunch this is the issue..&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;EDIT 2: solved - hung l3-svc was the issue. HA failing to an HA peer that had a "running" l3-svc immediately cleared up the issue.&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;Unfortunately during this maintenance we uncovered a whole new issue/behavior in that, when we rebooted a suspended Passive HA peer, it came back totally borked and HA is just constantly flapping. Working w/ Palo TAC on this now..&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 01 May 2024 18:36:43 GMT</pubDate>
    <dc:creator>NeonNetSec</dc:creator>
    <dc:date>2024-05-01T18:36:43Z</dc:date>
    <item>
      <title>Issues with Captive Portal / Continue URL Filtering Response page on 10.1.12</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/issues-with-captive-portal-continue-url-filtering-response-page/m-p/585269#M3076</link>
      <description>&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;Upgraded 30 days ago to 10.1.12. &lt;BR /&gt;~14 days ago started getting complains from users that sites are broken - getting "site cannot be reached". &lt;BR /&gt;Sites that cannot be reached are site we specifically have "continue" action in our URL Filtering profile for &lt;BR /&gt;Changing "continue" to either "alert" or "allow" fixes the issue &lt;BR /&gt;Tested verting our "continue" Response Page back to Palo predefined default - issue persists when action is "continue" &lt;BR /&gt;Broken sites show a redirect to :6080 &lt;BR /&gt;Traffic logs show 6080 traffic aged-out &lt;BR /&gt;Session log shows active captive-portal sessions for that traffic &lt;BR /&gt;Issue appears to be worsening (started w/ 1 particular site, more and more reports, another firewall affected, ...)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;Any one experience this? Palo TAC says other customers are complaining about similar issue, feels like a PanOS bug but they will not commit to that yet.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&lt;SPAN&gt;EDIT:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;also worth noting - I see the Captive Portal service is not healthy on this problem firewall. I tried restarting it, but no difference - &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;gt; debug software restart process l3-service&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;gt; show system software status | match l3svc&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Process&amp;nbsp; l3svc&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; stopping&amp;nbsp;&amp;nbsp; (pid: -1) - User Stop&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&lt;SPAN&gt;Judging by the fact that the browser shows :6080 when "site cannot be reached", I have a hunch this is the issue..&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;EDIT 2: solved - hung l3-svc was the issue. HA failing to an HA peer that had a "running" l3-svc immediately cleared up the issue.&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;Unfortunately during this maintenance we uncovered a whole new issue/behavior in that, when we rebooted a suspended Passive HA peer, it came back totally borked and HA is just constantly flapping. Working w/ Palo TAC on this now..&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 May 2024 18:36:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/issues-with-captive-portal-continue-url-filtering-response-page/m-p/585269#M3076</guid>
      <dc:creator>NeonNetSec</dc:creator>
      <dc:date>2024-05-01T18:36:43Z</dc:date>
    </item>
  </channel>
</rss>

