<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PaloAlto/Okta CaptivePortal Stopped Working in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/paloalto-okta-captiveportal-stopped-working/m-p/531572#M917</link>
    <description>&lt;P&gt;unfortunate, guess i'll wait too before i try mine again, last time i did this i saw the redirect back to the PA and where it also hung and ended up needing to drive to office to restore.&lt;/P&gt;</description>
    <pubDate>Fri, 17 Feb 2023 12:02:06 GMT</pubDate>
    <dc:creator>govindra</dc:creator>
    <dc:date>2023-02-17T12:02:06Z</dc:date>
    <item>
      <title>PaloAlto/Okta CaptivePortal Stopped Working</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/paloalto-okta-captiveportal-stopped-working/m-p/526831#M751</link>
      <description>&lt;P&gt;Hello!&amp;nbsp; I've had PaloAlto/Okta captive portal authentication working for awhile now.&amp;nbsp; I recently upgraded Okta to Okta Identity Engine, and also upgraded my PA to the latest 10.x.x version.&amp;nbsp; One of those upgrades appears to have broken the Okta/PA integration. SP initiated authentications STILL WORK.&amp;nbsp; IDP initiated authentications do NOT WORK - they redirect to Okta for entering credentials, and then hang on the re-direct back to the PA.&amp;nbsp; i.e, they hang on:&lt;/P&gt;
&lt;P class="p1"&gt;&lt;STRONG&gt;&lt;A href="https://xxxxxxxx.okta.com/login/token/redirect?stateToken=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx" target="_blank"&gt;https://xxxxxxxx.okta.com/login/token/redirect?stateToken=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;The Okta logs show only successful authentications, and no errors.&amp;nbsp; Thus Okta support says the issue is outside of their control.&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;Any suggestions?&lt;/P&gt;
&lt;P class="p1"&gt;Thank you!&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jan 2023 19:04:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/paloalto-okta-captiveportal-stopped-working/m-p/526831#M751</guid>
      <dc:creator>pomologist</dc:creator>
      <dc:date>2023-01-12T19:04:34Z</dc:date>
    </item>
    <item>
      <title>Re: PaloAlto/Okta CaptivePortal Stopped Working</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/paloalto-okta-captiveportal-stopped-working/m-p/527624#M779</link>
      <description>&lt;P&gt;I opened a case with PA about this and it turns out that broken&amp;nbsp;OKTA SAML authentication is a known bug PAN-OS 10.2.3 (version I'm on)!&lt;/P&gt;
&lt;P&gt;PA engineering is working on a fix. &amp;nbsp;PAN-OS 10.2.4 / 11.0.1 is the target fix version, with an ETA is "TBD"....&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jan 2023 23:54:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/paloalto-okta-captiveportal-stopped-working/m-p/527624#M779</guid>
      <dc:creator>pomologist</dc:creator>
      <dc:date>2023-01-18T23:54:30Z</dc:date>
    </item>
    <item>
      <title>Re: PaloAlto/Okta CaptivePortal Stopped Working</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/paloalto-okta-captiveportal-stopped-working/m-p/528784#M819</link>
      <description>&lt;P&gt;FYI the Okta doc about setting up PA CaptivePortal SSO (&lt;A href="https://saml-doc.okta.com/SAML_Docs/How-to-Configure-SAML-2.0-for-Palo-Alto-Networks-CaptivePortal.html" target="_blank" rel="noopener"&gt;https://saml-doc.okta.com/SAML_Docs/How-to-Configure-SAML-2.0-for-Palo-Alto-Networks-CaptivePortal.html&lt;/A&gt;) currently states that Idp-Initiated is not supported.&amp;nbsp; Not sure if that has always been there or is something new just for this issue.&lt;/P&gt;
&lt;P&gt;Quote:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;SP-initiated flows are supported.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;IdP-initiated flows and Just In Time (JIT) Provisioning are not supported.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2023 21:47:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/paloalto-okta-captiveportal-stopped-working/m-p/528784#M819</guid>
      <dc:creator>AaronAxvig</dc:creator>
      <dc:date>2023-01-26T21:47:45Z</dc:date>
    </item>
    <item>
      <title>Re: PaloAlto/Okta CaptivePortal Stopped Working</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/paloalto-okta-captiveportal-stopped-working/m-p/528823#M820</link>
      <description>&lt;P&gt;Hmm, very interesting. It has worked for me for years, and is set up following the standard procedure Okta outlines for integration. I suspect this must be a tacit acknowledgment of the bug. &amp;nbsp;Update from PA support on this is that the fix is supposed to be released sometime in March....&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 04:38:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/paloalto-okta-captiveportal-stopped-working/m-p/528823#M820</guid>
      <dc:creator>pomologist</dc:creator>
      <dc:date>2023-01-27T04:38:56Z</dc:date>
    </item>
    <item>
      <title>Re: PaloAlto/Okta CaptivePortal Stopped Working</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/paloalto-okta-captiveportal-stopped-working/m-p/531472#M914</link>
      <description>&lt;P&gt;A few months back I updated to 10.2.x, then my CP seemed to break using SAML to Ping. I went back to 10.1.x. I just saw in 10.2.3-h4, (PAN-210513) they fixed a CP SAML issue. Maybe that is your fix and maybe mine as well, will need to re-update and test later. Maybe if you test it first, reply and let us know if that addresses your issue.&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 21:09:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/paloalto-okta-captiveportal-stopped-working/m-p/531472#M914</guid>
      <dc:creator>govindra</dc:creator>
      <dc:date>2023-02-16T21:09:58Z</dc:date>
    </item>
    <item>
      <title>Re: PaloAlto/Okta CaptivePortal Stopped Working</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/paloalto-okta-captiveportal-stopped-working/m-p/531505#M915</link>
      <description>&lt;P&gt;Yes I noticed that too. &amp;nbsp;I updated to&amp;nbsp;&lt;SPAN&gt;10.2.3-h4 today, but it unfortunately did not fix the issue for me. &amp;nbsp;The rep told me earlier that&amp;nbsp;I'll have to wait until 10.2.4 for the fix.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 02:52:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/paloalto-okta-captiveportal-stopped-working/m-p/531505#M915</guid>
      <dc:creator>pomologist</dc:creator>
      <dc:date>2023-02-17T02:52:10Z</dc:date>
    </item>
    <item>
      <title>Re: PaloAlto/Okta CaptivePortal Stopped Working</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/paloalto-okta-captiveportal-stopped-working/m-p/531572#M917</link>
      <description>&lt;P&gt;unfortunate, guess i'll wait too before i try mine again, last time i did this i saw the redirect back to the PA and where it also hung and ended up needing to drive to office to restore.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 12:02:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/paloalto-okta-captiveportal-stopped-working/m-p/531572#M917</guid>
      <dc:creator>govindra</dc:creator>
      <dc:date>2023-02-17T12:02:06Z</dc:date>
    </item>
    <item>
      <title>Re: PaloAlto/Okta CaptivePortal Stopped Working</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/paloalto-okta-captiveportal-stopped-working/m-p/537223#M1097</link>
      <description>&lt;P&gt;I see 10.2.4 is out, if you get to test it and if fixes your issue, would like that feedback.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2023 10:35:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/paloalto-okta-captiveportal-stopped-working/m-p/537223#M1097</guid>
      <dc:creator>govindra</dc:creator>
      <dc:date>2023-03-31T10:35:17Z</dc:date>
    </item>
    <item>
      <title>Re: PaloAlto/Okta CaptivePortal Stopped Working</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/paloalto-okta-captiveportal-stopped-working/m-p/546990#M1420</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/176255"&gt;@pomologist&lt;/a&gt;&amp;nbsp;- curious if you made the jump to 10.2.4-h2 and if that fixed your captive portal issue?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2023 11:37:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/paloalto-okta-captiveportal-stopped-working/m-p/546990#M1420</guid>
      <dc:creator>govindra</dc:creator>
      <dc:date>2023-06-23T11:37:10Z</dc:date>
    </item>
    <item>
      <title>Re: PaloAlto/Okta CaptivePortal Stopped Working</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/paloalto-okta-captiveportal-stopped-working/m-p/547509#M1432</link>
      <description>&lt;P&gt;I'll be running the update in a couple weeks and will report at that time!&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2023 07:59:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/paloalto-okta-captiveportal-stopped-working/m-p/547509#M1432</guid>
      <dc:creator>pomologist</dc:creator>
      <dc:date>2023-06-28T07:59:41Z</dc:date>
    </item>
    <item>
      <title>Re: PaloAlto/Okta CaptivePortal Stopped Working</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/paloalto-okta-captiveportal-stopped-working/m-p/552685#M1673</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/176255"&gt;@pomologist&lt;/a&gt;&amp;nbsp;- I updated to 10.2.4-h3 and that seemed to address my CP issues we saw in 10.2.2&lt;/P&gt;</description>
      <pubDate>Sat, 05 Aug 2023 17:34:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/paloalto-okta-captiveportal-stopped-working/m-p/552685#M1673</guid>
      <dc:creator>govindra</dc:creator>
      <dc:date>2023-08-05T17:34:40Z</dc:date>
    </item>
  </channel>
</rss>

