<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authentication of Users through Captive portal query in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-of-users-through-captive-portal-query/m-p/442912#M100155</link>
    <description>&lt;P&gt;Thank you for the post&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/165087"&gt;@tamilvanan&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am running similar setup in multiple Firewalls. I just tried to reproduce the scenario you mentioned and I got the same result. For the session that has already user-ip mapping from user-id agent, I was not getting redirection to captive portal despite fact that I configured in authentication policy source as "any" and&amp;nbsp;Authentication Enforcement: default-web-form. Based on my test I would say what you are experiencing is expected, however I could not find any reference in documentation to back this up.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
    <pubDate>Fri, 22 Oct 2021 13:53:55 GMT</pubDate>
    <dc:creator>PavelK</dc:creator>
    <dc:date>2021-10-22T13:53:55Z</dc:date>
    <item>
      <title>Authentication of Users through Captive portal query</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-of-users-through-captive-portal-query/m-p/442886#M100152</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We had configured captive portal on the firewall recently.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In Authentication policy we had selected source users as any and we are using Active Directory for Authentication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also we had configured agentless user-id mapping on the firewall and server monitoring to fetch details from AD server for User-IP mapping to feed onto the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When an unknown user tries to access internet we are getting captive portal re-direction but for devices which have user-ip mapping fetched from AD server Captive portal redirection is not happening.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this an expected behaviour for users who are already got user-IP mapped through AD source to not get Captive portal redirection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had seen previously it works for Global Protect users but not sure about AD users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Done troubleshooting as per below doc also:&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClZiCAK#:~:text=Verify%20Captive%20Portal%20is%20enabled,for%20the%20traffic%20in%20question" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClZiCAK#:~:text=Verify%20Captive%20Portal%20is%20enabled,for%20the%20traffic%20in%20question&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also SSL forward proxy decryption is configured on the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2021 12:32:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-of-users-through-captive-portal-query/m-p/442886#M100152</guid>
      <dc:creator>tamilvanan</dc:creator>
      <dc:date>2021-10-22T12:32:47Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication of Users through Captive portal query</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-of-users-through-captive-portal-query/m-p/442912#M100155</link>
      <description>&lt;P&gt;Thank you for the post&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/165087"&gt;@tamilvanan&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am running similar setup in multiple Firewalls. I just tried to reproduce the scenario you mentioned and I got the same result. For the session that has already user-ip mapping from user-id agent, I was not getting redirection to captive portal despite fact that I configured in authentication policy source as "any" and&amp;nbsp;Authentication Enforcement: default-web-form. Based on my test I would say what you are experiencing is expected, however I could not find any reference in documentation to back this up.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2021 13:53:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-of-users-through-captive-portal-query/m-p/442912#M100155</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-10-22T13:53:55Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication of Users through Captive portal query</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-of-users-through-captive-portal-query/m-p/442926#M100157</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/165087"&gt;@tamilvanan&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;This is expected behavior. Captive Portal only triggers on unknown users and doesn't trigger for IPs that already have a user-id mapping.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2021 14:12:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-of-users-through-captive-portal-query/m-p/442926#M100157</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-10-22T14:12:54Z</dc:date>
    </item>
  </channel>
</rss>

