<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Captive Portal doesn't work for remote offices in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-doesn-t-work-for-remote-offices/m-p/451577#M101175</link>
    <description>&lt;P&gt;Hello!&lt;BR /&gt;&lt;BR /&gt;tunnel.2 does not have IP address.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I solved the issue.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Between the Firewall and the carrier link I placed an IPsec router.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I let the tunneling work to the new device and assing an IP and a management profile to the interface ethernet1/2.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;It seems that the authentication web interface cannot be read from incoming connections in a different interface.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I will share the new diagram.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="adiazm_0-1638807791074.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37967iBA3027DE77BFECC7/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="adiazm_0-1638807791074.png" alt="adiazm_0-1638807791074.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards.&lt;/P&gt;</description>
    <pubDate>Mon, 06 Dec 2021 16:21:57 GMT</pubDate>
    <dc:creator>adiazm</dc:creator>
    <dc:date>2021-12-06T16:21:57Z</dc:date>
    <item>
      <title>Captive Portal doesn't work for remote offices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-doesn-t-work-for-remote-offices/m-p/429689#M94930</link>
      <description>&lt;P&gt;Greetings to all&lt;/P&gt;&lt;P&gt;I have the scenario described in the graph:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="adiazm_0-1630073510049.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35911i71C5E0EA02B88F58/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="adiazm_0-1630073510049.png" alt="adiazm_0-1630073510049.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I use Captive Portal based authentication for certain devices.&amp;nbsp;It works fine for the LAN zone, but not for the WAN zone.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;In the WAN Zone we have remote offices that connect through the MPLS of a service provider. Then, over that data link, we build an IPSec tunnel to establish the connection between the main office and the branch office.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Time Out occurs when a device tries to access the Internet from the WAN.&lt;/P&gt;&lt;P&gt;The captive portal is assigned to Interface ethernet1 / 1 with IP address 192.168.1.1&lt;/P&gt;&lt;P&gt;Any idea what is the reason why the captive portal to the WAN is not working?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Best regards.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 14:16:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-doesn-t-work-for-remote-offices/m-p/429689#M94930</guid>
      <dc:creator>adiazm</dc:creator>
      <dc:date>2021-08-27T14:16:34Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal doesn't work for remote offices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-doesn-t-work-for-remote-offices/m-p/429717#M94934</link>
      <description>&lt;P&gt;If this is configured as auth policy with captive portal in redirect mode to&amp;nbsp;&lt;SPAN&gt;192.168.1.1:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1) Did the URL bar actually change (redirect) to&amp;nbsp;192.168.1.1:6080-6083 ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2) Check the traffic log for this, you may have a policy-deny from WAN to LAN 192.168.1.1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;3) Does the device 192.168.2.1 definitely have a route for 192.168.1.1 to the FW? Does the FW have a route back the right way?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- DM&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 16:19:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-doesn-t-work-for-remote-offices/m-p/429717#M94934</guid>
      <dc:creator>dmifsud</dc:creator>
      <dc:date>2021-08-27T16:19:54Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal doesn't work for remote offices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-doesn-t-work-for-remote-offices/m-p/435921#M96111</link>
      <description>&lt;P&gt;Hello!&lt;BR /&gt;&lt;BR /&gt;Thanks for your answer... I am very sorry for my delay answering....&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;technically, the three points you indicate are fulfilled.&lt;/P&gt;&lt;P&gt;I'll give you a detail of the session where the client tries to open the portal:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;adiaz@PA-220&amp;gt; show session id 39672&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;Session 39672&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;c2s flow:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;source: 192.168.2.133 [AGENCIAS]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;dst: 192.168.1.1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;proto: 6&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;sport: 53521 dport: 6082&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;state: INIT type: FLOW&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;src user: unknown&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;dst user: unknown&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;s2c flow:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;source: 192.168.1.1 [LAN]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;dst: 192.168.2.133&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;proto: 6&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;sport: 6082 dport: 53521&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;state: INIT type: FLOW&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;src user: unknown&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;dst user: unknown&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;qos node: tunnel.2, qos member N/A Qid 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;start time : Wed Sep 22 11:47:32 2021&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;timeout : 90 sec&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;total byte count(c2s) : 330&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;total byte count(s2c) : 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;layer7 packet count(c2s) : 5&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;layer7 packet count(s2c) : 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;vsys : vsys1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;application : incomplete&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;rule : AGENCIAS - MATRIZ&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;service timeout override(index) : False&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;session to be logged at end : True&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;session in session ager : False&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;session updated by HA peer : False&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;layer7 processing : enabled&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;URL filtering enabled : True&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;URL category : any&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;session via syn-cookies : False&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;session terminated on host : True&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;session traverses tunnel : True&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;session terminate tunnel : False&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;captive portal session : False&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;ingress interface : tunnel.2&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;egress interface : ethernet1/1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;session QoS rule : N/A (class 4)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;tracker stage firewall : host service&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;end-reason : aged-out&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the client:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="adiazm_0-1632330172377.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36568iE0840893430603F7/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="adiazm_0-1632330172377.png" alt="adiazm_0-1632330172377.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;auth.agroproduzca.com.ec points to the IP address 192.168.1.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Again, thanks for your apreciated help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;REgards!&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 17:03:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-doesn-t-work-for-remote-offices/m-p/435921#M96111</guid>
      <dc:creator>adiazm</dc:creator>
      <dc:date>2021-09-22T17:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal doesn't work for remote offices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-doesn-t-work-for-remote-offices/m-p/436680#M96293</link>
      <description>&lt;P&gt;Thank you for providing additional information&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192023"&gt;@adiazm&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you configured: management profile on interface: tunnel.2 and enabled: Response Page?&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClKZCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClKZCA0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Sun, 26 Sep 2021 07:59:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-doesn-t-work-for-remote-offices/m-p/436680#M96293</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-09-26T07:59:42Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal doesn't work for remote offices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-doesn-t-work-for-remote-offices/m-p/451577#M101175</link>
      <description>&lt;P&gt;Hello!&lt;BR /&gt;&lt;BR /&gt;tunnel.2 does not have IP address.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I solved the issue.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Between the Firewall and the carrier link I placed an IPsec router.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I let the tunneling work to the new device and assing an IP and a management profile to the interface ethernet1/2.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;It seems that the authentication web interface cannot be read from incoming connections in a different interface.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I will share the new diagram.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="adiazm_0-1638807791074.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37967iBA3027DE77BFECC7/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="adiazm_0-1638807791074.png" alt="adiazm_0-1638807791074.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Dec 2021 16:21:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-doesn-t-work-for-remote-offices/m-p/451577#M101175</guid>
      <dc:creator>adiazm</dc:creator>
      <dc:date>2021-12-06T16:21:57Z</dc:date>
    </item>
  </channel>
</rss>

