<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Captive Portal - users not supplying domain info in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-users-not-supplying-domain-info/m-p/17826#M12983</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is useful information.&amp;nbsp; I can see this working for a single domain but we have multi domains.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I suppose I could put a bogus domain name in the RADIUS profile, then at least the authentication attempts will fail and a bad ip-user-mapping will not be created.&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;I subsequently tried this but got undesirable results.&amp;nbsp; An authentication request with domain information is passed untouched to the RADIUS server but the resulting ip-user-mapping is created with whatever domain is set in the RADIUS profile.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&amp;nbsp; Jeff K&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 17 May 2013 01:35:58 GMT</pubDate>
    <dc:creator>Jeff_K</dc:creator>
    <dc:date>2013-05-17T01:35:58Z</dc:date>
    <item>
      <title>Captive Portal - users not supplying domain info</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-users-not-supplying-domain-info/m-p/17824#M12981</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Our captive portal is configured to use RADIUS (Cisco Secure ACS) to authenticate our AD users. The Cisco ACS will authenticate a user even if they do not include their domain information in the userid string... 'userid' rather than 'domain\userid'.&amp;nbsp; The problem with this is that a user who authenticates with only their userid ends up with a ip-user-mapping that will not match a userid that is pulled in with the User Identification Group Mapping Settings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our Cisco ACS box does not appear to be able to filter the undesirable ones out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone dealt with this already?&amp;nbsp; Maybe there is a way to sanitize the input on the Captive portal comfort/login page?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, Jeff K&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 May 2013 19:24:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-users-not-supplying-domain-info/m-p/17824#M12981</guid>
      <dc:creator>Jeff_K</dc:creator>
      <dc:date>2013-05-16T19:24:28Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal - users not supplying domain info</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-users-not-supplying-domain-info/m-p/17825#M12982</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jeff, &lt;/P&gt;&lt;P&gt;Try adding the domain name in the Radius Profile&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture.JPG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6567_Capture.JPG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also another good reference for similar issue can be seen here&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/message/27165#27165"&gt;https://live.paloaltonetworks.com/message/27165#27165&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Hopefully this helps.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;Thank you&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 May 2013 21:38:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-users-not-supplying-domain-info/m-p/17825#M12982</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2013-05-16T21:38:24Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal - users not supplying domain info</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-users-not-supplying-domain-info/m-p/17826#M12983</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is useful information.&amp;nbsp; I can see this working for a single domain but we have multi domains.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I suppose I could put a bogus domain name in the RADIUS profile, then at least the authentication attempts will fail and a bad ip-user-mapping will not be created.&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;I subsequently tried this but got undesirable results.&amp;nbsp; An authentication request with domain information is passed untouched to the RADIUS server but the resulting ip-user-mapping is created with whatever domain is set in the RADIUS profile.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&amp;nbsp; Jeff K&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 May 2013 01:35:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-users-not-supplying-domain-info/m-p/17826#M12983</guid>
      <dc:creator>Jeff_K</dc:creator>
      <dc:date>2013-05-17T01:35:58Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal - users not supplying domain info</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-users-not-supplying-domain-info/m-p/17827#M12984</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In regard to the Captive portal comfort page, it would be great if the user input form script called by &amp;lt;pan_form/&amp;gt; could be modified to include a field to enter the domain ... this would avoid a lot of confusion.&amp;nbsp; Anyone know if this is possible?&lt;/P&gt;&lt;P&gt;Thanks, Jeff K&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 May 2013 11:42:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-users-not-supplying-domain-info/m-p/17827#M12984</guid>
      <dc:creator>Jeff_K</dc:creator>
      <dc:date>2013-05-17T11:42:20Z</dc:date>
    </item>
  </channel>
</rss>

