<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Captive Portal to Internal Servers in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-to-internal-servers/m-p/18034#M13142</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a client that currently uses an ISA server to restrict access to back-end web servers.&amp;nbsp; The users authenticate at the ISA which then redirects to the back end web server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Palo Alto firewalls were sold as replacing this authentication mechanism using Captive Portal.&amp;nbsp; Is this a possible use?&amp;nbsp; I've only seen examples of Captive Portal for outbound traffic or to authenticate users for a wireless network.&amp;nbsp; This would be inbound traffic from the Internet going to specific servers internally.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this is possible, what would be the recommended setup?&amp;nbsp; Static NAT is configured for these servers and I'd want to use the User-ID agent for authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The client is also moving to using the Global Protect agent for SSL VPN.&amp;nbsp; The request is for Captive Portal to be used to protect access to certain web resources but if they want full access to internal resources they would use GP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 24 Dec 2012 21:26:23 GMT</pubDate>
    <dc:creator>CafNetMatt</dc:creator>
    <dc:date>2012-12-24T21:26:23Z</dc:date>
    <item>
      <title>Captive Portal to Internal Servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-to-internal-servers/m-p/18034#M13142</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a client that currently uses an ISA server to restrict access to back-end web servers.&amp;nbsp; The users authenticate at the ISA which then redirects to the back end web server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Palo Alto firewalls were sold as replacing this authentication mechanism using Captive Portal.&amp;nbsp; Is this a possible use?&amp;nbsp; I've only seen examples of Captive Portal for outbound traffic or to authenticate users for a wireless network.&amp;nbsp; This would be inbound traffic from the Internet going to specific servers internally.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this is possible, what would be the recommended setup?&amp;nbsp; Static NAT is configured for these servers and I'd want to use the User-ID agent for authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The client is also moving to using the Global Protect agent for SSL VPN.&amp;nbsp; The request is for Captive Portal to be used to protect access to certain web resources but if they want full access to internal resources they would use GP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Dec 2012 21:26:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-to-internal-servers/m-p/18034#M13142</guid>
      <dc:creator>CafNetMatt</dc:creator>
      <dc:date>2012-12-24T21:26:23Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal to Internal Servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-to-internal-servers/m-p/18035#M13143</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can use Captive Portal in your setup. As you said most of the times Captive Portal is used for outbound access,&amp;nbsp; you can also do it for inbound by configuring the Captive portal policies and I do not see any issues with it as long as the users are coming from different IP's. You can use Radius/LDAP or kerberos or even local user accounts for identifying and authenticating the users. You also mentioned that you would like to use User-id agent. Captive portal is used when user-id agent cannot be used; that is when the users are not logging into any domain controllers and the user traffic is directly reaching the firewall. So you can either use captive portal or user-id agent only. Regarding the full access if the users login to the SSL VPN they should be able to get the full access. I do not see any issues with your setup. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tx&lt;/P&gt;&lt;P&gt;Sandeep T&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Dec 2012 04:24:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-to-internal-servers/m-p/18035#M13143</guid>
      <dc:creator>sdurga</dc:creator>
      <dc:date>2012-12-25T04:24:15Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal to Internal Servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-to-internal-servers/m-p/18036#M13144</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the explanation.&amp;nbsp; I actually look forward to trying this out.&amp;nbsp; This is Step 3 in a PAN migration with steps 1 &amp;amp; 2 being replacing the existing firewalls and moving to Global Protect for SSL VPN.&amp;nbsp; Both of which are pretty much complete.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jan 2013 21:20:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-to-internal-servers/m-p/18036#M13144</guid>
      <dc:creator>CafNetMatt</dc:creator>
      <dc:date>2013-01-15T21:20:44Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal to Internal Servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-to-internal-servers/m-p/18037#M13145</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've had big problems setting this up. I can't seem to direct any incoming requests to the CP authentication system (tried both radius and local). I ended up going with an Citrix solution via F5 to farm out access to the internal resource.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you get it working I would be interested to see your configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rod&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2013 15:05:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-to-internal-servers/m-p/18037#M13145</guid>
      <dc:creator>djrodb</dc:creator>
      <dc:date>2013-01-16T15:05:57Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal to Internal Servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-to-internal-servers/m-p/18038#M13146</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Captive Portal was not designed for Internet -&amp;gt; Internal use so there could be some problems trying to implement it this way. One particular caveat, it is required to enable User-ID on the 'Internet' or 'External' zone. If you have User-ID Agent configured, this could flood the agent with the list of unknown IP addresses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would recommend deploying this configuration only if the 'Internet' or 'External' zone is controlled and not publicly accessible. If you decide to move forward with this deployment, it would be advisable to involve your Sales team so they are familiar in case issues arise.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Here is Tech Note on some specifics of User-ID: &lt;/SPAN&gt;&lt;A class="jive-link-wiki-small" data-containerid="2021" data-containertype="14" data-objectid="1807" data-objecttype="102" href="https://live.paloaltonetworks.com/docs/DOC-1807"&gt;https://live.paloaltonetworks.com/docs/DOC-1807&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Stefan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2013 18:25:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-to-internal-servers/m-p/18038#M13146</guid>
      <dc:creator>sspringer</dc:creator>
      <dc:date>2013-01-16T18:25:16Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal to Internal Servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-to-internal-servers/m-p/18039#M13147</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Curious to see how this fared for you? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Oct 2014 19:23:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-to-internal-servers/m-p/18039#M13147</guid>
      <dc:creator>greeng</dc:creator>
      <dc:date>2014-10-08T19:23:47Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal to Internal Servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-to-internal-servers/m-p/18040#M13148</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This was a bust.&amp;nbsp; It's just outside what Captive Portal was created to do.&lt;/P&gt;&lt;P&gt;The client moved to a different solution.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry for the late response.&amp;nbsp; For some reason your reply didn't end up in my inbox (The PAN inbox yes; my&amp;nbsp; regular mail inbox no).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Feb 2015 16:05:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-to-internal-servers/m-p/18040#M13148</guid>
      <dc:creator>CafNetMatt</dc:creator>
      <dc:date>2015-02-14T16:05:55Z</dc:date>
    </item>
  </channel>
</rss>

