<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Captive Portal for more than one security zone in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-for-more-than-one-security-zone/m-p/22562#M16475</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can apply Captive portal on any and all zones that you wish.&amp;nbsp; Captive config says go to the redirect host identified.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture.CP-Setup.PNG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6269_Capture.CP-Setup.PNG" width="450" /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;The Captive portal rules determine what traffic patterns will trigger a Captive portal redirection.&amp;nbsp; See the below image:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture.CP-Rules.PNG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6271_Capture.CP-Rules.PNG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps.&amp;nbsp; Within the rule set you can exclude traffic patterns from being captive portal redirected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 15 Apr 2013 19:29:55 GMT</pubDate>
    <dc:creator>HITSSEC</dc:creator>
    <dc:date>2013-04-15T19:29:55Z</dc:date>
    <item>
      <title>Captive Portal for more than one security zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-for-more-than-one-security-zone/m-p/22552#M16465</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Few months ago I sucessfully configured CaptivePortal (in redirect mode) with SSL certyficate from StartSSL for one of my local network connected to PA200.&lt;/P&gt;&lt;P&gt;Now I need to do the same for another local network, but on PAN I can only make one CP configuration, with one SSL cert.&lt;/P&gt;&lt;P&gt;I have SSL cert for host cp1.mydomain.com. This dns entry pointing to 192.168.110.1 that is a gateway for network where I have CP.&lt;/P&gt;&lt;P&gt;Until now evertything is clear for me, but when I enable CP to another network (with 192.168.30.1 gateway) its working too - why?&lt;/P&gt;&lt;P&gt;My networks are in separate security zones without policy that could enable traffic beetwen this zones/network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I tryed to put cp1.mydomain.com to one of my public IP (not used at the moment) but reachable from PAN. I changed entry in DNS, but its broken CP because users cant get CP webpage because this public IP isnt reachable without authenticate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My CP looks like:&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="6201" alt="2013-04-06_111801.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6201_2013-04-06_111801.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;and Security Policy:&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="6202" alt="2013-04-06_112009.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6202_2013-04-06_112009.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;and hear I'm not sure that this configuration is optimal and made according to best practices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd like to block p2p traffic, let DNS and ping and let all authenticated users access to internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I forgot .. I have one samll issue with SSL cert. Evertytime I started browser (ie. IE7) I get warning that browser has't information about cert issuer. Similar problem is described &lt;A __default_attr="3319" __jive_macro_name="message" class="jive_macro jive_macro_message" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;but I have cert from StartSSL. Where I can find IPs that I need to add to be reachable without CP policy?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I searched this community, read How to Configure Captive Portal.pdf but I cant find information about CP for two networks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help me in such configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 06 Apr 2013 09:34:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-for-more-than-one-security-zone/m-p/22552#M16465</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-04-06T09:34:28Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal for more than one security zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-for-more-than-one-security-zone/m-p/22553#M16466</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Noone has any sugegstion for me?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Apr 2013 12:18:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-for-more-than-one-security-zone/m-p/22553#M16466</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-04-09T12:18:54Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal for more than one security zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-for-more-than-one-security-zone/m-p/22554#M16467</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does your interface allow https Response pages?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="interface.PNG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6223_interface.PNG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="interface-mgmt.PNG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6227_interface-mgmt.PNG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Apr 2013 15:41:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-for-more-than-one-security-zone/m-p/22554#M16467</guid>
      <dc:creator>HITSSEC</dc:creator>
      <dc:date>2013-04-09T15:41:55Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal for more than one security zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-for-more-than-one-security-zone/m-p/22555#M16468</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes, I have exactly the same config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my opinion cert warning is because web browser cant verify ssl cert&amp;nbsp; issuer. But how (or where) to find list of server that I need to exclude from CP roule - I don't know.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Apr 2013 16:35:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-for-more-than-one-security-zone/m-p/22555#M16468</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-04-09T16:35:22Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal for more than one security zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-for-more-than-one-security-zone/m-p/22556#M16469</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We use a cert issued by a public certificate authority.&amp;nbsp; Certificate revocation checks to local domains could be the issue? If you use a commercial cert then just watch the log traffic for the CRL&amp;nbsp; check and add that as an allowed destination.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Apr 2013 16:51:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-for-more-than-one-security-zone/m-p/22556#M16469</guid>
      <dc:creator>HITSSEC</dc:creator>
      <dc:date>2013-04-09T16:51:55Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal for more than one security zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-for-more-than-one-security-zone/m-p/22557#M16470</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I using public certificate too. I'm using free &lt;A href="http://www.startssl.com/"&gt;StartSSL &lt;/A&gt;certs.&lt;/P&gt;&lt;P&gt;I tryed to find such informations from logs but I havnt such connections in log from this particular zone to Untrust zone.&lt;/P&gt;&lt;P&gt;I catched interesting screen shoot:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2013-04-11_093908.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6226_2013-04-11_093908.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;As you can see, IE is trying to connect to 192.168.110.1 - this is because cp1.mydomain.com is pointing to it. This&amp;nbsp; computer has 192.168.3.38 IP at the moment, and is UNABLE to communicate to 192.168.110.1 (for security reason, 192.168.3.x must only have access to untrust or 192.168.3.1 because it's a getaway from PAN).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Apr 2013 07:44:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-for-more-than-one-security-zone/m-p/22557#M16470</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-04-11T07:44:37Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal for more than one security zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-for-more-than-one-security-zone/m-p/22558#M16471</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;slv&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The web browser may not have a root cert.&amp;nbsp; Check like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture-Root-Certs.JPG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6251_Capture-Root-Certs.JPG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The other issue may be the certification revocation check.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture-cert-revocation.JPG" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6252_Capture-cert-revocation.JPG" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Apr 2013 01:32:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-for-more-than-one-security-zone/m-p/22558#M16471</guid>
      <dc:creator>HITSSEC</dc:creator>
      <dc:date>2013-04-12T01:32:08Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal for more than one security zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-for-more-than-one-security-zone/m-p/22559#M16472</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hitssec&lt;/P&gt;&lt;P&gt;I know that one way is to have root cert in local Cert store, but he second way is to give to browser information abaout intermidiate cert &lt;A href="http://www.startssl.com/?app=21" title="http://www.startssl.com/?app=21"&gt;StartSSL™ Certificates &amp;amp; Public Key Infrastructure&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Also IE uses windows cert store, but FF uses their own store so I prefer to make universal solution ("glue" cert with intermidiate cert).&lt;/P&gt;&lt;P&gt;I havent ability to put root cert into personal computer of my students.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On Windows IE6 complaining about ability to verify root cer, on the same computer FF 20.1 doesnt. Latest (but maybe not the last) FF on Linux complaining too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The same complaining is from 192.168.3.x as from 192.168.110.x network&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Apr 2013 06:43:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-for-more-than-one-security-zone/m-p/22559#M16472</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-04-12T06:43:11Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal for more than one security zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-for-more-than-one-security-zone/m-p/22560#M16473</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Slv,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since I can't read the warning message you posted (I only read english - sorry) there are only three possible causes:&lt;/P&gt;&lt;P&gt;Wrong cert being used&lt;/P&gt;&lt;P&gt;Private cert - not being able to validate&lt;/P&gt;&lt;P&gt;Public cert - not being able to validate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Public certs should be able to be validated (may need to select optional updates via windows update to get the root certs on the client.&amp;nbsp; The outher option is to tell them to accept the cert warning.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry if I can't help you more but I think you are on the right path.&amp;nbsp; You can always put a call into support and they can assist.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 13 Apr 2013 14:42:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-for-more-than-one-security-zone/m-p/22560#M16473</guid>
      <dc:creator>HITSSEC</dc:creator>
      <dc:date>2013-04-13T14:42:43Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal for more than one security zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-for-more-than-one-security-zone/m-p/22561#M16474</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You where right, problem with this warning is connected to root cert. After updating root cert store with latest package IE doenst show warning message.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lets back to main question.&lt;/P&gt;&lt;P&gt;- on which one IP I should setup Captive Portal, from which zone? I need to use CP for 3 zones.&lt;/P&gt;&lt;P&gt;- do my security policy are correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Apr 2013 07:43:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-for-more-than-one-security-zone/m-p/22561#M16474</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-04-15T07:43:18Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal for more than one security zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-for-more-than-one-security-zone/m-p/22562#M16475</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can apply Captive portal on any and all zones that you wish.&amp;nbsp; Captive config says go to the redirect host identified.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture.CP-Setup.PNG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6269_Capture.CP-Setup.PNG" width="450" /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;The Captive portal rules determine what traffic patterns will trigger a Captive portal redirection.&amp;nbsp; See the below image:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture.CP-Rules.PNG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6271_Capture.CP-Rules.PNG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps.&amp;nbsp; Within the rule set you can exclude traffic patterns from being captive portal redirected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Apr 2013 19:29:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-for-more-than-one-security-zone/m-p/22562#M16475</guid>
      <dc:creator>HITSSEC</dc:creator>
      <dc:date>2013-04-15T19:29:55Z</dc:date>
    </item>
  </channel>
</rss>

