<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Captive Portal with NTLM authentication redirect loop in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-with-ntlm-authentication-redirect-loop/m-p/27323#M19933</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;UPDATE:&lt;/P&gt;&lt;P&gt;today we've tried it with Mozilla and it works just fine.&lt;/P&gt;&lt;P&gt;So it must be something in the IE security settings. Tried clearing all cookies and browse history in IE - does not help. Tried with IE10 and IE11 - same issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone guide me which security settings might cause such issue - successful NTLM auth, therefore successful IP-to-user mapping in PA, but still redirect loop after that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 23 May 2014 10:09:56 GMT</pubDate>
    <dc:creator>BLazarov</dc:creator>
    <dc:date>2014-05-23T10:09:56Z</dc:date>
    <item>
      <title>Captive Portal with NTLM authentication redirect loop</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-with-ntlm-authentication-redirect-loop/m-p/27321#M19931</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have successfully configured a captive portal with NTLM authentication for User-ID and users are successfully authenticating using NTLM, but right after that they are stuck in a redirect loop on the following page:&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;User Authentication in Process&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;The original web page you requested will load when the authentication process completes.&lt;BR /&gt; Click &lt;A href="http://www.lirex.bg/"&gt;&lt;SPAN style="color: #0563c1;"&gt;here&lt;/SPAN&gt;&lt;/A&gt; if the page does not load automatically.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;Authentication Method: NTLM&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;I've seen the knowledgebase article for the similar problem, but i have enabled User-ID on both inside and outside interfaces (tried only on Inside as well) and still does not help.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;Any ideas?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;I can see that users are mapped to IP once they open the first page, but anyways they are stuck in the loop:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;admin@PA-2050-1(active)&amp;gt; show user ip-user-mapping ip 10.XX.YY.169&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IP address:&amp;nbsp; 10.183.224.169 (vsys1)&lt;/P&gt;&lt;P&gt;User:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; xy1\snikolov&lt;/P&gt;&lt;P&gt;From:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NTLM&lt;/P&gt;&lt;P&gt;Idle Timeout: 900s&lt;/P&gt;&lt;P&gt;Max. TTL:&amp;nbsp;&amp;nbsp;&amp;nbsp; 3590s&lt;/P&gt;&lt;P&gt;Groups that the user belongs to (used in policy)&lt;/P&gt;&lt;P&gt;Group(s):&amp;nbsp;&amp;nbsp;&amp;nbsp; cn=bg-sg tytyusers,ou=groups,ou=bg,dc=go1,dc=rtrt,dc=tyty,dc=com&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 May 2014 14:19:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-with-ntlm-authentication-redirect-loop/m-p/27321#M19931</guid>
      <dc:creator>BLazarov</dc:creator>
      <dc:date>2014-05-22T14:19:54Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal with NTLM authentication redirect loop</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-with-ntlm-authentication-redirect-loop/m-p/27322#M19932</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Blazarov,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Captive Portal Behavior &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Captive portal will only be triggered by a session that matches the following criteria: &lt;/P&gt;&lt;P&gt;1) There &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;is&lt;/SPAN&gt; no user data for the source IP of the session &lt;/P&gt;&lt;P&gt;2) The session is HTTP traffic &lt;/P&gt;&lt;P&gt;3) The session matches a Captive Portal policy on the firewall &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Captive Portal Redirect Steps &lt;/P&gt;&lt;P&gt;1) Web traffic from unknown IP that matches Web Form CP Policy &lt;/P&gt;&lt;P&gt;2) Traffic Redirected to L3 Interface &lt;/P&gt;&lt;P&gt;3) Firewall request credentials &lt;/P&gt;&lt;P&gt;- &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;the&lt;/SPAN&gt; same time firewall allocates &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;cookie value&lt;/SPAN&gt; (note that during first time allocation of cookie "Get Cookie and didn't find cookie" log message will appear on appweb3-l3svc&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;.&lt;/SPAN&gt;log &lt;/P&gt;&lt;P&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;if&lt;/SPAN&gt; "debug l3svc on debug" in &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;turned&lt;/SPAN&gt; on) &lt;/P&gt;&lt;P&gt;- Browser will save this cookie &lt;/P&gt;&lt;P&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;for&lt;/SPAN&gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;example Firefox&lt;/SPAN&gt; under Preferences &amp;gt; Privacy &amp;gt; Firefox will: Use custom settings for history &amp;gt; Show cookies &amp;gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;Site&lt;/SPAN&gt; (Cookie Name: PHPSESSID) &lt;/P&gt;&lt;P&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;the&lt;/SPAN&gt; PHPSESSID is the same value the PA Firewall use to check for session cookie if Captive Portal Session Cookie is enabled. &lt;/P&gt;&lt;P&gt;- Once the user-&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;ip&lt;/SPAN&gt;-mapping on the PA firewall times out of cleared manually Steps 1 - 2 will be repeated. Because of cookie Step 3 - 4 &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;wont&lt;/SPAN&gt; be necessary. &lt;/P&gt;&lt;P&gt;- In an event that the cookie is not present on the browser for some reason like corrupt cookie file the client won't be presented the Captive Portal Login Page because the firewall is still attempting to use the previous cookies. Manually removing the cookies on the browser might help.&lt;/P&gt;&lt;P&gt;4) Firewall authenticates user &lt;/P&gt;&lt;P&gt;5) User mapped and redirected to &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;original address&lt;/SPAN&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Link below might be helpful &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://support.mozilla.org/en-US/kb/fix-login-issues-on-websites-require-passwords" rel="nofollow"&gt;http://support.mozilla.org/en-US/kb/fix-login-issues-on-websites-require-passwords&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please try "Remove corrupt cookies file" on your test workstation to check if this will help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 May 2014 15:40:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-with-ntlm-authentication-redirect-loop/m-p/27322#M19932</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-05-22T15:40:24Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal with NTLM authentication redirect loop</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-with-ntlm-authentication-redirect-loop/m-p/27323#M19933</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;UPDATE:&lt;/P&gt;&lt;P&gt;today we've tried it with Mozilla and it works just fine.&lt;/P&gt;&lt;P&gt;So it must be something in the IE security settings. Tried clearing all cookies and browse history in IE - does not help. Tried with IE10 and IE11 - same issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone guide me which security settings might cause such issue - successful NTLM auth, therefore successful IP-to-user mapping in PA, but still redirect loop after that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 May 2014 10:09:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-with-ntlm-authentication-redirect-loop/m-p/27323#M19933</guid>
      <dc:creator>BLazarov</dc:creator>
      <dc:date>2014-05-23T10:09:56Z</dc:date>
    </item>
  </channel>
</rss>

