<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to skip CaptivePortal for one device? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-skip-captiveportal-for-one-device/m-p/29126#M21305</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Traffic logs show from zone as&lt;/P&gt;&lt;P&gt; Scholastcy instead of School.....?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 11 Apr 2013 11:32:37 GMT</pubDate>
    <dc:creator>UhMayYeah</dc:creator>
    <dc:date>2013-04-11T11:32:37Z</dc:date>
    <item>
      <title>How to skip CaptivePortal for one device?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-skip-captiveportal-for-one-device/m-p/29125#M21304</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you can see on this forum I have some configurations problems with CP.&lt;/P&gt;&lt;P&gt;In the zone where I have CP enabled I have Minolta BizHub c220 device (with static IP 192.168.3.251). This device has scan to email features. After I enabled CP for this zone of course noone email go to user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I checked almost every thread on this forum, but I didn't get solutions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I understand for CP we have three types of polices: security, NAT and captive portal. NAT is simple in this case, security I configured:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2013-04-10_144107.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6245_2013-04-10_144107.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;and Captive Portal policy:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2013-04-10_144142.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6246_2013-04-10_144142.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;in logs I have traffic:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2013-04-10_144401.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6247_2013-04-10_144401.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;NTP and DNS traffic is allowed by Security rule, thats OK&lt;/P&gt;&lt;P&gt;I add another security policy to allow all traffic from this zone to untrust zone. Thats doesnt working for me.&lt;/P&gt;&lt;P&gt;So I tryed to go further and I add CP policy that should allowed traffic on port 465, but as you can see in log - this doesn't working too&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How I should configure polices in such situation?&lt;/P&gt;&lt;P&gt;I believe that it is possible to configure on PAN. I didint find on BizHub ability to authenticate on CP/HotSpot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Apr 2013 08:03:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-skip-captiveportal-for-one-device/m-p/29125#M21304</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-04-11T08:03:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to skip CaptivePortal for one device?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-skip-captiveportal-for-one-device/m-p/29126#M21305</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Traffic logs show from zone as&lt;/P&gt;&lt;P&gt; Scholastcy instead of School.....?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Apr 2013 11:32:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-skip-captiveportal-for-one-device/m-p/29126#M21305</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-04-11T11:32:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to skip CaptivePortal for one device?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-skip-captiveportal-for-one-device/m-p/29127#M21306</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yep. Its's OK. In the meantime I changed zone name from Scholastcy to School.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm curious why today some of traffic are allowed when yestarday was blocked&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2013-04-11_150317.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6248_2013-04-11_150317.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;Is it possible to let 3.251 not all traffic to port 465 but only ssl (or even better google mail)?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Apr 2013 13:05:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-skip-captiveportal-for-one-device/m-p/29127#M21306</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-04-11T13:05:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to skip CaptivePortal for one device?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-skip-captiveportal-for-one-device/m-p/29128#M21307</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK - it's working. but ... I will "sleep better" when I limit type of application to google mail.&lt;/P&gt;&lt;P&gt;I have idea - in security rule "Scholastycy - ksero" change application from any to gmail - in my opinion it should limited ability to connect this BizHub to gmail.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have questions for you: are my polices&amp;nbsp; set up correctly according to best practices?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Apr 2013 12:44:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-skip-captiveportal-for-one-device/m-p/29128#M21307</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-04-12T12:44:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to skip CaptivePortal for one device?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-skip-captiveportal-for-one-device/m-p/29129#M21308</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Changing application to gmail-base should work and you can also use DNS name as destination in that rule for even more granular control.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To be on the safe side - I would attach more security profiles to rule "Scholastycy - DNS". But even better would be to delete that rule and set up DNS Proxy on PAN device to avoid, possible, DNS Tunneling.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jul 2013 16:15:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-skip-captiveportal-for-one-device/m-p/29129#M21308</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-07-22T16:15:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to skip CaptivePortal for one device?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-skip-captiveportal-for-one-device/m-p/29130#M21309</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt;can also use DNS name as destination&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so should I put there "gmail.com" ? I have very limited access to this device and I can't test this change...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If in security policy is Aplication:dns Service:aplication-defaul with anty-spyware:strict - is it still possible to make a DNS Tunneling??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so it's a time to setup DNS proxy ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jul 2013 08:34:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-skip-captiveportal-for-one-device/m-p/29130#M21309</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-07-23T08:34:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to skip CaptivePortal for one device?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-skip-captiveportal-for-one-device/m-p/29131#M21310</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You could put there DNS name of SMTP server the device is using. What it is - I do not know.&lt;/P&gt;&lt;P&gt;I believe it is, under some circumstances, check: &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/message/28579"&gt;https://live.paloaltonetworks.com/message/28579&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jul 2013 08:44:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-skip-captiveportal-for-one-device/m-p/29131#M21310</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-07-23T08:44:17Z</dc:date>
    </item>
  </channel>
</rss>

