<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Captive Portal Authentication in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-authentication/m-p/31817#M23280</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Samuel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I may be misunderstanding your question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Captive portal is part of the "User Identification" feature. If a user is identified by his AD login he will never see the the portal. Only unknown users, Linux devices and guest users, will be "Unknown" and the portal will present itself to the user to force authentication and use this as the identification method. You do not pick groups or users for Portal usage.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve Krall&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 30 Dec 2011 01:00:50 GMT</pubDate>
    <dc:creator>skrall</dc:creator>
    <dc:date>2011-12-30T01:00:50Z</dc:date>
    <item>
      <title>Captive Portal Authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-authentication/m-p/31814#M23277</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, I've PA-500 with 4.1.1 and I've configured Captive Portal with AD Authentication. Pan-agenty seems to work fine and I can select the AD groups when I configure Securtiy Policy. &lt;/P&gt;&lt;P&gt;I've created an authentication profile only for Captive Portal with Kerberos authentication and my Domain controller as Server profile but I cannot see the groups in allow list, only can see local users. Although with all in allow list, Captive Portal authentication works fine&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure if I need to configure Group Mappings but as I've read in Administrator Guide of 4.1 group mapping is configured as LDAP server, is it correct?, do I need to configure Group mapping only to have my AD groups in allow list of authentication Profile?.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Samuel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Dec 2011 10:06:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-authentication/m-p/31814#M23277</guid>
      <dc:creator>ssancho</dc:creator>
      <dc:date>2011-12-19T10:06:24Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal Authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-authentication/m-p/31815#M23278</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With PANOS 4.1.x, you need to configure Group Mapping Settings for PAN to get the user-group mappings.&amp;nbsp; You would need to create an LDAP server profile first and then apply that to the Group Mapping Settings.&amp;nbsp; With this configured, you will be able to reference groups in your policies.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks,&lt;/P&gt;&lt;P&gt;Ahsan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Dec 2011 03:39:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-authentication/m-p/31815#M23278</guid>
      <dc:creator>akhan</dc:creator>
      <dc:date>2011-12-21T03:39:15Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal Authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-authentication/m-p/31816#M23279</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, thanks for your reply. I supossed that, but the strange think is that I can select my groups in security policy but not in allow list of authentication Profile. Do I need to configure LDAP profile to have user-group mappings in allow list of Authentication Profile?.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems strange to have groups in policies without LDAP profile and need it to use groups in Authentication Profile.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;EDIT: Hi, I've configured LDAP server profile and install User-ID (not pan-agent) in domain controller. All seems to work fine, I can create policies with users and make the filter of groups in firewall (Device, User Identification, Group Mappings), BUT I cannot select the active directory groups in Authentication Profile.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How could I filter the users of Active Directory that can login in captive portal?, at the moment I only can select my local users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Samuel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Dec 2011 15:07:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-authentication/m-p/31816#M23279</guid>
      <dc:creator>ssancho</dc:creator>
      <dc:date>2011-12-22T15:07:13Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal Authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-authentication/m-p/31817#M23280</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Samuel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I may be misunderstanding your question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Captive portal is part of the "User Identification" feature. If a user is identified by his AD login he will never see the the portal. Only unknown users, Linux devices and guest users, will be "Unknown" and the portal will present itself to the user to force authentication and use this as the identification method. You do not pick groups or users for Portal usage.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve Krall&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Dec 2011 01:00:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-authentication/m-p/31817#M23280</guid>
      <dc:creator>skrall</dc:creator>
      <dc:date>2011-12-30T01:00:50Z</dc:date>
    </item>
  </channel>
</rss>

