<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Delay with User-ID and Captive Portal in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/delay-with-user-id-and-captive-portal/m-p/32383#M23732</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Amjad,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OK as I said I haven't used the captive portal yet, but the point still remains, in fact that document you linked to shows the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can see that logs have been written before the user is resolved, so that's after the security policy has been processed.&amp;nbsp; As the captive portal rules are run earlier than that, it is even more likely that the user won't have propagated to the database, so authenticated users will get prompted with the captive portal. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 15 May 2015 15:49:45 GMT</pubDate>
    <dc:creator>djr</dc:creator>
    <dc:date>2015-05-15T15:49:45Z</dc:date>
    <item>
      <title>Delay with User-ID and Captive Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/delay-with-user-id-and-captive-portal/m-p/32381#M23730</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is only theoretical for me as I don't use captive portal (yet) but I noticed a problem.&amp;nbsp; I am successfully authenticating pretty much all my users, but quite often I see a few flows at the start of a user session which doesn't have a user-id.&amp;nbsp; A few milliseconds later the user-id is populated, so I guess this is just down to a slight delay between the first packets hitting the firewall and the user-id coming up with an answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is no big deal but it made me think if I did have a captive portal to identify all unknown users, a domain-authenticated user would still find themselves presented with a captive portal login page if they fire off an HTTP request very early on in their session.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this a known behaviour?&amp;nbsp; It seems like a bit of an issue to me.&amp;nbsp; I know my users would moan about it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;David&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 May 2015 14:36:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/delay-with-user-id-and-captive-portal/m-p/32381#M23730</guid>
      <dc:creator>djr</dc:creator>
      <dc:date>2015-05-14T14:36:49Z</dc:date>
    </item>
    <item>
      <title>Re: Delay with User-ID and Captive Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/delay-with-user-id-and-captive-portal/m-p/32382#M23731</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello David&lt;/P&gt;&lt;P&gt;Please check this &lt;A href="https://live.paloaltonetworks.com/docs/DOC-1628"&gt;Packet Flow in PAN-OS&lt;/A&gt;&lt;/P&gt;&lt;P class="page" title="Page 9"&gt;&lt;/P&gt;&lt;DIV class="section" style="background-color: rgb(100.000000%, 100.000000%, 100.000000%);"&gt;&lt;DIV class="column"&gt;&lt;OL start="0" style="list-style-type: none;"&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10.000000pt; font-family: 'ArialMT';"&gt; a captive portal rule lookup is checked to see if the packet is subject to captive portal authentication. If captive portal is applicable, the packet is redirected to the captive portal daemon &lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is done prior to security policy lookup. Hope this answered your question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amjad&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 May 2015 14:55:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/delay-with-user-id-and-captive-portal/m-p/32382#M23731</guid>
      <dc:creator>aabdelhali</dc:creator>
      <dc:date>2015-05-15T14:55:58Z</dc:date>
    </item>
    <item>
      <title>Re: Delay with User-ID and Captive Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/delay-with-user-id-and-captive-portal/m-p/32383#M23732</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Amjad,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OK as I said I haven't used the captive portal yet, but the point still remains, in fact that document you linked to shows the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can see that logs have been written before the user is resolved, so that's after the security policy has been processed.&amp;nbsp; As the captive portal rules are run earlier than that, it is even more likely that the user won't have propagated to the database, so authenticated users will get prompted with the captive portal. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 May 2015 15:49:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/delay-with-user-id-and-captive-portal/m-p/32383#M23732</guid>
      <dc:creator>djr</dc:creator>
      <dc:date>2015-05-15T15:49:45Z</dc:date>
    </item>
    <item>
      <title>Re: Delay with User-ID and Captive Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/delay-with-user-id-and-captive-portal/m-p/32384#M23733</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;David&lt;/P&gt;&lt;P&gt;This will depends on how your firewall learns the IP-User mapping, for example if you use UIA, I don't expect this will happen because the agent is fast enough to learn the information from AD, and also the Windows OS takes some time to load all services and startup programs when the user log in (I guess at least 10 seconds) before the user is able to open an internet browser. But if you use other methods for example GP client, I guess yea because GP will take some time to connect and firewall to learn the mapping&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amjad&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 May 2015 16:01:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/delay-with-user-id-and-captive-portal/m-p/32384#M23733</guid>
      <dc:creator>aabdelhali</dc:creator>
      <dc:date>2015-05-15T16:01:44Z</dc:date>
    </item>
  </channel>
</rss>

