<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Captive Portal in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal/m-p/38634#M28304</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Below is a pretty good document with some details regarding Captive Portal, it has not changed very much since 4.0:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="1900" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Starting on page 19 is how to configure. Use your traffic monitor to see which source and destination zones are used for the incoming connections for the server in question. Make sure your source and destination zones in your CP policy match what you see in the traffic log. Also, check the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Make sure captive portal is 'enabled' under Device &amp;gt; User Identification &amp;gt; Captive Portal Settings&lt;/LI&gt;&lt;LI&gt;Make sure that User ID is enabled on the source zone under Network &amp;gt; Zones (should be your untrusted zone in your case)&lt;/LI&gt;&lt;LI&gt;Make sure the host name or IP address you specify for the "Redirect Host" is accessible to the public. If you use a host name make sure it has a resolvable public DNS record&lt;/LI&gt;&lt;LI&gt;Make sure that the interface being used for the Redirect host is using a management profile that has response pages turned on ( Network &amp;gt; Interface Mgmt &amp;gt; Profile Name ) The interface profile is configured under Network &amp;gt; Interfaces &amp;gt; Interface Name &amp;gt; Advanced &amp;gt; Network Management Profile &lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 10 Jan 2013 23:11:05 GMT</pubDate>
    <dc:creator>jteetsel</dc:creator>
    <dc:date>2013-01-10T23:11:05Z</dc:date>
    <item>
      <title>Captive Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal/m-p/38631#M28301</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;has anyone got configuration for captive portal on and incoming untrusted public ip&amp;nbsp; nat to private internal address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i need to authenticate incoming connections before they reach the internal server address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;under captive portal I have the source as the public nat address and the destination as the internal server address and it does seem to work. The server can be reached from the Internet without any prompt for authentication?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rod&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Jan 2013 19:34:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal/m-p/38631#M28301</guid>
      <dc:creator>djrodb</dc:creator>
      <dc:date>2013-01-09T19:34:14Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal/m-p/38632#M28302</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Rod, If your intention is to prompt a CP login page for inbound connections from the internet to a system that you have created a destination nat for you Captive Portal policy would like like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;source zone = Untrusted zone&lt;/P&gt;&lt;P&gt;source address = blank or whatever the public IP the traffic is comming from (if you want to be specific)&lt;/P&gt;&lt;P&gt;Destination Address = The Public IP for your server on the inside (not the private address)&lt;/P&gt;&lt;P&gt;Service = the service you are exposing (http,https)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will force any connections coming from the outside to that public address to be faced with a CP login. If the public address is shared between other systems on the inside be careful to be specific with the Service on the CP policy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jan 2013 01:31:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal/m-p/38632#M28302</guid>
      <dc:creator>jteetsel</dc:creator>
      <dc:date>2013-01-10T01:31:50Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal/m-p/38633#M28303</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;John, Thanks. That cleared things up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I still can't get the system to present the redirected authentication login page. The documentation for Captive Portal hasn't been updated to PANOS 5 yet. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rod&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jan 2013 09:41:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal/m-p/38633#M28303</guid>
      <dc:creator>djrodb</dc:creator>
      <dc:date>2013-01-10T09:41:19Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal/m-p/38634#M28304</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Below is a pretty good document with some details regarding Captive Portal, it has not changed very much since 4.0:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="1900" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Starting on page 19 is how to configure. Use your traffic monitor to see which source and destination zones are used for the incoming connections for the server in question. Make sure your source and destination zones in your CP policy match what you see in the traffic log. Also, check the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Make sure captive portal is 'enabled' under Device &amp;gt; User Identification &amp;gt; Captive Portal Settings&lt;/LI&gt;&lt;LI&gt;Make sure that User ID is enabled on the source zone under Network &amp;gt; Zones (should be your untrusted zone in your case)&lt;/LI&gt;&lt;LI&gt;Make sure the host name or IP address you specify for the "Redirect Host" is accessible to the public. If you use a host name make sure it has a resolvable public DNS record&lt;/LI&gt;&lt;LI&gt;Make sure that the interface being used for the Redirect host is using a management profile that has response pages turned on ( Network &amp;gt; Interface Mgmt &amp;gt; Profile Name ) The interface profile is configured under Network &amp;gt; Interfaces &amp;gt; Interface Name &amp;gt; Advanced &amp;gt; Network Management Profile &lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jan 2013 23:11:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal/m-p/38634#M28304</guid>
      <dc:creator>jteetsel</dc:creator>
      <dc:date>2013-01-10T23:11:05Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal/m-p/38635#M28305</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;John&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help so far. I'm strugling with the concept of CP redirect and how the following statement translates to a working example.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;M&lt;EM&gt;ake sure the host name or IP address you specify for the "Redirect Host" is accessible to the public. If you use a host name make sure it has a resolvable public DNS record&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;Does this imply that the redirect host has to be an internal web server? or does it mean an interface on the firwewall - say for example the main firewall inside (trust) L3 interface?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;If it's an internal web server do I need to go through the normal procedure of creating a static nat from the out side to the inside server IP for the captive portal bit?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;I've added my current config to see if you or anyone else can clear this up? thanks.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Jan 2013 10:35:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal/m-p/38635#M28305</guid>
      <dc:creator>djrodb</dc:creator>
      <dc:date>2013-01-11T10:35:23Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal/m-p/38636#M28306</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The redirect host will be an L3 interface on the firewall. Weather its a trusted or untrusted interface depends on where the CP clients are coming from. If your case you want to use an untrusted interface since your CP clients are coming from the outside. Also, in your CP policy should have 'outside' for both your source and destination zones since the destination address is your public IP. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 12 Jan 2013 00:51:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal/m-p/38636#M28306</guid>
      <dc:creator>jteetsel</dc:creator>
      <dc:date>2013-01-12T00:51:29Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal/m-p/38637#M28307</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Support,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding Captive Portal , my Wifi clients can use Skype &amp;amp; GTalk application without authenticated to Captive Portal.&amp;nbsp; But when to browse http (or) https, the captive port login page kicked in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I want is, every users have to authenticate at Captive Portal login page first, then can use internet accordingly even Skype or Gtalk applications.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;zn&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jul 2013 06:58:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal/m-p/38637#M28307</guid>
      <dc:creator>znlwin</dc:creator>
      <dc:date>2013-07-19T06:58:08Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal/m-p/38638#M28308</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Captive portal will only with with web based traffic: http and https (with decryption enabled).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Jul 2013 13:40:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal/m-p/38638#M28308</guid>
      <dc:creator>zarina</dc:creator>
      <dc:date>2013-07-20T13:40:25Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal/m-p/38639#M28309</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That’s correct, the CP intercept\logon page can only be displayed via a browser. You would need to deny Skype\Gtalk for unknown users in your security policy and force the users to hit a http\https page before expecting any internet dependent applications to function, this would force them to authenticate via CP before doing any web based type activity . This is usually how hotels do it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 21 Jul 2013 16:30:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal/m-p/38639#M28309</guid>
      <dc:creator>jteetsel</dc:creator>
      <dc:date>2013-07-21T16:30:33Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal/m-p/38640#M28310</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;Thanks zarina and jteetsel.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;Hi jteetsel, how to implement &lt;SPAN style="font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;unknown users&lt;/SPAN&gt; &lt;SPAN style="font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;t&lt;SPAN style="color: #000000;"&gt; force them to authenticate via CP&lt;/SPAN&gt; before expecting any internet dependent applications to function.&lt;/SPAN&gt;&amp;nbsp; I would like to implement like hotels scenario.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;My one is PA3020 &amp;amp; ver 5.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rgds,&lt;/P&gt;&lt;P&gt;zn&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jul 2013 04:06:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal/m-p/38640#M28310</guid>
      <dc:creator>znlwin</dc:creator>
      <dc:date>2013-07-22T04:06:41Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal/m-p/38641#M28311</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Zn, the Palo Alto cannot force a user to open a browser and visit a site. We can only redirect the user to the CP login page if they do. You would need to inform the users to open a browser and sign in to CP. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jul 2013 00:29:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal/m-p/38641#M28311</guid>
      <dc:creator>jteetsel</dc:creator>
      <dc:date>2013-07-23T00:29:55Z</dc:date>
    </item>
  </channel>
</rss>

