<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CP Policy in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/cp-policy/m-p/41579#M30573</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm trying to setup a captive portal and authenticate users via a user certificate, but I cannot get it to work in 5.0.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I already have a client certificate profile created but which setting do I need in the CP policy (action):&lt;/P&gt;&lt;P&gt;web-form =&amp;gt; does not work since the user needs to specify username/password&lt;/P&gt;&lt;P&gt;no-captive-portal =&amp;gt; does not prompt the user for a cert&lt;/P&gt;&lt;P&gt;browser-challenge =&amp;gt; used for NTLM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As in 4.x there is a setting captive-portal which is not available in version 5.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions ?&lt;/P&gt;&lt;P&gt;Johan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 08 Feb 2013 10:32:06 GMT</pubDate>
    <dc:creator>loosj</dc:creator>
    <dc:date>2013-02-08T10:32:06Z</dc:date>
    <item>
      <title>CP Policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cp-policy/m-p/41579#M30573</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm trying to setup a captive portal and authenticate users via a user certificate, but I cannot get it to work in 5.0.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I already have a client certificate profile created but which setting do I need in the CP policy (action):&lt;/P&gt;&lt;P&gt;web-form =&amp;gt; does not work since the user needs to specify username/password&lt;/P&gt;&lt;P&gt;no-captive-portal =&amp;gt; does not prompt the user for a cert&lt;/P&gt;&lt;P&gt;browser-challenge =&amp;gt; used for NTLM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As in 4.x there is a setting captive-portal which is not available in version 5.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions ?&lt;/P&gt;&lt;P&gt;Johan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Feb 2013 10:32:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cp-policy/m-p/41579#M30573</guid>
      <dc:creator>loosj</dc:creator>
      <dc:date>2013-02-08T10:32:06Z</dc:date>
    </item>
    <item>
      <title>Re: CP Policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cp-policy/m-p/41580#M30574</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Verify that you in the settings for the interface facing the clients have enabled "userid".&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Feb 2013 17:04:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cp-policy/m-p/41580#M30574</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-02-08T17:04:16Z</dc:date>
    </item>
    <item>
      <title>Re: CP Policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cp-policy/m-p/41581#M30575</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, there is a document on how to configure Captive Portal that you are can search for (it references the 4.0, with screen capture, etc), but essentially it is the same for 5.0, just renamed the options in the CP policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is a snippet from that document:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Go to the Policies tab -&amp;gt; Captive Portal rulebase. Configure a rule that requires the users to authenticate. &lt;/P&gt;&lt;P&gt;Note that possible actions/methods for these policies are:&lt;/P&gt;&lt;P&gt;· captive-portal – this option presents a web form to the user (scenarios 1 &amp;amp; 2), or doesn’t require any user prompting if using client certificates (scenario 3)&lt;/P&gt;&lt;P&gt;· ntlm-auth – this option attempts to use NTLM to authenticate the user behind the&lt;/P&gt;&lt;P&gt;scenes (scenario 4)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In 5.0, you have browser-based&amp;nbsp; (NTLM version) or Web-based (which is the web page OR can be the same method when using the client-certificates)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Feb 2013 17:32:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cp-policy/m-p/41581#M30575</guid>
      <dc:creator>scantwell</dc:creator>
      <dc:date>2013-02-08T17:32:04Z</dc:date>
    </item>
    <item>
      <title>Re: CP Policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cp-policy/m-p/41582#M30576</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When I select browser-based in my Captive Portal policy, the system needs an UID agent installed. Thats something I want to avoid since I want my users to authenticate via a certificate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, no other options left than ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Feb 2013 13:13:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cp-policy/m-p/41582#M30576</guid>
      <dc:creator>JohanL</dc:creator>
      <dc:date>2013-02-15T13:13:39Z</dc:date>
    </item>
    <item>
      <title>Re: CP Policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cp-policy/m-p/41583#M30577</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;CP for browser based requires a UserId agent to be installed.&amp;nbsp; The FW&amp;nbsp; fwds userid&amp;nbsp; requests to agent, which can communicate to AD or WMI active queries.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Feb 2013 06:06:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cp-policy/m-p/41583#M30577</guid>
      <dc:creator>scantwell</dc:creator>
      <dc:date>2013-02-28T06:06:22Z</dc:date>
    </item>
    <item>
      <title>Re: CP Policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cp-policy/m-p/41584#M30578</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Couldnt the CP policy use a radius or such or for that matter the internal userdb (for really small installations)?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Feb 2013 07:40:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cp-policy/m-p/41584#M30578</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-02-28T07:40:09Z</dc:date>
    </item>
    <item>
      <title>Re: CP Policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cp-policy/m-p/41585#M30579</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Of course it can.&amp;nbsp; That is where Web-Form CP comes in.&amp;nbsp; In that method it can go to many different types, Radius, Kerberos, or even local.&amp;nbsp; When I first set up CP (just to understand how it worked), I used Local as my authentication type.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Feb 2013 12:36:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cp-policy/m-p/41585#M30579</guid>
      <dc:creator>scantwell</dc:creator>
      <dc:date>2013-02-28T12:36:41Z</dc:date>
    </item>
  </channel>
</rss>

