<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Captive Portal Authentication - External and Local Domains in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-authentication-external-and-local-domains/m-p/41781#M30741</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Everyone!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for all replies and help!! really appreciated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did the suggested command as per above....&amp;nbsp; (&lt;SPAN style="color: #3b3b3b; font-family: 'courier new', courier; font-size: 12px; background-color: #f6f6f6;"&gt;set deviceconfig setting l3-service timeout 10&lt;/SPAN&gt;)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But it seems that didnt work.... I change the order, put europe AD at 2nd place, but that didnt work as well... depite I see auth success at monitor &amp;gt; system logs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;New sequence order&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ScreenShot024.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/16249_ScreenShot024.jpg" style="height: 124px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to login w/ a user from europe domain (AD-FRA)... same behavior&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ScreenShot023.jpg" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/16253_ScreenShot023.jpg" style="height: 297px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont understand, why PA doesnt check the domain.... I mean even if I use ie europe\user it still try to autheticate at other domains... PA should autheticate w/ europe domain... right ? Looks like it doesnt care about the "domain\"...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another screen shot might be helpful... sometimes I receive this error message....&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ScreenShot022.jpg" class="jive-image image-2" src="https://live.paloaltonetworks.com/legacyfs/online/16254_ScreenShot022.jpg" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other suggestion ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much guys !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 13 Oct 2014 20:57:41 GMT</pubDate>
    <dc:creator>FabioGarcia</dc:creator>
    <dc:date>2014-10-13T20:57:41Z</dc:date>
    <item>
      <title>Captive Portal Authentication - External and Local Domains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-authentication-external-and-local-domains/m-p/41777#M30737</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Everybody!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our Captive Portal is configured to authenticate according an "authentication sequence" LDAP based (&lt;STRONG&gt;LDAP-Local-Auth&lt;/STRONG&gt;). &lt;/P&gt;&lt;P&gt;&lt;IMG alt="ScreenShot003.jpg" class="jive-image image-2" src="https://live.paloaltonetworks.com/legacyfs/online/15774_ScreenShot003.jpg" style="height: 241px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We set 4 different AD servers from different Offices as per below&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ScreenShot001.jpg" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15773_ScreenShot001.jpg" style="height: 108px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Captive Portal can authenticate only for first 2 servers.... When users from AD-MEX try to authenticate they receive this page&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ScreenShot002.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15772_ScreenShot002.jpg" style="height: 401px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;At monitor &amp;gt; system we can see they are correctly authenticated,,,, but Captive Portal waits for only 2 tries... 1st and 2nd options... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example below, show a user from Mexico (3rd AD server in auth sequence)... &lt;/P&gt;&lt;P&gt;- 1st try he got deny (1st AD server... OK) - 6:20 PM&lt;/P&gt;&lt;P&gt;- 2nd try he got deny (2nd AD server from Colombia... OK deny expected) - 6:20PM&lt;/P&gt;&lt;P&gt;- then Captive block the access without wait the 3rd try (AD Mexico) - 6:20 PM&lt;/P&gt;&lt;P&gt;- 3rd try he got ALLOW .... but CP had already blocked the access.... - 6:21 PM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ScreenShot004.jpg" class="jive-image image-3" src="https://live.paloaltonetworks.com/legacyfs/online/15775_ScreenShot004.jpg" style="height: 131px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help on that ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks !!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2014 22:08:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-authentication-external-and-local-domains/m-p/41777#M30737</guid>
      <dc:creator>FabioGarcia</dc:creator>
      <dc:date>2014-09-24T22:08:04Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal Authentication - External and Local Domains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-authentication-external-and-local-domains/m-p/41778#M30738</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think this is caused by the l3 service timeout. By default, that timeout is 3 seconds. Try using the following command to increase that timeout value. You may have to modify the value some until you get the results you are looking for.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: 'courier new', courier;"&gt;&amp;gt; configure&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: 'courier new', courier;"&gt;&amp;gt; set deviceconfig setting l3-service timeout 10&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: 'courier new', courier;"&gt;&amp;gt; commit&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2014 22:56:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-authentication-external-and-local-domains/m-p/41778#M30738</guid>
      <dc:creator>jtyler</dc:creator>
      <dc:date>2014-09-24T22:56:50Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal Authentication - External and Local Domains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-authentication-external-and-local-domains/m-p/41779#M30739</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Essilorbr,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you move third profile to first in the list.And try captive portal. If it works than its a sequence/timeout issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it doesnt work than its something to do with config/authentication. It appears to be easiest step now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Sep 2014 00:35:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-authentication-external-and-local-domains/m-p/41779#M30739</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-09-25T00:35:16Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal Authentication - External and Local Domains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-authentication-external-and-local-domains/m-p/41780#M30740</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;seems to be a timeout issue for me too&lt;/P&gt;&lt;P&gt;Please update after trying the suggestion came from jtyler&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Sep 2014 13:39:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-authentication-external-and-local-domains/m-p/41780#M30740</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-09-25T13:39:22Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal Authentication - External and Local Domains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-authentication-external-and-local-domains/m-p/41781#M30741</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Everyone!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for all replies and help!! really appreciated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did the suggested command as per above....&amp;nbsp; (&lt;SPAN style="color: #3b3b3b; font-family: 'courier new', courier; font-size: 12px; background-color: #f6f6f6;"&gt;set deviceconfig setting l3-service timeout 10&lt;/SPAN&gt;)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But it seems that didnt work.... I change the order, put europe AD at 2nd place, but that didnt work as well... depite I see auth success at monitor &amp;gt; system logs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;New sequence order&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ScreenShot024.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/16249_ScreenShot024.jpg" style="height: 124px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to login w/ a user from europe domain (AD-FRA)... same behavior&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ScreenShot023.jpg" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/16253_ScreenShot023.jpg" style="height: 297px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont understand, why PA doesnt check the domain.... I mean even if I use ie europe\user it still try to autheticate at other domains... PA should autheticate w/ europe domain... right ? Looks like it doesnt care about the "domain\"...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another screen shot might be helpful... sometimes I receive this error message....&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ScreenShot022.jpg" class="jive-image image-2" src="https://live.paloaltonetworks.com/legacyfs/online/16254_ScreenShot022.jpg" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other suggestion ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much guys !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Oct 2014 20:57:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-authentication-external-and-local-domains/m-p/41781#M30741</guid>
      <dc:creator>FabioGarcia</dc:creator>
      <dc:date>2014-10-13T20:57:41Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal Authentication - External and Local Domains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-authentication-external-and-local-domains/m-p/41782#M30742</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey guys!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is working!!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have changed to 30 seconds!! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;now I can logging w/ anyone... from all ADs!!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks everyone!!!!!!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Oct 2014 21:27:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-authentication-external-and-local-domains/m-p/41782#M30742</guid>
      <dc:creator>FabioGarcia</dc:creator>
      <dc:date>2014-10-13T21:27:53Z</dc:date>
    </item>
  </channel>
</rss>

