<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Scheduled captive portal and byod.. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/scheduled-captive-portal-and-byod/m-p/43090#M31612</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A policy can be scheduled using the option of Schedulers (Object&amp;gt;Schedules) .&lt;/P&gt;&lt;P&gt;At present, schedules can be only applied to Security policies and not Captive portal policies.&lt;/P&gt;&lt;P&gt;You may speak to your SE if you would like to request this feature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Closest option for scheduling CP would be to apply schedules to the security rule that allows applications dns and web-browsing for unknown-users, this way CP auth page will not be presented, but this option could be a bit clumsy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Ameya &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 28 Oct 2013 18:45:41 GMT</pubDate>
    <dc:creator>UhMayYeah</dc:creator>
    <dc:date>2013-10-28T18:45:41Z</dc:date>
    <item>
      <title>Scheduled captive portal and byod..</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/scheduled-captive-portal-and-byod/m-p/43087#M31609</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We use a PA500 box on 5.0.3 in a boarding school environment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want CP only to be active during lessons and not in the afternoon / evenings..&amp;nbsp; However I cannot find how to apply a schedule to my CP.&amp;nbsp; How do I do that?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also the students are complaining about having to relogin every time one of their devices are powered up from suspended mode.&amp;nbsp; Which CP settings do change to avoid this?&amp;nbsp; &lt;/P&gt;&lt;P&gt;Can a CP user use multiple devices simultaneously under the same user account?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot for comments on this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards Tor&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Oct 2013 16:53:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/scheduled-captive-portal-and-byod/m-p/43087#M31609</guid>
      <dc:creator>LCMember4427</dc:creator>
      <dc:date>2013-10-28T16:53:46Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduled captive portal and byod..</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/scheduled-captive-portal-and-byod/m-p/43088#M31610</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Captiv Portal policies can't be scheduled then they will be prompted everytime.&lt;/P&gt;&lt;P&gt;Yes, one acccount can be used on many devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Oct 2013 17:21:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/scheduled-captive-portal-and-byod/m-p/43088#M31610</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2013-10-28T17:21:09Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduled captive portal and byod..</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/scheduled-captive-portal-and-byod/m-p/43089#M31611</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You mean prompted every time the schedule is switched on?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I meant to switch on the CP authentication at 7am and switch it off at 4pm.&amp;nbsp; Users should have to log on at the first time they needed internet after 7am and then relogin every 4 hours if the session timeout was set to 4hrs.&amp;nbsp; After 4pm they shouldn't be bugged with CP auth until next morning.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry if I misunderstood you, but I tried to elaborate my scenario.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards Tor&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Oct 2013 17:28:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/scheduled-captive-portal-and-byod/m-p/43089#M31611</guid>
      <dc:creator>LCMember4427</dc:creator>
      <dc:date>2013-10-28T17:28:57Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduled captive portal and byod..</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/scheduled-captive-portal-and-byod/m-p/43090#M31612</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A policy can be scheduled using the option of Schedulers (Object&amp;gt;Schedules) .&lt;/P&gt;&lt;P&gt;At present, schedules can be only applied to Security policies and not Captive portal policies.&lt;/P&gt;&lt;P&gt;You may speak to your SE if you would like to request this feature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Closest option for scheduling CP would be to apply schedules to the security rule that allows applications dns and web-browsing for unknown-users, this way CP auth page will not be presented, but this option could be a bit clumsy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Ameya &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Oct 2013 18:45:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/scheduled-captive-portal-and-byod/m-p/43090#M31612</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-10-28T18:45:41Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduled captive portal and byod..</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/scheduled-captive-portal-and-byod/m-p/43091#M31613</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Just before the 'offending' CP user policies I tried to insert a new security policy for 'any' user scheduled to be active after school hours.&amp;nbsp; I hoped that it would 'catch' everyone in the scheduled timeframe so they never jumped further to the CP policies further down.&amp;nbsp; However they are still prompted for username and password.&amp;nbsp; Is this because the Captive Portal policy for this subnet is active (and cannot be controlled by a schedule).&amp;nbsp; Please elaborate if I misunderstood how to do this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also there is abosolutely not way to 'log off' a PanOS &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;captive portal session?&amp;nbsp; Occasionally we make public computers available and it would be nice if the current user was able to log out before letting another user continue browsing the internet. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tor&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Nov 2013 13:41:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/scheduled-captive-portal-and-byod/m-p/43091#M31613</guid>
      <dc:creator>LCMember4427</dc:creator>
      <dc:date>2013-11-08T13:41:28Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduled captive portal and byod..</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/scheduled-captive-portal-and-byod/m-p/43092#M31614</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="; color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; text-decoration: underline;"&gt;&lt;EM&gt;&lt;STRONG&gt; Is this because the Captive Portal policy for this subnet is active (and cannot be controlled by a schedule).&amp;nbsp; Please elaborate if I misunderstood how to do this?&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;CP page would be prompted as long as the HTTP GET request/HTTPS transaction reaches firewall's CP zone.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Applying&amp;nbsp; schedules to the &lt;STRONG&gt;security rule&lt;/STRONG&gt; that allows applications &lt;STRONG&gt;dns&lt;/STRONG&gt;&lt;STRONG&gt; and web-browsing&lt;/STRONG&gt; for unknown-users would ensure that DNS resolution and web-traffic only succeeds during the desired schedule, indirectly controlling the prompting of CP auth page.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="; color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; text-decoration: underline;"&gt;&lt;EM style="color: #3b3b3b; text-decoration: underline; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; text-decoration: underline;"&gt;&lt;STRONG&gt;Also there is &lt;/STRONG&gt;&lt;STRONG&gt;abosolutely not way to 'log off' a PanOS &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b; text-decoration: underline;"&gt;&lt;STRONG&gt;captive portal session?&amp;nbsp; Occasionally we make public computers available and it would be nice if the current user was able to log out before letting another user continue browsing the internet.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Firewall sets a cookie so that future login requests&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; become transparent to the user using session cookies in redirect mode, if the browser has not been closed,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Try disabling this option so that a new user has to login when the current user closes the browser window.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Currently there is no option to log off a CP user.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;HTH,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Ameya &lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Nov 2013 21:16:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/scheduled-captive-portal-and-byod/m-p/43092#M31614</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-11-08T21:16:35Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduled captive portal and byod..</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/scheduled-captive-portal-and-byod/m-p/43093#M31615</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;a simple ssh-script that automatically logs in and runs the command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;to disable:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;configure&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;set rulebase captive-portal rules &lt;SPAN style="text-decoration: underline;"&gt;CWP&lt;/SPAN&gt; action no-captive-portal&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;commit&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt; or to enable:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;configure&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;set rulebase captive-portal rules &lt;SPAN style="text-decoration: underline;"&gt;CWP&lt;/SPAN&gt; action web-form&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;commit&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;'&lt;/P&gt;&lt;P&gt;Dirty, but running that on a schedule should do the trick.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Nov 2013 13:51:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/scheduled-captive-portal-and-byod/m-p/43093#M31615</guid>
      <dc:creator>raystr</dc:creator>
      <dc:date>2013-11-20T13:51:27Z</dc:date>
    </item>
  </channel>
</rss>

