<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Third party RADIUS + OTP + Captive Portal in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/third-party-radius-otp-captive-portal/m-p/5816#M4249</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As soon as you authenticate through SSL-VPN, we know the user and Captive Portal rules don't kick in anymore. Captive Portal rules are only applied for unknown-users. Based on what kind of firewall you have, you could setup two vsys and route traffic between them. The first vsys would terminate the SSL-VPN and then route traffic to the second one, which runs Captive Portal. User-ID information is not shared among vsys, which means that even though the first vsys identifies the user correctly, the user would be unknown for vsys two and Captive Portal rules would be applied.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 10 Feb 2012 18:13:22 GMT</pubDate>
    <dc:creator>mwalter</dc:creator>
    <dc:date>2012-02-10T18:13:22Z</dc:date>
    <item>
      <title>Third party RADIUS + OTP + Captive Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/third-party-radius-otp-captive-portal/m-p/5815#M4248</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are implementing a Nordic-Edge Server that provides radius and otp services. Once you have enter the user/password credentials in VPN-SSL portal , you get another screen which prompts you for the OTP that is sent by SMS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The auth is OK , but the security policies are based in Active Directory users and groups. In order to solve it we are implementing a Captive Portal which is never shown.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any Suggestions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Feb 2012 11:14:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/third-party-radius-otp-captive-portal/m-p/5815#M4248</guid>
      <dc:creator>LCMember1361</dc:creator>
      <dc:date>2012-02-10T11:14:30Z</dc:date>
    </item>
    <item>
      <title>Re: Third party RADIUS + OTP + Captive Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/third-party-radius-otp-captive-portal/m-p/5816#M4249</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As soon as you authenticate through SSL-VPN, we know the user and Captive Portal rules don't kick in anymore. Captive Portal rules are only applied for unknown-users. Based on what kind of firewall you have, you could setup two vsys and route traffic between them. The first vsys would terminate the SSL-VPN and then route traffic to the second one, which runs Captive Portal. User-ID information is not shared among vsys, which means that even though the first vsys identifies the user correctly, the user would be unknown for vsys two and Captive Portal rules would be applied.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Feb 2012 18:13:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/third-party-radius-otp-captive-portal/m-p/5816#M4249</guid>
      <dc:creator>mwalter</dc:creator>
      <dc:date>2012-02-10T18:13:22Z</dc:date>
    </item>
    <item>
      <title>Re: Third party RADIUS + OTP + Captive Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/third-party-radius-otp-captive-portal/m-p/5817#M4250</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you very much mwalter.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Feb 2012 12:41:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/third-party-radius-otp-captive-portal/m-p/5817#M4250</guid>
      <dc:creator>LCMember1361</dc:creator>
      <dc:date>2012-02-14T12:41:33Z</dc:date>
    </item>
  </channel>
</rss>

