<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Captive Portal pop-ups for AD users in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-pop-ups-for-ad-users/m-p/137597#M47818</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1006"&gt;@ZEBIT&lt;/a&gt; wrote:&lt;BR /&gt;
&lt;P&gt;My two AD&amp;nbsp;servers have&amp;nbsp;the User-Id agents installed&lt;/P&gt;
&lt;P&gt;Where I can find that caching? Does it need to be enabled?&lt;/P&gt;
&lt;P&gt;Where can I find probing?&lt;/P&gt;
&lt;P&gt;Screenshot of the User-ID settings on my AD servers&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/7245i904873D4C7B16F16/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;as displayed in your screenshot, your timeout is set to 45 minutes which means that the mapping is removed unless a new logon event is detected within the 45 minute timeframe&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in a normal environment a user will log on in the morning and may not require another logon event for a long time, so those 45 minutes may be a little too short. Unless you have many roaming users and several access levels i'd recommend setting the timeout to 540 minutes, which is an average working day. that way your users log on in the morning and have access throughout the day. additionally you can enable probing which will verify every x minutes if a user is still logged on, and remove the mapping if the user is logged off or the IP is no longer used by the workstation&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2017-01-16_09-34-37.png"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/EAF30C9A5814E020FF754681AA726920/responsive_peak/images/image_not_found.png" alt="2017-01-16_09-34-37.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2017-01-16_09-36-02.png"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/EAF30C9A5814E020FF754681AA726920/responsive_peak/images/image_not_found.png" alt="2017-01-16_09-36-02.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 16 Jan 2017 08:35:58 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2017-01-16T08:35:58Z</dc:date>
    <item>
      <title>Captive Portal pop-ups for AD users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-pop-ups-for-ad-users/m-p/137340#M47789</link>
      <description>&lt;P&gt;We have a huge problem with the captive portal.&lt;/P&gt;&lt;P&gt;There is a connection between our PA500 and two Active Directory servers through the user-id agent.&lt;/P&gt;&lt;P&gt;In a day our employees (who use AD credentials on there computers) get 3 - 5 pop-ups to fill in there credentials in the captive portal in there browser. We don't have a clue why and our partner can't find any solutions.&lt;/P&gt;&lt;P&gt;The moment they get this captive-portal I checked through CLI that our firewall knows who is behind the IP and there we see unknown.&lt;/P&gt;&lt;P&gt;We have a policy that an unknown user can't access the internet without authenticating with there Active Directory account.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope the community van help me out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jan 2017 10:58:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-pop-ups-for-ad-users/m-p/137340#M47789</guid>
      <dc:creator>ZEBIT</dc:creator>
      <dc:date>2017-01-13T10:58:13Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal pop-ups for AD users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-pop-ups-for-ad-users/m-p/137361#M47793</link>
      <description>&lt;P&gt;Hi There&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;how is the AD UserID set up? are you using agents or agentless&lt;/P&gt;
&lt;P&gt;did you enable User Identification Timeout (on the cache tab)? this will remove a mapping after x minutes, if you have this set up, you will want to increase the idle time (in an average office environment with not a lot of 'roaming' clients, a timeout of 9 hours is recommended)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;is probing enabled ?&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jan 2017 12:45:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-pop-ups-for-ad-users/m-p/137361#M47793</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-01-13T12:45:15Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal pop-ups for AD users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-pop-ups-for-ad-users/m-p/137374#M47795</link>
      <description>&lt;P&gt;My two AD&amp;nbsp;servers have&amp;nbsp;the User-Id agents installed&lt;/P&gt;&lt;P&gt;Where I can find that caching? Does it need to be enabled?&lt;/P&gt;&lt;P&gt;Where can I find probing?&lt;/P&gt;&lt;P&gt;Screenshot of the User-ID settings on my AD servers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/7245i904873D4C7B16F16/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jan 2017 15:11:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-pop-ups-for-ad-users/m-p/137374#M47795</guid>
      <dc:creator>ZEBIT</dc:creator>
      <dc:date>2017-01-13T15:11:00Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal pop-ups for AD users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-pop-ups-for-ad-users/m-p/137382#M47796</link>
      <description>&lt;P&gt;Open up you agent, that on the AD server changes these settings in the "Setup"&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uidagent.JPG" style="width: 528px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/7246iD120A8008A5B8A86/image-dimensions/528x437/is-moderation-mode/true?v=v2" width="528" height="437" role="button" title="uidagent.JPG" alt="uidagent.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jan 2017 15:32:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-pop-ups-for-ad-users/m-p/137382#M47796</guid>
      <dc:creator>JDominguez</dc:creator>
      <dc:date>2017-01-13T15:32:21Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal pop-ups for AD users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-pop-ups-for-ad-users/m-p/137384#M47797</link>
      <description>&lt;P&gt;Also do you have just one agent instance and that one agent "talks" to the secondary AD?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;or do you have two seperate Agents running individually on the respective AD's and those 2 Agents talk back to the PANW fw?&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jan 2017 15:34:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-pop-ups-for-ad-users/m-p/137384#M47797</guid>
      <dc:creator>JDominguez</dc:creator>
      <dc:date>2017-01-13T15:34:48Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal pop-ups for AD users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-pop-ups-for-ad-users/m-p/137590#M47817</link>
      <description>&lt;P&gt;Each AD has its own agent and talks with the PAN fw.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2017 07:05:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-pop-ups-for-ad-users/m-p/137590#M47817</guid>
      <dc:creator>ZEBIT</dc:creator>
      <dc:date>2017-01-16T07:05:19Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal pop-ups for AD users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-pop-ups-for-ad-users/m-p/137597#M47818</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1006"&gt;@ZEBIT&lt;/a&gt; wrote:&lt;BR /&gt;
&lt;P&gt;My two AD&amp;nbsp;servers have&amp;nbsp;the User-Id agents installed&lt;/P&gt;
&lt;P&gt;Where I can find that caching? Does it need to be enabled?&lt;/P&gt;
&lt;P&gt;Where can I find probing?&lt;/P&gt;
&lt;P&gt;Screenshot of the User-ID settings on my AD servers&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/7245i904873D4C7B16F16/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;as displayed in your screenshot, your timeout is set to 45 minutes which means that the mapping is removed unless a new logon event is detected within the 45 minute timeframe&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in a normal environment a user will log on in the morning and may not require another logon event for a long time, so those 45 minutes may be a little too short. Unless you have many roaming users and several access levels i'd recommend setting the timeout to 540 minutes, which is an average working day. that way your users log on in the morning and have access throughout the day. additionally you can enable probing which will verify every x minutes if a user is still logged on, and remove the mapping if the user is logged off or the IP is no longer used by the workstation&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2017-01-16_09-34-37.png"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/EAF30C9A5814E020FF754681AA726920/responsive_peak/images/image_not_found.png" alt="2017-01-16_09-34-37.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2017-01-16_09-36-02.png"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/EAF30C9A5814E020FF754681AA726920/responsive_peak/images/image_not_found.png" alt="2017-01-16_09-36-02.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2017 08:35:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-pop-ups-for-ad-users/m-p/137597#M47818</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-01-16T08:35:58Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal pop-ups for AD users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-pop-ups-for-ad-users/m-p/137606#M47823</link>
      <description>&lt;P&gt;I configured my settings like you example on the user-id agents.&lt;/P&gt;&lt;P&gt;It is not any problem that every ad server runs his own user-id agent and connect with the firewall?&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2017 11:24:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-pop-ups-for-ad-users/m-p/137606#M47823</guid>
      <dc:creator>ZEBIT</dc:creator>
      <dc:date>2017-01-16T11:24:46Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal pop-ups for AD users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-pop-ups-for-ad-users/m-p/137633#M47824</link>
      <description>&lt;P&gt;for the probing to work you need to make sure your clients accept the probes, make sure the client firewalls are set to allow netbios/wmi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;it is not a problem that you set up 2 agents, I would even recommend having 2 just in case one fails. You may want to consider having both agents read from both AD's so they have overlapping information, also in case one agent were to fail (so there is full redundancy), the firewall will automatically use one agent as primary and keep the second as backup&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2017 13:20:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-pop-ups-for-ad-users/m-p/137633#M47824</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-01-16T13:20:43Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal pop-ups for AD users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-pop-ups-for-ad-users/m-p/137896#M47855</link>
      <description>&lt;P&gt;There's some great comments here on this thread. &amp;nbsp;One additional comment I can make that I personally get value out of is the session monitoring feature. &amp;nbsp;I would suggest enabling that as well. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, I am no kerberos / windows / AD authentication expert, but processing this through my mind, I would think you would want to make sure that&amp;nbsp;there is a regular cadence of a client/server exchange that takes place on a shorter time interval than your User-ID timeout. &amp;nbsp;I believe this would register an authentication event on the AD server thus transparently renewing the User/IP mapping in the client.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another thing you could try is doing NTLM authentication through Captive Portal. &amp;nbsp;I tested this a bit in my infrastructure and got mixed results in regards to transparency, but it was on older versions of PanOS so that may have been the problem. &amp;nbsp;Of my positive results in testing NTLM, the captive portal page displayed momentarily but then NTLM passed the user's credentials through and automatically mapped the users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lastly, if you have PKI in your environment, you could use those certs to identify users through captive portal as well. &amp;nbsp;I really like this method of doing captive portal, however the one major drawback is that there is no fail-safe or manual login option should a client fail to have the proper cert for one reason or another. &amp;nbsp;We actually floated the idea of not using the UserID agents at all, and strictly forcing Captive Portal for all users, using cert base authentication. &amp;nbsp;Unfortunately it was that lack of having a manual authentication option that forced us to pull the plug on that initiative. &amp;nbsp;It may be more sensible in a smaller organization though. &amp;nbsp;We have 25,000+ clients that connect to our network so that introduced it's own host of problems.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2017 17:17:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-pop-ups-for-ad-users/m-p/137896#M47855</guid>
      <dc:creator>MRosloniec</dc:creator>
      <dc:date>2017-01-17T17:17:27Z</dc:date>
    </item>
  </channel>
</rss>

