<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is there a Captive Portal type solution for non http/https services? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-captive-portal-type-solution-for-non-http-https/m-p/141147#M48353</link>
    <description>&lt;P&gt;I am looking for a method to force identify users coming in over the internet trying to connect to an internal resource using&amp;nbsp;MS-RDP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I originally thought I could use Captive Portal for this but CP documentation indicates its only works with HTTP &amp;amp; HTTPS....obviously this makes sense because without an http interpreter, how else could an app that is not designed to talk to http recognize the HTTP/HTTPS Captive Port web-form or redirect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to force a type of user authentication for users coming from Untrust Internet (any IP) to Trust internal (specific IP). &amp;nbsp;Or what other method could I use or investigate?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Mon, 06 Feb 2017 14:55:05 GMT</pubDate>
    <dc:creator>Russell123</dc:creator>
    <dc:date>2017-02-06T14:55:05Z</dc:date>
    <item>
      <title>Is there a Captive Portal type solution for non http/https services?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-captive-portal-type-solution-for-non-http-https/m-p/141147#M48353</link>
      <description>&lt;P&gt;I am looking for a method to force identify users coming in over the internet trying to connect to an internal resource using&amp;nbsp;MS-RDP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I originally thought I could use Captive Portal for this but CP documentation indicates its only works with HTTP &amp;amp; HTTPS....obviously this makes sense because without an http interpreter, how else could an app that is not designed to talk to http recognize the HTTP/HTTPS Captive Port web-form or redirect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to force a type of user authentication for users coming from Untrust Internet (any IP) to Trust internal (specific IP). &amp;nbsp;Or what other method could I use or investigate?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2017 14:55:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-captive-portal-type-solution-for-non-http-https/m-p/141147#M48353</guid>
      <dc:creator>Russell123</dc:creator>
      <dc:date>2017-02-06T14:55:05Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a Captive Portal type solution for non http/https services?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-captive-portal-type-solution-for-non-http-https/m-p/142255#M48507</link>
      <description>&lt;P&gt;Use of User-ID based rules from Untrust (Internet) to Trust (internal) is discouraged.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As User-ID creates a mapping of the IP address to a single user, the multiple NAT scenarios that can come into play here can give you unintended results.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If we both happened to be at the same coffee shop and NAT'd to the same IP address, if you were the first to access the corporate resource and challenged by captive portal, I and all of the others in the coffee shop would inherit your access rights.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You might consider deploying a GlobalProtect gateway, and then using your App-ID/User-ID based rules to permit access for the appropriate users to the systems via RDP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2017 03:29:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-captive-portal-type-solution-for-non-http-https/m-p/142255#M48507</guid>
      <dc:creator>asilliker</dc:creator>
      <dc:date>2017-02-10T03:29:01Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a Captive Portal type solution for non http/https services?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-captive-portal-type-solution-for-non-http-https/m-p/142301#M48516</link>
      <description>&lt;P&gt;as &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/14490"&gt;@asilliker&lt;/a&gt; already mentions, I'd deploy GlobalProtect from a best practices perspective&lt;/P&gt;
&lt;P&gt;it will allow you to identify your users more easily and apply security policy based on their identity,&amp;nbsp; plus will add a layer of security (ipsec/ssl) to prevent snooping or MitM attacks when your users are making rdp connections from any random uncontrolled location to your infrastructure&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2017 09:24:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-captive-portal-type-solution-for-non-http-https/m-p/142301#M48516</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-02-10T09:24:08Z</dc:date>
    </item>
  </channel>
</rss>

