<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: In captive portal, not asking for authentication for https traffic. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/in-captive-portal-not-asking-for-authentication-for-https/m-p/6759#M4957</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The limit is rather how many concurrent ssl terminations the box you have can do. If you have plenty of SSL traffic to decrypt you might need to step up one or two models (in terms of number of concurrent ssl sessions).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 20 Aug 2012 22:46:15 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2012-08-20T22:46:15Z</dc:date>
    <item>
      <title>In captive portal, not asking for authentication for https traffic.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/in-captive-portal-not-asking-for-authentication-for-https/m-p/6754#M4952</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Captive portal is working fine for http traffic( asking for authentication ), But for https traffic it is not asking for the authentication. For example if user types facebook.com, asking authentication if types &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://facebook.com"&gt;https://facebook.com&lt;/A&gt;&lt;SPAN&gt; then it is allowing without asking for authentication. I have added both http and https services in captive portal policy.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Installed PAN OS version is 4.1.7 (As per release notes it should support captive portal for https traffic too)&lt;/P&gt;&lt;P&gt;Please help me to fix this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Guru.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Aug 2012 12:40:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/in-captive-portal-not-asking-for-authentication-for-https/m-p/6754#M4952</guid>
      <dc:creator>Gururaj</dc:creator>
      <dc:date>2012-08-08T12:40:52Z</dc:date>
    </item>
    <item>
      <title>Re: In captive portal, not asking for authentication for https traffic.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/in-captive-portal-not-asking-for-authentication-for-https/m-p/6755#M4953</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maybe you need to activate a SSL decryption in the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Marco Herrera.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Aug 2012 16:35:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/in-captive-portal-not-asking-for-authentication-for-https/m-p/6755#M4953</guid>
      <dc:creator>arkadios</dc:creator>
      <dc:date>2012-08-08T16:35:54Z</dc:date>
    </item>
    <item>
      <title>Re: In captive portal, not asking for authentication for https traffic.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/in-captive-portal-not-asking-for-authentication-for-https/m-p/6756#M4954</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Marco,&lt;/P&gt;&lt;P&gt;Thank You,..That worked, Please I need Some more help,&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;If i enable decryption for all traffic ( Any URL Category ) that will slow down's the box performance. Is there any other way to minimize this ?&lt;/LI&gt;&lt;LI&gt;And also it gives two certificates, one for decrypt policy and another for captive portal which will irritate the users.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Guru&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Aug 2012 04:52:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/in-captive-portal-not-asking-for-authentication-for-https/m-p/6756#M4954</guid>
      <dc:creator>Gururaj</dc:creator>
      <dc:date>2012-08-09T04:52:22Z</dc:date>
    </item>
    <item>
      <title>Re: In captive portal, not asking for authentication for https traffic.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/in-captive-portal-not-asking-for-authentication-for-https/m-p/6757#M4955</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just decrypt a Social pages or pages you need to "block" over SSL... to not slow down a box performance... (is just an idea), you can do this with 2 policies in Policies -&amp;gt; decryption: Options Tab -&amp;gt; No Decrypt / Decrypt&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And i don't know about point 2 &lt;img id="smileysad" class="emoticon emoticon-smileysad" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt; sorry...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Marco.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Aug 2012 16:07:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/in-captive-portal-not-asking-for-authentication-for-https/m-p/6757#M4955</guid>
      <dc:creator>arkadios</dc:creator>
      <dc:date>2012-08-09T16:07:48Z</dc:date>
    </item>
    <item>
      <title>Re: In captive portal, not asking for authentication for https traffic.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/in-captive-portal-not-asking-for-authentication-for-https/m-p/6758#M4956</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Decryption is done by dedicated CPUs , you shouldn't expect slowdowns (we don't over here)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you do the job correctly, decryption shoudldn't create SSL certificate warning ( Root CA must be trusted on your company computers). there are many guides about that on this portal.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Aug 2012 12:49:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/in-captive-portal-not-asking-for-authentication-for-https/m-p/6758#M4956</guid>
      <dc:creator>essnet</dc:creator>
      <dc:date>2012-08-14T12:49:38Z</dc:date>
    </item>
    <item>
      <title>Re: In captive portal, not asking for authentication for https traffic.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/in-captive-portal-not-asking-for-authentication-for-https/m-p/6759#M4957</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The limit is rather how many concurrent ssl terminations the box you have can do. If you have plenty of SSL traffic to decrypt you might need to step up one or two models (in terms of number of concurrent ssl sessions).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Aug 2012 22:46:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/in-captive-portal-not-asking-for-authentication-for-https/m-p/6759#M4957</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-08-20T22:46:15Z</dc:date>
    </item>
    <item>
      <title>Re: In captive portal, not asking for authentication for https traffic.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/in-captive-portal-not-asking-for-authentication-for-https/m-p/6760#M4958</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Guru.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Aug 2012 04:32:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/in-captive-portal-not-asking-for-authentication-for-https/m-p/6760#M4958</guid>
      <dc:creator>Gururaj</dc:creator>
      <dc:date>2012-08-21T04:32:04Z</dc:date>
    </item>
  </channel>
</rss>

