<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Captive Portal With SSO Breaks All Rules in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-with-sso-breaks-all-rules/m-p/177947#M55442</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70334"&gt;@Phil_Throumoulos&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;That appears to be your authentification profile. You should have a policy within the Policies tab on either Authentication Policy or It could be called Captive Portal policy depending on what version you are running.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 20 Sep 2017 21:07:04 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2017-09-20T21:07:04Z</dc:date>
    <item>
      <title>Captive Portal With SSO Breaks All Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-with-sso-breaks-all-rules/m-p/177675#M55388</link>
      <description>&lt;P&gt;Hello ALL -&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is my second post here regarding Captive Portal. I enabled Captive Portal in my environment the other day thinking it would be for webaccess for my users in the event the User ID tool did not work. Upon enabling this feature other rules on my firewall stopped processing since there was no users associated with those rules.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this really the way that Captive Portal is supposed to work? I have a rule that allows a certain IPA to ping an external resource, when captive portal is enabled the rule stops working till I authenticate through the captive portal and there is a user to IP mapping regadless if my rule has an associated user listed in it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That seems like a huge flaw to me especially since I have service like DNS that do not run as any user.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just so you are all aware, &amp;nbsp;I am currenlty running 2 850's in HA on 8.0.3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I really need a way for users to authenticate for web access if User ID fails without breaking all my other firewall rules. &amp;nbsp;I thought that enabling the captive portal would allow them to authenticate that way. My SSO rule covers my entire subnet as my network environment is flat network with no segregation between servers and clients(this could be changed if needed to get things to work) as I think this might be causing part of the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help would be appreicated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2017 18:37:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-with-sso-breaks-all-rules/m-p/177675#M55388</guid>
      <dc:creator>Phil_Throumoulos</dc:creator>
      <dc:date>2017-09-19T18:37:09Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal With SSO Breaks All Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-with-sso-breaks-all-rules/m-p/177883#M55418</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70334"&gt;@Phil_Throumoulos&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Can you send a screenshot of your Authentication policy list. If you have not made exceptions to allow the traffic to pass without authentication for the required source/destination on the proper app/service you will be presented with the captive portal page if that is how you have things configured. So in essence yes, this is how it will work until you tell it how to handle the traffic.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2017 14:11:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-with-sso-breaks-all-rules/m-p/177883#M55418</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-09-20T14:11:41Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal With SSO Breaks All Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-with-sso-breaks-all-rules/m-p/177914#M55432</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="ScreenShot1318.jpg" style="width: 1176px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11402iD1B2B5BCC86DF5A5/image-dimensions/1176x245/is-moderation-mode/true?v=v2" width="1176" height="245" role="button" title="ScreenShot1318.jpg" alt="ScreenShot1318.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;What you are saying makes sense. I am not sure how I would add the exception to say do not authenticate everyone. I have a group of users in AD that should be the only ones effected by the captive portal. Maybe I should put thier group in the SSO rule instead of Domain Users.?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2017 18:24:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-with-sso-breaks-all-rules/m-p/177914#M55432</guid>
      <dc:creator>Phil_Throumoulos</dc:creator>
      <dc:date>2017-09-20T18:24:18Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal With SSO Breaks All Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-with-sso-breaks-all-rules/m-p/177947#M55442</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70334"&gt;@Phil_Throumoulos&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;That appears to be your authentification profile. You should have a policy within the Policies tab on either Authentication Policy or It could be called Captive Portal policy depending on what version you are running.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2017 21:07:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-with-sso-breaks-all-rules/m-p/177947#M55442</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-09-20T21:07:04Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal With SSO Breaks All Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-with-sso-breaks-all-rules/m-p/178102#M55458</link>
      <description>&lt;P&gt;Ahh, yes. Sorry, I guess I misunderstood what you were looking for. Here is the screenshot of what you want.&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="ScreenShot1320.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11431i82C155FEA06BF237/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ScreenShot1320.jpg" alt="ScreenShot1320.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2017 12:50:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-with-sso-breaks-all-rules/m-p/178102#M55458</guid>
      <dc:creator>Phil_Throumoulos</dc:creator>
      <dc:date>2017-09-21T12:50:07Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal With SSO Breaks All Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-with-sso-breaks-all-rules/m-p/178111#M55461</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70334"&gt;@Phil_Throumoulos&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;That's going to be your issue as you are making everyone authenticate. For anything that you don't want to be presented the captive portal you need to configure a rule to proceed without a broswer challenge, the default-no-captive-portal Authentication Enforment should work for that.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Alternatively modify the source address to just exclude your server IP range should work perfectly fine as well.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2017 13:40:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-with-sso-breaks-all-rules/m-p/178111#M55461</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-09-21T13:40:11Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal With SSO Breaks All Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-with-sso-breaks-all-rules/m-p/178157#M55473</link>
      <description>&lt;P&gt;Ahhhh, yes. What you are saying now makes complete sense to me! I am requiring that everyone authenticate which I do not need. I just need certain users in certain subnets to authenticate. I will create another auth rule and put my servers in it and also change it to no captive portal. Thanks for the extra set of eyes on this BPry!!&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2017 17:52:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-with-sso-breaks-all-rules/m-p/178157#M55473</guid>
      <dc:creator>Phil_Throumoulos</dc:creator>
      <dc:date>2017-09-21T17:52:28Z</dc:date>
    </item>
  </channel>
</rss>

