<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect Enforce Connection for Network Access Captive Portal detection in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-enforce-connection-for-network-access-captive/m-p/184121#M56493</link>
    <description>&lt;P&gt;Ok the pac option was easy for us as used it prior to using GP to restrict access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;its a basic setup..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;proxy = 1.2.3.4 (obviously non exist)&lt;/P&gt;&lt;P&gt;allow = globalportal and gateways direct&lt;/P&gt;&lt;P&gt;if internal host is detected = send all traffic direct. (This part sends all traffic when GP has connected).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;obviously not the correct syntax and not everyones cup of tea but works for us on both windows and ipad.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To be honest... i would rather let GP do all the work and would be happy to see the pac file go as its a workaround and somewhat dated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 27 Oct 2017 09:09:54 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2017-10-27T09:09:54Z</dc:date>
    <item>
      <title>GlobalProtect Enforce Connection for Network Access Captive Portal detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-enforce-connection-for-network-access-captive/m-p/183693#M56434</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are using global protect with the following agent features :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;GlobalProtect Enforce Connection for Network Access enable and Captive Portal detection enable with timeout of 3600 seconds.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Howver&amp;nbsp;we can see&amp;nbsp;many cases at some hotels, and airports where the actual portal detection is not being recognised by Global Protect agent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hence user cannot access any ressources.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anybody knows how the global protect agent captive portal detection actually works (cannot find any docs)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pierrick L&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2017 18:26:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-enforce-connection-for-network-access-captive/m-p/183693#M56434</guid>
      <dc:creator>plevesque</dc:creator>
      <dc:date>2017-10-25T18:26:20Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Enforce Connection for Network Access Captive Portal detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-enforce-connection-for-network-access-captive/m-p/184000#M56470</link>
      <description>&lt;P&gt;I may be wrong but its my understanding that the grace period gives the user, not global protect, a limited time to activate a captive portal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the user should try to open a website within the time limit and if a captive portal is available it will intercept the web connection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so.... in your case... users have 3600 seconds to browse to a website manually before enforcement kicks in.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2017 19:46:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-enforce-connection-for-network-access-captive/m-p/184000#M56470</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-10-26T19:46:15Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Enforce Connection for Network Access Captive Portal detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-enforce-connection-for-network-access-captive/m-p/184089#M56483</link>
      <description>&lt;P&gt;Hi Mick,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your reply, yes you are right in this case a user will have 3600 seconds to browse the internet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What we found is that you have many hotels (Marriott for exemple), that do not rely on the HTTP redirect to send a splash page.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue is that Global protect agent captive portal detection is waiting for the HTTP redirect type 302 message ...which is never coming,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pierrick L&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2017 07:41:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-enforce-connection-for-network-access-captive/m-p/184089#M56483</guid>
      <dc:creator>plevesque</dc:creator>
      <dc:date>2017-10-27T07:41:14Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Enforce Connection for Network Access Captive Portal detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-enforce-connection-for-network-access-captive/m-p/184117#M56490</link>
      <description>&lt;P&gt;Sorry i never realised the expected behaviour of CP detection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we did have issues when we first used this option but decided to use a proxy.pac file to restrict internet access until GP connected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;most of our usage is via corporate or home wifi. For the occasional times a hotel connection is made the users have a desktop icon “connect to public wifi”. This bypasses proxy settings and opens IE to our corporate web page, the captive portal kicks in, users authenticate, GP detects route change an connects. Probably no use to you but it is another option to enforce connection only traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;please update if you find a solution.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2017 08:47:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-enforce-connection-for-network-access-captive/m-p/184117#M56490</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-10-27T08:47:50Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Enforce Connection for Network Access Captive Portal detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-enforce-connection-for-network-access-captive/m-p/184118#M56491</link>
      <description>&lt;P&gt;Hi Mick,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is interesting, thank you for this, indeed&amp;nbsp;it could be a potential solution, but will need to investigate further the .pac file option since it will require a change to the original design.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;will keep the post updated as soon as i got more feedback from PA .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pierrick L&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2017 08:59:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-enforce-connection-for-network-access-captive/m-p/184118#M56491</guid>
      <dc:creator>plevesque</dc:creator>
      <dc:date>2017-10-27T08:59:47Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Enforce Connection for Network Access Captive Portal detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-enforce-connection-for-network-access-captive/m-p/184121#M56493</link>
      <description>&lt;P&gt;Ok the pac option was easy for us as used it prior to using GP to restrict access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;its a basic setup..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;proxy = 1.2.3.4 (obviously non exist)&lt;/P&gt;&lt;P&gt;allow = globalportal and gateways direct&lt;/P&gt;&lt;P&gt;if internal host is detected = send all traffic direct. (This part sends all traffic when GP has connected).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;obviously not the correct syntax and not everyones cup of tea but works for us on both windows and ipad.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To be honest... i would rather let GP do all the work and would be happy to see the pac file go as its a workaround and somewhat dated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2017 09:09:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-enforce-connection-for-network-access-captive/m-p/184121#M56493</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-10-27T09:09:54Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Enforce Connection for Network Access Captive Portal detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-enforce-connection-for-network-access-captive/m-p/184383#M56555</link>
      <description>&lt;P&gt;Hi Mick,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for these details, technically using a .pac could be a workaround, eventhough&amp;nbsp;it looks to be an&amp;nbsp;old approach, i need to see as well how i could make use of it in our environment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Agree would be much more better if Palo Atlo could efficiently support global protect behind hotel proxies.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pierrick L&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2017 10:19:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-enforce-connection-for-network-access-captive/m-p/184383#M56555</guid>
      <dc:creator>plevesque</dc:creator>
      <dc:date>2017-10-30T10:19:55Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Enforce Connection for Network Access Captive Portal detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-enforce-connection-for-network-access-captive/m-p/185344#M56723</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just to let you know that Palo Alto TAC is still looking on this issue/limitation..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pierrick L&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2017 13:48:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-enforce-connection-for-network-access-captive/m-p/185344#M56723</guid>
      <dc:creator>plevesque</dc:creator>
      <dc:date>2017-11-03T13:48:31Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Enforce Connection for Network Access Captive Portal detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-enforce-connection-for-network-access-captive/m-p/185345#M56724</link>
      <description>&lt;P&gt;many thanks for the update.&lt;/P&gt;&lt;P&gt;do you have any good links on how this actually works. I know what it's meant to do but the best description on how it actually works came from you...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i would like to understand the process from start to fininsh and also was wondering if the page was returned via https so GP could not see what was needed...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you may guess by my previous statement that i really do need to understand the enforce connection process.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;many thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2017 14:04:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-enforce-connection-for-network-access-captive/m-p/185345#M56724</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-11-03T14:04:50Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Enforce Connection for Network Access Captive Portal detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-enforce-connection-for-network-access-captive/m-p/185348#M56725</link>
      <description>&lt;P&gt;Hi Mick,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Based on current PANGPS.log and Wiresharks trace, we can see that the Global Protect agent is waiting for an HTTP redirect message type 302 coming from the Proxy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As soon as the agent receive the 'HTTP redirect' message then local network ressource is enable and you can reach the captive portal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What i believe is that this agent function is not supported behind&amp;nbsp;any transparent proxy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Some hotels rely on transparent proxies to provide internet access for their customers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope Palo Alto would be able to provide more information on weither this function is fully supported behind hotel/airport proxies, or any other alternative.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pierrick L&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2017 14:16:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-enforce-connection-for-network-access-captive/m-p/185348#M56725</guid>
      <dc:creator>plevesque</dc:creator>
      <dc:date>2017-11-03T14:16:57Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Enforce Connection for Network Access Captive Portal detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-enforce-connection-for-network-access-captive/m-p/189084#M57288</link>
      <description>&lt;P&gt;This case has ben escalated to Palo Alto TAC 3 weeks ago and now closed with no resolution/solution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So far, Palo Alto TAC has not been able to provide any valuable feedback nor to solve the connectivity issue related to the use the Global Protect agent with the enforce connection option enable behind any transparent hotel/airports...proxies.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;They simply point the issue to the hotel or airport&amp;nbsp;providers which is of course not an acceptable answer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Until Palo Alto can provide a fix&amp;nbsp;on the usability of the global protect 'enforce connection&amp;nbsp;for network access' feature i will &amp;nbsp;not implement this option.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pierrick L&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2017 09:59:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-enforce-connection-for-network-access-captive/m-p/189084#M57288</guid>
      <dc:creator>plevesque</dc:creator>
      <dc:date>2017-12-04T09:59:12Z</dc:date>
    </item>
  </channel>
</rss>

