<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NTML authentcation for Captive Portal in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ntml-authentcation-for-captive-portal/m-p/10755#M7928</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tpiens,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much for the reply.&lt;/P&gt;&lt;P&gt;One question though.&lt;/P&gt;&lt;P&gt;"The deviceconfig needs to be set so the PA has it's domain configured in device &amp;gt; setup &amp;gt; general settings"&lt;/P&gt;&lt;P&gt;what does the device domain name&amp;nbsp; got to do with agentless deployment for NTLM authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;ARJUN DAS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 14 Apr 2015 14:27:58 GMT</pubDate>
    <dc:creator>ArjunDAS</dc:creator>
    <dc:date>2015-04-14T14:27:58Z</dc:date>
    <item>
      <title>NTML authentcation for Captive Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ntml-authentcation-for-captive-portal/m-p/10753#M7926</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am looking for ways to configure Captive portal policy with NTLM authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have read a good number of PDFs from Palo alto but still unable to understand how do i configure it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In short i need to know how do we configure NTLM authentication for captive portal for both Palo alto integreted hardware user agent and software user agent.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The last revision that are available on the net is "how to configure captive portal portal" is for PAN OS 4.0 and we are using PAN OS 6.0 and some of the settings are missing in PAN OS 6.0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anybody knows how to do it ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ARJUN DAS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Apr 2015 14:05:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ntml-authentcation-for-captive-portal/m-p/10753#M7926</guid>
      <dc:creator>ArjunDAS</dc:creator>
      <dc:date>2015-04-09T14:05:58Z</dc:date>
    </item>
    <item>
      <title>Re: NTML authentcation for Captive Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ntml-authentcation-for-captive-portal/m-p/10754#M7927</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Arjun&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First you will need to enable captive portal under Device &amp;gt; user identification &amp;gt; captive portal settings&lt;/P&gt;&lt;P&gt;- please note the authentication method does not matter as this is NOT used for the ntlm authentication&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2015-04-13_15-20-05.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/19159_2015-04-13_15-20-05.png" style="height: 506px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;secondly you will need to configure a captive portal policy that dictates which traffic can/needs to be intercepted to perform ntlm authentication, and set it to browser-challenge&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2015-04-13_15-23-41.png" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/19160_2015-04-13_15-23-41.png" style="height: 211px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;and third, make sure the "enable user identification" is enabled on the source zone:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2015-04-13_15-39-06.png" class="jive-image image-7" src="https://live.paloaltonetworks.com/legacyfs/online/19167_2015-04-13_15-39-06.png" style="height: 451px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then, depending on the choice of a software agent or agentless deployment you need to add some additional configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the case of a software agent you need to enable the ntlm authentication option, this proxies the ntlm request to the software agent &lt;/P&gt;&lt;P&gt;&lt;IMG alt="2015-04-13_15-25-54.png" class="jive-image image-2" src="https://live.paloaltonetworks.com/legacyfs/online/19161_2015-04-13_15-25-54.png" style="height: 194px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;and that should be it for this option&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the case of an agentless deployment more settings are required:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. The deviceconfig needs to be set so the PA has it's domain configured in device &amp;gt; setup &amp;gt; general settings, and is using the internal DNS in Device &amp;gt; setup &amp;gt; services&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;2. There needs to be a server added to the "server monitoring" section of device &amp;gt; user identification &amp;gt; user mapping&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2015-04-13_15-35-39.png" class="jive-image image-5" src="https://live.paloaltonetworks.com/legacyfs/online/19165_2015-04-13_15-35-39.png" style="height: 75px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;3. In the Palo Alto Network User ID Agent Setup, a valid WMI authentication account needs to be added and the NTLM section needs to be filled out (please not "username" is simply the username, no domain). All the other tabs can be disabled&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2015-04-13_15-31-32.png" class="jive-image image-3" src="https://live.paloaltonetworks.com/legacyfs/online/19163_2015-04-13_15-31-32.png" style="height: 194px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2015-04-13_15-31-04.png" class="jive-image image-4" src="https://live.paloaltonetworks.com/legacyfs/online/19164_2015-04-13_15-31-04.png" style="font-size: 10pt; line-height: 1.5em; height: 241px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;that should do it, hope this helps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Apr 2015 13:44:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ntml-authentcation-for-captive-portal/m-p/10754#M7927</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2015-04-13T13:44:43Z</dc:date>
    </item>
    <item>
      <title>Re: NTML authentcation for Captive Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ntml-authentcation-for-captive-portal/m-p/10755#M7928</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tpiens,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much for the reply.&lt;/P&gt;&lt;P&gt;One question though.&lt;/P&gt;&lt;P&gt;"The deviceconfig needs to be set so the PA has it's domain configured in device &amp;gt; setup &amp;gt; general settings"&lt;/P&gt;&lt;P&gt;what does the device domain name&amp;nbsp; got to do with agentless deployment for NTLM authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;ARJUN DAS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Apr 2015 14:27:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ntml-authentcation-for-captive-portal/m-p/10755#M7928</guid>
      <dc:creator>ArjunDAS</dc:creator>
      <dc:date>2015-04-14T14:27:58Z</dc:date>
    </item>
    <item>
      <title>Re: NTML authentcation for Captive Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ntml-authentcation-for-captive-portal/m-p/10756#M7929</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the configuration, a valid WMI authentication account needs to be added.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Device should be in a domain, to go for WMI authentication (domain\wmi_user)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Rahul Singh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Apr 2015 15:27:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ntml-authentcation-for-captive-portal/m-p/10756#M7929</guid>
      <dc:creator>rsingh</dc:creator>
      <dc:date>2015-04-14T15:27:00Z</dc:date>
    </item>
  </channel>
</rss>

