<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Captive Portal Redirect Issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-redirect-issue/m-p/408776#M92384</link>
    <description>&lt;P&gt;Hello!&amp;nbsp; Quick question:&lt;/P&gt;&lt;P&gt;I have captive portal set up for one zone and it works well, where my captive portal "redirect host" ip is in the same zone/subnet as my users who need to authenticate.&amp;nbsp; But I'm needing to expand this so that users from several zones/subnets can authenticate via captive portal.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem I'm having is that for users in zones/subnets external to the captive portal IP,&amp;nbsp; the redirection gets stuck.&amp;nbsp; External users are redirected to the correct zone URL, but they get no response at that URL and the redirection times out.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have set up the correct security policy rules to allow the user zones to communicate with the redirect host IP captive portal zone.&amp;nbsp;&lt;STRONG&gt; I can ping the redirect host IP from the external zones users are trying to authenticate from.&amp;nbsp;&lt;/STRONG&gt; But users in external zones never see the redirect web form.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone have this working and can you advise what I'm overlooking?&amp;nbsp; Thanks!&lt;/P&gt;</description>
    <pubDate>Mon, 24 May 2021 19:03:00 GMT</pubDate>
    <dc:creator>pomologist</dc:creator>
    <dc:date>2021-05-24T19:03:00Z</dc:date>
    <item>
      <title>Captive Portal Redirect Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-redirect-issue/m-p/408776#M92384</link>
      <description>&lt;P&gt;Hello!&amp;nbsp; Quick question:&lt;/P&gt;&lt;P&gt;I have captive portal set up for one zone and it works well, where my captive portal "redirect host" ip is in the same zone/subnet as my users who need to authenticate.&amp;nbsp; But I'm needing to expand this so that users from several zones/subnets can authenticate via captive portal.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem I'm having is that for users in zones/subnets external to the captive portal IP,&amp;nbsp; the redirection gets stuck.&amp;nbsp; External users are redirected to the correct zone URL, but they get no response at that URL and the redirection times out.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have set up the correct security policy rules to allow the user zones to communicate with the redirect host IP captive portal zone.&amp;nbsp;&lt;STRONG&gt; I can ping the redirect host IP from the external zones users are trying to authenticate from.&amp;nbsp;&lt;/STRONG&gt; But users in external zones never see the redirect web form.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone have this working and can you advise what I'm overlooking?&amp;nbsp; Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 24 May 2021 19:03:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-redirect-issue/m-p/408776#M92384</guid>
      <dc:creator>pomologist</dc:creator>
      <dc:date>2021-05-24T19:03:00Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal Redirect Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-redirect-issue/m-p/408799#M92386</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/176255"&gt;@pomologist&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did you check the traffic log if there is still something dropped? What did you allow in the security policy rule you mentionned?&lt;/P&gt;</description>
      <pubDate>Mon, 24 May 2021 19:55:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-redirect-issue/m-p/408799#M92386</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2021-05-24T19:55:02Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal Redirect Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-redirect-issue/m-p/409170#M92415</link>
      <description>&lt;P&gt;did you mke sure NAT is not being applied somehow, and did you set manual service ports (or 'any') in the security rule you created as CP uses port 6082 which could trip up 'application-default'&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2021 09:35:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-redirect-issue/m-p/409170#M92415</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-05-26T09:35:27Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal Redirect Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-redirect-issue/m-p/409190#M92417</link>
      <description>&lt;P&gt;Well I figured out how to get it working! The problem was that every zone users are authenticating&amp;nbsp;&lt;STRONG&gt;from&lt;/STRONG&gt; needed a management profile with response pages turned on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That seems counter intuitive as I was thinking only the destination zone should need that.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I turned on for both source and destination zone and everything immediately started working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FYI, I’m using the latest version of pan os 10.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2021 11:46:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-redirect-issue/m-p/409190#M92417</guid>
      <dc:creator>pomologist</dc:creator>
      <dc:date>2021-05-26T11:46:36Z</dc:date>
    </item>
  </channel>
</rss>

