<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Authentication Policy other ports confusion in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-policy-other-ports-confusion/m-p/419169#M93759</link>
    <description>&lt;P&gt;We just started looking into authentication policy and while testing it works for web services but what about any other services rdp/ssh/or anything else. The BPA document says we should set authentication policy to Any, but doing that SSH in our test gets blocked, with a auth-policy-deny, and there are no redirects for SSH.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also if the user information is already known to firewall form other sources such as user agent, is the firewall still supposed to redirect and ask for authentication.&lt;/P&gt;</description>
    <pubDate>Tue, 13 Jul 2021 22:18:51 GMT</pubDate>
    <dc:creator>raji_toor</dc:creator>
    <dc:date>2021-07-13T22:18:51Z</dc:date>
    <item>
      <title>Authentication Policy other ports confusion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-policy-other-ports-confusion/m-p/419169#M93759</link>
      <description>&lt;P&gt;We just started looking into authentication policy and while testing it works for web services but what about any other services rdp/ssh/or anything else. The BPA document says we should set authentication policy to Any, but doing that SSH in our test gets blocked, with a auth-policy-deny, and there are no redirects for SSH.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also if the user information is already known to firewall form other sources such as user agent, is the firewall still supposed to redirect and ask for authentication.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jul 2021 22:18:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-policy-other-ports-confusion/m-p/419169#M93759</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2021-07-13T22:18:51Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication Policy other ports confusion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-policy-other-ports-confusion/m-p/419196#M93760</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56221"&gt;@raji_toor&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The authentication policy really can't be used for things like RDP or SSH if you want to serve the authentication prompt properly because you can't redirect users, as you've experienced. In regards to your second question, that really depends on how you've configured the authentication policy. Since authentication policy can be used as an additional authentication check against users, if you want it to not apply to known users you would simply target unknown as your source-user so it doesn't match on know users.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jul 2021 00:54:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-policy-other-ports-confusion/m-p/419196#M93760</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-07-14T00:54:13Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication Policy other ports confusion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-policy-other-ports-confusion/m-p/419325#M93774</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp; Thanks, I had forgotten about the unknown user option. Why does the BPA say to set service to any as it will only work for HTTP/HTTPS. I understand we want to cover all the ports for web but setting it to any in authentication policy effects other applications, such as ssh in our example test.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Captive Portal identifies user information for web traffic (HTTP or HTTPS) that matches an Authentication policy rule so you can identify users whose information isn’t available to the firewall.&lt;BR /&gt;Setting service as 'any' in Authentication rules for captive portal functionality ensures web traffic on all ports can be monitored to learn user information. Hence not just HTTP and HTTPS but all ports need to be enabled as web traffic can originate on non standard ports too."&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jul 2021 14:13:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-policy-other-ports-confusion/m-p/419325#M93774</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2021-07-14T14:13:53Z</dc:date>
    </item>
  </channel>
</rss>

