I have the following use case for a large customer :
1/ Captive portal authentication with client certificate profiles.
2/ When the client has no valid cert, an authentication fallback mechanism is required with username/password ( radius or kerberos)
I know how to configure both authentication mechanisms seperate , but would it be possible to get them working in a "fallback" combined mode.
The way I would configure this is with an "authentication sequence" containing both a "client certificate profile" and a "radius profile", but this does not seem to be possible.
Anyone knows a workarround ?
Solved! Go to Solution.
Hi Bart - did you ever figure out how to accomplish your goal? I'm in a similar situation... I'd like to setup our captive portal for guest users, but use certificates for our ipads. Just curious...
As you have already figured out, this is not possible with the current design we have. If you need this functionality, please contact your SE to file a feature request. As for the authentication sequence, it can also be used for the server profiles and not with the cert profile.
I've tried to create a work-arround by adding a second captive portal , but this seems also not to be possible.
Even a second VSYS will not help, captive portal settings are PER device and not PER vsys.
So does this really mean that the only solution would be to buy additional box ?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!