Captive portal with Client Certificate Profile and fallback to radius/kerberos

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Captive portal with Client Certificate Profile and fallback to radius/kerberos

L3 Networker

Hi,

I have the following use case for a large customer :

1/ Captive portal authentication with client certificate profiles.

2/ When the client has no valid cert, an authentication fallback mechanism is required with username/password ( radius or kerberos)

I know how to configure both authentication mechanisms seperate , but would it be possible to get them working in a "fallback" combined mode.

The way I would configure this is with an "authentication sequence" containing both a "client certificate profile" and a "radius profile", but this does not seem to be possible.

Anyone knows a workarround ?

Thanks !

Bart

1 accepted solution

Accepted Solutions

L5 Sessionator

Bart,

As you have already figured out, this is not possible with the current design we have. If you need this functionality, please contact your SE to file a feature request. As for the authentication sequence, it can also be used for the server profiles and not with the cert profile.

Thanks,

Sri

View solution in original post

4 REPLIES 4

L3 Networker

Anyone ?

Not possible ?

Hi Bart - did you ever figure out how to accomplish your goal?  I'm in a similar situation... I'd like to setup our captive portal for guest users, but use certificates for our ipads.  Just curious...

Erik

L5 Sessionator

Bart,

As you have already figured out, this is not possible with the current design we have. If you need this functionality, please contact your SE to file a feature request. As for the authentication sequence, it can also be used for the server profiles and not with the cert profile.

Thanks,

Sri

Hi,

I've tried to create a work-arround by adding a second captive portal , but this seems also not to be possible.

Even a second VSYS will not help, captive portal settings are PER device and not PER vsys.

So does this really mean that the only solution would be to buy additional box ?

  • 1 accepted solution
  • 3719 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!