Captive Portal + Global Protect
cancel
Showing results for 
Search instead for 
Did you mean: 

Captive Portal + Global Protect

L3 Networker

 Hi team,

 

How to make work the Palo Alto Captive portal after users logged in to Global protect. ?

Users who got connected to GP should get captive portal auth page while they try to use internet.

Is there any way to achieve this ?

 

 

Thanks & Regards,
Sahithyan S
5 REPLIES 5

L7 Applicator

hi @sahithyan.subbu 

 

in the policy > authentication rulebase, create a new rule (at the top of your rulebase) that has 'users' set to 'any' or 'known-users', then set the action to 'default-web-form'

Tom Piens
Like my answer? check out my book! https://bit.ly/MasteringPAN

@reaper 

 

I got your ref from GOT. Good one.

 

I already configured as per you said,

i have configured authenticatoin rulebase and placed on top and also i have configure agent and captive portal accordingly, but it is not working.

Do u have any document to configure this ??

 

 

Thanks & Regards,
Sahithyan S

It will be in my book, stay tuned

 

Did you set a management profile on the tunnel interface with "response pages" enabled?

Tom Piens
Like my answer? check out my book! https://bit.ly/MasteringPAN

Hi @reaper 

 

yes I did.

 

 

Thanks & Regards,
Sahithyan S

Interesting

How did you set the captive portal (redirect, transparent) and how did you configure the auth rule?

 

Could you try setting redirect mode and set the ip of the tunnel interface

Make sure security policy allows the Cp connection

Tom Piens
Like my answer? check out my book! https://bit.ly/MasteringPAN
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!