- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-28-2021 04:41 AM
Hi all
I use captive portal on palo alto just zone Lan to internet and found issued about chrome
My client have window 7,8 and palo version 8.1
Test on firefox need open firefox and click to option for login to internet
But on chorme not option for click and we try to access website https but it can not redirect to webportal to login
Anyone have issued abd idea
I did install cert from palo on client trustroot cert
10-28-2021 05:32 AM
This chrome reirect only http like type 1.1.1.1 it can redirect to portal but we use https://facebook
It not redirect
10-28-2021 10:02 AM
Hi @nfsfantasy ,
From what I understand your problem is redirecting HTTPS (encrypted) traffic to captive portal.
Unfortunately this is expected, if you think about how the captive portal works:
- When user tried to access some resource with HTTP, firewall will act as man-in-the-middle and intercept the request to the server
- It will forge a reply redirecting the user to the captive portal
- Once the authentication is completed, firewall will forward the request to the destination and leave the user to continue his journey
If traffic is encrypted and you don't perform SSL decryption, firewall will not be able to intercept the HTTP request and reply with redirect.
Here is a really good KB explaining how to workaround this, without enabling full SSL decryption - https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClevCAC
Basically you will need to decrypt the request for any unknown users (IP that does not have ip-to-user mapping) and no-decrypt for known users.
11-01-2021 10:42 PM
Hi Astardzhiev
thank you for explain I will try to decrypt all the request from unknow
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!