Captive portal palo alto issued with chrome

cancel
Showing results for 
Search instead for 
Did you mean: 

Captive portal palo alto issued with chrome

L1 Bithead

Hi all

I use captive portal on palo alto just zone Lan to internet and found issued about chrome

My client have window 7,8 and palo version 8.1

Test on firefox need open firefox and click to option for login to internet

But on chorme not option for click and  we try to access website https but it can not redirect to webportal to login

Anyone have issued abd idea 

I did install cert from palo on client trustroot cert

3 REPLIES 3

L1 Bithead

This chrome reirect only http like type 1.1.1.1 it can redirect to portal but we use https://facebook

It not redirect

Hi @nfsfantasy ,

 

From what I understand your problem is redirecting HTTPS (encrypted) traffic to captive portal.

Unfortunately this is expected, if you think about how the captive portal works:

- When user tried to access some resource with HTTP, firewall will act as man-in-the-middle and intercept the request to the server

- It will forge a reply redirecting the user to the captive portal

- Once the authentication is completed, firewall will forward the request to the destination and leave the user to continue his journey

 

If traffic is encrypted and you don't perform SSL decryption, firewall will not be able to intercept the HTTP request and reply with redirect.

 

Here is a really good KB explaining how to workaround this, without enabling full SSL decryption - https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClevCAC

Basically you will need to decrypt the request for any unknown users (IP that does not have ip-to-user mapping) and no-decrypt for known users.

 

 

Hi Astardzhiev

thank you for explain I will try to decrypt all the request from unknow

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!