- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
05-24-2021 11:57 AM - edited 05-24-2021 12:03 PM
Hello! Quick question:
I have captive portal set up for one zone and it works well, where my captive portal "redirect host" ip is in the same zone/subnet as my users who need to authenticate. But I'm needing to expand this so that users from several zones/subnets can authenticate via captive portal.
The problem I'm having is that for users in zones/subnets external to the captive portal IP, the redirection gets stuck. External users are redirected to the correct zone URL, but they get no response at that URL and the redirection times out.
I have set up the correct security policy rules to allow the user zones to communicate with the redirect host IP captive portal zone. I can ping the redirect host IP from the external zones users are trying to authenticate from. But users in external zones never see the redirect web form.
Does anyone have this working and can you advise what I'm overlooking? Thanks!
05-26-2021 04:46 AM
Well I figured out how to get it working! The problem was that every zone users are authenticating from needed a management profile with response pages turned on.
That seems counter intuitive as I was thinking only the destination zone should need that.
But I turned on for both source and destination zone and everything immediately started working.
FYI, I’m using the latest version of pan os 10.
05-24-2021 12:55 PM
Hi @pomologist
Did you check the traffic log if there is still something dropped? What did you allow in the security policy rule you mentionned?
05-26-2021 02:35 AM
did you mke sure NAT is not being applied somehow, and did you set manual service ports (or 'any') in the security rule you created as CP uses port 6082 which could trip up 'application-default'
05-26-2021 04:46 AM
Well I figured out how to get it working! The problem was that every zone users are authenticating from needed a management profile with response pages turned on.
That seems counter intuitive as I was thinking only the destination zone should need that.
But I turned on for both source and destination zone and everything immediately started working.
FYI, I’m using the latest version of pan os 10.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!