Captive Portal Redirect Issue

cancel
Showing results for 
Search instead for 
Did you mean: 

Captive Portal Redirect Issue

L2 Linker

Hello!  Quick question:

I have captive portal set up for one zone and it works well, where my captive portal "redirect host" ip is in the same zone/subnet as my users who need to authenticate.  But I'm needing to expand this so that users from several zones/subnets can authenticate via captive portal. 

 

The problem I'm having is that for users in zones/subnets external to the captive portal IP,  the redirection gets stuck.  External users are redirected to the correct zone URL, but they get no response at that URL and the redirection times out. 

 

I have set up the correct security policy rules to allow the user zones to communicate with the redirect host IP captive portal zone.  I can ping the redirect host IP from the external zones users are trying to authenticate from.  But users in external zones never see the redirect web form. 

 

Does anyone have this working and can you advise what I'm overlooking?  Thanks!

1 ACCEPTED SOLUTION

Accepted Solutions

Well I figured out how to get it working! The problem was that every zone users are authenticating from needed a management profile with response pages turned on.

 

That seems counter intuitive as I was thinking only the destination zone should need that. 

 

But I turned on for both source and destination zone and everything immediately started working.

 

FYI, I’m using the latest version of pan os 10. 

View solution in original post

3 REPLIES 3

Cyber Elite
Cyber Elite

Hi @RSteffens 

Did you check the traffic log if there is still something dropped? What did you allow in the security policy rule you mentionned?

L7 Applicator

did you mke sure NAT is not being applied somehow, and did you set manual service ports (or 'any') in the security rule you created as CP uses port 6082 which could trip up 'application-default'

Tom Piens
Like my answer? check out my book! https://bit.ly/MasteringPAN

Well I figured out how to get it working! The problem was that every zone users are authenticating from needed a management profile with response pages turned on.

 

That seems counter intuitive as I was thinking only the destination zone should need that. 

 

But I turned on for both source and destination zone and everything immediately started working.

 

FYI, I’m using the latest version of pan os 10. 

View solution in original post

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!