Captive Portal Session Timeout

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Captive Portal Session Timeout

Not applicable

You can set the Timeout value of captive portal. Default is 60 min. In my case it is 240 min.

But this is the max TTL. There is a default TTL of 900 sec(15min)

So when a logged on user does not create any traffic for 15 min then the user must logon again.

IP                   dent. By      User                                                 TTL (s)      Max. TTL (s)
---------------      ---------           --------------------------------                       -------         ------------
145.8.245.40    CP             ce.altis.corusgroup.com\A193813       830           14327

Can the default ttl be changed?

Realy i don't know why there are 2 setting for the timeout value!!

Osman Bor

Network Engineer.

Corus group

1 accepted solution

Accepted Solutions

L0 Member

Hi,

The TTL is an idle timer. It is, as you correctly stated, set at 15 minutes (900 seconds). This timer

is reset when the system sees new sessions from the user. When this timer expires, e.g. when

there is no new sessions from the user for 15 minuets, then the user is aged out and will need to

re-authenticate with captive portal. This timer is not configurable.

The other timer you see labled "Max. TTL" is the timer which keeps track of how long the user

has been active. When this timer expires, the user is kicked off no matter how active he is. He will

need to re-authenticate using Captive Portal. This timer is user configurable from the UI.

Hope this clarifies the confusion.

View solution in original post

6 REPLIES 6

L0 Member

Hi,

The TTL is an idle timer. It is, as you correctly stated, set at 15 minutes (900 seconds). This timer

is reset when the system sees new sessions from the user. When this timer expires, e.g. when

there is no new sessions from the user for 15 minuets, then the user is aged out and will need to

re-authenticate with captive portal. This timer is not configurable.

The other timer you see labled "Max. TTL" is the timer which keeps track of how long the user

has been active. When this timer expires, the user is kicked off no matter how active he is. He will

need to re-authenticate using Captive Portal. This timer is user configurable from the UI.

Hope this clarifies the confusion.

Thanks for your reply.

It's only too bad that this can't be changed for the Captive Portal. I think it's have to do with security but maybe it's better to let it decide by the organization if it's acceptable security.

Currently we are planning to move from a Cisco FW to the PaloAlto. And we are used to validate every 4 hours and it's very hard and impossible to sell this solution, that users need to logon every 15 min. with the PaloAlto.

At this moment the project stopped because this is not accepted by the users group.

So the Captive Portal is not a solution for us and we must try to find a way to use NTLM or AD with SSO. This way the users will not be prompt to logon. But this is very difficult to implement when you have mixed users in AD and not in AD. Captive portal was our fallback method.

Regards,

Osman Bor

There is an existing feature request for "Captive Portal Rule-Based Timeout" already which may address your

needs. Or, you could contact your PaloAlto Networks SE to open a feature request specifically for your

requirements.

But just to be clear, the 15 minute timeout is an *idle* timeout. So as long as the user is doing something

on the system that generates new sessions across the PA firewall, he will not have to re-login every 15

minutes.

Cheers

Both the TTL timeout and the Captive Portal Authorization fail back have been created as a request for Change.

Captive portal TTL can be changed with the CLI command:

admin@PA-2020-1(active)# set captive-portal idle-timer
  <value>  <1-1440> idle timer (minutes)

So for TTL if 15 minutes idle.  What if the user has a tool bar like a weather toolbar talking to a server outbound making queries.  Wouldn't that show as not idle?  I work for a hospital and users on mobile machines are bringing up the fact that they are not being timed out or do not have the option to log theirselves out of the Captive portal system. Any suggestions?

  • 1 accepted solution
  • 6774 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!