Captive portal SSL decryption policy requirement

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Captive portal SSL decryption policy requirement

L2 Linker

Hi,

 

PAN has the following document [1] which says you need to have SSL decryption in order to redirect SSL pages to captive portal.

To me it doesn't seem to be accurate. Response page [2] workaround seems to be doing the same i.e without having an SSL decryption policy, I see that SSL pages are redirected to captive portal properly. What am I missing? I have found

several posts about this topic referring response page document too but PAN's document contradicts this.

I have created a PAN case for clarification/document update though, I would appreciate forum users' feedback.

 

thanks.

 

[1] https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClH8CAK

 

[2] https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFKCA0

4 REPLIES 4

Cyber Elite
Cyber Elite

That first article is simply very old and should have been archived, I'll go ahead and do that 

 

Thanks for reporting this!

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Hi,

  that is fine but please publish a new article as TAC keep telling us that SSL decryption is required for captive portal

and as per experience, it is not a correct statement. New article can be helpful for TAC and users like us 🙂

 

thanks.

 

L1 Bithead

What is the actual requirement? We are trying to redirect to a captive portal for an auth policy for https traffic and are being told by TAC this isn't supported unless we are decrypting all of the https traffic. 

I think TaC is wrong here. The 2nd link has always worked for me, although I will say I've found it not to work 100% of the time with https traffic. SSL decryption certain does help.

 

I think this is an issue with 1st level TAC not knowing something.  

  • 3064 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!