Captive portal to redirect to intranet site

Reply
Highlighted

Captive portal to redirect to intranet site

Trying to set it so when users open their web browser and no matter what they go they are redirected to an intranet site for the first web request of the day. Same thing as a captive portal at a hotel, coffee shop, etc. Want it to redirect to http://intranet.company.com/ just once.

 

Hoping the splash page could come up and just require an accept opposed to a login or something like that. As soon as the user clicks Accept, bounces to http://intranet.company.com/. Accepting this happens every 8 hours or so. Hoping it would be IP dependent so if the user switches browsers, no new splash page.

 

It is a mix of Windows, Mac, and many different browsers, so trying to do something on the network level opposed to the machine level.

 

Have a PA-3220 and a PA-820 in different sites both running 8.1.3.

Tags (2)
Highlighted
L7 Applicator

Re: Captive portal to redirect to intranet site

the built-in captive portal can't do this, but you could use redirect mode and send the user to your intranet page directly, then use kerberos/NTLM to log them in via the intranet and use that login session through AD polling (or API) to populate a user-ip mapping on the firewall which would allow the user to open their next webpage to the internet

reaper - PANgurus.com
I drink and I know things
Highlighted

Re: Captive portal to redirect to intranet site

I'm okay if the PA just has a splash page with a click-through and then redirects somewhere. Trying not to add another piece of equpiment in the mix.

 

Not trying to use it for user identiication. Higher ups want to make sure everyone touches the intranet site once a day.

Highlighted
Cyber Elite

Re: Captive portal to redirect to intranet site

How familiar are you with javascript programming?

Out of the box PA does not offer a feature you are asking for

Highlighted
Cyber Elite

Re: Captive portal to redirect to intranet site

Hello,

The captive portal is there for userid to IP mapping. If the PAN already knows it, it will not display the captive portal.

 

https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-admin/user-id/map-ip-addresses-to-users.html

 

Its not intended to be used in the scenario you are proposing.

 

Hope that makes sense.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!