Captive Portal - users not supplying domain info

Reply
Highlighted
L2 Linker

Captive Portal - users not supplying domain info

Our captive portal is configured to use RADIUS (Cisco Secure ACS) to authenticate our AD users. The Cisco ACS will authenticate a user even if they do not include their domain information in the userid string... 'userid' rather than 'domain\userid'.  The problem with this is that a user who authenticates with only their userid ends up with a ip-user-mapping that will not match a userid that is pulled in with the User Identification Group Mapping Settings.

Our Cisco ACS box does not appear to be able to filter the undesirable ones out.

Has anyone dealt with this already?  Maybe there is a way to sanitize the input on the Captive portal comfort/login page?

Thanks, Jeff K

Highlighted
L5 Sessionator

Hi Jeff,

Try adding the domain name in the Radius Profile

Example:

Capture.JPG

Also another good reference for similar issue can be seen here

https://live.paloaltonetworks.com/message/27165#27165

Hopefully this helps.


Thank you

Highlighted
L2 Linker

This is useful information.  I can see this working for a single domain but we have multi domains.

I suppose I could put a bogus domain name in the RADIUS profile, then at least the authentication attempts will fail and a bad ip-user-mapping will not be created.

I subsequently tried this but got undesirable results.  An authentication request with domain information is passed untouched to the RADIUS server but the resulting ip-user-mapping is created with whatever domain is set in the RADIUS profile.

Thanks!  Jeff K

Highlighted
L2 Linker

In regard to the Captive portal comfort page, it would be great if the user input form script called by <pan_form/> could be modified to include a field to enter the domain ... this would avoid a lot of confusion.  Anyone know if this is possible?

Thanks, Jeff K

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!