Is Captive Portal triggered when using "any" as user in security policy?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Is Captive Portal triggered when using "any" as user in security policy?

L1 Bithead

I read a lot of captive portal set up. In almost every documents says that the user "unknown" doesn't trigger the captive portal. I think that the "any" user also included the "unknown" user, I'm not quite sure if those rules are gonna trigger the captive portal policy [And I don't want to]

2 REPLIES 2

L4 Transporter

Yes, I have tested this in the lab and it does trigger Captive Portal when using "any" as user in security policy.

If you have security rule with user as "Unknown" it will work fine, and triggers captive portal login page..

If you have security rule with user as "any" it will work fine. and triggers captive portal login page

If you have security rule with user as "Known-user" it will not work because captive portal is only for unknown users.

To learn more about captive portal here is a link:

How to Configure Captive Portal

Let me know if you have any questions.'

Regards,

Dileep

L4 Transporter

When you have no IP to user mapping for a particular IP address, for traffic that comes in on a zone that has User Identification enabled, AND a CP policy is enabled, then the CP page should be triggered.

When looking at the Security policy, you are trying to restrict traffic for only "Known" users - whether they known via the User ID agent, or CP, or GP, the security policy will control what traffic is allowed for what users.

If you choose to put "unknown" or "any" - that would imply that you do not really care about "known" users.

The security policy is more for controlling who gets what access.

To trigger the CP policy, you ought to look at the CP policy and the zones and addresses for which you'd like the CP policy triggered.

  • 2684 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!