Palo Alto and Captive Portal for Kerberos

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Palo Alto and Captive Portal for Kerberos

L0 Member

HI all

We have a Palo Alto deployed in AWS and have a requirement to check for a users AD group before letting them into the network.

We cannot use User ID Agent as we are not allowed to set up connections to domain controllers as we have over 10 and the traffic load will be too much at the moment. So only option is to use kerberos to check user group.

However Palo Alto docs say Captive Portal re direct for kerberos does not support SSL Decryption.

Does this mean the Captive portal page itself cannot use inbound decryption or any URLs cannot use it if we enable CP?

I.E User on WAN browses and the Palo Alto redirects to captive portal on and does the Auth then redirects back to original URL. So in this this can we still keep SSL decrypt on the original URL and disable it on CP URL?

What other options are there?



L0 Member


any solution. the samething i am trying in Azure cloud 


Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!