<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Some doubts about Captive Portal authentication in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-doubts-about-Captive-Portal-authentication/m-p/145812#M23056</link>
    <description>&lt;P&gt;I believe thats actually correct...think about it this way. When you have captive portal enabled, if any given user can NOT be even passively authenticated, they would be redirected to captive portal page to log in.&lt;/P&gt;
&lt;P&gt;So, based on rule you had given as an example, anyone in the source access role would get authentication prompt when trying to access any of those applications. As far as guest access, I cant recall now, but I believe thats enabled by default. Maybe&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;can confirm for you 100% the behaviour based on screenshot and the questions.&lt;/P&gt;
&lt;P&gt;What&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;gave you is helpful, but you can also refer to below, it gives solid explanation:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_IdentityAwareness_AdminGuide/html_frameset.htm?topic=documents/R80.30/WebAdminGuides/EN/CP_R80.30_IdentityAwareness_AdminGuide/148468" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_IdentityAwareness_AdminGuide/html_frameset.htm?topic=documents/R80.30/WebAdminGuides/EN/CP_R80.30_IdentityAwareness_AdminGuide/148468&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Fri, 08 Apr 2022 12:23:28 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2022-04-08T12:23:28Z</dc:date>
    <item>
      <title>Some doubts about Captive Portal authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-doubts-about-Captive-Portal-authentication/m-p/145804#M23050</link>
      <description>&lt;P&gt;Hi experts,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Suppose that I select AD Query and Browser-Based Authentication as my methods acquiring identity on my network. And I create a rule like this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rule.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15964i1DDFFFF907B9F116/image-size/large?v=v2&amp;amp;px=999" role="button" title="rule.PNG" alt="rule.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;To my knowledge, this is what happens in the following situations:&lt;/P&gt;&lt;P&gt;1 - When I user which belongs to the Marketing group (supposing the Marketing Access Role is mapped to the Marketing AD group) logs in and open &lt;A href="https://youtube.com" target="_blank" rel="noopener"&gt;https://youtube.com&lt;/A&gt;, this user can access with no problem.&lt;/P&gt;&lt;P&gt;2 - If a guest user try to access&amp;nbsp;&lt;A href="https://youtube.com" target="_blank" rel="noopener"&gt;https://youtube.com&lt;/A&gt;, it will be redirected to the captive portal to authenticate.&lt;/P&gt;&lt;P&gt;3 -&amp;nbsp;When I user which belongs to the Operations group logs in and open &lt;A href="https://youtube.com" target="_blank" rel="noopener"&gt;https://youtube.com&lt;/A&gt;, this user will be redirected to the captive portal to authenticate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am I correct?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Julián&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2022 10:09:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-doubts-about-Captive-Portal-authentication/m-p/145804#M23050</guid>
      <dc:creator>fjulianom</dc:creator>
      <dc:date>2022-04-08T10:09:23Z</dc:date>
    </item>
    <item>
      <title>Re: Some doubts about Captive Portal authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-doubts-about-Captive-Portal-authentication/m-p/145806#M23052</link>
      <description>&lt;P&gt;See&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk121074&amp;amp;partition=Advanced&amp;amp;product=Identity" target="_blank"&gt;sk121074: Identity Awareness Redirect to &lt;STRONG&gt;Captive&lt;/STRONG&gt; &lt;STRONG&gt;Portal&lt;/STRONG&gt; in R80.10 and above&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2022 10:38:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-doubts-about-Captive-Portal-authentication/m-p/145806#M23052</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-04-08T10:38:21Z</dc:date>
    </item>
    <item>
      <title>Re: Some doubts about Captive Portal authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-doubts-about-Captive-Portal-authentication/m-p/145812#M23056</link>
      <description>&lt;P&gt;I believe thats actually correct...think about it this way. When you have captive portal enabled, if any given user can NOT be even passively authenticated, they would be redirected to captive portal page to log in.&lt;/P&gt;
&lt;P&gt;So, based on rule you had given as an example, anyone in the source access role would get authentication prompt when trying to access any of those applications. As far as guest access, I cant recall now, but I believe thats enabled by default. Maybe&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;can confirm for you 100% the behaviour based on screenshot and the questions.&lt;/P&gt;
&lt;P&gt;What&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;gave you is helpful, but you can also refer to below, it gives solid explanation:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_IdentityAwareness_AdminGuide/html_frameset.htm?topic=documents/R80.30/WebAdminGuides/EN/CP_R80.30_IdentityAwareness_AdminGuide/148468" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_IdentityAwareness_AdminGuide/html_frameset.htm?topic=documents/R80.30/WebAdminGuides/EN/CP_R80.30_IdentityAwareness_AdminGuide/148468&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2022 12:23:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-doubts-about-Captive-Portal-authentication/m-p/145812#M23056</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-04-08T12:23:28Z</dc:date>
    </item>
    <item>
      <title>Re: Some doubts about Captive Portal authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-doubts-about-Captive-Portal-authentication/m-p/145842#M23071</link>
      <description>&lt;P&gt;Hi Andy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you say “&lt;SPAN&gt;anyone in the source access role would get authentication prompt when trying to access any of those applications”, do you mean users in the Marketing AD group as well? Because as long as the gateways are integrated with the AD server, these users should be authenticated passively without authentication prompt, am I right?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;By the other hand, the users who get the captive portal page and type the username and password, against which database are authenticated? Where are these usernames and passwords stored?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Julian&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2022 17:20:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-doubts-about-Captive-Portal-authentication/m-p/145842#M23071</guid>
      <dc:creator>fjulianom</dc:creator>
      <dc:date>2022-04-08T17:20:46Z</dc:date>
    </item>
    <item>
      <title>Re: Some doubts about Captive Portal authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-doubts-about-Captive-Portal-authentication/m-p/145843#M23072</link>
      <description>&lt;P&gt;Thats my understanding, I was referring to source marketing access role. Technically, since access roles are tied with IA and thats tied to AD, credentials would be "coming" from AD side.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2022 17:21:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-doubts-about-Captive-Portal-authentication/m-p/145843#M23072</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-04-08T17:21:07Z</dc:date>
    </item>
    <item>
      <title>Re: Some doubts about Captive Portal authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-doubts-about-Captive-Portal-authentication/m-p/145847#M23075</link>
      <description>&lt;P&gt;And for this part?&lt;/P&gt;&lt;P&gt;&lt;EM&gt;By the other hand, the users who get the captive portal page and type the username and password, against which database are authenticated? Where are these usernames and passwords stored?&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For example, for users outside the company which are not in AD, where are their credentials stored?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Julian&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2022 17:29:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-doubts-about-Captive-Portal-authentication/m-p/145847#M23075</guid>
      <dc:creator>fjulianom</dc:creator>
      <dc:date>2022-04-08T17:29:51Z</dc:date>
    </item>
    <item>
      <title>Re: Some doubts about Captive Portal authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-doubts-about-Captive-Portal-authentication/m-p/145849#M23077</link>
      <description>&lt;P&gt;Thats a good point...not sure about guests, I will let someone else confirm that. I see there is an option for unregistered guests login under portal settings, so I assume they would need to fill out registration before being granted access. You know, sort of like what you have to do at certain restaurants, hotels, etc...I believe thats how it works, but its more my educated guess, have not tested it yet.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2022 17:35:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-doubts-about-Captive-Portal-authentication/m-p/145849#M23077</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-04-08T17:35:00Z</dc:date>
    </item>
    <item>
      <title>Re: Some doubts about Captive Portal authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-doubts-about-Captive-Portal-authentication/m-p/145865#M23081</link>
      <description>&lt;P&gt;Yeah, it works like that. In the following link there are two cases very well explained:&lt;/P&gt;&lt;P&gt;1 - AD user with BYOD.&lt;/P&gt;&lt;P&gt;2 - Guest user.&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_IdentityAwareness_AdminGuide/Topics-IDAG/Acquiring-Identities-with-Browser-Based-Authentication.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_IdentityAwareness_AdminGuide/Topics-IDAG/Acquiring-Identities-with-Browser-Based-Authentication.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Take a look!&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2022 22:08:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-doubts-about-Captive-Portal-authentication/m-p/145865#M23081</guid>
      <dc:creator>fjulianom</dc:creator>
      <dc:date>2022-04-08T22:08:47Z</dc:date>
    </item>
    <item>
      <title>Re: Some doubts about Captive Portal authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-doubts-about-Captive-Portal-authentication/m-p/145866#M23082</link>
      <description>&lt;P&gt;Thats super helpful, ty!!&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2022 22:19:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-doubts-about-Captive-Portal-authentication/m-p/145866#M23082</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-04-08T22:19:06Z</dc:date>
    </item>
  </channel>
</rss>

