<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configuring captive portal in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Configuring-captive-portal/m-p/61392#M1480</link>
    <description>&lt;P&gt;Thx for the update Mike.&lt;/P&gt;&lt;P&gt;I indeed found out I have create a rule with an access role and action-Captive portal.&lt;/P&gt;&lt;P&gt;However what I don't understand is, In order to create an access role, I have to identify an AD-group, so the traffic can match to that rule and redirect to captive portal.&lt;/P&gt;&lt;P&gt;But in my case, the user is unknown so the traffic can never match a rule and redirect to CP?&lt;/P&gt;&lt;P&gt;And in a rule with CP redirection, you can't define a source network, it has to be a user-object.&lt;/P&gt;&lt;P&gt;Best scenario would be:&lt;/P&gt;&lt;P&gt;- if src-network is 10.10.10.0/24 dst-network is 20.20.20.0/24, then redirect to CP&lt;/P&gt;</description>
    <pubDate>Wed, 28 Aug 2019 12:50:01 GMT</pubDate>
    <dc:creator>Bart_Vos</dc:creator>
    <dc:date>2019-08-28T12:50:01Z</dc:date>
    <item>
      <title>Configuring captive portal</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Configuring-captive-portal/m-p/61385#M1477</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a cluster of 2 security gateways.&lt;/P&gt;&lt;P&gt;I'd like to implement captive portal for following scenario:&lt;/P&gt;&lt;P&gt;During examinations, in group of students (AD group StudInternet) should have internet access and another group (AD group StudNoInternet) not.&lt;/P&gt;&lt;P&gt;All student have their own laptop and the laptops are not in Active Directory.&lt;/P&gt;&lt;P&gt;When a student surfs to the internet, he should see a captive portal.&lt;/P&gt;&lt;P&gt;At the moment the student surfs to the internet, identity is unknown, so the student is treated as a guest.&lt;/P&gt;&lt;P&gt;When surfing to internet, they should see a captive portal, login, and based ont he AD group membership, internet should be allowed or disallowed.&lt;/P&gt;&lt;P&gt;How should I configure the identity awareness?&lt;/P&gt;&lt;P&gt;These settings are already setup.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2019-08-28 12_40_58-Gateway Cluster Properties - checkpoint-cluster.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2352i5C7645946342123E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2019-08-28 12_40_58-Gateway Cluster Properties - checkpoint-cluster.jpg" alt="2019-08-28 12_40_58-Gateway Cluster Properties - checkpoint-cluster.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I suppose the Captive portal Authentication should also be set up.&lt;/P&gt;&lt;P&gt;Do I do this on the cluster, on the gateways or both the cluster and de gateways?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Turan ASCIOGLU&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2019 10:43:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Configuring-captive-portal/m-p/61385#M1477</guid>
      <dc:creator>Bart_Vos</dc:creator>
      <dc:date>2019-08-28T10:43:23Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring captive portal</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Configuring-captive-portal/m-p/61387#M1479</link>
      <description>&lt;P&gt;I believe what you are looking for is Browser Based Authentication and all configuration is done at the cluster object.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Browser-Based Authentication&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- Sends users to a Web page to acquire identities from unidentified users. If Transparent Kerberos Authentication is configured, AD users may be identified transparently.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You would then setup a rule with an Access Role associated to the AD security group you desire.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here are a couple links that may get you headed in the right direction.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_IdentityAwareness_AdminGuide/html_frameset.htm?topic=documents/R80.10/WebAdminGuides/EN/CP_R80.10_IdentityAwareness_AdminGuide/62050" target="_blank" rel="noopener"&gt;Configuring Identity Awareness&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_IdentityAwareness_AdminGuide/html_frameset.htm?topic=documents/R80.10/WebAdminGuides/EN/CP_R80.10_IdentityAwareness_AdminGuide/162368" target="_blank" rel="noopener"&gt;Configuring Browser-Based Authentication in SmartConsole&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2019 11:43:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Configuring-captive-portal/m-p/61387#M1479</guid>
      <dc:creator>Mike_A</dc:creator>
      <dc:date>2019-08-28T11:43:19Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring captive portal</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Configuring-captive-portal/m-p/61392#M1480</link>
      <description>&lt;P&gt;Thx for the update Mike.&lt;/P&gt;&lt;P&gt;I indeed found out I have create a rule with an access role and action-Captive portal.&lt;/P&gt;&lt;P&gt;However what I don't understand is, In order to create an access role, I have to identify an AD-group, so the traffic can match to that rule and redirect to captive portal.&lt;/P&gt;&lt;P&gt;But in my case, the user is unknown so the traffic can never match a rule and redirect to CP?&lt;/P&gt;&lt;P&gt;And in a rule with CP redirection, you can't define a source network, it has to be a user-object.&lt;/P&gt;&lt;P&gt;Best scenario would be:&lt;/P&gt;&lt;P&gt;- if src-network is 10.10.10.0/24 dst-network is 20.20.20.0/24, then redirect to CP&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2019 12:50:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Configuring-captive-portal/m-p/61392#M1480</guid>
      <dc:creator>Bart_Vos</dc:creator>
      <dc:date>2019-08-28T12:50:01Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring captive portal</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Configuring-captive-portal/m-p/61412#M1482</link>
      <description>&lt;P&gt;Based upon your original message, the laptop us unknown, but it seemed like the user behind unknown laptop had an AD username/password, they just have not used the laptop to authenticate to AD, thats how I read the original post anyway. If so, this should work.&lt;/P&gt;&lt;P&gt;Here is my cluster configuration. As you can see there is no Identity Collector/AD Query or anything else enabled, just Browser Based Authentication.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IA.JPG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2358i9E12BE2F2956AE16/image-size/medium?v=v2&amp;amp;px=400" role="button" title="IA.JPG" alt="IA.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;From there I created an Access Role called InternetUsers and used it in a rule. That Access Role maps to an AD group called InternetUsers also.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rule.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2359i65B696E923541B89/image-size/large?v=v2&amp;amp;px=999" role="button" title="rule.JPG" alt="rule.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;When I tried to access google.com I was presented the captive portal page. I logged in with a test AD username/password with an account in the AD group InternetUsers and google.com then loaded.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2019 15:41:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Configuring-captive-portal/m-p/61412#M1482</guid>
      <dc:creator>Mike_A</dc:creator>
      <dc:date>2019-08-28T15:41:00Z</dc:date>
    </item>
  </channel>
</rss>

