<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Isn't there anyone with any in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/captive-portal-does-not-load-some-times/m-p/2887055#M1030725</link>
    <description>&lt;P&gt;Isn't there anyone with any experience with captive portals?&lt;/P&gt;</description>
    <pubDate>Tue, 24 May 2016 06:45:00 GMT</pubDate>
    <dc:creator>kh.farhad</dc:creator>
    <dc:date>2016-05-24T06:45:00Z</dc:date>
    <item>
      <title>Captive portal does not load some times</title>
      <link>https://community.cisco.com/t5/network-security/captive-portal-does-not-load-some-times/m-p/2887052#M1030721</link>
      <description>&lt;P&gt;We're using an asa firepower 5515 which it's sfr is managed by a firesight management center vm. I've configured it's captive portal and it was working for about 1 month with some problems. For some clients the address in addressbar of browser redirects to ip address of inside firewall interface on captive port but it takes about 5 minutes to load and when I checked the logs it seems that all the time sfr is requesting a drop for trraffic to captive portal but I have configured a trust for traffic to port 4455 (captive port). For some other users it never opens. So I decided to use passive authentication with user agent. Now other users that are not joint in Microsoft AD can not be authenticated because captive portal never shows up.&lt;/P&gt;
&lt;P&gt;I have used this link&amp;nbsp;&lt;A href="http://www.cisco.com/c/en/us/support/docs/security/asa-firepower-services/200329-Configure-Active-Directory-Integration-w.html" target="_blank"&gt;http://www.cisco.com/c/en/us/support/docs/security/asa-firepower-services/200329-Configure-Active-Directory-Integration-w.html&lt;/A&gt; to configure the firesight manager and I have generated the certificate in firesight manager NOT in sfr expert mode. Can it be the cause of problem?&lt;/P&gt;
&lt;P&gt;This is the log of&amp;nbsp;/var/log/captive_portal.log on sfr expert mode attached.&lt;/P&gt;
&lt;P&gt;I also used this thread&amp;nbsp;&lt;A href="https://supportforums.cisco.com/discussion/12424996/cisco-asa-sourcefire-captive-portal" target="_blank"&gt;https://supportforums.cisco.com/discussion/12424996/cisco-asa-sourcefire-captive-portal&lt;/A&gt; and output of all commands are attached.&lt;/P&gt;
&lt;P&gt;By the way this device is driving me crazy please someone help me on this.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 13:01:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/captive-portal-does-not-load-some-times/m-p/2887052#M1030721</guid>
      <dc:creator>kh.farhad</dc:creator>
      <dc:date>2019-03-12T13:01:16Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-security/captive-portal-does-not-load-some-times/m-p/2887053#M1030722</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What's the code version on SFR module and ASA. It works on 6.0 but there are some known issues there. If you are on 6.0, I would suggest to upgrade to 6.0.1 first and then test.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2016 08:05:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/captive-portal-does-not-load-some-times/m-p/2887053#M1030722</guid>
      <dc:creator>yogdhanu</dc:creator>
      <dc:date>2016-05-23T08:05:18Z</dc:date>
    </item>
    <item>
      <title>Hi, thank you for replying.</title>
      <link>https://community.cisco.com/t5/network-security/captive-portal-does-not-load-some-times/m-p/2887054#M1030723</link>
      <description>&lt;P&gt;Hi, thank you for replying. ASA os is 9.6(1), sfr is 6.0.1 (Build 29), firesight manager is 6.0.1.1-4 which are the latest versions. I don't know what is wrong with it.&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2016 09:43:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/captive-portal-does-not-load-some-times/m-p/2887054#M1030723</guid>
      <dc:creator>kh.farhad</dc:creator>
      <dc:date>2016-05-23T09:43:59Z</dc:date>
    </item>
    <item>
      <title>Isn't there anyone with any</title>
      <link>https://community.cisco.com/t5/network-security/captive-portal-does-not-load-some-times/m-p/2887055#M1030725</link>
      <description>&lt;P&gt;Isn't there anyone with any experience with captive portals?&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2016 06:45:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/captive-portal-does-not-load-some-times/m-p/2887055#M1030725</guid>
      <dc:creator>kh.farhad</dc:creator>
      <dc:date>2016-05-24T06:45:00Z</dc:date>
    </item>
    <item>
      <title>Same Issue</title>
      <link>https://community.cisco.com/t5/network-security/captive-portal-does-not-load-some-times/m-p/2887056#M1030727</link>
      <description>&lt;P&gt;Same Issue&lt;/P&gt;
&lt;P&gt;Firesigth 6.0.1&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Firepower 6.0.1&lt;/P&gt;
&lt;P&gt;ASA 9.6.1 (you can fix the problem of 90% cpu &amp;nbsp;whit command no threat-detection basic-threat &amp;nbsp;&amp;amp; no threat-detection statistics access-list)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;the certificate for the active actentication (captive portal) we made that with OpenSSL but not work&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;and also TAC create a new one on Firesigth but the same result &amp;nbsp;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;if we test the connectiviti to the ASA IP addres and port &amp;nbsp;it looks like is open&amp;nbsp;&lt;/P&gt;
&lt;P&gt;on windows CMD&lt;/P&gt;
&lt;P&gt;telnet 10.10.10.1 885&lt;/P&gt;
&lt;P&gt;when a suer try to see any web page (even if the web page belongs to a rule that not have to filter by user) the web browser try to reach the asa ip add and the port for authentication and not load the response page (the one that can be customised ) or the basic web authentication (it shoud appear a dialog box asking for username and pass)&lt;/P&gt;
&lt;P&gt;the ip add of the inside interface on asa is 10.10.10.1 and the host is 10.10.11.23&lt;/P&gt;
&lt;P&gt;on ASDM -&amp;gt;real-time log viewer&lt;/P&gt;
&lt;P&gt;SFR requested to drop TCP packet from inside:10.10.11.23/58852 to identity:10.10.10.1/885&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;i have installed the Cisco Firsigth User Agent 2.3 on a machine that IS NOT the AD (and the status of connections to the AD and to the Firesigth is OK)&lt;/P&gt;
&lt;P&gt;AD server is 2k8 windows&lt;/P&gt;
&lt;P&gt;and when we download users and groups (from firesigth&amp;gt;system&amp;gt;realm&amp;gt;User download&amp;gt;download now) in the tasks show&lt;/P&gt;
&lt;P&gt;&lt;STRONG id="yui_3_3_0_1_1464892866324402"&gt;Download users/groups from Realm-Test.&lt;/STRONG&gt;&lt;SPAN&gt; LDAP download successful: 12 groups, 0 users downloaded&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;The customer wanna kill me i have an Open case whit TAC if they answer me i will post it&lt;/P&gt;
&lt;P&gt;Regards and i hope that some one could help!&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jun 2016 18:46:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/captive-portal-does-not-load-some-times/m-p/2887056#M1030727</guid>
      <dc:creator>RAFAEL LOPEZ</dc:creator>
      <dc:date>2016-06-02T18:46:21Z</dc:date>
    </item>
    <item>
      <title>Hi Rafael,</title>
      <link>https://community.cisco.com/t5/network-security/captive-portal-does-not-load-some-times/m-p/2887057#M1030729</link>
      <description>&lt;P&gt;Hi Rafael,&lt;/P&gt;
&lt;P&gt;I have installed AD agent it's working fine for users that their systems are joined to the domain. When they login or logoff its notification goes to the management center immediately. But not all of the computers are joined to the domain so the problem still exist and for some users accidentally the page does not load and the same message is shown in the log messages of asdm &amp;gt; sfr requests drop for packets destined to captive portal.&lt;/P&gt;
&lt;P&gt;Any solution yet?&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jun 2016 10:26:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/captive-portal-does-not-load-some-times/m-p/2887057#M1030729</guid>
      <dc:creator>kh.farhad</dc:creator>
      <dc:date>2016-06-05T10:26:45Z</dc:date>
    </item>
    <item>
      <title>Hello Farhad,</title>
      <link>https://community.cisco.com/t5/network-security/captive-portal-does-not-load-some-times/m-p/2887058#M1030730</link>
      <description>&lt;P&gt;Hello Farhad,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If you think all the configurations are correct as per the version and still face issues, then please contact TAC to verify the issue.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Jetsy&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jun 2016 12:16:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/captive-portal-does-not-load-some-times/m-p/2887058#M1030730</guid>
      <dc:creator>Jetsy Mathew</dc:creator>
      <dc:date>2016-06-05T12:16:31Z</dc:date>
    </item>
    <item>
      <title>Hi, kh.farhad i make it work,</title>
      <link>https://community.cisco.com/t5/network-security/captive-portal-does-not-load-some-times/m-p/2887059#M1030731</link>
      <description>&lt;P&gt;Hi, kh.farhad &lt;BR /&gt;i make it work, when i press download button under realm i get the groups and users !&lt;BR /&gt;&lt;BR /&gt;1.-change on realm type from Ldap to AD &lt;BR /&gt;&lt;BR /&gt;2.-secure conection to AD (ssl) and also upload the server certificate &lt;BR /&gt;&lt;BR /&gt;3.-i change all ip to FQD &lt;BR /&gt;the identity source instade of use ip i use the fqdn of the host where is installed the User Agent, and also on the aplication &lt;BR /&gt;on the Firepower user Agent aplication(is not instaled on the AD)&amp;gt;general &amp;gt;Agent name FQDN of that local host&lt;BR /&gt;on the tab "Active directory Servers"&amp;gt;host i use the fqdn of AD(active directory server)&lt;BR /&gt;on tab "firepower Management Center" &amp;gt;host the fqdn of Firesigth&lt;BR /&gt;&lt;BR /&gt;even if all looks good doublecheck on the folder where the Cisco firepower user agent is isntalled&lt;BR /&gt;C:\Program Files (x86)\Cisco Systems, Inc\Cisco Firepower User Agent for Active Directory&amp;gt;&lt;BR /&gt;&lt;BR /&gt;there is an application called &amp;gt;Tools&amp;gt;under "User MAP" tab&amp;gt; check export IPv4 addresses with mapped users&lt;BR /&gt;&lt;BR /&gt;and download it to CSV&lt;BR /&gt;&lt;BR /&gt;4.-on the firesith&amp;gt;events&amp;gt;users you should be able to see users&lt;BR /&gt;&lt;BR /&gt;5.-on the AD server you should be able to see logon logof events,!!! very important&lt;BR /&gt;&lt;BR /&gt;the Firepowers have to resolve the fqdn of the AD (tha have to have internal DNS and the serch domain)&lt;BR /&gt;try to nslookup on expert level or&lt;BR /&gt;&lt;BR /&gt;use on the firepower cli&lt;BR /&gt;&amp;gt; system support ping AD.server.local &lt;BR /&gt;&lt;BR /&gt;where AD.server.local is your fqdn AD&lt;BR /&gt;&lt;BR /&gt;6.- under access control polocy&amp;gt;make the first rule to allow &lt;BR /&gt;source local network ;destination any to the port 885&lt;BR /&gt;(the one that you define under identity policy &amp;gt;advanced port &amp;amp; the same port should be configured on the ASA captiveportal config)&lt;BR /&gt;&lt;BR /&gt;7.-at the end of the access rules if you have the default action to trust before that make a new rule that allow any any&lt;BR /&gt;&lt;BR /&gt;8.-at the identity policy i use the certificate created by openssl on a win 7 machine&lt;BR /&gt;&lt;BR /&gt;9.-reboot all (firesigth,firepowers,ASAs)&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;!!!!!&lt;BR /&gt;the behavior is if a user is not on the local database (when you download users and groups) the computer should &lt;BR /&gt;prompt on a web browser like firefox or chrome and show a warning (if you dont have an trusted CA)&lt;BR /&gt;&lt;A href="https://10.10.10.1:885/x.auth?r=3&amp;amp;s=10.10.10.47&amp;amp;a=1&amp;amp;u=http%3A%2F%2Fslither.io%2F" target="_blank"&gt;https://10.10.10.1:885/x.auth?r=3&amp;amp;s=10.10.10.47&amp;amp;a=1&amp;amp;u=http%3A%2F%2Fslither.io%2F&lt;/A&gt;&lt;BR /&gt;where 10.10.10.1 is the interfaces of inside and the 10.10.10.47 is the ip add of the user&lt;BR /&gt;!!!!!&lt;BR /&gt;&lt;BR /&gt;10.-try again and if it works take a vacations!&lt;BR /&gt;&lt;BR /&gt;i have a question can you change &lt;A href="https://10.10.10.1:885/x.auth?&amp;nbsp;" target="_blank"&gt;https://10.10.10.1:885/x.auth?&amp;nbsp;&lt;/A&gt;; to https://ASAxxxx:885/x.auth?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;i&amp;nbsp; explain this in my very bad english, because i did found that on the guides. and maybe i cloud help to someone.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jun 2016 00:02:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/captive-portal-does-not-load-some-times/m-p/2887059#M1030731</guid>
      <dc:creator>RAFAEL LOPEZ</dc:creator>
      <dc:date>2016-06-09T00:02:56Z</dc:date>
    </item>
  </channel>
</rss>

