09-25-2024 12:24 AM
Dears,
I'am using FTD 6.6.1 managed with FMC, i Configured Internal Certificats, Trusted Certificat, add DNS target with the routed interface, configured the Identity Policy, added it to the Access Policy and allowed it.
When now i go the user computer to go to internet, first i dont have the redirection, secundary, when i write the full URl : https://dj-captiveportal.rasdika.dj:885/ , I get this output : The requested URL / was not found on this server.
Solved! Go to Solution.
09-30-2024 09:48 AM
Active auth is ALWAYS better than passive auth. That being said captive portal sucks. The best solution is active authentication using 802.1X to ISE and share that context with FMC via pxGrid. If that is not available for whatever reason I would personally position ISE-PIC as a "good enough" solution before enforcing an annoying captive portal.
09-25-2024 01:19 AM
Can I know what you try here
Thanks
MHM
09-25-2024 02:48 AM
Take a look at this video please and see if it helps:
18. Cisco FTD Identity Policy: Active Authentication (youtube.com)
09-29-2024 06:26 AM
Hi
@MHM Cisco World i am trying to make acitve authentication with FMC.
@Aref Alsouqi i did exactly what he does in video youtube, but nothing !!!!
09-30-2024 01:09 AM
Can you make double check steps by view this doc
MHM
09-30-2024 01:27 AM
how about only domain name with out port 885 ? what you get.
have you session analysis active user and events ?
@Aref Alsouqi suggested i have used many times and it works as expected.
check also guide from Cisco : (it has some videos )
09-30-2024 05:06 AM
09-30-2024 05:21 AM
Thanks @ahollifield i will upgrade the version, because it isn't working correctly
@MHM Cisco World your recent link is for FDM, i'am using FMC to manage and think it is a bit different !
The big issues is, that the portal captive work once per day, after i disconnect, i have issue to reconnect !
09-30-2024 05:42 AM
I would also question why captive portal on the FTD at all? Why not perform captive portal redirect on the NAD instead?
09-30-2024 06:04 AM
The captive portal is for Active Authentication in Identity Policy inside FMC, authenticate Users in LAN through to captiveportal before to access some ressources(like internet ...) ::::
what you mean in NAD ?
09-30-2024 06:08 AM
09-30-2024 06:30 AM
I have only Switchs, Small AccessPoint, and FTD managed with FMC. No ISE or ISE-PIC
09-30-2024 06:38 AM
09-30-2024 06:45 AM
FTD integrated with realm AD..
09-30-2024 06:48 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide