Captive portal is not redirecting to IdP while authentiacting to CIE with CAS
861
Created On 08/29/23 14:54 PM - Last Modified 10/21/25 20:33 PM
Symptom
- Users are not being redirected to the Identity Provider (IdP)
- The connection is stuck on URL https://cloud-auth.nl.apps.paloaltonetworks.com/auth and error ERR_CONNECTION_RESET is displayed.
Environment
- PANOS 10.1+
- Captive Portal with user identification via Cloud Identity Engine (CIE)
- Authentication with Cloud Authentication Service (CAS)
Cause
- The request to CIE also matches the authentication rule "DEF-CP" and it never reaches to the CIE.
Resolution
1. To avoid the situation, create custom URL category with CIE URL "*.apps.paloaltonetworks.com"
2. Create authentication rule with Authentication Enforcement set to 'default-no-captive-portal'
3. Attach the custom URL category created earlier, which includes the CIE URL.
Additional Information
To allow SAML authentication, it's important to remember to exclude traffic to the Identity Provider (IdP), as outlined in this article.