{"id":125,"date":"2022-04-25T07:32:34","date_gmt":"2022-04-25T11:32:34","guid":{"rendered":"https:\/\/pressbooks.bccampus.ca\/paloalto\/?post_type=chapter&#038;p=125"},"modified":"2026-02-19T15:32:11","modified_gmt":"2026-02-19T20:32:11","slug":"captive-portal","status":"publish","type":"chapter","link":"https:\/\/pressbooks.bccampus.ca\/paloalto\/chapter\/captive-portal\/","title":{"raw":"3.1 Captive Portal","rendered":"3.1 Captive Portal"},"content":{"raw":"<div class=\"textbox textbox--learning-objectives\"><header class=\"textbox__header\">\r\n<p class=\"textbox__title\">Learning Objectives<\/p>\r\n\r\n<\/header>\r\n<div class=\"textbox__content\">\r\n<ul>\r\n \t<li>Configure VLANs<\/li>\r\n \t<li>Configure captive portal<\/li>\r\n<\/ul>\r\n<\/div>\r\n<\/div>\r\n<div class=\"textbox\">\r\n\r\n<strong>Prerequisites<\/strong>:\r\n<ul>\r\n \t<li>Setup Zones<\/li>\r\n \t<li>Some interface configuration<\/li>\r\n \t<li>Configuring VLANs on the GNS3 switch<\/li>\r\n \t<li>Knowledge of previous labs<\/li>\r\n<\/ul>\r\n<\/div>\r\n<div class=\"textbox shaded\">\r\n\r\n<strong>Scenario<\/strong>: Now let's push for some advanced networking configurations. Sometimes you just have to push departments into their own VLANs for organization and compliance. Say we have a guest and employee network. We want to prevent communication between the two as much as possible. We would also want to implement some sort of login to access the internet for guests, much like hotels.\r\n\r\n<\/div>\r\n\r\n[caption id=\"attachment_252\" align=\"aligncenter\" width=\"1073\"]<img class=\"wp-image-252 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/usethisone.png\" alt=\"Main scenario\" width=\"1073\" height=\"549\" \/> Figure 3.1: Main scenario[\/caption]\r\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%\" border=\"0\"><caption>Table 3.1: Addressing Table<\/caption>\r\n<tbody>\r\n<tr>\r\n<th style=\"width: 50%\" scope=\"col\">Device<\/th>\r\n<th style=\"width: 50%\" scope=\"col\">Configuration<\/th>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 50%\">PaloAlto-1<\/td>\r\n<td style=\"width: 50%\">management: 192.168.0.1\/24\r\nEthernet1\/1: Trunking\r\nEthernet1\/1.10: 10.10.10.1\/24\r\nEthernet1\/1.20: 20.20.20.1\/24\r\nEthernet1\/2: DHCP<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 50%\">VLAN-10<\/td>\r\n<td style=\"width: 50%\">eth0: 10.10.10.10\/24 GW: 10.10.10.1 DNS: 8.8.8.8<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 50%\">VLAN-20<\/td>\r\n<td style=\"width: 50%\">eth0: 20.20.20.20\/24 GW: 20.20.20.1 DNS: 8.8.8.8<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 50%\">Management<\/td>\r\n<td style=\"width: 50%\">eth0: 192.168.0.2\/24<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 50%\">Switchy<\/td>\r\n<td style=\"width: 50%\">e0: Access mode, VLAN 10\r\ne1: Access mode, VLAN 20\r\ne7: dot1q, VLAN 1<\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%\" border=\"0\"><caption>Table 3.2: Zone Configuration<\/caption>\r\n<tbody>\r\n<tr>\r\n<th style=\"width: 50%\" scope=\"col\">Zone<\/th>\r\n<th style=\"width: 50%\" scope=\"col\">Interface<\/th>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 50%\">VLAN10<\/td>\r\n<td style=\"width: 50%\">Ethernet1\/1.10<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 50%\">VLAN20<\/td>\r\n<td style=\"width: 50%\">Ethernet1\/1.20<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 50%\">Outside<\/td>\r\n<td style=\"width: 50%\">Ethernet1\/2<\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n<h2>Configure Sub Interfaces<\/h2>\r\nUnder <strong>Network &gt; Interfaces<\/strong>. Click on<strong> ethernet1\/1.<\/strong>\r\n\r\n[caption id=\"attachment_407\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-407 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN1.jpg\" alt=\"Ethernet 1\/1 configuration\" width=\"1026\" height=\"830\" \/> Figure 3.2: Ethernet 1\/1 configuration[\/caption]\r\n\r\nIn this window, we just want to set the interface type to <strong>layer 3<\/strong>.\r\n\r\n[caption id=\"attachment_408\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-408 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN2.jpg\" alt=\"Set Interface type to Layer3\" width=\"1026\" height=\"830\" \/> Figure 3.3: Set Interface type to Layer3[\/caption]\r\n\r\nThen press <strong>OK<\/strong>.\r\n\r\nNow while <strong>ethernet1\/1<\/strong> is still selected, click on add sub interface.\r\n\r\n[caption id=\"attachment_409\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-409 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN3.jpg\" alt=\"Add Sub interfaces\" width=\"1026\" height=\"830\" \/> Figure 3.4: Add Sub interfaces[\/caption]\r\n\r\nWe want to add 2 sub-interfaces. Here is what you should configure:\r\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%\" border=\"0\"><caption>Table 3.3: Sub Interface Configuration<\/caption>\r\n<tbody>\r\n<tr>\r\n<th style=\"width: 50%\" scope=\"col\">Interface<\/th>\r\n<th style=\"width: 50%\" scope=\"col\">Configuration<\/th>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 50%\">Ethernet1\/1.10<\/td>\r\n<td style=\"width: 50%\"><span style=\"background-color: #ffff00\">Interface Name: 10<\/span>\r\n<span style=\"background-color: #ffff00\">Tag: 10<\/span>\r\n<span style=\"background-color: #ffff00\"><strong>Config tab:<\/strong><\/span>\r\n<span style=\"background-color: #ffff00\">- Virtual Router: <em style=\"font-family: inherit;font-size: inherit;background-color: #ffff00\">default\r\n<\/em>- Security Zone: <em>VLAN10\r\n<\/em><strong>IPv4:<\/strong><em>\r\n<\/em>- Type: <em>Static\r\n- IP: 10.10.10.1\/24<\/em><\/span><\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 50%\"><span style=\"background-color: #ffff00\">Ethernet1\/1.20<\/span><\/td>\r\n<td style=\"width: 50%\"><span style=\"background-color: #ffff00\">Interface Name: 20<\/span>\r\n<span style=\"background-color: #ffff00\">Tag: 20<\/span>\r\n<span style=\"background-color: #ffff00\"><strong>Config tab:<\/strong><\/span>\r\n<span style=\"background-color: #ffff00\">- Virtual Router: <em style=\"font-family: inherit;font-size: inherit;background-color: #ffff00\">default\r\n<\/em>- Security Zone: <em>VLAN20\r\n<\/em><strong>IPv4:<\/strong><em>\r\n<\/em>- Type: <em>Static\r\n- IP: 20.20.20.1\/24<\/em><\/span><\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n[caption id=\"attachment_410\" align=\"aligncenter\" width=\"550\"]<img class=\"wp-image-410\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN4.jpg\" alt=\"Verify Sub interfaces\" width=\"550\" height=\"445\" \/> Figure 3.5: Verify Sub interfaces[\/caption]\r\n<h2>Semi-Advanced Security Policies<\/h2>\r\nWell, it's not really advanced, but under <strong>Policies &gt; Security<\/strong>, click <strong>Add<\/strong>.\r\n\r\n[caption id=\"attachment_411\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-411 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN5.jpg\" alt=\"Add a Security Policy\" width=\"1026\" height=\"830\" \/> Figure 3.6: Add a Security Policy[\/caption]\r\n\r\nWe will be making a policy to allow <strong>VLAN10<\/strong> and <strong>VLAN20<\/strong> into the Outside zone. We can do this by adding multiple zones under the source zone.\r\n\r\n[caption id=\"attachment_412\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-412 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN6.jpg\" alt=\"Security Policy Rule - Source Zone\" width=\"1026\" height=\"830\" \/> Figure 3.7: Security Policy Rule - Source Zone[\/caption]\r\n\r\nThen click <strong>OK<\/strong>.\r\n<h2>Semi-Advanced NAT Policies<\/h2>\r\nStill not really advanced. But under <strong>Policies &gt; NAT<\/strong>, click <strong>Add<\/strong>.\r\n\r\n[caption id=\"attachment_623\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-623 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/1-2.jpg\" alt=\"Add a NAT Policy\" width=\"1026\" height=\"830\" \/> Figure 3.8: Add a NAT Policy[\/caption]\r\n\r\nWe want to make a Static NAT policy for the Internet connectivity. But under the Original Packet tab, we can select multiple zones.\r\n\r\n[caption id=\"attachment_413\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-413 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN7.jpg\" alt=\"Select the Source Zone in NAT Policy Rule\" width=\"1026\" height=\"830\" \/> Figure 3.9: Select the Source Zone[\/caption]\r\n\r\nConfigure the rest for static NAT, then press <strong>OK<\/strong>.\r\n\r\n[caption id=\"attachment_624\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-624 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2-1.jpg\" alt=\"SNAT Translated Packet Tab\" width=\"1026\" height=\"830\" \/> Figure 3.10: SNAT Translated Packet Tab[\/caption]\r\n<h2>Add a User<\/h2>\r\nUnder <strong>Device &gt; Local User Database &gt; Users<\/strong>. Click <strong>Add<\/strong>.\r\n\r\n[caption id=\"attachment_414\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-414 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN8.jpg\" alt=\"Add Users\" width=\"1026\" height=\"830\" \/> Figure 3.11: Add Users[\/caption]\r\n\r\nCreate any user you want with a username and password. Here is an example:\r\n\r\n[caption id=\"attachment_262\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-262 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-22-00-image.png\" alt=\"Add an user Xav\" width=\"1026\" height=\"830\" \/> Figure 3.12: Add a user xav[\/caption]\r\n\r\nThen click <strong>OK<\/strong>.\r\n<h2>Create an Authentication Profile<\/h2>\r\nUnder <strong>Device &gt; Authentication Profile<\/strong>, click <strong>Add<\/strong>.\r\n\r\n[caption id=\"attachment_415\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-415 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN9.jpg\" alt=\"Add an Authentication Profile\" width=\"1026\" height=\"830\" \/> Figure 3.13: Add an Authentication Profile[\/caption]\r\n\r\nUnder the Authentication tab, change the type to Local Database.\r\n\r\n[caption id=\"attachment_416\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-416 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN10.jpg\" alt=\"Select Local Database\" width=\"1026\" height=\"830\" \/> Figure 3.14: Select Local Database[\/caption]\r\n\r\nUnder the Advanced tab, add your user.\r\n\r\n[caption id=\"attachment_265\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-265 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-27-00-image.png\" alt=\"Add user xav as Allow List\" width=\"1026\" height=\"830\" \/> Figure 3.15: Add user xav as Allow List[\/caption]\r\n\r\nThen press <strong>OK<\/strong>.\r\n<h2>Configure the Captive Portal<\/h2>\r\nUnder Device, User Identification in the Authentication Portal Settings tab, click the settings icon.\r\n\r\n[caption id=\"attachment_417\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-417 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN11.jpg\" alt=\"Authentication Portal Settings\" width=\"1026\" height=\"830\" \/> Figure 3.16: Authentication Portal Settings[\/caption]\r\n\r\nConfigure these settings:\r\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%;height: 60px\" border=\"0\"><caption>Table 3.4: Authentication Portal Configuration<\/caption>\r\n<tbody>\r\n<tr style=\"height: 15px\">\r\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Parameter<\/th>\r\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Value<\/th>\r\n<\/tr>\r\n<tr style=\"height: 15px\">\r\n<td style=\"width: 50%;height: 15px\">Enable Authentication Portal<\/td>\r\n<td style=\"width: 50%;height: 15px\"><em>Tick this box<\/em><\/td>\r\n<\/tr>\r\n<tr style=\"height: 15px\">\r\n<td style=\"width: 50%;height: 15px\">Authentication Profile<\/td>\r\n<td style=\"width: 50%;height: 15px\"><em>Select the one you created<\/em><\/td>\r\n<\/tr>\r\n<tr style=\"height: 15px\">\r\n<td style=\"width: 50%;height: 15px\">Mode<\/td>\r\n<td style=\"width: 50%;height: 15px\">Transparent<\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n[caption id=\"attachment_267\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-267 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-30-11-image.png\" alt=\"Authentication Portal Settings - Select Transparent\" width=\"1026\" height=\"830\" \/> Figure 3.17: Authentication Portal Settings - Select Transparent[\/caption]\r\n\r\nThen press <strong>OK<\/strong>.\r\n\r\nUnder <strong>Network &gt; Zones<\/strong>, click on the VLAN10 zone.\r\n\r\n[caption id=\"attachment_418\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-418 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN12.jpg\" alt=\"Select Vlan 10\" width=\"1026\" height=\"830\" \/> Figure 3.18: Select Vlan 10[\/caption]\r\n\r\nIn this window, we just want to tick the <strong>Enable User Identification<\/strong> checkbox.\r\n\r\n[caption id=\"attachment_419\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-419 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN13.jpg\" alt=\"Enable User Identification\" width=\"1026\" height=\"830\" \/> Figure 3.19: Enable User Identification[\/caption]\r\n\r\nThen press <strong>OK<\/strong>.\r\n\r\nFinally, under<strong> Policies &gt; Authentication<\/strong>. Click <strong>Add<\/strong>.\r\n\r\n[caption id=\"attachment_420\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-420 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN14.jpg\" alt=\"Add an authentication Policy\" width=\"1026\" height=\"830\" \/> Figure 3.20: Add an authentication Policy[\/caption]\r\n\r\nUnder the Source tab, add <strong>VLAN 10<\/strong> in the source zone.\r\n\r\n[caption id=\"attachment_421\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-421 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN15.jpg\" alt=\"Add the Source Zone\" width=\"1026\" height=\"830\" \/> Figure 3.21: Add the Source Zone[\/caption]\r\n\r\nUnder the Destination tab, add Outside in <strong>Destination Zone<\/strong>.\r\n\r\n[caption id=\"attachment_422\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-422 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN16.jpg\" alt=\"Add the Destination Zone\" width=\"1026\" height=\"830\" \/> Figure 3.22: Add the Destination Zone[\/caption]\r\n\r\nUnder Actions, change the Authentication Enforcement setting, change it to <strong>default-web-form<\/strong>.\r\n\r\n[caption id=\"attachment_423\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-423 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN17.jpg\" alt=\"Select default-web-form\" width=\"1026\" height=\"830\" \/> Figure 3.23: Select default-web-form[\/caption]\r\n\r\nThen press <strong>OK<\/strong>.\r\n<h2>Test VLANs and Captive Portal<\/h2>\r\nOn the VLAN-20 webterm, navigate to any website. If all was right, the desired website should appear.\r\n\r\n[caption id=\"attachment_274\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-274 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-55-20-image.png\" alt=\"Verify your configuration\" width=\"1026\" height=\"830\" \/> Figure 3.24: Verify your configuration[\/caption]\r\n\r\nOn the VLAN-10 webterm, navigate to any website. If all was right, you should see a certificate error, accept this. Then you should see a login page.\r\n\r\n[caption id=\"attachment_275\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-275 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-56-58-image.png\" alt=\"Login Page\" width=\"1026\" height=\"830\" \/> Figure 3.25: Login Page[\/caption]\r\n\r\nEnter your credentials and log in. If all was successful, you should see the website appear.\r\n\r\n[caption id=\"attachment_276\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-276 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-57-51-image.png\" alt=\"Verify your configuration\" width=\"1026\" height=\"830\" \/> Figure 3.26: Verify your configuration[\/caption]","rendered":"<div class=\"textbox textbox--learning-objectives\">\n<header class=\"textbox__header\">\n<p class=\"textbox__title\">Learning Objectives<\/p>\n<\/header>\n<div class=\"textbox__content\">\n<ul>\n<li>Configure VLANs<\/li>\n<li>Configure captive portal<\/li>\n<\/ul>\n<\/div>\n<\/div>\n<div class=\"textbox\">\n<p><strong>Prerequisites<\/strong>:<\/p>\n<ul>\n<li>Setup Zones<\/li>\n<li>Some interface configuration<\/li>\n<li>Configuring VLANs on the GNS3 switch<\/li>\n<li>Knowledge of previous labs<\/li>\n<\/ul>\n<\/div>\n<div class=\"textbox shaded\">\n<p><strong>Scenario<\/strong>: Now let&#8217;s push for some advanced networking configurations. Sometimes you just have to push departments into their own VLANs for organization and compliance. Say we have a guest and employee network. We want to prevent communication between the two as much as possible. We would also want to implement some sort of login to access the internet for guests, much like hotels.<\/p>\n<\/div>\n<figure id=\"attachment_252\" aria-describedby=\"caption-attachment-252\" style=\"width: 1073px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-252 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/usethisone.png\" alt=\"Main scenario\" width=\"1073\" height=\"549\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/usethisone.png 1073w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/usethisone-300x153.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/usethisone-1024x524.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/usethisone-768x393.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/usethisone-65x33.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/usethisone-225x115.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/usethisone-350x179.png 350w\" sizes=\"auto, (max-width: 1073px) 100vw, 1073px\" \/><figcaption id=\"caption-attachment-252\" class=\"wp-caption-text\">Figure 3.1: Main scenario<\/figcaption><\/figure>\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%\">\n<caption>Table 3.1: Addressing Table<\/caption>\n<tbody>\n<tr>\n<th style=\"width: 50%\" scope=\"col\">Device<\/th>\n<th style=\"width: 50%\" scope=\"col\">Configuration<\/th>\n<\/tr>\n<tr>\n<td style=\"width: 50%\">PaloAlto-1<\/td>\n<td style=\"width: 50%\">management: 192.168.0.1\/24<br \/>\nEthernet1\/1: Trunking<br \/>\nEthernet1\/1.10: 10.10.10.1\/24<br \/>\nEthernet1\/1.20: 20.20.20.1\/24<br \/>\nEthernet1\/2: DHCP<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 50%\">VLAN-10<\/td>\n<td style=\"width: 50%\">eth0: 10.10.10.10\/24 GW: 10.10.10.1 DNS: 8.8.8.8<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 50%\">VLAN-20<\/td>\n<td style=\"width: 50%\">eth0: 20.20.20.20\/24 GW: 20.20.20.1 DNS: 8.8.8.8<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 50%\">Management<\/td>\n<td style=\"width: 50%\">eth0: 192.168.0.2\/24<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 50%\">Switchy<\/td>\n<td style=\"width: 50%\">e0: Access mode, VLAN 10<br \/>\ne1: Access mode, VLAN 20<br \/>\ne7: dot1q, VLAN 1<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%\">\n<caption>Table 3.2: Zone Configuration<\/caption>\n<tbody>\n<tr>\n<th style=\"width: 50%\" scope=\"col\">Zone<\/th>\n<th style=\"width: 50%\" scope=\"col\">Interface<\/th>\n<\/tr>\n<tr>\n<td style=\"width: 50%\">VLAN10<\/td>\n<td style=\"width: 50%\">Ethernet1\/1.10<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 50%\">VLAN20<\/td>\n<td style=\"width: 50%\">Ethernet1\/1.20<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 50%\">Outside<\/td>\n<td style=\"width: 50%\">Ethernet1\/2<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Configure Sub Interfaces<\/h2>\n<p>Under <strong>Network &gt; Interfaces<\/strong>. Click on<strong> ethernet1\/1.<\/strong><\/p>\n<figure id=\"attachment_407\" aria-describedby=\"caption-attachment-407\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-407 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN1.jpg\" alt=\"Ethernet 1\/1 configuration\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN1.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN1-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN1-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN1-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN1-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN1-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN1-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-407\" class=\"wp-caption-text\">Figure 3.2: Ethernet 1\/1 configuration<\/figcaption><\/figure>\n<p>In this window, we just want to set the interface type to <strong>layer 3<\/strong>.<\/p>\n<figure id=\"attachment_408\" aria-describedby=\"caption-attachment-408\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-408 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN2.jpg\" alt=\"Set Interface type to Layer3\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN2.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN2-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN2-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN2-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN2-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN2-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN2-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-408\" class=\"wp-caption-text\">Figure 3.3: Set Interface type to Layer3<\/figcaption><\/figure>\n<p>Then press <strong>OK<\/strong>.<\/p>\n<p>Now while <strong>ethernet1\/1<\/strong> is still selected, click on add sub interface.<\/p>\n<figure id=\"attachment_409\" aria-describedby=\"caption-attachment-409\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-409 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN3.jpg\" alt=\"Add Sub interfaces\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN3.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN3-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN3-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN3-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN3-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN3-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN3-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-409\" class=\"wp-caption-text\">Figure 3.4: Add Sub interfaces<\/figcaption><\/figure>\n<p>We want to add 2 sub-interfaces. Here is what you should configure:<\/p>\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%\">\n<caption>Table 3.3: Sub Interface Configuration<\/caption>\n<tbody>\n<tr>\n<th style=\"width: 50%\" scope=\"col\">Interface<\/th>\n<th style=\"width: 50%\" scope=\"col\">Configuration<\/th>\n<\/tr>\n<tr>\n<td style=\"width: 50%\">Ethernet1\/1.10<\/td>\n<td style=\"width: 50%\"><span style=\"background-color: #ffff00\">Interface Name: 10<\/span><br \/>\n<span style=\"background-color: #ffff00\">Tag: 10<\/span><br \/>\n<span style=\"background-color: #ffff00\"><strong>Config tab:<\/strong><\/span><br \/>\n<span style=\"background-color: #ffff00\">&#8211; Virtual Router: <em style=\"font-family: inherit;font-size: inherit;background-color: #ffff00\">default<br \/>\n<\/em>&#8211; Security Zone: <em>VLAN10<br \/>\n<\/em><strong>IPv4:<\/strong><em><br \/>\n<\/em>&#8211; Type: <em>Static<br \/>\n&#8211; IP: 10.10.10.1\/24<\/em><\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 50%\"><span style=\"background-color: #ffff00\">Ethernet1\/1.20<\/span><\/td>\n<td style=\"width: 50%\"><span style=\"background-color: #ffff00\">Interface Name: 20<\/span><br \/>\n<span style=\"background-color: #ffff00\">Tag: 20<\/span><br \/>\n<span style=\"background-color: #ffff00\"><strong>Config tab:<\/strong><\/span><br \/>\n<span style=\"background-color: #ffff00\">&#8211; Virtual Router: <em style=\"font-family: inherit;font-size: inherit;background-color: #ffff00\">default<br \/>\n<\/em>&#8211; Security Zone: <em>VLAN20<br \/>\n<\/em><strong>IPv4:<\/strong><em><br \/>\n<\/em>&#8211; Type: <em>Static<br \/>\n&#8211; IP: 20.20.20.1\/24<\/em><\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<figure id=\"attachment_410\" aria-describedby=\"caption-attachment-410\" style=\"width: 550px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-410\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN4.jpg\" alt=\"Verify Sub interfaces\" width=\"550\" height=\"445\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN4.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN4-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN4-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN4-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN4-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN4-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN4-350x283.jpg 350w\" sizes=\"auto, (max-width: 550px) 100vw, 550px\" \/><figcaption id=\"caption-attachment-410\" class=\"wp-caption-text\">Figure 3.5: Verify Sub interfaces<\/figcaption><\/figure>\n<h2>Semi-Advanced Security Policies<\/h2>\n<p>Well, it&#8217;s not really advanced, but under <strong>Policies &gt; Security<\/strong>, click <strong>Add<\/strong>.<\/p>\n<figure id=\"attachment_411\" aria-describedby=\"caption-attachment-411\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-411 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN5.jpg\" alt=\"Add a Security Policy\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN5.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN5-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN5-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN5-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN5-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN5-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN5-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-411\" class=\"wp-caption-text\">Figure 3.6: Add a Security Policy<\/figcaption><\/figure>\n<p>We will be making a policy to allow <strong>VLAN10<\/strong> and <strong>VLAN20<\/strong> into the Outside zone. We can do this by adding multiple zones under the source zone.<\/p>\n<figure id=\"attachment_412\" aria-describedby=\"caption-attachment-412\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-412 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN6.jpg\" alt=\"Security Policy Rule - Source Zone\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN6.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN6-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN6-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN6-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN6-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN6-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN6-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-412\" class=\"wp-caption-text\">Figure 3.7: Security Policy Rule &#8211; Source Zone<\/figcaption><\/figure>\n<p>Then click <strong>OK<\/strong>.<\/p>\n<h2>Semi-Advanced NAT Policies<\/h2>\n<p>Still not really advanced. But under <strong>Policies &gt; NAT<\/strong>, click <strong>Add<\/strong>.<\/p>\n<figure id=\"attachment_623\" aria-describedby=\"caption-attachment-623\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-623 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/1-2.jpg\" alt=\"Add a NAT Policy\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/1-2.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/1-2-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/1-2-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/1-2-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/1-2-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/1-2-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/1-2-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-623\" class=\"wp-caption-text\">Figure 3.8: Add a NAT Policy<\/figcaption><\/figure>\n<p>We want to make a Static NAT policy for the Internet connectivity. But under the Original Packet tab, we can select multiple zones.<\/p>\n<figure id=\"attachment_413\" aria-describedby=\"caption-attachment-413\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-413 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN7.jpg\" alt=\"Select the Source Zone in NAT Policy Rule\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN7.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN7-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN7-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN7-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN7-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN7-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN7-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-413\" class=\"wp-caption-text\">Figure 3.9: Select the Source Zone<\/figcaption><\/figure>\n<p>Configure the rest for static NAT, then press <strong>OK<\/strong>.<\/p>\n<figure id=\"attachment_624\" aria-describedby=\"caption-attachment-624\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-624 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2-1.jpg\" alt=\"SNAT Translated Packet Tab\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2-1.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2-1-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2-1-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2-1-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2-1-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2-1-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2-1-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-624\" class=\"wp-caption-text\">Figure 3.10: SNAT Translated Packet Tab<\/figcaption><\/figure>\n<h2>Add a User<\/h2>\n<p>Under <strong>Device &gt; Local User Database &gt; Users<\/strong>. Click <strong>Add<\/strong>.<\/p>\n<figure id=\"attachment_414\" aria-describedby=\"caption-attachment-414\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-414 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN8.jpg\" alt=\"Add Users\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN8.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN8-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN8-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN8-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN8-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN8-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN8-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-414\" class=\"wp-caption-text\">Figure 3.11: Add Users<\/figcaption><\/figure>\n<p>Create any user you want with a username and password. Here is an example:<\/p>\n<figure id=\"attachment_262\" aria-describedby=\"caption-attachment-262\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-262 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-22-00-image.png\" alt=\"Add an user Xav\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-22-00-image.png 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-22-00-image-300x243.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-22-00-image-1024x828.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-22-00-image-768x621.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-22-00-image-65x53.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-22-00-image-225x182.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-22-00-image-350x283.png 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-262\" class=\"wp-caption-text\">Figure 3.12: Add a user xav<\/figcaption><\/figure>\n<p>Then click <strong>OK<\/strong>.<\/p>\n<h2>Create an Authentication Profile<\/h2>\n<p>Under <strong>Device &gt; Authentication Profile<\/strong>, click <strong>Add<\/strong>.<\/p>\n<figure id=\"attachment_415\" aria-describedby=\"caption-attachment-415\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-415 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN9.jpg\" alt=\"Add an Authentication Profile\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN9.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN9-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN9-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN9-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN9-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN9-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN9-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-415\" class=\"wp-caption-text\">Figure 3.13: Add an Authentication Profile<\/figcaption><\/figure>\n<p>Under the Authentication tab, change the type to Local Database.<\/p>\n<figure id=\"attachment_416\" aria-describedby=\"caption-attachment-416\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-416 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN10.jpg\" alt=\"Select Local Database\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN10.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN10-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN10-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN10-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN10-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN10-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN10-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-416\" class=\"wp-caption-text\">Figure 3.14: Select Local Database<\/figcaption><\/figure>\n<p>Under the Advanced tab, add your user.<\/p>\n<figure id=\"attachment_265\" aria-describedby=\"caption-attachment-265\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-265 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-27-00-image.png\" alt=\"Add user xav as Allow List\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-27-00-image.png 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-27-00-image-300x243.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-27-00-image-1024x828.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-27-00-image-768x621.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-27-00-image-65x53.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-27-00-image-225x182.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-27-00-image-350x283.png 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-265\" class=\"wp-caption-text\">Figure 3.15: Add user xav as Allow List<\/figcaption><\/figure>\n<p>Then press <strong>OK<\/strong>.<\/p>\n<h2>Configure the Captive Portal<\/h2>\n<p>Under Device, User Identification in the Authentication Portal Settings tab, click the settings icon.<\/p>\n<figure id=\"attachment_417\" aria-describedby=\"caption-attachment-417\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-417 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN11.jpg\" alt=\"Authentication Portal Settings\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN11.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN11-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN11-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN11-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN11-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN11-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN11-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-417\" class=\"wp-caption-text\">Figure 3.16: Authentication Portal Settings<\/figcaption><\/figure>\n<p>Configure these settings:<\/p>\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%;height: 60px\">\n<caption>Table 3.4: Authentication Portal Configuration<\/caption>\n<tbody>\n<tr style=\"height: 15px\">\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Parameter<\/th>\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Value<\/th>\n<\/tr>\n<tr style=\"height: 15px\">\n<td style=\"width: 50%;height: 15px\">Enable Authentication Portal<\/td>\n<td style=\"width: 50%;height: 15px\"><em>Tick this box<\/em><\/td>\n<\/tr>\n<tr style=\"height: 15px\">\n<td style=\"width: 50%;height: 15px\">Authentication Profile<\/td>\n<td style=\"width: 50%;height: 15px\"><em>Select the one you created<\/em><\/td>\n<\/tr>\n<tr style=\"height: 15px\">\n<td style=\"width: 50%;height: 15px\">Mode<\/td>\n<td style=\"width: 50%;height: 15px\">Transparent<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<figure id=\"attachment_267\" aria-describedby=\"caption-attachment-267\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-267 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-30-11-image.png\" alt=\"Authentication Portal Settings - Select Transparent\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-30-11-image.png 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-30-11-image-300x243.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-30-11-image-1024x828.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-30-11-image-768x621.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-30-11-image-65x53.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-30-11-image-225x182.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-30-11-image-350x283.png 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-267\" class=\"wp-caption-text\">Figure 3.17: Authentication Portal Settings &#8211; Select Transparent<\/figcaption><\/figure>\n<p>Then press <strong>OK<\/strong>.<\/p>\n<p>Under <strong>Network &gt; Zones<\/strong>, click on the VLAN10 zone.<\/p>\n<figure id=\"attachment_418\" aria-describedby=\"caption-attachment-418\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-418 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN12.jpg\" alt=\"Select Vlan 10\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN12.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN12-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN12-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN12-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN12-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN12-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN12-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-418\" class=\"wp-caption-text\">Figure 3.18: Select Vlan 10<\/figcaption><\/figure>\n<p>In this window, we just want to tick the <strong>Enable User Identification<\/strong> checkbox.<\/p>\n<figure id=\"attachment_419\" aria-describedby=\"caption-attachment-419\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-419 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN13.jpg\" alt=\"Enable User Identification\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN13.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN13-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN13-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN13-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN13-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN13-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN13-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-419\" class=\"wp-caption-text\">Figure 3.19: Enable User Identification<\/figcaption><\/figure>\n<p>Then press <strong>OK<\/strong>.<\/p>\n<p>Finally, under<strong> Policies &gt; Authentication<\/strong>. Click <strong>Add<\/strong>.<\/p>\n<figure id=\"attachment_420\" aria-describedby=\"caption-attachment-420\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-420 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN14.jpg\" alt=\"Add an authentication Policy\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN14.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN14-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN14-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN14-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN14-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN14-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN14-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-420\" class=\"wp-caption-text\">Figure 3.20: Add an authentication Policy<\/figcaption><\/figure>\n<p>Under the Source tab, add <strong>VLAN 10<\/strong> in the source zone.<\/p>\n<figure id=\"attachment_421\" aria-describedby=\"caption-attachment-421\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-421 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN15.jpg\" alt=\"Add the Source Zone\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN15.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN15-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN15-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN15-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN15-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN15-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN15-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-421\" class=\"wp-caption-text\">Figure 3.21: Add the Source Zone<\/figcaption><\/figure>\n<p>Under the Destination tab, add Outside in <strong>Destination Zone<\/strong>.<\/p>\n<figure id=\"attachment_422\" aria-describedby=\"caption-attachment-422\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-422 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN16.jpg\" alt=\"Add the Destination Zone\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN16.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN16-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN16-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN16-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN16-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN16-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN16-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-422\" class=\"wp-caption-text\">Figure 3.22: Add the Destination Zone<\/figcaption><\/figure>\n<p>Under Actions, change the Authentication Enforcement setting, change it to <strong>default-web-form<\/strong>.<\/p>\n<figure id=\"attachment_423\" aria-describedby=\"caption-attachment-423\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-423 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN17.jpg\" alt=\"Select default-web-form\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN17.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN17-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN17-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN17-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN17-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN17-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/VLAN17-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-423\" class=\"wp-caption-text\">Figure 3.23: Select default-web-form<\/figcaption><\/figure>\n<p>Then press <strong>OK<\/strong>.<\/p>\n<h2>Test VLANs and Captive Portal<\/h2>\n<p>On the VLAN-20 webterm, navigate to any website. If all was right, the desired website should appear.<\/p>\n<figure id=\"attachment_274\" aria-describedby=\"caption-attachment-274\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-274 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-55-20-image.png\" alt=\"Verify your configuration\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-55-20-image.png 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-55-20-image-300x243.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-55-20-image-1024x828.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-55-20-image-768x621.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-55-20-image-65x53.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-55-20-image-225x182.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-55-20-image-350x283.png 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-274\" class=\"wp-caption-text\">Figure 3.24: Verify your configuration<\/figcaption><\/figure>\n<p>On the VLAN-10 webterm, navigate to any website. If all was right, you should see a certificate error, accept this. Then you should see a login page.<\/p>\n<figure id=\"attachment_275\" aria-describedby=\"caption-attachment-275\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-275 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-56-58-image.png\" alt=\"Login Page\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-56-58-image.png 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-56-58-image-300x243.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-56-58-image-1024x828.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-56-58-image-768x621.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-56-58-image-65x53.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-56-58-image-225x182.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-56-58-image-350x283.png 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-275\" class=\"wp-caption-text\">Figure 3.25: Login Page<\/figcaption><\/figure>\n<p>Enter your credentials and log in. If all was successful, you should see the website appear.<\/p>\n<figure id=\"attachment_276\" aria-describedby=\"caption-attachment-276\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-276 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-57-51-image.png\" alt=\"Verify your configuration\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-57-51-image.png 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-57-51-image-300x243.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-57-51-image-1024x828.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-57-51-image-768x621.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-57-51-image-65x53.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-57-51-image-225x182.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-23-14-57-51-image-350x283.png 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-276\" class=\"wp-caption-text\">Figure 3.26: Verify your configuration<\/figcaption><\/figure>\n","protected":false},"author":1572,"menu_order":1,"template":"","meta":{"pb_show_title":"on","pb_short_title":"","pb_subtitle":"","pb_authors":[],"pb_section_license":""},"chapter-type":[],"contributor":[],"license":[],"class_list":["post-125","chapter","type-chapter","status-publish","hentry"],"part":123,"_links":{"self":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters\/125","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters"}],"about":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/wp\/v2\/types\/chapter"}],"author":[{"embeddable":true,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/wp\/v2\/users\/1572"}],"version-history":[{"count":25,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters\/125\/revisions"}],"predecessor-version":[{"id":1223,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters\/125\/revisions\/1223"}],"part":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/parts\/123"}],"metadata":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters\/125\/metadata\/"}],"wp:attachment":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/wp\/v2\/media?parent=125"}],"wp:term":[{"taxonomy":"chapter-type","embeddable":true,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapter-type?post=125"},{"taxonomy":"contributor","embeddable":true,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/wp\/v2\/contributor?post=125"},{"taxonomy":"license","embeddable":true,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/wp\/v2\/license?post=125"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}