156-215.80 · Question #528
You have created a rule at the top of your Rule Base to permit Guest Wireless access to the Internet. However, when guest users attempt to reach the Internet, they are not seeing the splash page to…
The correct answer is A. Right click Accept in the rule, select "More", and then check "Enable Identity Captive Portal". Captive Portal for a specific firewall rule must be enabled directly on that rule's Accept action, not in global or object-level settings.
Question
You have created a rule at the top of your Rule Base to permit Guest Wireless access to the Internet. However, when guest users attempt to reach the Internet, they are not seeing the splash page to accept your Terms of Service, and cannot access the Internet. How can you fix this?
Options
- ARight click Accept in the rule, select "More", and then check "Enable Identity Captive Portal"
- BOn the firewall object, Legacy Authentication screen, check "Enable Identity Captive Portal"
- CIn the Captive Portal screen of Global Properties, check "Enable Identity Captive Portal"
- DOn the Security Management Server object, check the box "Identity Logging"
How the community answered
(31 responses)- A81% (25)
- B3% (1)
- C6% (2)
- D10% (3)
Why each option
Captive Portal for a specific firewall rule must be enabled directly on that rule's Accept action, not in global or object-level settings.
In Check Point SmartConsole, Captive Portal is enabled on a per-rule basis by right-clicking the Accept action, choosing 'More', and enabling 'Enable Identity Captive Portal'. This ties the splash page challenge to the specific rule governing guest traffic, ensuring users are redirected before being granted access.
The firewall object's Legacy Authentication screen controls authentication methods for the gateway itself, not per-rule Captive Portal enforcement.
Global Properties contains general Identity Awareness settings, but enabling Captive Portal globally does not activate it for a specific rule - it must be set at the rule's action level.
'Identity Logging' on the Security Management Server controls log enrichment with identity data, not the enforcement of a Captive Portal splash page.
Concept tested: Check Point per-rule Captive Portal configuration
Source: https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_IdentityAwareness_AdminGuide/Topics-IDAG/Configuring-Captive-Portal.htm
Topics
Community Discussion
No community discussion yet for this question.