Palo Alto Integration Guide

This guide covers the full integration between a Palo Alto firewall and Useroam Cloud: zone and interface configuration, RADIUS authentication, certificates, the Authentication Portal, DNS, log forwarding, and the firewall rules.

Before you start: you need administrator access to the Palo Alto web interface, the external interface IP address the firewall will use to talk to Useroam, and your SSL certificate together with its key file and password.


1 - Adding the firewall to the panel

First sign in to your panel at panel.useroam.com and add a New Device. In the Device Address field, enter the external interface IP address the firewall will use to communicate.

Adding a Palo Alto device in the Useroam panel

2 - Zone settings

For the interface where Useroam will be enabled, create a new zone under Network > Zone and tick Enable User Identification.

Palo Alto zone settings

3 - Interface and profile settings

On the interface where Useroam will be enabled, create a new profile from the Advanced section. While doing so, tick the Response Pages checkbox.

Palo Alto interface management profile

4 - RADIUS settings

Apply the settings below under Device > Server Profiles > RADIUS:

Palo Alto RADIUS server profile

5 - Authentication Profile

Define the new profile under Device > Authentication Profile.

Palo Alto authentication profile

6 - Certificate configuration

Before the certificates are installed on the device, the relevant root certificates (Root CA or Intermediate) must already be added to the system. This completes the certificate trust chain and prevents SSL/TLS errors on the client devices that connect.

6A - Importing the Root CA

As the first step, import the Root CA or CA certificate.

Palo Alto Root CA import

6B - Uploading the certificate and key file

Next, upload the certificate file to the firewall together with the key file and its password.

Palo Alto certificate and key upload

6C - Verifying the layered certificate chain

Once the upload is complete, the view should show a layered structure — a certificate chain in which the entries are linked to one another.

Palo Alto certificate chain

7 - Authentication Portal settings

Next, open the Settings section under Device > User Identification > Authentication Portal.

Palo Alto Authentication Portal settings

If you need to create a new profile, follow these steps:


8 - Uploading the captive portal design (Comfort Page)

In panel.useroam.com, go to Settings > Device Settings and copy the entire code block that starts with <html>. Paste it into a text editor and save it in HTML format under a name such as captive.html. Then upload that document on the firewall via Device > Response Pages > Captive Portal Comfort Page.

Palo Alto Captive Portal Comfort Page

9 - DHCP settings

So that DNS queries from the internal network are handled without problems, the DHCP and DNS Proxy configuration must be updated if you do not have a separate DNS server. Go to Network > DHCP > Options.

Note: if you already have an internal DNS server, add the record required for the domain redirect to your internal DNS as well (in the Static Entries section) and continue from step 11.

Palo Alto DHCP options

10 - DNS Proxy settings

Next, define a new proxy under Network > DNS Proxy so DNS queries resolve correctly.

Palo Alto DNS Proxy settings

11 - Forwarding logs to Useroam (Log Forwarding)

Go to Objects > Log Forwarding and add a new profile with Add. A separate profile must be created for each of the five log types (auth, data, decryption, traffic, url). For every entry, remember to select the Useroam profile in the Syslog section.

Palo Alto log forwarding profile
Palo Alto log forwarding syslog selection

Creating the firewall rules

Two sets of rules are needed for the Palo Alto integration. When you first create the rules, Palo Alto needs to learn the traffic — so set Service to Any at first and change it to application-default afterwards.

12A - RULE SET 1: Authentication rules

Go to Policies > Authentication and define the three rules below. Useroam must be selected in the Log Forwarding field on every rule.

Palo Alto authentication policy list
Palo Alto authentication rules

12B - RULE SET 2: Security rules

Go to Policies > Security. On every rule, Log at Session End must be selected under Log Settings and Useroam must be assigned in Log Forwarding.

Palo Alto security policy list

Additional technical note (disconnecting a signed-in user): to end an active guest session or clear its cache, sign in to the Palo Alto CLI and run the following commands in order.

To list all signed-in active users and their IP addresses:
show user ip-user-mapping all

To drop the relevant IP address from the network, run:
clear user-cache ip <ip-address>
debug user-id reset captive-portal ip-address <ip-address>


Important — integration complete

That's it — your Palo Alto integration and server change are complete. If you run into any technical problems during the process, contact our support team at destek@useroamteknoloji.com.


Login with WhatsApp — firewall allowlist (walled garden)

For the Login with WhatsApp flow to work while the guest is still behind the captive portal (before internet access is granted), the following addresses must be allowed in your firewall or walled-garden configuration. Without these rules the WhatsApp login screen will not open and the automatic login based on delivery confirmation will not work.

Domains to allow (FQDN)

IP addresses to allow

Note: 157.240.0.0 and 31.13.0.0 are typically /16 network blocks (Meta infrastructure); we recommend defining them as blocks in the firewall (157.240.0.0/16, 31.13.0.0/16). 104.247.174.120 is the Useroam panel IP (/32). Use the domain list if your firewall supports FQDN-based filtering; otherwise use the IP blocks.


Revizyon #1
tugay tarafından 10 Ağustos 2026 22:59:09 oluşturuldu
tugay tarafından 10 Ağustos 2026 22:59:09 güncellendi