INTEGRATION
Palo Alto Captive Portal
Integration
Palo Alto leads on identity-based policy. Guest WiFi, though, is where identity usually stops — an open SSID and no idea who used it. Useroam builds on the PAN-OS Authentication Portal so the guest side gets an identity too.
What the Palo Alto integration does
Useroam Cloud takes the user connecting to the guest network behind your Palo Alto firewall, presents a branded captive portal, verifies their identity and writes access records to signed, timestamped storage. Nothing new is deployed on site.
How the integration works
Authentication Portal
The Authentication Portal and a guest security policy are defined in PAN-OS; unauthenticated traffic is redirected to the Useroam Cloud portal, with exemptions opened through authentication policy (walled garden behaviour).
Portal and walled garden
A branded welcome page is designed in Useroam Cloud; the portal and verification services are added to the walled garden so they stay reachable before login.
RADIUS authorisation
The guest verifies their identity over SMS or WhatsApp; the verified mobile number becomes the RADIUS username for the session and the firewall authorises access.
Syslog and signed logs
Access and NAT records are collected from the firewall over syslog, signed with a trusted timestamp and retained for a configurable period. Any record needed for an audit is served from the panel.
The welcome screen carries your brand
The captive portal is designed in the panel with your logo, colours and background image, and published with a live per-device preview. The same screen doubles as a placement for your campaigns and announcements.
What to know on the Palo Alto side
- Runs on PA-Series physical firewalls and VM-Series virtual deployments with current PAN-OS releases.
- Palo Alto does not make access points, so the guest SSID is broadcast by your existing wireless infrastructure — the integration is AP-vendor agnostic.
- The guest network runs on its own security policy; corporate traffic and existing rules are unaffected.
A marketing layer on the same network
The Palo Alto integration is not only about getting guests online: every guest who connects becomes permissioned data. The Bumerang modules run from the same panel, with no additional deployment.
Campaigns
Welcome and win-back flows go out automatically over WhatsApp/SMS, and the return visit is measured in the panel.
Surveys
Happy guests are routed to a Google review, unhappy feedback comes to you — your reputation is fed by the WiFi.
QR Menu
Multilingual menu and order-from-table, with reporting on which item drew interest and when.
Other integrations
Useroam is vendor-agnostic: even when sites run different devices, everything is managed from one panel.
Your hardware is ready. Let's open the guest network.
Send us your model and we will plan the integration steps together and open a demo environment the same day.
Frequently asked questions
Do I need extra hardware or a licence for Palo Alto guest WiFi?
How are access logs handled?
Which PAN-OS versions and access points does it work with?
Related guides
Firewall Guest WiFi Integrations: Sophos, FortiGate & More
A brand-by-brand look at how guest WiFi authentication and logging integrate with Sophos, FortiGate, Palo Alto, Zyxel and MikroTik — and how to choose.
What Is a Captive Portal and How Does It Work?
The captive portal is the sign-in screen guests see when they join your WiFi. Here is how it works, what it does for your business and why cloud-based portals win.