<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN access can be made without credentials After GP 5.2.9 version update in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/vpn-access-can-be-made-without-credentials-after-gp-5-2-9/m-p/457204#M2264</link>
    <description>&lt;P&gt;Hi Blilal,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ive tested this on 5.2.9 and do not see the same problem.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kindly can you confirm if you have authentication override setup?&lt;/P&gt;&lt;P&gt;Network&amp;gt; Portal/Gateway &amp;gt; Agent &amp;gt; Relevant Agent Config &amp;gt; Authentication &amp;gt; Authentication Override:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Sarc845_1-1641459579587.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38533iF527020841A636D2/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Sarc845_1-1641459579587.png" alt="Sarc845_1-1641459579587.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have this setup it could be that the agent has a cookie and is using the cookie to authenticate.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/8-1/globalprotect-admin/authentication/about-globalprotect-user-authentication/how-does-the-app-know-what-credentials-to-supply/cookie-authentication-on-the-portal-or-gateway.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/globalprotect/8-1/globalprotect-admin/authentication/about-globalprotect-user-authentication/how-does-the-app-know-what-credentials-to-supply/cookie-authentication-on-the-portal-or-gateway.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you do not have this on the portal and gateway I would recommend opening a case with PANW to investigate.&lt;/P&gt;</description>
    <pubDate>Thu, 06 Jan 2022 08:59:49 GMT</pubDate>
    <dc:creator>Sarc845</dc:creator>
    <dc:date>2022-01-06T08:59:49Z</dc:date>
    <item>
      <title>VPN access can be made without credentials After GP 5.2.9 version update</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/vpn-access-can-be-made-without-credentials-after-gp-5-2-9/m-p/457186#M2262</link>
      <description>&lt;P class=""&gt;Connection problem without credentials in version 5.2.9&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;We switched from GP 5.2.4 version to 5.2.9 version with transparent update. Windows users report that they can connect directly without entering a password when making vpn connections.&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;In the global protect &amp;gt; portal &amp;gt; agent configuration, save user credentials section is selected as no.&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;In the Globalprotect &amp;gt;portal &amp;gt; agent&amp;gt; app configuration, the option to save Windows SSO information is selected as no.&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;However, windows users using version 5.2.9 can connect directly without entering a username and password.&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;Anyone have this problem or have a solution ?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jan 2022 07:54:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/vpn-access-can-be-made-without-credentials-after-gp-5-2-9/m-p/457186#M2262</guid>
      <dc:creator>bilal_guclu</dc:creator>
      <dc:date>2022-01-06T07:54:04Z</dc:date>
    </item>
    <item>
      <title>Re: VPN access can be made without credentials After GP 5.2.9 version update</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/vpn-access-can-be-made-without-credentials-after-gp-5-2-9/m-p/457204#M2264</link>
      <description>&lt;P&gt;Hi Blilal,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ive tested this on 5.2.9 and do not see the same problem.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kindly can you confirm if you have authentication override setup?&lt;/P&gt;&lt;P&gt;Network&amp;gt; Portal/Gateway &amp;gt; Agent &amp;gt; Relevant Agent Config &amp;gt; Authentication &amp;gt; Authentication Override:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Sarc845_1-1641459579587.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38533iF527020841A636D2/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Sarc845_1-1641459579587.png" alt="Sarc845_1-1641459579587.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have this setup it could be that the agent has a cookie and is using the cookie to authenticate.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/8-1/globalprotect-admin/authentication/about-globalprotect-user-authentication/how-does-the-app-know-what-credentials-to-supply/cookie-authentication-on-the-portal-or-gateway.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/globalprotect/8-1/globalprotect-admin/authentication/about-globalprotect-user-authentication/how-does-the-app-know-what-credentials-to-supply/cookie-authentication-on-the-portal-or-gateway.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you do not have this on the portal and gateway I would recommend opening a case with PANW to investigate.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jan 2022 08:59:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/vpn-access-can-be-made-without-credentials-after-gp-5-2-9/m-p/457204#M2264</guid>
      <dc:creator>Sarc845</dc:creator>
      <dc:date>2022-01-06T08:59:49Z</dc:date>
    </item>
    <item>
      <title>Re: VPN access can be made without credentials After GP 5.2.9 version update</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/vpn-access-can-be-made-without-credentials-after-gp-5-2-9/m-p/457218#M2266</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;yes, I override authentication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Ekran Resmi 2022-01-06 12.41.21.png" style="width: 773px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38534iB70EA5B3F79056B0/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Ekran Resmi 2022-01-06 12.41.21.png" alt="Ekran Resmi 2022-01-06 12.41.21.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;The strange thing is that this problem is fixed in authentication, only when I register with the username.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At the same time, when I uninstall the global protect application and reinstall it, it is temporarily fixed and after a while it happens again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All windows machines that have this problem are in the company domain. I guess somehow it uses global protect by taking the credentials on windows machines from the cache.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created a case for this situation. I haven't received an answer yet&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jan 2022 09:59:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/vpn-access-can-be-made-without-credentials-after-gp-5-2-9/m-p/457218#M2266</guid>
      <dc:creator>bilal_guclu</dc:creator>
      <dc:date>2022-01-06T09:59:49Z</dc:date>
    </item>
    <item>
      <title>Re: VPN access can be made without credentials After GP 5.2.9 version update</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/vpn-access-can-be-made-without-credentials-after-gp-5-2-9/m-p/457242#M2267</link>
      <description>&lt;P&gt;Do you see SSO login in the agent logs?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jan 2022 15:18:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/vpn-access-can-be-made-without-credentials-after-gp-5-2-9/m-p/457242#M2267</guid>
      <dc:creator>kinanakelstcs</dc:creator>
      <dc:date>2022-01-06T15:18:04Z</dc:date>
    </item>
    <item>
      <title>Re: VPN access can be made without credentials After GP 5.2.9 version update</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/vpn-access-can-be-made-without-credentials-after-gp-5-2-9/m-p/457365#M2269</link>
      <description>&lt;P&gt;From the system logs, are the users authenticating against the portal or the gateway when reconnecting (or both)? And also what method was the authentication?&lt;/P&gt;&lt;P&gt;Monitor -&amp;gt; Logs -&amp;gt; System -&amp;gt; filter: ( eventid eq globalprotectportal-auth-succ ) or ( eventid eq globalprotectgateway-auth-succ )&lt;/P&gt;&lt;P&gt;&amp;nbsp; "GlobalProtect portal user authentication... Auth type: ????"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, I see you that you do not have Components that Require Dynamic Passwords enabled. Seems like the GP client saves and reuses the user creds after a successful connection, regardless if the save creds option is set. If you forcibly logout a user after a period of time this is troublesome... You don't actually seem to need to have a dual auth setup, as the section would seem to imply, to use the dynamic password option. From the note attached "&lt;EM&gt;...to authenticate users as opposed to using saved credentials. As a result, the user will always be prompted to enter new credentials...&lt;/EM&gt;"&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jan 2022 21:25:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/vpn-access-can-be-made-without-credentials-after-gp-5-2-9/m-p/457365#M2269</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-01-06T21:25:31Z</dc:date>
    </item>
    <item>
      <title>Re: VPN access can be made without credentials After GP 5.2.9 version update</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/vpn-access-can-be-made-without-credentials-after-gp-5-2-9/m-p/457456#M2270</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No, ı dont see, but I have already blocked using sso under agent&amp;gt;app&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Ekran Resmi 2022-01-07 10.07.51.png" style="width: 431px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38541iED507D6D5227816D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Ekran Resmi 2022-01-07 10.07.51.png" alt="Ekran Resmi 2022-01-07 10.07.51.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jan 2022 07:08:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/vpn-access-can-be-made-without-credentials-after-gp-5-2-9/m-p/457456#M2270</guid>
      <dc:creator>bilal_guclu</dc:creator>
      <dc:date>2022-01-07T07:08:32Z</dc:date>
    </item>
    <item>
      <title>Re: VPN access can be made without credentials After GP 5.2.9 version update</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/vpn-access-can-be-made-without-credentials-after-gp-5-2-9/m-p/457457#M2271</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;VPN Authentication is done with ldap. Windows users are included in the domain, they login with ldap.I guess it somehow gets this data from the cache.&lt;/P&gt;&lt;P&gt;Also even though the Auto Restore VPN Connection Timeout duration is selected as 0 min. When these users change wi-fi, they can establish a direct connection without entering a username and password.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jan 2022 07:25:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/vpn-access-can-be-made-without-credentials-after-gp-5-2-9/m-p/457457#M2271</guid>
      <dc:creator>bilal_guclu</dc:creator>
      <dc:date>2022-01-07T07:25:33Z</dc:date>
    </item>
    <item>
      <title>Re: VPN access can be made without credentials After GP 5.2.9 version update</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/vpn-access-can-be-made-without-credentials-after-gp-5-2-9/m-p/509885#M3025</link>
      <description>&lt;P&gt;Have you solved this issue? We have same issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 07:52:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/vpn-access-can-be-made-without-credentials-after-gp-5-2-9/m-p/509885#M3025</guid>
      <dc:creator>JeongHoonKim</dc:creator>
      <dc:date>2022-07-26T07:52:55Z</dc:date>
    </item>
    <item>
      <title>Re: VPN access can be made without credentials After GP 5.2.9 version update</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/vpn-access-can-be-made-without-credentials-after-gp-5-2-9/m-p/523380#M3479</link>
      <description>&lt;P&gt;No, unfortunately we couldn't. After gp update the problem has not recurred so far.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2022 11:05:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/vpn-access-can-be-made-without-credentials-after-gp-5-2-9/m-p/523380#M3479</guid>
      <dc:creator>bilal_guclu</dc:creator>
      <dc:date>2022-12-06T11:05:17Z</dc:date>
    </item>
  </channel>
</rss>

