<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What's stored in the GlobalProtect encrypted cookie on the endpoint? in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/what-s-stored-in-the-globalprotect-encrypted-cookie-on-the/m-p/463575#M2438</link>
    <description>&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;Does anyone know what data is stored in the GlobalProtect authentication cookie?&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;Is it something like a session token, session data unique to that connected VPN session? Would it contain user credential information if it's not a pre-logon setup? I know it can be setup to only be accepted from the original endpoint IP it was issued to, but is there anything else keeping it from being used on another machine?&lt;/DIV&gt;</description>
    <pubDate>Fri, 04 Feb 2022 23:32:15 GMT</pubDate>
    <dc:creator>claner</dc:creator>
    <dc:date>2022-02-04T23:32:15Z</dc:date>
    <item>
      <title>What's stored in the GlobalProtect encrypted cookie on the endpoint?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/what-s-stored-in-the-globalprotect-encrypted-cookie-on-the/m-p/463575#M2438</link>
      <description>&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;Does anyone know what data is stored in the GlobalProtect authentication cookie?&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;Is it something like a session token, session data unique to that connected VPN session? Would it contain user credential information if it's not a pre-logon setup? I know it can be setup to only be accepted from the original endpoint IP it was issued to, but is there anything else keeping it from being used on another machine?&lt;/DIV&gt;</description>
      <pubDate>Fri, 04 Feb 2022 23:32:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/what-s-stored-in-the-globalprotect-encrypted-cookie-on-the/m-p/463575#M2438</guid>
      <dc:creator>claner</dc:creator>
      <dc:date>2022-02-04T23:32:15Z</dc:date>
    </item>
    <item>
      <title>Re: What's stored in the GlobalProtect encrypted cookie on the endpoint?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/what-s-stored-in-the-globalprotect-encrypted-cookie-on-the/m-p/463864#M2441</link>
      <description>&lt;P&gt;I don't have any particular knowledge of what is in the auth cookie, but I believe it is just a cert-signed session token. I currently use auth cookies to handle login to multiple gateways (different IPs) from a single portal. Just use a unique cert for auth and copy it (and the private key) to multiple PAs.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Feb 2022 15:30:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/what-s-stored-in-the-globalprotect-encrypted-cookie-on-the/m-p/463864#M2441</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-02-07T15:30:44Z</dc:date>
    </item>
  </channel>
</rss>

