<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Issues with GlobalProtect Pre-logon on Mac in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/issues-with-globalprotect-pre-logon-on-mac/m-p/505783#M2914</link>
    <description>&lt;P class=""&gt;I'm having problems getting pre-logon to work on MacOS. There are a number of issues.&lt;/P&gt;&lt;P class=""&gt;- To start with, I can't seem to get the GlobalProtect icon from the login screen after several tries.&lt;/P&gt;&lt;P class=""&gt;- Then, even when I log in to the device and try to connect to GlobalProtect, I get prompted for keychain access so that GlobalProtect can access the machine certificate. I've seen the document that explains how to give GlobalProtect access to keychain so that I don't get this prompt. Even after making those changes, GlobalProtect doesn't attempt to connect from the login screen. It only attempts to connect when I've logged in to the device.&lt;/P&gt;&lt;P class=""&gt;- Another thing I've noticed is, when I look at the GlobalProtect logs for the Mac, I actually see the 'Auth Method' as 'Certificate'. BUT, the source user is the device name (which is defined in the certificate) rather than the 'pre-logon' user which I would expect for pre-logon, before the actual source user.&lt;/P&gt;&lt;P class=""&gt;- GlobalProtect version is 5.2.10. Mac OS version is Monterey 12.4&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;Config settings used:&lt;/P&gt;&lt;P class=""&gt;&lt;U&gt;&lt;STRONG&gt;GlobalProtect Portal&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P class=""&gt;- GlobalProtect portal &amp;gt; Authentication&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp; &amp;nbsp;- Allow authentication with user credentials or client certificate: &lt;STRONG&gt;Yes&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp; &amp;nbsp;- Certificate profile: &lt;STRONG&gt;None&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;- GlobalProtect portal &amp;gt; Agent&lt;/P&gt;&lt;P class=""&gt;&lt;U&gt;&lt;STRONG&gt;Config 1&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp; &amp;nbsp;- Save User credentials: &lt;STRONG&gt;Yes&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp; &amp;nbsp;- Generate cookie for authentication override: &lt;STRONG&gt;Yes&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp; &amp;nbsp;- Allow cookie for authentication override: &lt;STRONG&gt;Yes&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp; &amp;nbsp;- User: &lt;STRONG&gt;pre-logon&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp; &amp;nbsp;- Connect method: &lt;STRONG&gt;Pre-logon (Always-On)&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;U&gt;&lt;STRONG&gt;Config 2&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp; &amp;nbsp;- Save User credentials: &lt;STRONG&gt;Yes&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp; &amp;nbsp;- Generate cookie for authentication override: &lt;STRONG&gt;Yes&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp; &amp;nbsp;- Allow cookie for authentication override: &lt;STRONG&gt;Yes&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp; &amp;nbsp;- User: &lt;STRONG&gt;any&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp; &amp;nbsp;- Connect method: Pre-logon &lt;STRONG&gt;(Always-On)&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;U&gt;&lt;STRONG&gt;GlobalProtect Gateway&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P class=""&gt;- GlobalProtect gateway &amp;gt; Authentication&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp; &amp;nbsp;- Allow authentication with user credentials or client certificate: &lt;STRONG&gt;Yes&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp; &amp;nbsp;- Certificate profile: &lt;STRONG&gt;&amp;lt;root certificate&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;Any ideas on what I'm missing?&lt;/P&gt;</description>
    <pubDate>Thu, 23 Jun 2022 14:28:43 GMT</pubDate>
    <dc:creator>MartinE</dc:creator>
    <dc:date>2022-06-23T14:28:43Z</dc:date>
    <item>
      <title>Issues with GlobalProtect Pre-logon on Mac</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/issues-with-globalprotect-pre-logon-on-mac/m-p/505783#M2914</link>
      <description>&lt;P class=""&gt;I'm having problems getting pre-logon to work on MacOS. There are a number of issues.&lt;/P&gt;&lt;P class=""&gt;- To start with, I can't seem to get the GlobalProtect icon from the login screen after several tries.&lt;/P&gt;&lt;P class=""&gt;- Then, even when I log in to the device and try to connect to GlobalProtect, I get prompted for keychain access so that GlobalProtect can access the machine certificate. I've seen the document that explains how to give GlobalProtect access to keychain so that I don't get this prompt. Even after making those changes, GlobalProtect doesn't attempt to connect from the login screen. It only attempts to connect when I've logged in to the device.&lt;/P&gt;&lt;P class=""&gt;- Another thing I've noticed is, when I look at the GlobalProtect logs for the Mac, I actually see the 'Auth Method' as 'Certificate'. BUT, the source user is the device name (which is defined in the certificate) rather than the 'pre-logon' user which I would expect for pre-logon, before the actual source user.&lt;/P&gt;&lt;P class=""&gt;- GlobalProtect version is 5.2.10. Mac OS version is Monterey 12.4&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;Config settings used:&lt;/P&gt;&lt;P class=""&gt;&lt;U&gt;&lt;STRONG&gt;GlobalProtect Portal&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P class=""&gt;- GlobalProtect portal &amp;gt; Authentication&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp; &amp;nbsp;- Allow authentication with user credentials or client certificate: &lt;STRONG&gt;Yes&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp; &amp;nbsp;- Certificate profile: &lt;STRONG&gt;None&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;- GlobalProtect portal &amp;gt; Agent&lt;/P&gt;&lt;P class=""&gt;&lt;U&gt;&lt;STRONG&gt;Config 1&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp; &amp;nbsp;- Save User credentials: &lt;STRONG&gt;Yes&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp; &amp;nbsp;- Generate cookie for authentication override: &lt;STRONG&gt;Yes&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp; &amp;nbsp;- Allow cookie for authentication override: &lt;STRONG&gt;Yes&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp; &amp;nbsp;- User: &lt;STRONG&gt;pre-logon&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp; &amp;nbsp;- Connect method: &lt;STRONG&gt;Pre-logon (Always-On)&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;U&gt;&lt;STRONG&gt;Config 2&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp; &amp;nbsp;- Save User credentials: &lt;STRONG&gt;Yes&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp; &amp;nbsp;- Generate cookie for authentication override: &lt;STRONG&gt;Yes&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp; &amp;nbsp;- Allow cookie for authentication override: &lt;STRONG&gt;Yes&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp; &amp;nbsp;- User: &lt;STRONG&gt;any&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp; &amp;nbsp;- Connect method: Pre-logon &lt;STRONG&gt;(Always-On)&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;U&gt;&lt;STRONG&gt;GlobalProtect Gateway&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P class=""&gt;- GlobalProtect gateway &amp;gt; Authentication&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp; &amp;nbsp;- Allow authentication with user credentials or client certificate: &lt;STRONG&gt;Yes&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp; &amp;nbsp;- Certificate profile: &lt;STRONG&gt;&amp;lt;root certificate&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;Any ideas on what I'm missing?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2022 14:28:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/issues-with-globalprotect-pre-logon-on-mac/m-p/505783#M2914</guid>
      <dc:creator>MartinE</dc:creator>
      <dc:date>2022-06-23T14:28:43Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with GlobalProtect Pre-logon on Mac</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/issues-with-globalprotect-pre-logon-on-mac/m-p/539409#M3951</link>
      <description>&lt;P&gt;We are about to embark on this path. Have you found answers to your problems?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2023 17:14:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/issues-with-globalprotect-pre-logon-on-mac/m-p/539409#M3951</guid>
      <dc:creator>giapperreault</dc:creator>
      <dc:date>2023-04-19T17:14:11Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with GlobalProtect Pre-logon on Mac</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/issues-with-globalprotect-pre-logon-on-mac/m-p/544431#M4078</link>
      <description>&lt;P&gt;Came here to say this as we are having the same experience on MAC devices.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2023 19:42:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/issues-with-globalprotect-pre-logon-on-mac/m-p/544431#M4078</guid>
      <dc:creator>eumbach</dc:creator>
      <dc:date>2023-06-01T19:42:19Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with GlobalProtect Pre-logon on Mac</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/issues-with-globalprotect-pre-logon-on-mac/m-p/544841#M4093</link>
      <description>&lt;P&gt;This is due to a MacOS limitation. Check out this Apple Support link to confirm.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;DIV id="sece289e23d1" class="Subhead"&gt;
&lt;H2 class="Name"&gt;VPN deployments supported&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;iOS, iPadOS, and macOS support the following:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;EM&gt;VPN On Demand:&amp;nbsp;&lt;/EM&gt;For networks that use certificate-based authentication. IT policies specify which domains require a VPN connection by using a VPN configuration profile.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;EM&gt;Per App VPN:&amp;nbsp;&lt;/EM&gt;For facilitating VPN connections on a much more granular basis.&amp;nbsp;&lt;A class="xRef Aside" href="https://support.apple.com/guide/security/aside/sec1a32cff88/1/web/1" target="_blank"&gt;Mobile device management (MDM)&lt;/A&gt;&amp;nbsp;solutions can specify a connection for each managed app and specific domains in Safari. This helps ensure that secure data always goes to and from the corporate network—and that a user’s personal data doesn’t.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;iOS and iPadOS support the following:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;EM&gt;Always On VPN:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;For devices managed through an MDM solution and supervised using&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="NoBreak"&gt;Apple Configurator&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;for Mac,&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="xRef Aside" href="https://support.apple.com/guide/security/aside/sec76b4b5232/1/web/1" target="_blank"&gt;Apple School Manager&lt;/A&gt;, or&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="xRef Aside" href="https://support.apple.com/guide/security/aside/sec940ec17e5/1/web/1" target="_blank"&gt;Apple Business Manager&lt;/A&gt;. Always On VPN eliminates the need for users to turn on VPN to enable protection when connecting to cellular and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="NoBreak"&gt;Wi-Fi&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;networks. It also gives an organization full control over device traffic by tunneling all IP traffic back to the organization. The default exchange of parameters and keys for the subsequent encryption, IKEv2, secures traffic transmission with data encryption. The organization can monitor and filter traffic to and from its devices, secure data within its network, and restrict device access to the internet.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;A href="https://support.apple.com/guide/security/vpn-security-sec802e8ab55/web" target="_self"&gt;Virtual private network (VPN) security&lt;/A&gt;&amp;nbsp;(External Link)&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2023 17:45:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/issues-with-globalprotect-pre-logon-on-mac/m-p/544841#M4093</guid>
      <dc:creator>mishelton</dc:creator>
      <dc:date>2023-06-05T17:45:03Z</dc:date>
    </item>
  </channel>
</rss>

