<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect Prelogon not working in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-prelogon-not-working/m-p/340463#M297</link>
    <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1289"&gt;@fatboy1607&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One of the biggest issues involving Pre-Logon tends to be related to the certificate deployment process.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We must ensure the client certificates being deployed are stored in the correct directories and signed by the same root CA which signed the server certificate(s) being used for the Portal and/or Gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've included a document below discussing this in more detail for you to review as well:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/kCSArticleDetail?id=kA10g000000PPfM" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/kCSArticleDetail?id=kA10g000000PPfM&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, if the configurations for the "pre-logon" and "any" users are the same, you won't need to specify a separate configuration for the pre-logon user as this will be matched by the "any" user!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 24 Jul 2020 05:06:48 GMT</pubDate>
    <dc:creator>trivers01</dc:creator>
    <dc:date>2020-07-24T05:06:48Z</dc:date>
    <item>
      <title>Global Protect Prelogon not working</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-prelogon-not-working/m-p/340380#M294</link>
      <description>&lt;P&gt;Scenario is we recieve new laptop with pre loded certs. I want that laptop to get connected to globalprotect gateway using pre-logon once it has IP it will get connectivity with DC and later it gets renamed to user name we login.&lt;/P&gt;&lt;P&gt;I am working on above scenario but unable to get it working.&lt;/P&gt;&lt;P&gt;That new laptop get pre-logon registry settings pushed like&lt;BR /&gt;gateway - ip or fqdn&lt;BR /&gt;pre-logon -yes&lt;BR /&gt;showprelogonbuttton -yes&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Portal config.&lt;/P&gt;&lt;P&gt;Authentication :- Using certificate , certificate profile mapped under authentication.&lt;/P&gt;&lt;P&gt;Portal Config :-&lt;/P&gt;&lt;P&gt;Create 2 Profiles&lt;/P&gt;&lt;P&gt;1. Pre Logon Profile - Prelogon Always On. , User - Pre-logon&lt;/P&gt;&lt;P&gt;2. Pre Logon Profile - 2 - Pre Logon Always on - User - Any.&lt;/P&gt;&lt;P&gt;Gateway config&lt;/P&gt;&lt;P&gt;Authenication - LDAP&lt;BR /&gt;CLient setting - Tunnel Interface , IP Pool , Split Tunnel&lt;/P&gt;&lt;P&gt;Is this config enough to get above scenario worked ?&lt;/P&gt;&lt;P&gt;we tried above config , Pre logon does not trigger.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help Appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2020 18:03:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-prelogon-not-working/m-p/340380#M294</guid>
      <dc:creator>fatboy1607</dc:creator>
      <dc:date>2020-07-23T18:03:42Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Prelogon not working</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-prelogon-not-working/m-p/340463#M297</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1289"&gt;@fatboy1607&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One of the biggest issues involving Pre-Logon tends to be related to the certificate deployment process.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We must ensure the client certificates being deployed are stored in the correct directories and signed by the same root CA which signed the server certificate(s) being used for the Portal and/or Gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've included a document below discussing this in more detail for you to review as well:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/kCSArticleDetail?id=kA10g000000PPfM" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/kCSArticleDetail?id=kA10g000000PPfM&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, if the configurations for the "pre-logon" and "any" users are the same, you won't need to specify a separate configuration for the pre-logon user as this will be matched by the "any" user!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jul 2020 05:06:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-prelogon-not-working/m-p/340463#M297</guid>
      <dc:creator>trivers01</dc:creator>
      <dc:date>2020-07-24T05:06:48Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Prelogon not working</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-prelogon-not-working/m-p/340470#M298</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/135907"&gt;@trivers01&lt;/a&gt;&amp;nbsp; Appreciate your reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Query is it is always recommended to use public cert for IP&amp;nbsp; facing public so portal IP is public&amp;nbsp; lets say we use cert from well known CA's like commdo , symantec,verizon etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. If that is same cert I need to use as server cert on gateway ( As I have gateway and Portal on Same firewall ) then issue is with client authentication as we cannot get client certificate from well root CA's I mean not a good practice.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then for Portal authentication If use LDAP or Local , for the machines that are newly build I dont have user name and password for those users&amp;nbsp; going to use it , so we want to make authentication using certificate. I think only using cert profile on portaln to match subnet name will solve it , your suggestion ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MandarKulkarni_0-1595570159333.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27003i7A14A1FB06912464/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MandarKulkarni_0-1595570159333.png" alt="MandarKulkarni_0-1595570159333.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then I dont see document mentioning use of cookie authentication ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;some documents refer using cookie authentication ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. Any specific logs on firewall side we can see if pre-logon is getting triggered ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks Again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jul 2020 06:01:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-prelogon-not-working/m-p/340470#M298</guid>
      <dc:creator>fatboy1607</dc:creator>
      <dc:date>2020-07-24T06:01:53Z</dc:date>
    </item>
  </channel>
</rss>

