<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Global Protect - Require Machine Cert only for Windows and MAC machines (and all other systems can just use username/password) in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-require-machine-cert-only-for-windows-and-mac/m-p/518455#M3335</link>
    <description>&lt;P&gt;Hi there,&lt;BR /&gt;&lt;BR /&gt;I'm trying to build out a config in my lab where my global protect configuration requires a machine cert and username/password for only Windows OS and MAC OS systems and then for IOS and ANDROID devices, they will only require username/password.&amp;nbsp; My lab is running an old PA-5050 on PAN OS 8.1.23.&amp;nbsp; I'm finding that the only option is to enable a certificate profile for ALL systems and we cannot specify specific settings based on OS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone successfully done this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Alternatively is it possible to configure multiple gateways on the same edge and then use the portal 'agent configuration' to redirect to different gateways that enforce different certificate profiles?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm also looking at options on PAN OS 9.1.X.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Michael&lt;/P&gt;</description>
    <pubDate>Wed, 19 Oct 2022 22:16:40 GMT</pubDate>
    <dc:creator>mslavens</dc:creator>
    <dc:date>2022-10-19T22:16:40Z</dc:date>
    <item>
      <title>Global Protect - Require Machine Cert only for Windows and MAC machines (and all other systems can just use username/password)</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-require-machine-cert-only-for-windows-and-mac/m-p/518455#M3335</link>
      <description>&lt;P&gt;Hi there,&lt;BR /&gt;&lt;BR /&gt;I'm trying to build out a config in my lab where my global protect configuration requires a machine cert and username/password for only Windows OS and MAC OS systems and then for IOS and ANDROID devices, they will only require username/password.&amp;nbsp; My lab is running an old PA-5050 on PAN OS 8.1.23.&amp;nbsp; I'm finding that the only option is to enable a certificate profile for ALL systems and we cannot specify specific settings based on OS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone successfully done this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Alternatively is it possible to configure multiple gateways on the same edge and then use the portal 'agent configuration' to redirect to different gateways that enforce different certificate profiles?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm also looking at options on PAN OS 9.1.X.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Michael&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 22:16:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-require-machine-cert-only-for-windows-and-mac/m-p/518455#M3335</guid>
      <dc:creator>mslavens</dc:creator>
      <dc:date>2022-10-19T22:16:40Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect - Require Machine Cert only for Windows and MAC machines (and all other systems can just use username/password)</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-require-machine-cert-only-for-windows-and-mac/m-p/518756#M3353</link>
      <description>&lt;P&gt;Hi Michael,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Certificate profile config is indeed for all operating systems, but at least in 9.1 the "&lt;SPAN&gt;&lt;STRONG&gt;Allow Authentication with User Credentials OR Client Certificate&lt;/STRONG&gt;" setting can be configured per operating system. You could have it like this for example:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Cert profile:&lt;/STRONG&gt; configured for all&lt;BR /&gt;&lt;STRONG&gt;OS Windows:&lt;/STRONG&gt;&amp;nbsp;&lt;EM&gt;Allow Authentication with User Credentials OR Client Certificate&lt;/EM&gt; = NO&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;OS Android:&lt;/STRONG&gt;&amp;nbsp;&lt;EM&gt;Allow Authentication with User Credentials OR Client Certificate&lt;/EM&gt; = YES&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This should result in Windows needing a Client Cert + User Credentials, but Android would need only one or the other.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your second option is also valid. You can use OS in the Config Selection Criteria of the Portal to give a different Portal config to different OS's, and those different Portal configs send them to different Gateways which have different cert profile configs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- DM&lt;/P&gt;</description>
      <pubDate>Fri, 21 Oct 2022 18:08:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-require-machine-cert-only-for-windows-and-mac/m-p/518756#M3353</guid>
      <dc:creator>dmifsud</dc:creator>
      <dc:date>2022-10-21T18:08:41Z</dc:date>
    </item>
  </channel>
</rss>

