<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Something about Global Protect agent seems off in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/something-about-global-protect-agent-seems-off/m-p/354682#M475</link>
    <description>&lt;P&gt;It looks like Global Protect is a hot issue and specifically in combination with prelogon functionality.&lt;/P&gt;&lt;P&gt;We're also having a situation that appears to difficult to explain.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The idea is:&lt;/P&gt;&lt;P&gt;When handing out devices with global protect preinstalled and preconfigured in the windows registry.&lt;/P&gt;&lt;P&gt;A receiving user who has never logged into that device should be able to do so with the help of global protect prelogon (creating a device tunnel before any user tries to log in to windows).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From then on, the device should always try to setup a device tunnel when it is turned on. But it should use the device certificate to do so.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For some unknown reason, with some of our users (yes not all !?!) at a certain moment something happens (yes very vague so far).&lt;/P&gt;&lt;P&gt;The device will start trying to create a tunnel with seemingly user authentication (because 2FA request is triggered), before any user actually logs in to Windows.&lt;/P&gt;&lt;P&gt;So, for some reason the agent is no longer trying to create a device tunnel with the device certificate. It is all of sudden trying to create a (prelogon) tunnel with user creds.&lt;/P&gt;&lt;P&gt;Since the 2FA request is triggered, I assume that the username and password have been succesfully provided by saved credentials. Because the cookie lifetimes are configured so, they are no longer valid the next morning.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 07 Oct 2020 06:50:04 GMT</pubDate>
    <dc:creator>Klaverblad</dc:creator>
    <dc:date>2020-10-07T06:50:04Z</dc:date>
    <item>
      <title>Something about Global Protect agent seems off</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/something-about-global-protect-agent-seems-off/m-p/354682#M475</link>
      <description>&lt;P&gt;It looks like Global Protect is a hot issue and specifically in combination with prelogon functionality.&lt;/P&gt;&lt;P&gt;We're also having a situation that appears to difficult to explain.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The idea is:&lt;/P&gt;&lt;P&gt;When handing out devices with global protect preinstalled and preconfigured in the windows registry.&lt;/P&gt;&lt;P&gt;A receiving user who has never logged into that device should be able to do so with the help of global protect prelogon (creating a device tunnel before any user tries to log in to windows).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From then on, the device should always try to setup a device tunnel when it is turned on. But it should use the device certificate to do so.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For some unknown reason, with some of our users (yes not all !?!) at a certain moment something happens (yes very vague so far).&lt;/P&gt;&lt;P&gt;The device will start trying to create a tunnel with seemingly user authentication (because 2FA request is triggered), before any user actually logs in to Windows.&lt;/P&gt;&lt;P&gt;So, for some reason the agent is no longer trying to create a device tunnel with the device certificate. It is all of sudden trying to create a (prelogon) tunnel with user creds.&lt;/P&gt;&lt;P&gt;Since the 2FA request is triggered, I assume that the username and password have been succesfully provided by saved credentials. Because the cookie lifetimes are configured so, they are no longer valid the next morning.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2020 06:50:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/something-about-global-protect-agent-seems-off/m-p/354682#M475</guid>
      <dc:creator>Klaverblad</dc:creator>
      <dc:date>2020-10-07T06:50:04Z</dc:date>
    </item>
  </channel>
</rss>

