<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic auto (pre)logon unconfigured installations in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/auto-pre-logon-unconfigured-installations/m-p/574273#M4871</link>
    <description>&lt;P&gt;Hi everybody,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I use pre-logon (always on) for our users which works pretty well. One of the goals is to prohibit Internet access without VPN.&lt;/P&gt;
&lt;P&gt;Now consider the following situation: People receive a freshly installed notebook (Windows). The GlobalProtect client is installed but it was never configured. In fact, no user logged into Windows so far as the process is automated a lot (thankfully).&lt;/P&gt;
&lt;P&gt;How do I get the GP client to connect to the firewall without any user login in order to apply the "Enforce GlobalProtect Connection for Network Access" policy?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 24 Jan 2024 13:17:06 GMT</pubDate>
    <dc:creator>bfuchs_lbrstbr</dc:creator>
    <dc:date>2024-01-24T13:17:06Z</dc:date>
    <item>
      <title>auto (pre)logon unconfigured installations</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/auto-pre-logon-unconfigured-installations/m-p/574273#M4871</link>
      <description>&lt;P&gt;Hi everybody,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I use pre-logon (always on) for our users which works pretty well. One of the goals is to prohibit Internet access without VPN.&lt;/P&gt;
&lt;P&gt;Now consider the following situation: People receive a freshly installed notebook (Windows). The GlobalProtect client is installed but it was never configured. In fact, no user logged into Windows so far as the process is automated a lot (thankfully).&lt;/P&gt;
&lt;P&gt;How do I get the GP client to connect to the firewall without any user login in order to apply the "Enforce GlobalProtect Connection for Network Access" policy?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jan 2024 13:17:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/auto-pre-logon-unconfigured-installations/m-p/574273#M4871</guid>
      <dc:creator>bfuchs_lbrstbr</dc:creator>
      <dc:date>2024-01-24T13:17:06Z</dc:date>
    </item>
    <item>
      <title>Re: auto (pre)logon unconfigured installations</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/auto-pre-logon-unconfigured-installations/m-p/574563#M4885</link>
      <description>&lt;P&gt;we are currently testing imaged devices that connect via pre-logon when posted to users home address...&amp;nbsp; &amp;nbsp;but prior to all this and to date, we use a proxy.pac file that is auto read by browser. it tries to do a reverse lookup internally and if succeeds then proxy is set to "direct" (no proxy), if the internal host is not detected then it adds a false proxy of 1.2.3.4 , which prevents any browsing.&lt;/P&gt;
&lt;P&gt;also in the pac file is an exception to allow connections to our portals and gateways, this works well and also good for iPads.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2024 13:27:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/auto-pre-logon-unconfigured-installations/m-p/574563#M4885</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2024-01-26T13:27:51Z</dc:date>
    </item>
  </channel>
</rss>

