<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GP Agent Machine Certificate Check in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-agent-machine-certificate-check/m-p/577645#M4982</link>
    <description>&lt;P&gt;Hi, have you managed to solve this issue? Struggling with the same problem...&lt;/P&gt;</description>
    <pubDate>Mon, 19 Feb 2024 11:33:01 GMT</pubDate>
    <dc:creator>Merl</dc:creator>
    <dc:date>2024-02-19T11:33:01Z</dc:date>
    <item>
      <title>GP Agent Machine Certificate Check</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-agent-machine-certificate-check/m-p/551500#M4240</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am trying to find out more information about a GP portal setting called Machine Certificate Check under Portal Configuration / Agent / Agent Config / Config Selection Criteria / Device Checks. I was hoping to use a machine certificate check outside of the authentication tab to allow or disallow machines based on user/user group, but I can't seem to get it to work. I get a "You are not authorized to connect to GlobalProtect Portal" message. If I set the same certificate profile in the authentication tab, it works just fine when the cert is installed in the machine store. GlobalProtect connects as it should.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My question is, what is the difference between setting it in the authentication tab and setting it as a device check? It is using the same certificate profile and same certificate issued by the CA. I would think it should work set in either place.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PA-220 running 10.2.4&lt;/P&gt;
&lt;P&gt;This is a test portal/gateway configuration I am using.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance for any input.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Michael&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 23:09:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-agent-machine-certificate-check/m-p/551500#M4240</guid>
      <dc:creator>Michael.Martin</dc:creator>
      <dc:date>2023-07-27T23:09:07Z</dc:date>
    </item>
    <item>
      <title>Re: GP Agent Machine Certificate Check</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-agent-machine-certificate-check/m-p/552191#M4251</link>
      <description>&lt;P&gt;I would say that the authentication tab just allows you to connect to the gateway... the device check will decide which config within the gateway agent setting you would get once authenticated, if you only have 1 config in the agent it would not really be of any use...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For user/group membership you will need to look at Device&amp;gt;User Identification&amp;gt;user mapping.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 13:06:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-agent-machine-certificate-check/m-p/552191#M4251</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2023-08-02T13:06:41Z</dc:date>
    </item>
    <item>
      <title>Re: GP Agent Machine Certificate Check</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-agent-machine-certificate-check/m-p/577645#M4982</link>
      <description>&lt;P&gt;Hi, have you managed to solve this issue? Struggling with the same problem...&lt;/P&gt;</description>
      <pubDate>Mon, 19 Feb 2024 11:33:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-agent-machine-certificate-check/m-p/577645#M4982</guid>
      <dc:creator>Merl</dc:creator>
      <dc:date>2024-02-19T11:33:01Z</dc:date>
    </item>
    <item>
      <title>Re: GP Agent Machine Certificate Check</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-agent-machine-certificate-check/m-p/588136#M5394</link>
      <description>&lt;P&gt;Any idea what is the main idea from the above (&amp;nbsp;&lt;SPAN&gt;what is the difference between setting it in the authentication tab and setting it as a device check? It is using the same certificate profile and same certificate issued by the CA. I would think it should work set in either place) ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2024 19:05:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-agent-machine-certificate-check/m-p/588136#M5394</guid>
      <dc:creator>DKh Al Obaidi</dc:creator>
      <dc:date>2024-05-28T19:05:45Z</dc:date>
    </item>
    <item>
      <title>Re: GP Agent Machine Certificate Check</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-agent-machine-certificate-check/m-p/588238#M5399</link>
      <description>&lt;P&gt;Authentication may be shared for several user groups and with a disabled certificate option. But at the same time you might be needed to have several Agent options with different criteria. My personal case: one GW, single Authentication method without cert, several Agent options for different groups. Some users only need authentication, other users need 2FA with a machine cert.&lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2024 09:53:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-agent-machine-certificate-check/m-p/588238#M5399</guid>
      <dc:creator>Merl</dc:creator>
      <dc:date>2024-05-29T09:53:03Z</dc:date>
    </item>
  </channel>
</rss>

