<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect Prelogon in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-prelogon/m-p/1222648#M6552</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/694766011"&gt;@GroupITSvc&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;You didn't actually include the guide that you're following so we can't actually certify what step you can/cannot skip to. Whether or not you would need a separate interface or not would depend on how you're configuring things, generally speaking I would say a small environment has the same gateway in use for fully authenticated users and pre-logon but you don't have to. &lt;/P&gt;</description>
    <pubDate>Tue, 04 Mar 2025 22:22:56 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2025-03-04T22:22:56Z</dc:date>
    <item>
      <title>GlobalProtect Prelogon</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-prelogon/m-p/1222361#M6537</link>
      <description>&lt;P style="box-sizing: border-box; margin: 0px; font-weight: 400; color: #3e3e3e; font-family: Lato, 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;"&gt;Hello,&lt;/P&gt;
&lt;P style="box-sizing: border-box; margin: 0px; font-weight: 400; color: #3e3e3e; font-family: Lato, 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;"&gt;Recently we had the new PANFW migration, together with the GlobalProtect VPN enabled. We are working fine with what has setup. As of our staffs we login to the GP VPN with the corporate computers pre-installed with machine certificates and also the client certificates.&amp;nbsp;&lt;/P&gt;
&lt;P style="box-sizing: border-box; margin: 0px; font-weight: 400; color: #3e3e3e; font-family: Lato, 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="box-sizing: border-box; margin: 0px; font-weight: 400; color: #3e3e3e; font-family: Lato, 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;"&gt;Now we are going to settle the issue when the staffs trying to login with their Windows AD accounts and if the AD account was expired. Although helpdesk has settled the password for them, the problem happened to be the users still unable to login to the computer.&lt;/P&gt;
&lt;P style="box-sizing: border-box; margin: 0px; font-weight: 400; color: #3e3e3e; font-family: Lato, 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;"&gt;I have a quick search to the PAN, it should be called Pre-logon authentication. (please advise me if it is not correct)&lt;/P&gt;
&lt;P style="box-sizing: border-box; margin: 0px; font-weight: 400; color: #3e3e3e; font-family: Lato, 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="box-sizing: border-box; margin: 0px; font-weight: 400; color: #3e3e3e; font-family: Lato, 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;"&gt;The current environment we have is having a policy that allows GP VPN formed. A separate Subnet range is assigned for those authenticated users (in VPN_Zone).&lt;/P&gt;
&lt;P style="box-sizing: border-box; margin: 0px; font-weight: 400; color: #3e3e3e; font-family: Lato, 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="box-sizing: border-box; margin: 0px; font-weight: 400; color: #3e3e3e; font-family: Lato, 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;"&gt;Now I am planning to setup the Pre-logon authentication for our staffs. In this case, do I have to create a separate interface? It seems we have most of the part done, am I right to skip to Step 6 of Remote Access VPN with Pre-Logon? (create a certificate profile PrelogonCert)?&lt;/P&gt;
&lt;P style="box-sizing: border-box; margin: 0px; font-weight: 400; color: #3e3e3e; font-family: Lato, 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="box-sizing: border-box; margin: 0px; font-weight: 400; color: #3e3e3e; font-family: Lato, 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;"&gt;Thanks in advance. Best Regards,&lt;/P&gt;
&lt;P style="box-sizing: border-box; margin: 0px; font-weight: 400; color: #3e3e3e; font-family: Lato, 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;"&gt;Timothy&lt;/P&gt;</description>
      <pubDate>Mon, 03 Mar 2025 02:26:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-prelogon/m-p/1222361#M6537</guid>
      <dc:creator>GroupITSvc</dc:creator>
      <dc:date>2025-03-03T02:26:59Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Prelogon</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-prelogon/m-p/1222648#M6552</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/694766011"&gt;@GroupITSvc&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;You didn't actually include the guide that you're following so we can't actually certify what step you can/cannot skip to. Whether or not you would need a separate interface or not would depend on how you're configuring things, generally speaking I would say a small environment has the same gateway in use for fully authenticated users and pre-logon but you don't have to. &lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 22:22:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-prelogon/m-p/1222648#M6552</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2025-03-04T22:22:56Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Prelogon</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-prelogon/m-p/1222834#M6554</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp; Thanks for you reply.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-quick-configs/remote-access-vpn-with-pre-logon" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-quick-configs/remote-access-vpn-with-pre-logon&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Here is the doc that I followed. &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I did not create extra interface for my testing.&lt;/P&gt;
&lt;P&gt;Now I come to a stage that to create two Agents inside the GlobalProtect Portal.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The first agent is for PreLogon, so I setup the Config Selection Criteria to pre-logon, and the Connect Method I use is set to PreLogon then On-Demand.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GroupITSvc_0-1741232255905.png" style="width: 602px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66400i68D7E4042DE50351/image-dimensions/602x282?v=v2" width="602" height="282" role="button" title="GroupITSvc_0-1741232255905.png" alt="GroupITSvc_0-1741232255905.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GroupITSvc_1-1741232291047.png" style="width: 751px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66401iE26F56CAD0DAA22F/image-dimensions/751x430?v=v2" width="751" height="430" role="button" title="GroupITSvc_1-1741232291047.png" alt="GroupITSvc_1-1741232291047.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The other is for normal VPN access, I set Config Selection Criteria to Any, and the Connect Method to On-Demand (Manual user initiated connection)&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GroupITSvc_2-1741232357167.png" style="width: 770px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66402i3FB9C194C5A7CAF9/image-dimensions/770x351?v=v2" width="770" height="351" role="button" title="GroupITSvc_2-1741232357167.png" alt="GroupITSvc_2-1741232357167.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GroupITSvc_3-1741232383159.png" style="width: 815px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66403i9E3373FB79C4E5E2/image-dimensions/815x336?v=v2" width="815" height="336" role="button" title="GroupITSvc_3-1741232383159.png" alt="GroupITSvc_3-1741232383159.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Timothy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2025 03:56:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-prelogon/m-p/1222834#M6554</guid>
      <dc:creator>GroupITSvc</dc:creator>
      <dc:date>2025-03-06T03:56:38Z</dc:date>
    </item>
  </channel>
</rss>

