<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic GlobalProtect machine pre-logon coverted into a user connection without user certificate in device in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-machine-pre-logon-coverted-into-a-user-connection/m-p/379905#M791</link>
    <description>&lt;P&gt;Hi there, we are facing a weird situation with GlobalProtect pre-logon connections.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;We have some laptops with &lt;STRONG&gt;machine certificate only&lt;/STRONG&gt; (they do not have user certificates deployed).&lt;/LI&gt;&lt;LI&gt;We want them to connect using this machine certificate, as "pre-logon", so they got limited/specific access to some company resources&lt;/LI&gt;&lt;LI&gt;They are able to establish GP VPN connection but their session is a normal user connection instead of a pre-logon connection because, somehow, the Machine Certificate value is used as if it were a user. So, in short, this is what I'm saying:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="10.png" style="width: 1042px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29516iE87032529842832B/image-dimensions/1042x75/is-moderation-mode/true?v=v2" width="1042" height="75" role="button" title="10.png" alt="10.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="11.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29517iF58E9737FA52F796/image-dimensions/999x261/is-moderation-mode/true?v=v2" width="999" height="261" role="button" title="11.png" alt="11.png" /&gt;&lt;/span&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;These are some useful logs I found in the Tech Support files:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2021/01/14 13:23:05 info globalp GP-Por globalp 0 GlobalProtect portal client configuration generated. Login from: xxx.xxx.xxx.xxx, Source region: ES, User name: &lt;STRONG&gt;7836523f-2a31-4e61-8583-252ad100fc62&lt;/STRONG&gt;, Client OS version: Microsoft Windows 10 Pro , 64-bit, Config name: &lt;STRONG&gt;GP-Agent-HUB01-On-Demand&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2021/01/14 13:23:11 info globalp GP-Gat globalp 0 GlobalProtect gateway user login succeeded. Login from: xxx.xxx.xxx.xxx, Source region: ES, User name: &lt;STRONG&gt;7836523f-2a31-4e61-8583-252ad100fc62&lt;/STRONG&gt;, Client OS version: Microsoft Windows 10 Pro , 64-bit.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2021/01/14 13:23:11 info auth auth-su 0 &lt;STRONG&gt;Certificate validated for user&lt;/STRONG&gt; '&lt;STRONG&gt;7836523f-2a31-4e61-8583-252ad100fc62&lt;/STRONG&gt;'. From: xxx.xxx.xxx.xxx.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2021/01/14 13:23:12 info globalp GP-Gat globalp 0 GlobalProtect gateway client configuration generated. User name: &lt;STRONG&gt;7836523f-2a31-4e61-8583-252ad100fc62&lt;/STRONG&gt;, Private IP: 10.x.x.39, Client version: 5.1.3-12, Device name: &lt;STRONG&gt;COMMXTF47SVPGIT&lt;/STRONG&gt;, Client OS version: Microsoft Windows 10 Pro , 64-bit, &lt;STRONG&gt;VPN type: Device Level VPN.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And this is the GlobalProtect Portal profile they are matching as per the logs (GP-Agent-HUB01-On-Demand):&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="9.png" style="width: 449px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29504i8BFD3A72F02F8D66/image-dimensions/449x410/is-moderation-mode/true?v=v2" width="449" height="410" role="button" title="9.png" alt="9.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="8.png" style="width: 480px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29505i4FB57EE2CC404608/image-dimensions/480x413/is-moderation-mode/true?v=v2" width="480" height="413" role="button" title="8.png" alt="8.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="7.png" style="width: 486px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29507iA628539BC2AE704E/image-dimensions/486x407/is-moderation-mode/true?v=v2" width="486" height="407" role="button" title="7.png" alt="7.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="6.png" style="width: 525px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29506i9F4867A507881E88/image-dimensions/525x437/is-moderation-mode/true?v=v2" width="525" height="437" role="button" title="6.png" alt="6.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="5.png" style="width: 541px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29509i263B6C16218B22B9/image-dimensions/541x443/is-moderation-mode/true?v=v2" width="541" height="443" role="button" title="5.png" alt="5.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="4.png" style="width: 812px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29508i3DE82C98BDAA2353/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="4.png" alt="4.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29511i7A15C4A611C3B254/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="3.png" alt="3.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.png" style="width: 808px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29510i5C8D1A0D8154CBE3/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2.png" alt="2.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 810px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29512i20AF4EDD1616094B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 14 Jan 2021 13:40:51 GMT</pubDate>
    <dc:creator>MarcelST</dc:creator>
    <dc:date>2021-01-14T13:40:51Z</dc:date>
    <item>
      <title>GlobalProtect machine pre-logon coverted into a user connection without user certificate in device</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-machine-pre-logon-coverted-into-a-user-connection/m-p/379905#M791</link>
      <description>&lt;P&gt;Hi there, we are facing a weird situation with GlobalProtect pre-logon connections.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;We have some laptops with &lt;STRONG&gt;machine certificate only&lt;/STRONG&gt; (they do not have user certificates deployed).&lt;/LI&gt;&lt;LI&gt;We want them to connect using this machine certificate, as "pre-logon", so they got limited/specific access to some company resources&lt;/LI&gt;&lt;LI&gt;They are able to establish GP VPN connection but their session is a normal user connection instead of a pre-logon connection because, somehow, the Machine Certificate value is used as if it were a user. So, in short, this is what I'm saying:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="10.png" style="width: 1042px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29516iE87032529842832B/image-dimensions/1042x75/is-moderation-mode/true?v=v2" width="1042" height="75" role="button" title="10.png" alt="10.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="11.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29517iF58E9737FA52F796/image-dimensions/999x261/is-moderation-mode/true?v=v2" width="999" height="261" role="button" title="11.png" alt="11.png" /&gt;&lt;/span&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;These are some useful logs I found in the Tech Support files:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2021/01/14 13:23:05 info globalp GP-Por globalp 0 GlobalProtect portal client configuration generated. Login from: xxx.xxx.xxx.xxx, Source region: ES, User name: &lt;STRONG&gt;7836523f-2a31-4e61-8583-252ad100fc62&lt;/STRONG&gt;, Client OS version: Microsoft Windows 10 Pro , 64-bit, Config name: &lt;STRONG&gt;GP-Agent-HUB01-On-Demand&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2021/01/14 13:23:11 info globalp GP-Gat globalp 0 GlobalProtect gateway user login succeeded. Login from: xxx.xxx.xxx.xxx, Source region: ES, User name: &lt;STRONG&gt;7836523f-2a31-4e61-8583-252ad100fc62&lt;/STRONG&gt;, Client OS version: Microsoft Windows 10 Pro , 64-bit.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2021/01/14 13:23:11 info auth auth-su 0 &lt;STRONG&gt;Certificate validated for user&lt;/STRONG&gt; '&lt;STRONG&gt;7836523f-2a31-4e61-8583-252ad100fc62&lt;/STRONG&gt;'. From: xxx.xxx.xxx.xxx.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2021/01/14 13:23:12 info globalp GP-Gat globalp 0 GlobalProtect gateway client configuration generated. User name: &lt;STRONG&gt;7836523f-2a31-4e61-8583-252ad100fc62&lt;/STRONG&gt;, Private IP: 10.x.x.39, Client version: 5.1.3-12, Device name: &lt;STRONG&gt;COMMXTF47SVPGIT&lt;/STRONG&gt;, Client OS version: Microsoft Windows 10 Pro , 64-bit, &lt;STRONG&gt;VPN type: Device Level VPN.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And this is the GlobalProtect Portal profile they are matching as per the logs (GP-Agent-HUB01-On-Demand):&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="9.png" style="width: 449px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29504i8BFD3A72F02F8D66/image-dimensions/449x410/is-moderation-mode/true?v=v2" width="449" height="410" role="button" title="9.png" alt="9.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="8.png" style="width: 480px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29505i4FB57EE2CC404608/image-dimensions/480x413/is-moderation-mode/true?v=v2" width="480" height="413" role="button" title="8.png" alt="8.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="7.png" style="width: 486px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29507iA628539BC2AE704E/image-dimensions/486x407/is-moderation-mode/true?v=v2" width="486" height="407" role="button" title="7.png" alt="7.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="6.png" style="width: 525px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29506i9F4867A507881E88/image-dimensions/525x437/is-moderation-mode/true?v=v2" width="525" height="437" role="button" title="6.png" alt="6.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="5.png" style="width: 541px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29509i263B6C16218B22B9/image-dimensions/541x443/is-moderation-mode/true?v=v2" width="541" height="443" role="button" title="5.png" alt="5.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="4.png" style="width: 812px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29508i3DE82C98BDAA2353/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="4.png" alt="4.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29511i7A15C4A611C3B254/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="3.png" alt="3.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.png" style="width: 808px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29510i5C8D1A0D8154CBE3/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2.png" alt="2.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 810px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29512i20AF4EDD1616094B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2021 13:40:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-machine-pre-logon-coverted-into-a-user-connection/m-p/379905#M791</guid>
      <dc:creator>MarcelST</dc:creator>
      <dc:date>2021-01-14T13:40:51Z</dc:date>
    </item>
  </channel>
</rss>

