<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic GlobalProtect Pre-Login Certificate with BYOD in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-pre-login-certificate-with-byod/m-p/385561#M922</link>
    <description>&lt;P&gt;I'm looking to rollout GlobalProtect to my company and trying to do it properly the first time around.&amp;nbsp; We need need pre-login VPN capabilities and I've got that functioning with the user-based pre-login but I know it's also available to do using a certificate.&amp;nbsp; In my testing this worked but required the certificate to be installed on the machine ahead of time for pre-login or post-login connection.&amp;nbsp; I'm trying to roll this out in such a fashion that users can connect from home devices if needed but not be required/need to do pre-login because they would obviously not be on company-issued devices and we don't really want to burden them or IT with installing a certificate on every home computer now or in the future.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is has anyone come up with a single deployment that can be used to cover both company issued and BYOD devices that will invoke pre-login only if the situation matches (ie - the certificate exists therefore pre-login is performed)?&amp;nbsp; I'd really like to be able to set things up in this fashion but haven't found a way to do this thus far.&amp;nbsp; If anyone had thoughts or ideas I would be most grateful.&amp;nbsp; Thank you!&lt;/P&gt;</description>
    <pubDate>Fri, 12 Feb 2021 06:49:09 GMT</pubDate>
    <dc:creator>rix_jborgen</dc:creator>
    <dc:date>2021-02-12T06:49:09Z</dc:date>
    <item>
      <title>GlobalProtect Pre-Login Certificate with BYOD</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-pre-login-certificate-with-byod/m-p/385561#M922</link>
      <description>&lt;P&gt;I'm looking to rollout GlobalProtect to my company and trying to do it properly the first time around.&amp;nbsp; We need need pre-login VPN capabilities and I've got that functioning with the user-based pre-login but I know it's also available to do using a certificate.&amp;nbsp; In my testing this worked but required the certificate to be installed on the machine ahead of time for pre-login or post-login connection.&amp;nbsp; I'm trying to roll this out in such a fashion that users can connect from home devices if needed but not be required/need to do pre-login because they would obviously not be on company-issued devices and we don't really want to burden them or IT with installing a certificate on every home computer now or in the future.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is has anyone come up with a single deployment that can be used to cover both company issued and BYOD devices that will invoke pre-login only if the situation matches (ie - the certificate exists therefore pre-login is performed)?&amp;nbsp; I'd really like to be able to set things up in this fashion but haven't found a way to do this thus far.&amp;nbsp; If anyone had thoughts or ideas I would be most grateful.&amp;nbsp; Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 12 Feb 2021 06:49:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-pre-login-certificate-with-byod/m-p/385561#M922</guid>
      <dc:creator>rix_jborgen</dc:creator>
      <dc:date>2021-02-12T06:49:09Z</dc:date>
    </item>
  </channel>
</rss>

