<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect Prelogon tunnel and Portal authentication in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-prelogon-tunnel-and-portal-authentication/m-p/587618#M117223</link>
    <description>&lt;P&gt;&lt;SPAN&gt;I'm not sure I understood the question &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt; You wrote about SAML login failures at pre-logon (what is normal), but you also expect this behavior at 1. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For cookie auth you need a valid certificate oder user auth at first. This should be the reason for your unserilied cookie problem.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The user result from the SAML auth. If it was successful, you see the user in the logs and can setup different agent configs also&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 22 May 2024 11:31:05 GMT</pubDate>
    <dc:creator>TorstenForster</dc:creator>
    <dc:date>2024-05-22T11:31:05Z</dc:date>
    <item>
      <title>GlobalProtect Prelogon tunnel and Portal authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-prelogon-tunnel-and-portal-authentication/m-p/587134#M117148</link>
      <description>&lt;P&gt;Looking for assistance on a GP setup. I want to have a pre-logon tunnel (certificate, always on) and a portal, which uses SAML authentication.&amp;nbsp; I also need the user to have to re-authenticate any time they disable, sign-out, reboot, etc. The problem I'm running into is because the portal uses SAML auth, the portal communication during pre-logon fails and therefore the pre-logon tunnel doesn't start. I thought I should be able to set the Generate and Authenticate cookie options on the pre-logon portal agent configuration but it's not working. I thought it would flow like this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;User boot machine for first time, no pre-logon tunnel as expected.&lt;/LI&gt;
&lt;LI&gt;User logs into machine, GP starts, user gets our internal SAML authentication window for the Portal&lt;/LI&gt;
&lt;LI&gt;User logs in, portal generates cookie.&lt;/LI&gt;
&lt;LI&gt;User logs into Post Logon gateway (no cookie options set here because I do not want cookie to auth post logon)&lt;/LI&gt;
&lt;LI&gt;User reboots, portal auth is handled by cookie, pre-logon tunnel starts.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;The portal auth by cookie after reboot is apparently not happening. PanGPS.log shows the messages "Unserialized empty cookie on portal..." and there are no attempts to connect to the portal in the FW Monitor log.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JamesH1318_0-1715954968880.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59833i8943CDB6393D41B5/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="JamesH1318_0-1715954968880.png" alt="JamesH1318_0-1715954968880.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;For my testing, I have my cookie lifetime set to 10 minutes. My reboots, logons, reboots are all occurring within 3 minutes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PAN-OS 10.2.9-h1&lt;/P&gt;
&lt;P&gt;GP 6.2.3&lt;BR /&gt;&lt;BR /&gt;FYI, there are no certificate issues or anything like that.&amp;nbsp; This is a modification of an existing setup where the pre-logon and portal use the machine certificate. I need to be able to have different portal agent configs for different groups of people, which means I need to know the user at the portal level so I can use AD groups. User certificates are not an option.&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2024 15:31:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-prelogon-tunnel-and-portal-authentication/m-p/587134#M117148</guid>
      <dc:creator>JamesH1318</dc:creator>
      <dc:date>2024-05-17T15:31:44Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Prelogon tunnel and Portal authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-prelogon-tunnel-and-portal-authentication/m-p/587184#M117155</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;if you always&amp;nbsp;want prelogon with certificate auth, deactivate the authenticaten overwrite. Then you dont run into the cookie problems.&lt;/P&gt;
&lt;P&gt;What is your portal authentication setup?&lt;/P&gt;
&lt;P&gt;You cannot activate User Credentials And Client Certificate. With pre-logon, you can only activate&amp;nbsp;User Credentials Or Client Certificate. Because you don't have a user at pre-logon.&lt;/P&gt;
&lt;P&gt;What says your GP log on the firewall?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 18 May 2024 10:20:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-prelogon-tunnel-and-portal-authentication/m-p/587184#M117155</guid>
      <dc:creator>TorstenForster</dc:creator>
      <dc:date>2024-05-18T10:20:03Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Prelogon tunnel and Portal authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-prelogon-tunnel-and-portal-authentication/m-p/587273#M117169</link>
      <description>&lt;P&gt;Thank you for the reply but I'm not sure you understood the question.&amp;nbsp;I have a machine certificate portal and pre-logon setup today. However, now I need to know who the user is at the portal for the post logon agent config.&amp;nbsp; The question basically comes down to, how do I do that without breaking the pre-logon tunnel?&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2024 11:44:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-prelogon-tunnel-and-portal-authentication/m-p/587273#M117169</guid>
      <dc:creator>JamesH1318</dc:creator>
      <dc:date>2024-05-20T11:44:03Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Prelogon tunnel and Portal authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-prelogon-tunnel-and-portal-authentication/m-p/587618#M117223</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I'm not sure I understood the question &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt; You wrote about SAML login failures at pre-logon (what is normal), but you also expect this behavior at 1. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For cookie auth you need a valid certificate oder user auth at first. This should be the reason for your unserilied cookie problem.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The user result from the SAML auth. If it was successful, you see the user in the logs and can setup different agent configs also&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2024 11:31:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-prelogon-tunnel-and-portal-authentication/m-p/587618#M117223</guid>
      <dc:creator>TorstenForster</dc:creator>
      <dc:date>2024-05-22T11:31:05Z</dc:date>
    </item>
  </channel>
</rss>

