<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Global protect with AD integrated issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-with-ad-integrated-issue/m-p/24908#M18181</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Friends,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How are you. i hope you are doing well. i need one suggestion from you guys... One of the our customer&amp;nbsp; using Global Protect Remote VPN with PACluster Gateway. they have integrated AD with PA deviceand GP users connecting through AD credential and now lots user credential needto change. So will itimpact when GP client connect with PA GW can you suggest&amp;nbsp; what isthe way to connect GP clients when changing credential on AD users how we cancome out from this before changing AD users credentials because to changecredential on GP client application for more than 200 users is very pathetic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Satish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 17 Nov 2014 08:04:39 GMT</pubDate>
    <dc:creator>Satish</dc:creator>
    <dc:date>2014-11-17T08:04:39Z</dc:date>
    <item>
      <title>Global protect with AD integrated issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-with-ad-integrated-issue/m-p/24908#M18181</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Friends,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How are you. i hope you are doing well. i need one suggestion from you guys... One of the our customer&amp;nbsp; using Global Protect Remote VPN with PACluster Gateway. they have integrated AD with PA deviceand GP users connecting through AD credential and now lots user credential needto change. So will itimpact when GP client connect with PA GW can you suggest&amp;nbsp; what isthe way to connect GP clients when changing credential on AD users how we cancome out from this before changing AD users credentials because to changecredential on GP client application for more than 200 users is very pathetic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Satish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Nov 2014 08:04:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-with-ad-integrated-issue/m-p/24908#M18181</guid>
      <dc:creator>Satish</dc:creator>
      <dc:date>2014-11-17T08:04:39Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect with AD integrated issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-with-ad-integrated-issue/m-p/24909#M18182</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Satish,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based on your problem description, it looks, you want to change credentials on GP clients when there is a change in your AD for the corresponding users. If so&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;,&lt;/SPAN&gt;you have to uncheck SSO &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;single sign on) from portal configuration &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;Network &amp;gt; GP portal &amp;gt; Genaral) and use connect method as "on-demand mode". So, while the GP user will initiate the GP connection, he may manually change the saved username/password &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;on&lt;/SPAN&gt; GP &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;agent&lt;/SPAN&gt;.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;•&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;on&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;-demand—Select this option to allow users to establish a connection on demand. With this option, the user must explicitly initiate the connection. This function is primarily used for remote access connections.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;•&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;user&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;-logon—When this option is set, the GlobalProtect agent will automatically establish a connection after users log in to their computers. If you select Use single sign-on, the username and password used to log in to Windows is captured by the GlobalProtect agent and used to authenticate.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Nov 2014 12:51:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-with-ad-integrated-issue/m-p/24909#M18182</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-11-17T12:51:50Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect with AD integrated issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-with-ad-integrated-issue/m-p/24910#M18183</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi hulk,&lt;/P&gt;&lt;P&gt;i think you didn't get the my point. my question is are :- GP client with AD integration , if AD User change his credential and login with his Laptop window using new credential then the GP client also need to change manually, is there any Automatic way that user don’t need to change credential in GP client console.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If Point-1 don’t have automatic mechanism then can we integrate user-based certificate using pre-login mechanism, userbased certificate means certificate will be individual for each user&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Satish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Nov 2014 09:43:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-with-ad-integrated-issue/m-p/24910#M18183</guid>
      <dc:creator>Satish</dc:creator>
      <dc:date>2014-11-18T09:43:57Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect with AD integrated issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-with-ad-integrated-issue/m-p/24911#M18184</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hulk, Thanks, issue has been resolve. Regards Satish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2014 07:48:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-with-ad-integrated-issue/m-p/24911#M18184</guid>
      <dc:creator>Satish</dc:creator>
      <dc:date>2014-11-19T07:48:59Z</dc:date>
    </item>
  </channel>
</rss>

