<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Connect client at boot time in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/connect-client-at-boot-time/m-p/40943#M30095</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bdunbar,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can focus on following logs,&amp;nbsp; sslvpn.log and ramgr.log are most important.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sslvpn.log, rasmgr.log, authd.log, sslvpn-access.log, sslvpn-error.log&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;HArdik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 08 Oct 2014 17:17:15 GMT</pubDate>
    <dc:creator>hshah</dc:creator>
    <dc:date>2014-10-08T17:17:15Z</dc:date>
    <item>
      <title>Connect client at boot time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/connect-client-at-boot-time/m-p/40935#M30087</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Or&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Further Adventures of a Networking Neophyte &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA-200&lt;/P&gt;&lt;P&gt;Software Version: 6.0.1&lt;/P&gt;&lt;P&gt;GlobalProtect Agent 2.0.4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now what I need, and desire, is to have client PCs, in an office remote from the data center, login to the domain controller -in- the data center.&amp;nbsp; They would like this as transparent as possible, i.e. to present that domain at login via the standard login menu, and not have it available after boot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe the way forward is to - somehow - enable the GlobalProtect client to authenticate during boot.&amp;nbsp; I see ways to do this using Windows VPN client, and Cisco has the process documented, but I can't tell how to make it work for GlobalProtect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm searching, and will continue to look, but .. is it even possible?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Oct 2014 19:15:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/connect-client-at-boot-time/m-p/40935#M30087</guid>
      <dc:creator>bdunbar</dc:creator>
      <dc:date>2014-10-07T19:15:34Z</dc:date>
    </item>
    <item>
      <title>Re: Connect client at boot time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/connect-client-at-boot-time/m-p/40936#M30088</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bdunbar,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Solution that you are looking for is pre-logon. It will take domain credentials and establish tunnel before users gets to windows desktop. Please refer to following documents for explanation :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-6586"&gt;GlobalProtect Administrator's Guide 6.0 (English)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps. Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Oct 2014 19:19:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/connect-client-at-boot-time/m-p/40936#M30088</guid>
      <dc:creator>ssharma</dc:creator>
      <dc:date>2014-10-07T19:19:16Z</dc:date>
    </item>
    <item>
      <title>Re: Connect client at boot time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/connect-client-at-boot-time/m-p/40937#M30089</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/28274"&gt;bdunbar&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you check the pre-logon feature available in globalprotect: &lt;A href="https://live.paloaltonetworks.com/docs/DOC-6586"&gt;GlobalProtect Administrator's Guide 6.0 (English)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think that might be feature you are looking into&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Oct 2014 19:20:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/connect-client-at-boot-time/m-p/40937#M30089</guid>
      <dc:creator>bat</dc:creator>
      <dc:date>2014-10-07T19:20:15Z</dc:date>
    </item>
    <item>
      <title>Re: Connect client at boot time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/connect-client-at-boot-time/m-p/40938#M30090</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Oct 2014 19:21:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/connect-client-at-boot-time/m-p/40938#M30090</guid>
      <dc:creator>bdunbar</dc:creator>
      <dc:date>2014-10-07T19:21:01Z</dc:date>
    </item>
    <item>
      <title>Re: Connect client at boot time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/connect-client-at-boot-time/m-p/40939#M30091</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bdunbar,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may want to try pre-login option for GP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Oct 2014 19:21:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/connect-client-at-boot-time/m-p/40939#M30091</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-10-07T19:21:32Z</dc:date>
    </item>
    <item>
      <title>Re: Connect client at boot time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/connect-client-at-boot-time/m-p/40940#M30092</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="1415" data-externalid="" data-presence="null" data-userid="28274" data-username="bdunbar" href="https://live.paloaltonetworks.com/people/bdunbar" style="padding: 0 3px 0 0; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #006595;"&gt;bdunbar&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Just wanted to add this document to the thread. It gives a step by step configuration assistance to set up pre-logon with self signed certificate on the PAN firewall. &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-5229"&gt;How To Configure GlobalProtect SSO With Pre-Logon Access Using Self-Signed Certificates&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this is helpful to you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Oct 2014 22:05:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/connect-client-at-boot-time/m-p/40940#M30092</guid>
      <dc:creator>tshiv</dc:creator>
      <dc:date>2014-10-07T22:05:15Z</dc:date>
    </item>
    <item>
      <title>Re: Connect client at boot time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/connect-client-at-boot-time/m-p/40941#M30093</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've setup and having some minor issues.&amp;nbsp; What log files on the PAN-200 should I be looking at?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Oct 2014 14:43:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/connect-client-at-boot-time/m-p/40941#M30093</guid>
      <dc:creator>bdunbar</dc:creator>
      <dc:date>2014-10-08T14:43:13Z</dc:date>
    </item>
    <item>
      <title>Re: Connect client at boot time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/connect-client-at-boot-time/m-p/40942#M30094</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I will suggest first checking the global protect PanGP Agent logs and then move to the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are multiple logs to check on the firewall depending on what you see in agent logs:&lt;/P&gt;&lt;P&gt;less mp-log authd.log&lt;/P&gt;&lt;P&gt;show log system direction equal backward subtype equal globalprotect&lt;/P&gt;&lt;P&gt;less webserver-log sslvpn-access.log&lt;/P&gt;&lt;P&gt;less webserver-log sslvpn-error.log&lt;/P&gt;&lt;P&gt;less mp-log sslvpn.log&lt;/P&gt;&lt;P&gt;less mp-log rasmgr.log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Oct 2014 17:04:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/connect-client-at-boot-time/m-p/40942#M30094</guid>
      <dc:creator>bat</dc:creator>
      <dc:date>2014-10-08T17:04:58Z</dc:date>
    </item>
    <item>
      <title>Re: Connect client at boot time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/connect-client-at-boot-time/m-p/40943#M30095</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bdunbar,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can focus on following logs,&amp;nbsp; sslvpn.log and ramgr.log are most important.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sslvpn.log, rasmgr.log, authd.log, sslvpn-access.log, sslvpn-error.log&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;HArdik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Oct 2014 17:17:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/connect-client-at-boot-time/m-p/40943#M30095</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-10-08T17:17:15Z</dc:date>
    </item>
    <item>
      <title>Re: Connect client at boot time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/connect-client-at-boot-time/m-p/40944#M30096</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We're partially up: Following the guide linked to by tshiv, I'm generating self-signed certs from the PAN-200, sending them to the machines, importing to the test client machine, and we're set.&amp;nbsp; After lunch I'll see about getting the clients logged in at boot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem I had was that the PA-200's self-signed cert did not match the it's DNS or IP - my mistake when I created it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've got a card on my board to circle back to this after we go-live and do it 'right' using certs from our PKI, but that's another battle.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Oct 2014 17:23:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/connect-client-at-boot-time/m-p/40944#M30096</guid>
      <dc:creator>bdunbar</dc:creator>
      <dc:date>2014-10-08T17:23:54Z</dc:date>
    </item>
  </channel>
</rss>

