<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: meaning of source-user pre-logon in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/meaning-of-source-user-pre-logon/m-p/44503#M32663</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Its a new feature in PANOS 5.0 which is described in the release notes:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;P&gt;Pre-logon Connection – The pre-logon option is part of the GlobalProtect agent configuration and is used to preserve pre-logon and post-logon services provided by a corporate infrastructure regardless of where the user machine is located. By doing this, a company can create a logical network that maintains the security and management features normally achieved by a physical network. Tunnel selection and establishment occurs pre-logon based on machine certificates. Examples of some of the services that can be maintained include: Active Directory group policy enforcement, drive mapping to server resources, and the ability to receive central software deployment downloads while working remotely. One specific example of how the pre-logon feature works is remote users forget their passwords, a helpdesk admin can reset their domain passwords and the users can log in with the new password because the VPN is already established and direct domain authentication will work. &lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So in short, Globalprotect can establish a VPN-tunnel before the user is authenticated in his/her machine (using machine cert).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This way you can for example set user=pre-logon to access AD, DNS, AV, WSUS. And the other rules can have user=ad-group(s) or user=userX,userY... for your other systems.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 26 Nov 2012 08:31:20 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2012-11-26T08:31:20Z</dc:date>
    <item>
      <title>meaning of source-user pre-logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/meaning-of-source-user-pre-logon/m-p/44502#M32662</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone explain what the option "pre-logon" means as a value for source-user in a security policy?&lt;/P&gt;&lt;P&gt;I can't find anything about it. Not in the build in help, the admin guide nor the CLI reference.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Nov 2012 07:52:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/meaning-of-source-user-pre-logon/m-p/44502#M32662</guid>
      <dc:creator>nwsol</dc:creator>
      <dc:date>2012-11-26T07:52:40Z</dc:date>
    </item>
    <item>
      <title>Re: meaning of source-user pre-logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/meaning-of-source-user-pre-logon/m-p/44503#M32663</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Its a new feature in PANOS 5.0 which is described in the release notes:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;P&gt;Pre-logon Connection – The pre-logon option is part of the GlobalProtect agent configuration and is used to preserve pre-logon and post-logon services provided by a corporate infrastructure regardless of where the user machine is located. By doing this, a company can create a logical network that maintains the security and management features normally achieved by a physical network. Tunnel selection and establishment occurs pre-logon based on machine certificates. Examples of some of the services that can be maintained include: Active Directory group policy enforcement, drive mapping to server resources, and the ability to receive central software deployment downloads while working remotely. One specific example of how the pre-logon feature works is remote users forget their passwords, a helpdesk admin can reset their domain passwords and the users can log in with the new password because the VPN is already established and direct domain authentication will work. &lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So in short, Globalprotect can establish a VPN-tunnel before the user is authenticated in his/her machine (using machine cert).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This way you can for example set user=pre-logon to access AD, DNS, AV, WSUS. And the other rules can have user=ad-group(s) or user=userX,userY... for your other systems.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Nov 2012 08:31:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/meaning-of-source-user-pre-logon/m-p/44503#M32663</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-11-26T08:31:20Z</dc:date>
    </item>
    <item>
      <title>Re: meaning of source-user pre-logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/meaning-of-source-user-pre-logon/m-p/44504#M32664</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also an exert from the 5.0 admin guide:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;****************************************************************************************************************************************************************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="page" title="Page 336"&gt;&lt;/P&gt;&lt;DIV class="column"&gt;&lt;UL&gt;&lt;LI&gt; &lt;SPAN style="font-size: 9.000000pt; font-family: 'Palatino';"&gt;–&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="font-size: 9.000000pt; font-family: 'Palatino'; font-weight: bold;"&gt;pre-logon&lt;/SPAN&gt;&lt;SPAN style="font-size: 9.000000pt; font-family: 'Palatino';"&gt;—Select this option to preserve pre-logon and post-logon services provided by a corporate infrastructure regardless of where the user machine is located. GlobalProtect will establish a connection prior to user login to the computer. By doing this, a company can create a “logical network” that maintains the security &lt;/SPAN&gt; &lt;P&gt;&lt;SPAN style="font-size: 9.000000pt; font-family: 'Palatino';"&gt;and management features normally achieved by a physical network. Tunnel selection and establishment happens pre-logon based on machine certificates that need to be pre-deployed on client systems outside of GlobalProtect. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.000000pt; font-family: 'Palatino';"&gt;Examples of some of the services that can be maintained include: Active Directory group policy enforcement, maintaining drive mapping to server resources, and the ability to receive central software deployment downloads while remote. One specific example of how the pre-logon feature works is if a remote user forgets his/her password, since GlobalProtect would connect and use the cached credentials and establish a VPN before the login prompt even appears, a domain administrator could reset the user’s password as if they were logged in directly to a domain controller on the physical network. &lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;****************************************************************************************************************************************************************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Nov 2012 08:35:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/meaning-of-source-user-pre-logon/m-p/44504#M32664</guid>
      <dc:creator>James</dc:creator>
      <dc:date>2012-11-26T08:35:43Z</dc:date>
    </item>
    <item>
      <title>Re: meaning of source-user pre-logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/meaning-of-source-user-pre-logon/m-p/44505#M32665</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So, the pre-logon user value is linked to global protect?&lt;/P&gt;&lt;P&gt;I indeed found it in the admin guide under global protect. But there's no mention about the two things being linked.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Nov 2012 08:42:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/meaning-of-source-user-pre-logon/m-p/44505#M32665</guid>
      <dc:creator>nwsol</dc:creator>
      <dc:date>2012-11-26T08:42:14Z</dc:date>
    </item>
    <item>
      <title>Re: meaning of source-user pre-logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/meaning-of-source-user-pre-logon/m-p/44506#M32666</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm hitting the same issue. Can you or anyone clear up pre-logon definition? for example do I need to create a user called pre-logon on the PA and create a security rule matching the GP VPN or do I create a pre-logon user in AD? or do I not need to create a pre-logon user ID?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've got pre-logon partly working. The pre-logon feature fails with the error' user domain\pre-logon&amp;nbsp; failed authentication' invalid username/password'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However when I log into the laptop with my AD credentials the GP client authenticates.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rod&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Dec 2012 09:02:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/meaning-of-source-user-pre-logon/m-p/44506#M32666</guid>
      <dc:creator>djrodb</dc:creator>
      <dc:date>2012-12-10T09:02:36Z</dc:date>
    </item>
    <item>
      <title>Re: meaning of source-user pre-logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/meaning-of-source-user-pre-logon/m-p/44507#M32667</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've resolved my problem. Please refer to &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/message/21662#21662"&gt;https://live.paloaltonetworks.com/message/21662#21662&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Dec 2012 09:51:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/meaning-of-source-user-pre-logon/m-p/44507#M32667</guid>
      <dc:creator>djrodb</dc:creator>
      <dc:date>2012-12-10T09:51:32Z</dc:date>
    </item>
  </channel>
</rss>

