<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect Prelogon - using non-cached AD account in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-prelogon-using-non-cached-ad-account/m-p/45364#M33342</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yea - the GP client does&amp;nbsp; run and say services connected after login.&amp;nbsp; I have one portal client config for prelogon&amp;nbsp; configured for ANY user/user group with SSO enabled &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My thinking is that because of the user account im testing with did not initially download the config settings it doesn't have a cookie but I thought if SSO is enabled it passes the user credentials used during login to the GP client.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 30 Jul 2015 17:07:01 GMT</pubDate>
    <dc:creator>sross79</dc:creator>
    <dc:date>2015-07-30T17:07:01Z</dc:date>
    <item>
      <title>GlobalProtect Prelogon - using non-cached AD account</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-prelogon-using-non-cached-ad-account/m-p/45360#M33338</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So i 've been having some issues getting GP prelogon working correctly.&amp;nbsp; As of right now - GP will make the VPN connection before logon(i am able to ping my device prior to logon) and after i login with a cached account it maintains its VPN connection and i have full network access, no issues. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, when i log in using a non-cached account - it creates a temp profile, while still maintaining the VPN connection.&amp;nbsp; I am under the impression that that prior to logon i have a network connection will full access(which i do) so i should be able to create a regular user profile.&amp;nbsp; My non-cached user account is obviously being authenticated but i am still getting a temp profile.&amp;nbsp;&amp;nbsp;&amp;nbsp; I do not see any errors in the system log and no traffic is being denied.&amp;nbsp; Only thing that sticks out is a few errors in the panGPS.log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(T2256) 07/09/15 13:05:41:193 Info ( 109): SSL connect failed (error:00000001:lib(0):func(0):reason(1))&lt;/P&gt;&lt;P&gt;(T2256) 07/09/15 13:05:41:193 Info ( 157): connect() failed&lt;/P&gt;&lt;P&gt;(T2256) 07/09/15 13:05:41:193 Error(5765): Protocol error. Check server certificate. Failed to ssl connect to 'xx.xxxxx.com:443', Disconect ssl and returns false.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which i don't understand because it still works technically. The server cert works fine i dont get any cert errors when i web browse to the address.&amp;nbsp; So any ideas on why i am getting a temp profile after i log in?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Jul 2015 21:30:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-prelogon-using-non-cached-ad-account/m-p/45360#M33338</guid>
      <dc:creator>sross79</dc:creator>
      <dc:date>2015-07-09T21:30:47Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Prelogon - using non-cached AD account</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-prelogon-using-non-cached-ad-account/m-p/45361#M33339</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi sross79&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First I have some questions:&lt;/P&gt;&lt;P&gt;What OS are you using?&lt;/P&gt;&lt;P&gt;What version of GP Client do you have installed?&lt;/P&gt;&lt;P&gt;Are you able to ping the computer over the VPN connection during the whole loginprocess?&lt;/P&gt;&lt;P&gt;Is it possible to map the drive of the computer while it is connected and no user is logged in?&lt;/P&gt;&lt;P&gt;(I assume this is working when you log in with this particular user while the computer is located in your corporate network?)&lt;/P&gt;&lt;P&gt;Do you also checked the thead log for blocked connections?&lt;/P&gt;&lt;P&gt;Do you habe this error messages before or after the userlogin?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you also could try if the connection is there without any deny entries in the log is decreasing the MTU size on the computer where you have installed GP.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Remo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Jul 2015 16:47:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-prelogon-using-non-cached-ad-account/m-p/45361#M33339</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2015-07-30T16:47:44Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Prelogon - using non-cached AD account</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-prelogon-using-non-cached-ad-account/m-p/45362#M33340</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi thanks for the Reply - I actually got it create a standard profile now.&amp;nbsp; It was an error on my part. I incorrectly deleted the profile.&amp;nbsp; Once deleted some registry keys it worked correctly. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem I have now - is that it doesn't switch to the logged in user from Prelogon. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So Prelogon is working correctly - I can ping the device prior to logon and full network access.&amp;nbsp; After I login, the prelogon user is still being used and it does not SSO to show the logged in user.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Jul 2015 16:57:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-prelogon-using-non-cached-ad-account/m-p/45362#M33340</guid>
      <dc:creator>sross79</dc:creator>
      <dc:date>2015-07-30T16:57:24Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Prelogon - using non-cached AD account</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-prelogon-using-non-cached-ad-account/m-p/45363#M33341</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does a GP Login window show up after you are logged in completely? Did you configre the client config in the portal configuration to use SSO for this particular user or only for the pre-logon user?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Jul 2015 17:02:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-prelogon-using-non-cached-ad-account/m-p/45363#M33341</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2015-07-30T17:02:31Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Prelogon - using non-cached AD account</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-prelogon-using-non-cached-ad-account/m-p/45364#M33342</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yea - the GP client does&amp;nbsp; run and say services connected after login.&amp;nbsp; I have one portal client config for prelogon&amp;nbsp; configured for ANY user/user group with SSO enabled &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My thinking is that because of the user account im testing with did not initially download the config settings it doesn't have a cookie but I thought if SSO is enabled it passes the user credentials used during login to the GP client.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Jul 2015 17:07:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-prelogon-using-non-cached-ad-account/m-p/45364#M33342</guid>
      <dc:creator>sross79</dc:creator>
      <dc:date>2015-07-30T17:07:01Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Prelogon - using non-cached AD account</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-prelogon-using-non-cached-ad-account/m-p/45365#M33343</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Depends on what login credential provider you used for logging in. This problem I had also&amp;nbsp; that it didnt pass the credentials even I had SSO configured&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Jul 2015 17:09:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-prelogon-using-non-cached-ad-account/m-p/45365#M33343</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2015-07-30T17:09:35Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Prelogon - using non-cached AD account</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-prelogon-using-non-cached-ad-account/m-p/45366#M33344</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not sure I follow - what do you mean login credential provider? Just windows 7 login screen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Jul 2015 17:12:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-prelogon-using-non-cached-ad-account/m-p/45366#M33344</guid>
      <dc:creator>sross79</dc:creator>
      <dc:date>2015-07-30T17:12:42Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Prelogon - using non-cached AD account</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-prelogon-using-non-cached-ad-account/m-p/45367#M33345</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think Palo creates his own login credential provider. So you have to make sure that you use the Global Protect login credential provider in order to make SSO work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On this picture you should see what I mean:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="cp-tiles.jpg" class="image-0 jive-image" src="https://ip1.i.lithium.com/e58147ba14c6d9f66557702492f68357a5ca96a9/68747470733a2f2f74777269676874736f6e2e66696c65732e776f726470726573732e636f6d2f323031322f30312f63702d74696c65732e6a7067" style="height: 232px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Jul 2015 18:42:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-prelogon-using-non-cached-ad-account/m-p/45367#M33345</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2015-07-30T18:42:31Z</dc:date>
    </item>
  </channel>
</rss>

