<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is there an idiots guide to deploying certificate-based pre-logon for Global protect? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-an-idiots-guide-to-deploying-certificate-based-pre/m-p/4606#M3380</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;
&lt;P&gt;nato wrote:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;this didn't help? if not, create a case after you're initial config and we can assist further&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;A _jive_internal="true" data-containerid="2027" data-containertype="14" data-objectid="5229" data-objecttype="102" href="https://live.paloaltonetworks.com/docs/DOC-5229"&gt;How To Configure GlobalProtect SSO With Pre-Logon Access Using Self-Signed Certificates&lt;/A&gt;&lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That wasn't the doc I found and was referring to - but it looks like the doc I need!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 29 Apr 2014 23:03:42 GMT</pubDate>
    <dc:creator>darren_g</dc:creator>
    <dc:date>2014-04-29T23:03:42Z</dc:date>
    <item>
      <title>Is there an idiots guide to deploying certificate-based pre-logon for Global protect?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-an-idiots-guide-to-deploying-certificate-based-pre/m-p/4603#M3377</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Folks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As the subject requests, is there an "idiots guide" to deploying certificate-based pre-login for Global Protect?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My boss wants me to implement it so that pc's which are VPN-only connected can run domain scripts (machine policies) which only run on login - but you obviously don't connect to the domain until *after* you've logged in locally to the PC in the case of a VPN connected client - which means we need to have the PC connected to the VPN *before* login, so it can run scripts when the user actually logs in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've looked through the docs a bit, but can;t get my head around a few things - mainly, how you create and deploy the certificates which the PC's use to verify/connect to the firewall before the user logs in and supplies actual credentials to Global Protect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any pointers appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Apr 2014 01:48:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-an-idiots-guide-to-deploying-certificate-based-pre/m-p/4603#M3377</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2014-04-29T01:48:53Z</dc:date>
    </item>
    <item>
      <title>Re: Is there an idiots guide to deploying certificate-based pre-logon for Global protect?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-an-idiots-guide-to-deploying-certificate-based-pre/m-p/4604#M3378</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;this didn't help? if not, create a case after you're initial config and we can assist further&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-5229"&gt;How To Configure GlobalProtect SSO With Pre-Logon Access Using Self-Signed Certificates&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Apr 2014 13:59:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-an-idiots-guide-to-deploying-certificate-based-pre/m-p/4604#M3378</guid>
      <dc:creator>gswcowboy</dc:creator>
      <dc:date>2014-04-29T13:59:50Z</dc:date>
    </item>
    <item>
      <title>Re: Is there an idiots guide to deploying certificate-based pre-logon for Global protect?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-an-idiots-guide-to-deploying-certificate-based-pre/m-p/4605#M3379</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote" modifiedtitle="true"&gt;
&lt;P&gt;darren.g wrote:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;mainly, how you create and deploy the certificates which the PC's use to verify/connect to the firewall before the user logs in and supplies actual credentials to Global Protect.&lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For certificate authentication on a windows domain you can use group policy to automatically create the certificates and auto enroll the domain computers.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://technet.microsoft.com/en-us/library/cc947849%28v=ws.10%29.aspx" title="http://technet.microsoft.com/en-us/library/cc947849%28v=ws.10%29.aspx"&gt;Configure Group Policy to Autoenroll and Deploy Certificates&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With windows GINA pre login you essentially connect the login process on the computer to the creation of the vpn connection at login time.&amp;nbsp; This way you do get the benefits of on network login from the vpn connected computers. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Apr 2014 19:44:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-an-idiots-guide-to-deploying-certificate-based-pre/m-p/4605#M3379</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-04-29T19:44:06Z</dc:date>
    </item>
    <item>
      <title>Re: Is there an idiots guide to deploying certificate-based pre-logon for Global protect?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-an-idiots-guide-to-deploying-certificate-based-pre/m-p/4606#M3380</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;
&lt;P&gt;nato wrote:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;this didn't help? if not, create a case after you're initial config and we can assist further&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;A _jive_internal="true" data-containerid="2027" data-containertype="14" data-objectid="5229" data-objecttype="102" href="https://live.paloaltonetworks.com/docs/DOC-5229"&gt;How To Configure GlobalProtect SSO With Pre-Logon Access Using Self-Signed Certificates&lt;/A&gt;&lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That wasn't the doc I found and was referring to - but it looks like the doc I need!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Apr 2014 23:03:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-an-idiots-guide-to-deploying-certificate-based-pre/m-p/4606#M3380</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2014-04-29T23:03:42Z</dc:date>
    </item>
    <item>
      <title>Re: Is there an idiots guide to deploying certificate-based pre-logon for Global protect?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-an-idiots-guide-to-deploying-certificate-based-pre/m-p/4607#M3381</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No prob. If you get stuck, please open a case so we can rectify issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Apr 2014 15:37:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-an-idiots-guide-to-deploying-certificate-based-pre/m-p/4607#M3381</guid>
      <dc:creator>gswcowboy</dc:creator>
      <dc:date>2014-04-30T15:37:50Z</dc:date>
    </item>
  </channel>
</rss>

