<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Anyone tried to connect GP from iphone/ipad with ClientCert? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-tried-to-connect-gp-from-iphone-ipad-with-clientcert/m-p/5801#M4242</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This has been setup and works with other customers, the following should help:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the PAN device &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;1: configure a Global Protect Portal (fairly simple and straight forward, refer to the Global Protect setup doc) &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;2: configure a Global Protect Gateway (this is where you get into the Xauth feature needed for iOS VPN) &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;A: server cert, authentication setup is as usual, do not use a client cert &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;B: enable tunnel mode &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;C: enable X-auth support (IPSEC will already be enabled, leave this as-is) &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;&lt;span class="lia-unicode-emoji" title=":anguished_face:"&gt;😧&lt;/span&gt; make up a group name and a group password, leave ‘skip auth on IKE Rekey’ enabled &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;E: tunnel Gateway: I used the same as my GP Portal &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;F: client configuration tab of the GP gateway is more or less the same as NetConnect setup parameters so I will not cover them here &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;G: iOS VPN does not use HIP so do NOT create any HIP profiles &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;3: make sure you have security policy and NAT policy configured as needed &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;4: commit &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the iOS device: &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;General -&amp;gt; Network -&amp;gt; VPN -&amp;gt; Add a VPN Configuration &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;Select the IPSec tab &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;Description: choose a name &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;Server: the IP address or FQDN of your GP Portal &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;Account: username for VPN access &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;Password: password for the user in previous step &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;Use certificate: greyed out on my setup (I am not sure if we can enable this on iOS, need to do research) &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;Group name: use the same group name you created on the GP Gateway &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;Secret: the group password from your GP Gateway &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;Save the config &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;Connect the VPN &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;Test connectivity in your web browser on the iOS device. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 24 Jan 2012 21:31:02 GMT</pubDate>
    <dc:creator>jdelio</dc:creator>
    <dc:date>2012-01-24T21:31:02Z</dc:date>
    <item>
      <title>Anyone tried to connect GP from iphone/ipad with ClientCert?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-tried-to-connect-gp-from-iphone-ipad-with-clientcert/m-p/5800#M4241</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm tring to connect GP from iPhone5 and iPad4.3.3 with Client Cert Auth.&lt;/P&gt;&lt;P&gt;I can't see the establishment of IPSec VPN, however, I could establish VPN from Windows with same client cert.&lt;/P&gt;&lt;P&gt;I want to see the working sample cofiguration.&lt;/P&gt;&lt;P&gt;Could anyone share the information?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My testbed:&lt;/P&gt;&lt;P&gt;-PA-5020 v4.1.1&lt;/P&gt;&lt;P&gt;-GP v1.1.1&lt;/P&gt;&lt;P&gt;-Windows 2003R2 as Client Cert CA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BTW, I know the following document and could not work well.&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1972"&gt;https://live.paloaltonetworks.com/docs/DOC-1972&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;﻿&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Emr&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jan 2012 07:56:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-tried-to-connect-gp-from-iphone-ipad-with-clientcert/m-p/5800#M4241</guid>
      <dc:creator>emr_1</dc:creator>
      <dc:date>2012-01-04T07:56:25Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone tried to connect GP from iphone/ipad with ClientCert?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-tried-to-connect-gp-from-iphone-ipad-with-clientcert/m-p/5801#M4242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This has been setup and works with other customers, the following should help:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the PAN device &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;1: configure a Global Protect Portal (fairly simple and straight forward, refer to the Global Protect setup doc) &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;2: configure a Global Protect Gateway (this is where you get into the Xauth feature needed for iOS VPN) &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;A: server cert, authentication setup is as usual, do not use a client cert &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;B: enable tunnel mode &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;C: enable X-auth support (IPSEC will already be enabled, leave this as-is) &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;&lt;span class="lia-unicode-emoji" title=":anguished_face:"&gt;😧&lt;/span&gt; make up a group name and a group password, leave ‘skip auth on IKE Rekey’ enabled &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;E: tunnel Gateway: I used the same as my GP Portal &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;F: client configuration tab of the GP gateway is more or less the same as NetConnect setup parameters so I will not cover them here &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;G: iOS VPN does not use HIP so do NOT create any HIP profiles &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;3: make sure you have security policy and NAT policy configured as needed &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;4: commit &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the iOS device: &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;General -&amp;gt; Network -&amp;gt; VPN -&amp;gt; Add a VPN Configuration &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;Select the IPSec tab &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;Description: choose a name &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;Server: the IP address or FQDN of your GP Portal &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;Account: username for VPN access &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;Password: password for the user in previous step &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;Use certificate: greyed out on my setup (I am not sure if we can enable this on iOS, need to do research) &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;Group name: use the same group name you created on the GP Gateway &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;Secret: the group password from your GP Gateway &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;Save the config &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;Connect the VPN &lt;BR style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #e3f3ff;" /&gt;Test connectivity in your web browser on the iOS device. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Jan 2012 21:31:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-tried-to-connect-gp-from-iphone-ipad-with-clientcert/m-p/5801#M4242</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2012-01-24T21:31:02Z</dc:date>
    </item>
  </channel>
</rss>

