<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: globalprotect key in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/130279#M46826</link>
    <description>&lt;P&gt;yes I showed them through the packet capture and the monitor logs that the first connection is a ssl one. thanks reaper I really like your new avatar&lt;/P&gt;</description>
    <pubDate>Thu, 01 Dec 2016 14:10:44 GMT</pubDate>
    <dc:creator>jdprovine</dc:creator>
    <dc:date>2016-12-01T14:10:44Z</dc:date>
    <item>
      <title>globalprotect key</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/129637#M46775</link>
      <description>&lt;P&gt;When I install the globalprotect client on a pc I never have to enter a key, how and when does the key get passed&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2016 17:09:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/129637#M46775</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-11-29T17:09:23Z</dc:date>
    </item>
    <item>
      <title>Re: globalprotect key</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/129648#M46776</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine﻿&lt;/a&gt;&amp;nbsp;can you expand by what you mean by 'key'?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2016 17:43:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/129648#M46776</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-11-29T17:43:03Z</dc:date>
    </item>
    <item>
      <title>Re: globalprotect key</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/129672#M46778</link>
      <description>&lt;P&gt;security key like for cisco vpn client. There has to be a way for global protect to secure the connections&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2016 19:02:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/129672#M46778</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-11-29T19:02:25Z</dc:date>
    </item>
    <item>
      <title>Re: globalprotect key</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/129692#M46780</link>
      <description>&lt;P&gt;The first time you put in your password to connect, what keeps that from being clear text how is it encrypted. We have group name and password setup but that is no where on the client software that is installed on the pc&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2016 20:16:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/129692#M46780</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-11-29T20:16:48Z</dc:date>
    </item>
    <item>
      <title>Re: globalprotect key</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/129787#M46783</link>
      <description>&lt;P&gt;I hope its future of Global protect, check this configuration under&amp;nbsp;&lt;/P&gt;&lt;P&gt;Network-&amp;gt;Gllbal protect-&amp;gt;gateway-&amp;gt;selcet gateway-&amp;gt;agent-&amp;gt;external gateway&lt;/P&gt;&lt;P&gt;check is it manuall or not?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2016 07:56:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/129787#M46783</guid>
      <dc:creator>KotreshaMC</dc:creator>
      <dc:date>2016-11-30T07:56:41Z</dc:date>
    </item>
    <item>
      <title>Re: globalprotect key</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/129798#M46786</link>
      <description>&lt;P&gt;GlobalProtect uses certificates to secure the connection, rather than a preshared key &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2016 09:27:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/129798#M46786</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-11-30T09:27:46Z</dc:date>
    </item>
    <item>
      <title>Re: globalprotect key</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/129885#M46788</link>
      <description>&lt;P&gt;so if you don't put on a cert then your connection is not secure&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2016 14:45:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/129885#M46788</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-11-30T14:45:19Z</dc:date>
    </item>
    <item>
      <title>Re: globalprotect key</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/129886#M46789</link>
      <description>&lt;P&gt;then the device's default certificates will be used &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2016 14:46:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/129886#M46789</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-11-30T14:46:37Z</dc:date>
    </item>
    <item>
      <title>Re: globalprotect key</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/129888#M46790</link>
      <description>&lt;P&gt;you mean the portal configuration not the gateway configuration right?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2016 14:48:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/129888#M46790</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-11-30T14:48:41Z</dc:date>
    </item>
    <item>
      <title>Re: globalprotect key</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/129892#M46791</link>
      <description>&lt;P&gt;We are using IPSec connections not ssl does that make a difference? My main concern is the first time then connect using the VPN that their password is encrypted and then does it download the key after the first connection&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2016 14:51:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/129892#M46791</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-11-30T14:51:59Z</dc:date>
    </item>
    <item>
      <title>Re: globalprotect key</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/129893#M46792</link>
      <description>&lt;P&gt;there's several bits and pieces to it, please check out &lt;A href="https://www.paloaltonetworks.com/documentation/60/globalprotect/global_protect_6-0/set-up-the-globalprotect-infrastructure/globalprotect-certificate-best-practices" target="_blank"&gt;this bit in the admin guide&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;hopefully it helps clarify what you're looking for&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2016 14:55:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/129893#M46792</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-11-30T14:55:02Z</dc:date>
    </item>
    <item>
      <title>Re: globalprotect key</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/129902#M46793</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt; wrote:&lt;BR /&gt;
&lt;P&gt;We are using IPSec connections not ssl does that make a difference? My main concern is the first time then connect using the VPN that their password is encrypted and then does it download the key after the first connection&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;The first time you're going to set up an ssl connection, using the server certificate attached to the portal to get to the config file, all communication will always be encrypted (ssl uses, at the least, a server and client hello where encryption is negotiated and established before any user information is transmitted)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;client to server will always be encrypted even before username and password are shared&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2016 14:59:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/129902#M46793</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-11-30T14:59:51Z</dc:date>
    </item>
    <item>
      <title>Re: globalprotect key</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/129903#M46794</link>
      <description>&lt;P&gt;First glance at the document not sure it answers my question but I will give it another look and see. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2016 15:01:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/129903#M46794</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-11-30T15:01:29Z</dc:date>
    </item>
    <item>
      <title>Re: globalprotect key</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/129911#M46795</link>
      <description>&lt;P&gt;I can always cound on good information from you reaper &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2016 15:14:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/129911#M46795</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-11-30T15:14:23Z</dc:date>
    </item>
    <item>
      <title>Re: globalprotect key</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/129914#M46796</link>
      <description>&lt;P&gt;Is there a log or anything where I can get the information you are talking about to show my boss that this is occuring&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2016 15:17:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/129914#M46796</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-11-30T15:17:11Z</dc:date>
    </item>
    <item>
      <title>Re: globalprotect key</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/129923#M46797</link>
      <description>&lt;P&gt;ehm&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;well you can slap him with the SSL rfc &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt; (rfc 6101 and 5246 , if you realy want to know &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; )&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the globalprotect ssl relies on exactly the same mechanism any website uses to establish a connection, so you do the&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-3 way TCP handshake,&lt;/P&gt;
&lt;P&gt;-client hello (i can accommodate these encryption algorythms),&lt;/P&gt;
&lt;P&gt;-server hello (i prefer this 'ciphersuite', here is my certificate, and do you happen to have a client cert of your own)&lt;/P&gt;
&lt;P&gt;-client key exchange w/ client certificate if you set it up&amp;nbsp;(send secret key info encrypted with server's public key, based off of the server certificate)&lt;/P&gt;
&lt;P&gt;-server verifies and finishes&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-communication is encrypted&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;---- and here globalprotect kicks in----&lt;/P&gt;
&lt;P&gt;globalprotect sends username/password&lt;/P&gt;
&lt;P&gt;GP server authenticates&lt;/P&gt;
&lt;P&gt;etc&lt;/P&gt;
&lt;P&gt;etc&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you do a packetcapture of the communication between the client and GP portal, that first sequence of events is visible (the client/server hellos&amp;nbsp;and all), the bit where GP sends user/passwd information will not be visible as it is encrypted&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope this makes more sense ? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2016 15:48:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/129923#M46797</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-11-30T15:48:02Z</dc:date>
    </item>
    <item>
      <title>Re: globalprotect key</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/129930#M46798</link>
      <description>&lt;P&gt;The real question came up when we do installs of the client on a users pc and there is no place to enter a key on the client like there is with a cisco vpn client, so it appears to them that there is no key to pass and no way to encrypt the users password&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2016 15:57:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/129930#M46798</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-11-30T15:57:11Z</dc:date>
    </item>
    <item>
      <title>Re: globalprotect key</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/129934#M46799</link>
      <description>&lt;P&gt;so when he says to me we aren't using ssl we are using IPsec? How do I answer that?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2016 16:05:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/129934#M46799</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-11-30T16:05:40Z</dc:date>
    </item>
    <item>
      <title>Re: globalprotect key</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/129997#M46805</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine﻿&lt;/a&gt;&amp;nbsp;This page might get you what you need to know: &lt;A href="https://www.paloaltonetworks.com/documentation/60/globalprotect/global_protect_6-0/set-up-the-globalprotect-infrastructure/reference-globalprotect-agent-cryptographic-functions#42969" target="_blank"&gt;LINK&lt;/A&gt;. Take a look at the Network tab under IPSec Crypto and you'll see that the default key (the one I believe reaper referenced) uses ases-128-cbc and 3des with sha1 authentication.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2016 20:02:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/129997#M46805</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-11-30T20:02:25Z</dc:date>
    </item>
    <item>
      <title>Re: globalprotect key</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/130003#M46807</link>
      <description>&lt;P&gt;I did a packet capture as well as verified that the user through the GP client is connecting via SSL (no clear password) and then the key exchange occurs which is found in the configuration on the firewall. I think the fact that you can't find a place to manually enter the key on the GP client was what was tripping my coworkers up.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2016 20:46:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-key/m-p/130003#M46807</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2016-11-30T20:46:28Z</dc:date>
    </item>
  </channel>
</rss>

