<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What is the Agent User Override Key used for in GlobalProtect in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-agent-user-override-key-used-for-in-globalprotect/m-p/205621#M60356</link>
    <description>&lt;P&gt;you can set the agent (in the agent config) to allow, disallow, or allow with comment/passcode/ticket the ability to diable the VPN client (this could be a concern if your policy is to have an 'always-on' stance and the user need/wants to disable the VPN client to get to local resources or other reasons&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the override key is the latter option, that requires an interaction with a firewall admin or operator that is able to provide a responce, the one before requires the knowledge of a password and the 3rd last simply requires the user to fill out a comment (which is logged) before being able to disable the VPN client&lt;/P&gt;</description>
    <pubDate>Thu, 15 Mar 2018 12:18:18 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2018-03-15T12:18:18Z</dc:date>
    <item>
      <title>What is the Agent User Override Key used for in GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-agent-user-override-key-used-for-in-globalprotect/m-p/204561#M60160</link>
      <description>&lt;P&gt;In the GlobalProtect Portal config(under the Agent tab), there's a setting for "Agent User Override Key".&amp;nbsp; I'm finding conflicting information on what this might be used for.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The firewall's help file says this field is used for disabling GlobalProtect with a Ticket....&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;"after a user attempts to disable GlobalProtect, the endpoint displays an 8-character, hexadecimal, ticket request number. The user then contacts the firewall administrator or support team (preferably by phone for security) and provides this number. The administrator or support person types the hexadecimal ticket request number into the&amp;nbsp;&lt;SPAN class="uicontrol"&gt;Agent User Override Key&lt;/SPAN&gt;&amp;nbsp;field (in the GlobalProtect agent configuration&amp;nbsp;&lt;SPAN class="uicontrol"&gt;Agent&lt;/SPAN&gt;&amp;nbsp;tab) so they can see the ticket number (also an 8-character hexadecimal number). The administrator or support person then provides this ticket number to the user who then enters the ticket number into the challenge field to disable the agent."&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;...but, the online GlobalProtect admin guide gives different instructions for disabling GlobalProtect with a Ticket...&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;"the disconnect action triggers the agent to generate a Request Number. The end user must then communicate the Request Number to the administrator. The administrator then clicks &lt;SPAN class="ph uicontrol"&gt;Generate Ticket&lt;/SPAN&gt; on the &lt;SPAN class="ph menucascade"&gt;&lt;SPAN class="ph uicontrol"&gt;Network&lt;/SPAN&gt;&lt;SPAN class="ph uicontrol"&gt;GlobalProtect&lt;/SPAN&gt;&lt;SPAN class="ph uicontrol"&gt;Portals&lt;/SPAN&gt;&lt;/SPAN&gt; page and enters the request number from the user to generate the ticket. The administrator then provides the ticket to the end user, who enters it into the Disable GlobalProtect dialog to enable the agent to disconnect."&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;(&lt;A href="https://www.paloaltonetworks.com/documentation/80/globalprotect/globalprotect-admin-guide/globalprotect-portals/define-the-globalprotect-client-authentication-configurations/customize-the-globalprotect-agent#id0cd8a407-0254-4fca-89a1-fc143b3ab483" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/globalprotect/globalprotect-admin-guide/globalprotect-portals/define-the-globalprotect-client-authentication-configurations/customize-the-globalprotect-agent#id0cd8a407-0254-4fca-89a1-fc143b3ab483&lt;/A&gt;) &lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;...it looks like the online admin guide might be more accurate.&amp;nbsp; So then, what is the purpose of the "Agent User Override Key" field?&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AgentUserOverrideKey.PNG" style="width: 440px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14183iC0BE2E2E0F55B847/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="AgentUserOverrideKey.PNG" alt="AgentUserOverrideKey.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Mar 2018 14:36:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-agent-user-override-key-used-for-in-globalprotect/m-p/204561#M60160</guid>
      <dc:creator>jambulo</dc:creator>
      <dc:date>2018-03-09T14:36:45Z</dc:date>
    </item>
    <item>
      <title>Re: What is the Agent User Override Key used for in GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-agent-user-override-key-used-for-in-globalprotect/m-p/205621#M60356</link>
      <description>&lt;P&gt;you can set the agent (in the agent config) to allow, disallow, or allow with comment/passcode/ticket the ability to diable the VPN client (this could be a concern if your policy is to have an 'always-on' stance and the user need/wants to disable the VPN client to get to local resources or other reasons&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the override key is the latter option, that requires an interaction with a firewall admin or operator that is able to provide a responce, the one before requires the knowledge of a password and the 3rd last simply requires the user to fill out a comment (which is logged) before being able to disable the VPN client&lt;/P&gt;</description>
      <pubDate>Thu, 15 Mar 2018 12:18:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-agent-user-override-key-used-for-in-globalprotect/m-p/205621#M60356</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-03-15T12:18:18Z</dc:date>
    </item>
    <item>
      <title>Re: What is the Agent User Override Key used for in GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-agent-user-override-key-used-for-in-globalprotect/m-p/205694#M60380</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;So what's the difference between "User Agent Override Key" and the "Generate Ticket" button(under Portals)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would you be able to explain to me the process of disabling GP when "allow with ticket" is enabled?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Mar 2018 16:31:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-agent-user-override-key-used-for-in-globalprotect/m-p/205694#M60380</guid>
      <dc:creator>jambulo</dc:creator>
      <dc:date>2018-03-15T16:31:18Z</dc:date>
    </item>
    <item>
      <title>Re: What is the Agent User Override Key used for in GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-agent-user-override-key-used-for-in-globalprotect/m-p/205881#M60419</link>
      <description>&lt;P&gt;ok I've gone through the process&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the 'user agent override key' is more of a base key (like the master key) that sets the root for the ticket system&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;once the config is running, the user requests the disable and gets a 2 part challenge that the admin can input into the 'generate ticket' and then get a responce which the user needs to complete the transaction, the 'user override key' serves as the 'public key' for this transaction&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i'll see if i can get the documentation updated&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GlobalProtect Ticket.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14270iF42866E8FEF0A6F0/image-size/large?v=v2&amp;amp;px=999" role="button" title="GlobalProtect Ticket.png" alt="GlobalProtect Ticket.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 10:59:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-agent-user-override-key-used-for-in-globalprotect/m-p/205881#M60419</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-03-16T10:59:17Z</dc:date>
    </item>
    <item>
      <title>Re: What is the Agent User Override Key used for in GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-agent-user-override-key-used-for-in-globalprotect/m-p/205987#M60469</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;Ok, so at no point in the disable process, will the user, or firewall admin, need to enter in this Agent User Override Key? Are you saying this "user override key" is just being used to validate the connection(much like an SSL certificate on a web server is used to validate the connection)?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 15:58:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-agent-user-override-key-used-for-in-globalprotect/m-p/205987#M60469</guid>
      <dc:creator>jambulo</dc:creator>
      <dc:date>2018-03-16T15:58:23Z</dc:date>
    </item>
    <item>
      <title>Re: What is the Agent User Override Key used for in GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-agent-user-override-key-used-for-in-globalprotect/m-p/205991#M60471</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7542"&gt;@jambulo&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;it allows you to change the system default 'key' for the ticket system with one you decide (kind of like a certificate authority used to sign the certificates on the web server)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is part of the system configuration, not part of the ticket transaction&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 16:06:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-agent-user-override-key-used-for-in-globalprotect/m-p/205991#M60471</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-03-16T16:06:50Z</dc:date>
    </item>
  </channel>
</rss>

