<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Switching GP from User (Always On) to Pre Logon in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/switching-gp-from-user-always-on-to-pre-logon/m-p/234520#M67228</link>
    <description>&lt;P&gt;This one has me confused...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;'s link&amp;nbsp; "&lt;SPAN&gt;A pre-logon VPN tunnel has no username association because the user has not logged in.&amp;nbsp;"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When you're doing "pre-login" that inherently means no known user.&amp;nbsp; So I'm confused&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/46057"&gt;@MikeC&lt;/a&gt;&amp;nbsp;when you say you want to establish a VPN tunnel, but you also want to user user ID and PW.&amp;nbsp; "I want to establish the VPN connection prior to login but I also want to make use of username/password."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Do you mean once the user supplies credentials to the computer you want GP to also ask for creds from the user to make the connection to the gateway?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 08 Oct 2018 23:26:10 GMT</pubDate>
    <dc:creator>Brandon_Wertz</dc:creator>
    <dc:date>2018-10-08T23:26:10Z</dc:date>
    <item>
      <title>Switching GP from User (Always On) to Pre Logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/switching-gp-from-user-always-on-to-pre-logon/m-p/234038#M67084</link>
      <description>I’m looking at switching GP from User (Always On) to Pre-Logon (always On).&lt;BR /&gt;&lt;BR /&gt;Current setup is one firewall serving as both the portal and gateway. I’m doing both username/password with client user certificates for multiple authentication factors, as this is a requirement.&lt;BR /&gt;&lt;BR /&gt;I deployed a computer cert to test Pre-Logon but it doesnt seem to work as expected it too. I thought it would be like a competitor’s “secure domain login” feature. I want to establish the VPN connection prior to login but I also want to make use of username/password. Also, the vpn connection must be always on. Pre-logon with OnDemand is not an option.&lt;BR /&gt;&lt;BR /&gt;Is this possible?</description>
      <pubDate>Fri, 05 Oct 2018 04:30:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/switching-gp-from-user-always-on-to-pre-logon/m-p/234038#M67084</guid>
      <dc:creator>MikeC</dc:creator>
      <dc:date>2018-10-05T04:30:12Z</dc:date>
    </item>
    <item>
      <title>Re: Switching GP from User (Always On) to Pre Logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/switching-gp-from-user-always-on-to-pre-logon/m-p/234250#M67155</link>
      <description>&lt;P&gt;Anyone? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Oct 2018 16:07:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/switching-gp-from-user-always-on-to-pre-logon/m-p/234250#M67155</guid>
      <dc:creator>MikeC</dc:creator>
      <dc:date>2018-10-06T16:07:45Z</dc:date>
    </item>
    <item>
      <title>Re: Switching GP from User (Always On) to Pre Logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/switching-gp-from-user-always-on-to-pre-logon/m-p/234433#M67213</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Not sure if I am answering the correct question, but I would take a look at the following article:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/81/globalprotect/globalprotect-admin-guide/globalprotect-quick-configs/remote-access-vpn-with-pre-logon.html" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/81/globalprotect/globalprotect-admin-guide/globalprotect-quick-configs/remote-access-vpn-with-pre-logon.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps,&lt;/P&gt;</description>
      <pubDate>Mon, 08 Oct 2018 14:12:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/switching-gp-from-user-always-on-to-pre-logon/m-p/234433#M67213</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-10-08T14:12:45Z</dc:date>
    </item>
    <item>
      <title>Re: Switching GP from User (Always On) to Pre Logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/switching-gp-from-user-always-on-to-pre-logon/m-p/234520#M67228</link>
      <description>&lt;P&gt;This one has me confused...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;'s link&amp;nbsp; "&lt;SPAN&gt;A pre-logon VPN tunnel has no username association because the user has not logged in.&amp;nbsp;"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When you're doing "pre-login" that inherently means no known user.&amp;nbsp; So I'm confused&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/46057"&gt;@MikeC&lt;/a&gt;&amp;nbsp;when you say you want to establish a VPN tunnel, but you also want to user user ID and PW.&amp;nbsp; "I want to establish the VPN connection prior to login but I also want to make use of username/password."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Do you mean once the user supplies credentials to the computer you want GP to also ask for creds from the user to make the connection to the gateway?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Oct 2018 23:26:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/switching-gp-from-user-always-on-to-pre-logon/m-p/234520#M67228</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2018-10-08T23:26:10Z</dc:date>
    </item>
    <item>
      <title>Re: Switching GP from User (Always On) to Pre Logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/switching-gp-from-user-always-on-to-pre-logon/m-p/234528#M67231</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz&lt;/a&gt;&amp;nbsp;I was really comparing pre-logon to checkpoint's "secure domain logon" feature. With CP, the computer would boot up, user would enter their windows login info, which would then prompt the CP VPN to pop up, user would enter vpn credentials, vpn would connect and then log into windows.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm currently using "Always on" with both username/pw and client certificates for multiple factors requirement. Initially, looking at pre-logon, it seemed it only uses a computer certificate, so can't really have multiple factor auth (not counting windows login). Based on the link &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;posted, it seems I can use computer cert to establish the VPN and also use username/pw + client cert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also use Internal Host Detection for when laptops are in the office, not sure if that will be an issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to test what happens if there is no internet connection when the computer boots up. I have a requirement to make sure VPN connects if there is an internet connection. Will it automatically connect, or will it require the user to hit connect&lt;/P&gt;</description>
      <pubDate>Tue, 09 Oct 2018 00:49:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/switching-gp-from-user-always-on-to-pre-logon/m-p/234528#M67231</guid>
      <dc:creator>MikeC</dc:creator>
      <dc:date>2018-10-09T00:49:13Z</dc:date>
    </item>
    <item>
      <title>Re: Switching GP from User (Always On) to Pre Logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/switching-gp-from-user-always-on-to-pre-logon/m-p/234529#M67232</link>
      <description>The way "pre-logon" works is it uses the machines certificate to establish a VPN tunnel at boot up. The user doesn't need to click or connect to anything, click a button (et al).&lt;BR /&gt;&lt;BR /&gt;The service starts at start up and you can see at the login screen that the VPN tunnel has been established by looking at other "login options."</description>
      <pubDate>Tue, 09 Oct 2018 00:55:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/switching-gp-from-user-always-on-to-pre-logon/m-p/234529#M67232</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2018-10-09T00:55:12Z</dc:date>
    </item>
    <item>
      <title>Re: Switching GP from User (Always On) to Pre Logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/switching-gp-from-user-always-on-to-pre-logon/m-p/234530#M67233</link>
      <description>&lt;P&gt;Here's an example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/41/globalprotect/globalprotect-app-new-features/new-features-released-in-gp-agent-4_1/globalprotect-credential-provider-prelogon-connection-status" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/41/globalprotect/globalprotect-app-new-features/new-features-released-in-gp-agent-4_1/globalprotect-credential-provider-prelogon-connection-status&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Oct 2018 01:01:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/switching-gp-from-user-always-on-to-pre-logon/m-p/234530#M67233</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2018-10-09T01:01:47Z</dc:date>
    </item>
    <item>
      <title>Re: Switching GP from User (Always On) to Pre Logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/switching-gp-from-user-always-on-to-pre-logon/m-p/234531#M67234</link>
      <description>&lt;P&gt;Here's a pretty detailed example of the pre-logon config:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEYCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEYCA0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Of note there's security policy that you need to also have, that allows a "pre-logon" connection.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Oct 2018 01:06:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/switching-gp-from-user-always-on-to-pre-logon/m-p/234531#M67234</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2018-10-09T01:06:50Z</dc:date>
    </item>
    <item>
      <title>Re: Switching GP from User (Always On) to Pre Logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/switching-gp-from-user-always-on-to-pre-logon/m-p/234532#M67235</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz&lt;/a&gt;&amp;nbsp;thanks for the links, I'll check them out.&amp;nbsp; I guess the way it works is part of my issue, I can't really have multiple factors&amp;nbsp;before establishing the&amp;nbsp;VPN.&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What about when these machines are on the internal network? the VPN is still going to connect? That would be unnessary&lt;/P&gt;</description>
      <pubDate>Tue, 09 Oct 2018 01:15:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/switching-gp-from-user-always-on-to-pre-logon/m-p/234532#M67235</guid>
      <dc:creator>MikeC</dc:creator>
      <dc:date>2018-10-09T01:15:26Z</dc:date>
    </item>
    <item>
      <title>Re: Switching GP from User (Always On) to Pre Logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/switching-gp-from-user-always-on-to-pre-logon/m-p/234534#M67236</link>
      <description>That's where internal host detection comes into play. The VPN tunnel won't come up because the PCs ip would tell GP that the host is internal</description>
      <pubDate>Tue, 09 Oct 2018 01:20:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/switching-gp-from-user-always-on-to-pre-logon/m-p/234534#M67236</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2018-10-09T01:20:24Z</dc:date>
    </item>
    <item>
      <title>Re: Switching GP from User (Always On) to Pre Logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/switching-gp-from-user-always-on-to-pre-logon/m-p/234535#M67237</link>
      <description>&lt;P&gt;That's what I was hoping you'd say.&amp;nbsp; I don't use internal gateways, but that never seemed to affect internal host detection for me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm going to spin this up in my lab right now.&amp;nbsp; Thanks for the help&lt;/P&gt;</description>
      <pubDate>Tue, 09 Oct 2018 01:26:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/switching-gp-from-user-always-on-to-pre-logon/m-p/234535#M67237</guid>
      <dc:creator>MikeC</dc:creator>
      <dc:date>2018-10-09T01:26:51Z</dc:date>
    </item>
  </channel>
</rss>

