<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help - Certificate pre-login globalprotect VPN, with SAML tunnel adoption in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/help-certificate-pre-login-globalprotect-vpn-with-saml-tunnel/m-p/243135#M69514</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the reply,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The way i read the Palo KB article&amp;nbsp;&lt;SPAN&gt;&lt;STRONG&gt;GPC-3794 &lt;/STRONG&gt;suggests that this is a current and supported config? Could&amp;nbsp;you please tell me why you don't think this is supported?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't suppose you have any ideas on how to get to the same level of functionality with a currently supported solution?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 13 Dec 2018 10:19:44 GMT</pubDate>
    <dc:creator>darrencassano</dc:creator>
    <dc:date>2018-12-13T10:19:44Z</dc:date>
    <item>
      <title>Help - Certificate pre-login globalprotect VPN, with SAML tunnel adoption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-certificate-pre-login-globalprotect-vpn-with-saml-tunnel/m-p/242985#M69477</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are working to create a global protect vpn connetion between&amp;nbsp;our windows 10 devices and the PA FW ver. 8.0.1.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The VPN tunnel needs to use a&amp;nbsp;pre-login tunnel initially (authenticating via the machine cert) which when the user logs in re-authenticates the user using SAML (Azure via ADFS) and renames the existing VPN tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have an existing ADFS / Azure SAML environment which is working for other 3rd party app connections.&lt;/P&gt;&lt;P&gt;Windows Client devices currently use globalprotect client version 4.1.1-14&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone successfully completed pre-login passing over to SAML user login? Could you please share an anonymised config? The pre-login VPN is up but we are struggling to configure the 2nd part without having the VPN drop (rather than renamed).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Palo Alto known issues log suggests that Palo have this working, but there is no configuration example as to how they got there that we can reference to assist us.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 12 Dec 2018 11:58:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-certificate-pre-login-globalprotect-vpn-with-saml-tunnel/m-p/242985#M69477</guid>
      <dc:creator>darrencassano</dc:creator>
      <dc:date>2018-12-12T11:58:20Z</dc:date>
    </item>
    <item>
      <title>Re: Help - Certificate pre-login globalprotect VPN, with SAML tunnel adoption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-certificate-pre-login-globalprotect-vpn-with-saml-tunnel/m-p/243010#M69478</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/103167"&gt;@darrencassano&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Bad news for you ... this is not supported yet ...&lt;/P&gt;</description>
      <pubDate>Wed, 12 Dec 2018 15:17:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-certificate-pre-login-globalprotect-vpn-with-saml-tunnel/m-p/243010#M69478</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-12-12T15:17:34Z</dc:date>
    </item>
    <item>
      <title>Re: Help - Certificate pre-login globalprotect VPN, with SAML tunnel adoption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-certificate-pre-login-globalprotect-vpn-with-saml-tunnel/m-p/243135#M69514</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the reply,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The way i read the Palo KB article&amp;nbsp;&lt;SPAN&gt;&lt;STRONG&gt;GPC-3794 &lt;/STRONG&gt;suggests that this is a current and supported config? Could&amp;nbsp;you please tell me why you don't think this is supported?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't suppose you have any ideas on how to get to the same level of functionality with a currently supported solution?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Dec 2018 10:19:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-certificate-pre-login-globalprotect-vpn-with-saml-tunnel/m-p/243135#M69514</guid>
      <dc:creator>darrencassano</dc:creator>
      <dc:date>2018-12-13T10:19:44Z</dc:date>
    </item>
    <item>
      <title>Re: Help - Certificate pre-login globalprotect VPN, with SAML tunnel adoption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-certificate-pre-login-globalprotect-vpn-with-saml-tunnel/m-p/243139#M69516</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/103167"&gt;@darrencassano&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;GPC-3794 is still in the known issues list (&lt;A href="https://www.paloaltonetworks.com/documentation/41/globalprotect/globalprotect-app-release-notes/gp-app-release-information/known-issues-related-to-gp-app" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/41/globalprotect/globalprotect-app-release-notes/gp-app-release-information/known-issues-related-to-gp-app&lt;/A&gt;). This unfortunately means it is not fixed yet.&lt;/P&gt;&lt;P&gt;So far I cannot tell you more than that, but your SE maybe has some more information.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Remo&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Dec 2018 12:44:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-certificate-pre-login-globalprotect-vpn-with-saml-tunnel/m-p/243139#M69516</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-12-13T12:44:55Z</dc:date>
    </item>
    <item>
      <title>Re: Help - Certificate pre-login globalprotect VPN, with SAML tunnel adoption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-certificate-pre-login-globalprotect-vpn-with-saml-tunnel/m-p/243140#M69517</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes we knew there was a known issue, however, as yet we have been unable to get our configuration to the point where we encounter the known issue.. My request for help was hoping that someone may post / provide an example (anonymised) config for cert pre-logon &amp;amp; saml user logon to help us get our configuration moved forward.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't believe the KB issue prevents a connection, it suggests you just need to logon twice.&amp;nbsp; Our SE suggests that PA are hoping to resolve this in a new build of the GP client, potentially v5, but still a work in progress.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks again!&lt;/P&gt;</description>
      <pubDate>Thu, 13 Dec 2018 13:13:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-certificate-pre-login-globalprotect-vpn-with-saml-tunnel/m-p/243140#M69517</guid>
      <dc:creator>darrencassano</dc:creator>
      <dc:date>2018-12-13T13:13:18Z</dc:date>
    </item>
    <item>
      <title>Re: Help - Certificate pre-login globalprotect VPN, with SAML tunnel adoption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-certificate-pre-login-globalprotect-vpn-with-saml-tunnel/m-p/243204#M69551</link>
      <description>&lt;P&gt;Oh ... I missed the part that you are asking for a config example anyway ... even with the vpn drop between prelogon and user-logon.&lt;/P&gt;&lt;P&gt;I can try to help, but right now I don't have a SAML config up and running.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you already have something configured or are you searching help about how to begin?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="1 2 3 4 5 6 7" color="#999999"&gt;PS: Ask you SE about GPv5 Beta access&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Dec 2018 17:41:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-certificate-pre-login-globalprotect-vpn-with-saml-tunnel/m-p/243204#M69551</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-12-13T17:41:28Z</dc:date>
    </item>
    <item>
      <title>Re: Help - Certificate pre-login globalprotect VPN, with SAML tunnel adopti</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-certificate-pre-login-globalprotect-vpn-with-saml-tunnel/m-p/334377#M84357</link>
      <description>&lt;P&gt;Very interested in something like this.&amp;nbsp; &amp;nbsp;Wondering if supported now.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2020 19:45:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-certificate-pre-login-globalprotect-vpn-with-saml-tunnel/m-p/334377#M84357</guid>
      <dc:creator>Sec101</dc:creator>
      <dc:date>2020-06-19T19:45:04Z</dc:date>
    </item>
  </channel>
</rss>

