<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect Configuration Opinions in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-configuration-opinions/m-p/245102#M69886</link>
    <description>&lt;P&gt;Thanks Mickball,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yeah&amp;nbsp; I definitelty understand everyone's requirements, setup, etc are different. We too are required to use HD encryption as well. We liked the promise of prelogon so users can change passwords, login for the first time, etc. With all the other requirements in the scenario, it just has gotten overly conviluted IMO. I like your question about whether the users need to reconnect to refresh their policies because it makes things easier for the users as well. My experience says that the simplier the config, the easier it is to support and secure so anything that can pare things down, I'm for.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Really appreciate your two cents on this one!&lt;/P&gt;</description>
    <pubDate>Mon, 07 Jan 2019 13:19:03 GMT</pubDate>
    <dc:creator>mbahen</dc:creator>
    <dc:date>2019-01-07T13:19:03Z</dc:date>
    <item>
      <title>GlobalProtect Configuration Opinions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-configuration-opinions/m-p/244953#M69865</link>
      <description>&lt;P&gt;Greetings!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just to be upfront, I have my configuration working for the most part but I'm interested to hear if there's not a better/safer/quicker way of bending GlobalProtect to my needs. Please feel free to chime in with ideas, opinions or suggestions! Only as much detail as you feel is necessary but I'm happy to hear what you're thinking&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Scenario&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Globalprotect prelogon scenario with 2 level of post logon access&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Process&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;All hosts&amp;nbsp;will connect on the pre-logon level with limited access to internal resources (AD, etc) using our internal PKI&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;After logon all users will automatically stay connected via Globalprotect (the pre-logon tunnel will switch to the username) and retain access to limited internal resources via security policies and LDAP&lt;/LI&gt;&lt;LI&gt;Select users after they logon will have the ability to "reconnect" to the GlobalProtect gateway and have full access to the internal network (again through security policies and LDAP)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Other requirements&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TFA is not in play but may be in the future.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Reference&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Most of the config is based in this article:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEYCA0" target="_blank"&gt;here&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Again. I'm not stuck (currently). Just wanted to hear your opinions. Appreciate any feedback.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jan 2019 21:20:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-configuration-opinions/m-p/244953#M69865</guid>
      <dc:creator>mbahen</dc:creator>
      <dc:date>2019-01-04T21:20:11Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Configuration Opinions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-configuration-opinions/m-p/244980#M69871</link>
      <description>&lt;P&gt;Sounds like an ok setup but it really depends on your corporate security policies.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for us, PKI is a must but not acceptable without some form of hard drive encryption protected by a PIN.&lt;/P&gt;&lt;P&gt;this has nothing to do with certificate exposure but just an additional protection as you are currently relying on a password only policy if device is stolen.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we do not use pre-login as users are unable to join wifi until they auth on the device.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;not sure about the 3rd option in your process section, why would they need to re-connect to obtain different policies.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if you move to 2FA then you may need to look at authentication overide especially if using OTP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All of the above will not be everyones cup of tea but works well for us and we need to adhere to strict corp policies.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jan 2019 12:26:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-configuration-opinions/m-p/244980#M69871</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-01-07T12:26:16Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Configuration Opinions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-configuration-opinions/m-p/245102#M69886</link>
      <description>&lt;P&gt;Thanks Mickball,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yeah&amp;nbsp; I definitelty understand everyone's requirements, setup, etc are different. We too are required to use HD encryption as well. We liked the promise of prelogon so users can change passwords, login for the first time, etc. With all the other requirements in the scenario, it just has gotten overly conviluted IMO. I like your question about whether the users need to reconnect to refresh their policies because it makes things easier for the users as well. My experience says that the simplier the config, the easier it is to support and secure so anything that can pare things down, I'm for.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Really appreciate your two cents on this one!&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jan 2019 13:19:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-configuration-opinions/m-p/245102#M69886</guid>
      <dc:creator>mbahen</dc:creator>
      <dc:date>2019-01-07T13:19:03Z</dc:date>
    </item>
  </channel>
</rss>

