<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GP external gateway - Connection method Pre logon Always on in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/gp-external-gateway-connection-method-pre-logon-always-on/m-p/307340#M79808</link>
    <description>&lt;P&gt;TAC confirmed with Engineering team this is not possible.&lt;/P&gt;</description>
    <pubDate>Mon, 20 Jan 2020 20:48:08 GMT</pubDate>
    <dc:creator>MP18</dc:creator>
    <dc:date>2020-01-20T20:48:08Z</dc:date>
    <item>
      <title>GP external gateway - Connection method Pre logon Always on</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-external-gateway-connection-method-pre-logon-always-on/m-p/305891#M79503</link>
      <description>&lt;P&gt;We are using SAML in Azure for GP external gateway connection.&lt;/P&gt;&lt;P&gt;When connection method is on demand we get mobile push notification and user gets connected to the GP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Testing with&amp;nbsp;Connection method Pre logon Always on, i am not getting mobile push notification.&lt;/P&gt;&lt;P&gt;Need to confirm is this by design?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;or is there any config i can do so that&amp;nbsp;Connection method Pre logon Always on&amp;nbsp; gives me mobile push notification?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2020 21:31:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-external-gateway-connection-method-pre-logon-always-on/m-p/305891#M79503</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-01-07T21:31:02Z</dc:date>
    </item>
    <item>
      <title>Re: GP external gateway - Connection method Pre logon Always on</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-external-gateway-connection-method-pre-logon-always-on/m-p/305969#M79516</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not sure if this is by design.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd recommend reaching out to TAC and have them confirm with engineering if it's by design or not.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Wed, 08 Jan 2020 10:15:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-external-gateway-connection-method-pre-logon-always-on/m-p/305969#M79516</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2020-01-08T10:15:35Z</dc:date>
    </item>
    <item>
      <title>Re: GP external gateway - Connection method Pre logon Always on</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-external-gateway-connection-method-pre-logon-always-on/m-p/305996#M79525</link>
      <description>&lt;P&gt;As per TAC this is by design but i asked him to confirm with Engineering also.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2020 15:24:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-external-gateway-connection-method-pre-logon-always-on/m-p/305996#M79525</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-01-08T15:24:44Z</dc:date>
    </item>
    <item>
      <title>Re: GP external gateway - Connection method Pre logon Always on</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-external-gateway-connection-method-pre-logon-always-on/m-p/307340#M79808</link>
      <description>&lt;P&gt;TAC confirmed with Engineering team this is not possible.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2020 20:48:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-external-gateway-connection-method-pre-logon-always-on/m-p/307340#M79808</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-01-20T20:48:08Z</dc:date>
    </item>
    <item>
      <title>Re: GP external gateway - Connection method Pre logon Always on</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-external-gateway-connection-method-pre-logon-always-on/m-p/307341#M79809</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't really get it. Why isn't this possible exactly? With SAML you get single sign on, but as you have another loginfactor the push notification should be sent - so why not in your configuration? Don't give up too easily with answers from TAC &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If there really isn't a way without a feature request where you have to wait, what about using RADIUS MFA connectior for your always-on clients? Does it maybe work this way with SSO and push notifications?&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2020 21:24:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-external-gateway-connection-method-pre-logon-always-on/m-p/307341#M79809</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2020-01-20T21:24:02Z</dc:date>
    </item>
    <item>
      <title>Re: GP external gateway - Connection method Pre logon Always on</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-external-gateway-connection-method-pre-logon-always-on/m-p/307342#M79810</link>
      <description>&lt;P&gt;We have Global protect PRe log on&amp;nbsp; Always on for pilot testing.&lt;/P&gt;&lt;P&gt;We have SAML configured where we get the push notifications on mobile for authentication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are using Azure SAML.&lt;/P&gt;&lt;P&gt;When user put the domain password during log on then GP client connects automatically they do not get mobile push notifications.&lt;/P&gt;&lt;P&gt;Opened ticket with TAC almost 2 weeks ago and today he confirmed that this is expected behaviour.&lt;/P&gt;&lt;P&gt;We can not force push mobile notifications while using pre log on always on connection method.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also as our current setup we only want to use SAML using Azure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2020 21:33:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-external-gateway-connection-method-pre-logon-always-on/m-p/307342#M79810</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-01-20T21:33:16Z</dc:date>
    </item>
    <item>
      <title>Re: GP external gateway - Connection method Pre logon Always on</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-external-gateway-connection-method-pre-logon-always-on/m-p/307343#M79811</link>
      <description>&lt;P&gt;You are using the newest GP version? Or at least something above 5.0.2?&lt;/P&gt;&lt;P&gt;(I am asking as I intended to do a similar setup ... but this now does not sound very good ...)&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2020 21:41:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-external-gateway-connection-method-pre-logon-always-on/m-p/307343#M79811</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2020-01-20T21:41:06Z</dc:date>
    </item>
    <item>
      <title>Re: GP external gateway - Connection method Pre logon Always on</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-external-gateway-connection-method-pre-logon-always-on/m-p/307344#M79812</link>
      <description>&lt;P&gt;I am using GP client 5.0.4.16&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2020 21:45:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-external-gateway-connection-method-pre-logon-always-on/m-p/307344#M79812</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-01-20T21:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: GP external gateway - Connection method Pre logon Always on</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-external-gateway-connection-method-pre-logon-always-on/m-p/307345#M79813</link>
      <description>&lt;P&gt;But the push notification is sent by your SAML IdP or the attached MFA service right? And GP officially supports "Pre-logon followed by SAML". So when viewing from the other side: why is this an issue of GP as the IdP is sending or at least triggering the push notification?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2020 22:24:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-external-gateway-connection-method-pre-logon-always-on/m-p/307345#M79813</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2020-01-20T22:24:26Z</dc:date>
    </item>
    <item>
      <title>Re: GP external gateway - Connection method Pre logon Always on</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-external-gateway-connection-method-pre-logon-always-on/m-p/307346#M79814</link>
      <description>&lt;P&gt;We do not have MFA configured.&lt;/P&gt;&lt;P&gt;As per PA while using Global protect External&amp;nbsp; and using SAML you can not have MFA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I could not find answer for this checked with PA and also with our SE.&lt;/P&gt;&lt;P&gt;Only option is to use on demand connection method.&lt;/P&gt;&lt;P&gt;As per PA we can submit the feature request to them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2020 22:32:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-external-gateway-connection-method-pre-logon-always-on/m-p/307346#M79814</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-01-20T22:32:08Z</dc:date>
    </item>
  </channel>
</rss>

