<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Password Reset using Global Protect App without PreLogon in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/password-reset-using-global-protect-app-without-prelogon/m-p/311091#M80531</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have the same problem. Requirements you were talking about seem to be met.&lt;/P&gt;&lt;P&gt;When a user has a valid, non expired password everything works fine.&amp;nbsp;&lt;/P&gt;&lt;P&gt;When using a user with an expired password, nothing is logged in event viewer in NPS server, authentication fails, and user is not prompted to change his password.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you please share the guide you were talking before?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cristiano.&lt;/P&gt;</description>
    <pubDate>Thu, 13 Feb 2020 15:26:11 GMT</pubDate>
    <dc:creator>Digital</dc:creator>
    <dc:date>2020-02-13T15:26:11Z</dc:date>
    <item>
      <title>Password Reset using Global Protect App without PreLogon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/password-reset-using-global-protect-app-without-prelogon/m-p/261856#M74214</link>
      <description>&lt;P&gt;Has anyone been able to configure their firewall so that users will be able to change thier password via the global protect app while using LDAP for authentication and NOT using Pre-Logon&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2019 20:25:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/password-reset-using-global-protect-app-without-prelogon/m-p/261856#M74214</guid>
      <dc:creator>Victor.Newsom</dc:creator>
      <dc:date>2019-05-21T20:25:03Z</dc:date>
    </item>
    <item>
      <title>Re: Password Reset using Global Protect App without PreLogon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/password-reset-using-global-protect-app-without-prelogon/m-p/278490#M75641</link>
      <description>&lt;P&gt;Hello Victor,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is supported in the newer versions of PANOS and GP, however there are some requirements that have to be met on the RADIUS server.&lt;/P&gt;&lt;P&gt;1. The firewall only supports changing expired passwords when utilizing RADIUS with PEAP-MSCHAP-V2 authentication.&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; The RADIUS server has to be registered in AD and have permissions in the RAS and IAS Servers group.&lt;/P&gt;&lt;P&gt;3.&amp;nbsp; The RADIUS server must have a certificate configured from a CA that can be validated/trusted by the firewall with a client certificate profile.&lt;/P&gt;&lt;P&gt;4.&amp;nbsp; &amp;nbsp;The firewall has to be a RADIUS client configured on the RADIUS server and have the desired authentication policies in place.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a lengthy guide for setting this up from scratch and utilizing Microsoft NPS.&amp;nbsp; I will also warn you that in the event that the user tries to change their password to something that isn't in compliance with the AD Password policy, the message to the user is just a generic error, so its something to make people aware of that will be using the feature.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Brandon&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2019 20:02:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/password-reset-using-global-protect-app-without-prelogon/m-p/278490#M75641</guid>
      <dc:creator>BrandonWright</dc:creator>
      <dc:date>2019-07-23T20:02:19Z</dc:date>
    </item>
    <item>
      <title>Re: Password Reset using Global Protect App without PreLogon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/password-reset-using-global-protect-app-without-prelogon/m-p/311091#M80531</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have the same problem. Requirements you were talking about seem to be met.&lt;/P&gt;&lt;P&gt;When a user has a valid, non expired password everything works fine.&amp;nbsp;&lt;/P&gt;&lt;P&gt;When using a user with an expired password, nothing is logged in event viewer in NPS server, authentication fails, and user is not prompted to change his password.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you please share the guide you were talking before?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cristiano.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2020 15:26:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/password-reset-using-global-protect-app-without-prelogon/m-p/311091#M80531</guid>
      <dc:creator>Digital</dc:creator>
      <dc:date>2020-02-13T15:26:11Z</dc:date>
    </item>
    <item>
      <title>Re: Password Reset using Global Protect App without PreLogon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/password-reset-using-global-protect-app-without-prelogon/m-p/311301#M80573</link>
      <description>&lt;P&gt;Hello Cristiano,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;See the document I've posted here -&amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://drive.google.com/file/d/1_wjjrIILr2akt63ueUIK-xAq9zPwGqWw/view?usp=sharing" target="_blank" rel="noopener"&gt;https://drive.google.com/file/d/1_wjjrIILr2akt63ueUIK-xAq9zPwGqWw/view?usp=sharing&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Keep in mind that you should use a Windows PKI issued Certificate on the RADIUS server, but I wrote this up since I've run into customers in the past that may not have that infrastructure available.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Brandon&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2020 21:21:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/password-reset-using-global-protect-app-without-prelogon/m-p/311301#M80573</guid>
      <dc:creator>BrandonWright</dc:creator>
      <dc:date>2020-02-14T21:21:01Z</dc:date>
    </item>
    <item>
      <title>Re: Password Reset using Global Protect App without PreLogon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/password-reset-using-global-protect-app-without-prelogon/m-p/311545#M80625</link>
      <description>&lt;P&gt;Hi Brandon,&lt;/P&gt;&lt;P&gt;great doc.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll give it a try asap.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cristiano.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2020 17:16:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/password-reset-using-global-protect-app-without-prelogon/m-p/311545#M80625</guid>
      <dc:creator>Digital</dc:creator>
      <dc:date>2020-02-17T17:16:14Z</dc:date>
    </item>
    <item>
      <title>Re: Password Reset using Global Protect App without PreLogon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/password-reset-using-global-protect-app-without-prelogon/m-p/311897#M80691</link>
      <description>&lt;P&gt;Hi Brandon,&lt;/P&gt;&lt;P&gt;I've tried your document, but I have two problems:&lt;/P&gt;&lt;P&gt;1) at connection request level, it always hit the default (99999) policy, but I think this should not be a problem: reading your document It seemed to me that your making a specific policy only to override authentication polcy for a more clear readbility, am I right?&lt;/P&gt;&lt;P&gt;2) This insted is more problematic: I see that network policy hit is correct, but then I see this error in security event id on nps server:&lt;/P&gt;&lt;P&gt;"unable to authenticate client. Eap type could not be processed by the server". Googling around I always hit into certificate problems, but I don't think this is my case. In fact first of all, this only happens when I have a user password expired or in change password at next logon. Second, if I take a look at certificate in properties of peap it shows the right certificate ( signed by PA-CA ), so I think certificate chain should be ok.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have any advices?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cristiano.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2020 11:33:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/password-reset-using-global-protect-app-without-prelogon/m-p/311897#M80691</guid>
      <dc:creator>Digital</dc:creator>
      <dc:date>2020-02-19T11:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: Password Reset using Global Protect App without PreLogon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/password-reset-using-global-protect-app-without-prelogon/m-p/313176#M80891</link>
      <description>&lt;P&gt;HI Brandon,&amp;nbsp; this setup should work regardless what type of GP agents one uses, correct?&amp;nbsp; we have users using ios GP agents.&amp;nbsp; Thank you very much in advance for your response.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2020 18:15:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/password-reset-using-global-protect-app-without-prelogon/m-p/313176#M80891</guid>
      <dc:creator>SabrinaChen</dc:creator>
      <dc:date>2020-02-26T18:15:17Z</dc:date>
    </item>
    <item>
      <title>Re: Password Reset using Global Protect App without PreLogon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/password-reset-using-global-protect-app-without-prelogon/m-p/313192#M80895</link>
      <description>&lt;P&gt;Hello Cristiano,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Make sure that you have EAP type added for PEAP, on the connection policy:&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PEAP-CONNECTIONPROPERTIES.png" style="width: 725px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24120i7ADE7953954FC07A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PEAP-CONNECTIONPROPERTIES.png" alt="PEAP-CONNECTIONPROPERTIES.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also ensure you have a condition set for the connection request policy:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ConditionForConnectionRequestPolicy.png" style="width: 777px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24121i32C425242FAC8B76/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ConditionForConnectionRequestPolicy.png" alt="ConditionForConnectionRequestPolicy.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also ensure that after you put the cert and key pair on the RADIUS server that you make sure that's being used by the RADIUS server, and that the profile is set to trust from that CA.&amp;nbsp; It needs to be in the Machine store I believe:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2020 20:07:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/password-reset-using-global-protect-app-without-prelogon/m-p/313192#M80895</guid>
      <dc:creator>BrandonWright</dc:creator>
      <dc:date>2020-02-26T20:07:41Z</dc:date>
    </item>
    <item>
      <title>Re: Password Reset using Global Protect App without PreLogon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/password-reset-using-global-protect-app-without-prelogon/m-p/313193#M80896</link>
      <description>&lt;P&gt;Hello Cristiano,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe it should work with any variant of the GP client since the RADIUS challenge response stuff is built into all of the clients.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Brandon&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2020 20:09:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/password-reset-using-global-protect-app-without-prelogon/m-p/313193#M80896</guid>
      <dc:creator>BrandonWright</dc:creator>
      <dc:date>2020-02-26T20:09:10Z</dc:date>
    </item>
    <item>
      <title>Re: Password Reset using Global Protect App without PreLogon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/password-reset-using-global-protect-app-without-prelogon/m-p/336884#M84907</link>
      <description>&lt;P&gt;Not supported on SAML?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2020 16:55:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/password-reset-using-global-protect-app-without-prelogon/m-p/336884#M84907</guid>
      <dc:creator>Sec101</dc:creator>
      <dc:date>2020-07-07T16:55:46Z</dc:date>
    </item>
  </channel>
</rss>

