<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Administrative Install in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/administrative-install/m-p/315337#M81250</link>
    <description>&lt;P&gt;Does it fit within your usage requirements to do one portal with two different gateways?&amp;nbsp; For example, if it will all be the same users, but sometimes they'll connect to Site A, and sometimes to Site B, do one portal config with both gateways listed as options for manual connection?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="gateways.png" style="width: 781px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24326i5B82499A2ED0A06C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="gateways.png" alt="gateways.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 09 Mar 2020 20:32:59 GMT</pubDate>
    <dc:creator>OwenFuller</dc:creator>
    <dc:date>2020-03-09T20:32:59Z</dc:date>
    <item>
      <title>Administrative Install</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/administrative-install/m-p/315287#M81242</link>
      <description>&lt;P&gt;I'm having trouble finding the correct administrative installation process.&amp;nbsp; I have several field reps that do not have administrative rights to their laptops.&amp;nbsp; I need to install GlobalProtect for them and have it pre-configured with proper certificates, portal addresses, etc.&amp;nbsp; My certificates are self-generated by the firewalls, so are not trusted by a third-party such as goDaddy.&amp;nbsp;&lt;/P&gt;&lt;P&gt;My installation process is:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;login with a proper administrative account&lt;/LI&gt;&lt;LI&gt;install the proper certificates into local computer and local user stores&lt;/LI&gt;&lt;LI&gt;install the agent using msiexec /i globalprotect.msi POSTVPNCONNECTCOMMAND=\\server\path\logon.bat PORTAL=vpn.domain.us&amp;nbsp;/quiet&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;This sets up the first portal, but I have two portals.&amp;nbsp; I've tried importing registry files for the second portal and it works for user that ran the install, but not for any other user on the system.&amp;nbsp; All other users only have the portal created by the msiexec install.&amp;nbsp; So how do I install the agent with two portals?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When the user first logs in, they are asked to accept the certificate of the portal, even though the cert is previously installed.&amp;nbsp; This acceptance is only required the first time the user logs in.&amp;nbsp; How do I have the agent accept this certificate so not to ask the end user?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 16:48:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/administrative-install/m-p/315287#M81242</guid>
      <dc:creator>blwallace</dc:creator>
      <dc:date>2020-03-09T16:48:27Z</dc:date>
    </item>
    <item>
      <title>Re: Administrative Install</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/administrative-install/m-p/315328#M81246</link>
      <description>&lt;P&gt;The GlobalProtect agent uses Internet Explorer in the background, so it should trust whatever certs are in the Trusted Root Certificate Authorities store.&amp;nbsp; Are you placing the signing certificate used on the firewall in this store?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not sure as to the multiple portal configuration.&amp;nbsp; If you don't mind me asking, why are you doing two separate portals?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 20:17:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/administrative-install/m-p/315328#M81246</guid>
      <dc:creator>OwenFuller</dc:creator>
      <dc:date>2020-03-09T20:17:11Z</dc:date>
    </item>
    <item>
      <title>Re: Administrative Install</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/administrative-install/m-p/315333#M81248</link>
      <description>&lt;P&gt;Yes, I'm placing the signing certificate from the firewall in both the Local Computer and Current User Trusted Root Certification Authorities.&lt;/P&gt;&lt;P&gt;I have two portals because I have two different sites.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 20:26:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/administrative-install/m-p/315333#M81248</guid>
      <dc:creator>blwallace</dc:creator>
      <dc:date>2020-03-09T20:26:06Z</dc:date>
    </item>
    <item>
      <title>Re: Administrative Install</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/administrative-install/m-p/315337#M81250</link>
      <description>&lt;P&gt;Does it fit within your usage requirements to do one portal with two different gateways?&amp;nbsp; For example, if it will all be the same users, but sometimes they'll connect to Site A, and sometimes to Site B, do one portal config with both gateways listed as options for manual connection?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="gateways.png" style="width: 781px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24326i5B82499A2ED0A06C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="gateways.png" alt="gateways.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 20:32:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/administrative-install/m-p/315337#M81250</guid>
      <dc:creator>OwenFuller</dc:creator>
      <dc:date>2020-03-09T20:32:59Z</dc:date>
    </item>
    <item>
      <title>Re: Administrative Install</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/administrative-install/m-p/315372#M81255</link>
      <description>&lt;P&gt;No.&amp;nbsp; My second site is a warm backup site - so if my primary portal is down, that means my primary portal site is down and there wouldn't be any way to get to the second gateway configured on the primary.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 22:48:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/administrative-install/m-p/315372#M81255</guid>
      <dc:creator>blwallace</dc:creator>
      <dc:date>2020-03-09T22:48:09Z</dc:date>
    </item>
    <item>
      <title>Re: Administrative Install</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/administrative-install/m-p/349165#M86804</link>
      <description>&lt;P&gt;Good Day Blwallace&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only way to install GP with multiple portals is to add a reg key to inside the users hive&lt;BR /&gt;I used this PS script to install the app using SCCM&lt;BR /&gt;$Location = (Get-ChildItem -Path C:\Windows\ccmcache -Filter "GlobalProtect64.msi" -Recurse | Select -Last 1 -Property Directory).Directory&lt;BR /&gt;Set-Location $Location&lt;BR /&gt;&amp;amp; ".\GlobalProtect64.msi" /q PORTAL="XXX.XXX.XXX.XX" CONNECTMETHOD="on-demand"&lt;BR /&gt;Start-Sleep -Seconds 15&lt;BR /&gt;$User = (Get-WmiObject -Class Win32_ComputerSystem).username&lt;BR /&gt;$SID = (Get-WmiObject Win32_UserAccount -Filter "Name= '$($user.substring(3))' AND Domain= '$($user.substring(0,2))'").SID&lt;BR /&gt;New-Item -Path "Registry::HKEY_USERS\$SID\Software\Palo Alto Networks\GlobalProtect\Settings" -Name 'xx.xx.xxx.xxx' -Force&lt;BR /&gt;New-Item -Path "Registry::HKEY_USERS\$SID\Software\Palo Alto Networks\GlobalProtect\Settings" -Name 'xxx.xxx.xxx.xxx' -Force&lt;BR /&gt;Start-Sleep -Seconds 10&lt;BR /&gt;Get-Service -Name PanGPS | Restart-Service -Force&lt;BR /&gt;If you dont use SCCM you can skip line 1 and 2&amp;nbsp;&lt;BR /&gt;Hope this works out for you&lt;BR /&gt;Any comment or question please let me know&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2020 16:10:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/administrative-install/m-p/349165#M86804</guid>
      <dc:creator>A.Saenz</dc:creator>
      <dc:date>2020-09-14T16:10:21Z</dc:date>
    </item>
  </channel>
</rss>

