<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect Pre-Logon NULL issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pre-logon-null-issue/m-p/337044#M84919</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56221"&gt;@raji_toor&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Make sure Cert in SSL/TLS profile has CN the FQDN of the VPN url and is trusted by the PA and end user.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Portal/Gateway authentication - Certificate Profile - This is using internal PKI root and intermediate certs&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My assumption is that if you are using Cert PRofile with internal root and intermediate certs need to be same as Cert in&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;SSL/TLS profile -&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Can you please test by using either external Root or Internal Root certs and intermediate certs for both SSL/TLS and&amp;nbsp;&lt;SPAN&gt;Certificate Profile?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 08 Jul 2020 02:10:47 GMT</pubDate>
    <dc:creator>MP18</dc:creator>
    <dc:date>2020-07-08T02:10:47Z</dc:date>
    <item>
      <title>GlobalProtect Pre-Logon NULL issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pre-logon-null-issue/m-p/336785#M84878</link>
      <description>&lt;P&gt;Trying to setup new config for pre-logon, seems to be not working. I am getting machine certificate null error.&amp;nbsp;&lt;/P&gt;&lt;P&gt;First i was using internal PKI but then i found this KB and i was hitting the same issue.&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClR8CAK" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClR8CAK&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I then tried to setup with self generated certs, while i have asked the system admin team to add subject info, but still having same issue.&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Below are portal config screenshots, i don't know what i am missing. PANOS 9.0.8, GP 5.1.4&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26606iD449D5C255414D4F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;External Gateways in both agent configs point to same public fqdn/ip&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26607iFCE6249117471129/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I have also tried selecting both options below&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26608iBA68665D6BF7A146/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 795px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26611iB73A1D05DAB9BA9E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 808px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26609i19D8B45571C059F3/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 475px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26610iC08863A82A3CAC8B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Server Authentication below uses public cert, while certificate profile use self generated root CA on firewall.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26613i1251C8CCE1C76799/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below are the local root CA and profile screenshots&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26614i2982FBAD0C36CD59/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26615i9DDA307ED9483839/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26616iE4E164421652769D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Certificate imported in to personal store of local machine, generated on firewall.&lt;/P&gt;&lt;P&gt;On reinstall of Agent it asks to select certificate which is this that i select and get not authorized message.&lt;/P&gt;&lt;P&gt;Also imported root certificate from firewall in trusted certs.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 554px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26617i0058BA84315E39E9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 22:20:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pre-logon-null-issue/m-p/336785#M84878</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2020-07-06T22:20:28Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Pre-Logon NULL issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pre-logon-null-issue/m-p/336799#M84880</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56221"&gt;@raji_toor&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Seems you need Root and Intermediate Cert in Device and Certificate&amp;nbsp; profile.&lt;/P&gt;
&lt;P&gt;Also your Machine cert need to be part of&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Root&lt;/P&gt;
&lt;P&gt;Intermediate&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Machine&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When you create Machine cert then it need to be signed by Intermediate cert.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2020 01:21:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pre-logon-null-issue/m-p/336799#M84880</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-07-07T01:21:14Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Pre-Logon NULL issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pre-logon-null-issue/m-p/336815#M84887</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt; As per your suggestion i have made below changes. new root &amp;gt; inter &amp;gt; sever cert created&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26625i0F953B713F101F88/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Included them in server profile used in Gateway authentication config tab&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 905px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26624i8F88803873A16E69/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;exported and imported rajv-test.xxx.yyy.ca from firewall into Windows local store.&lt;/P&gt;&lt;P&gt;reinstalled GP and tried connection, same result. Null with not authorized.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 605px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26626i871A4C45CEC6E83B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And this time i did not see any popup from GP for which cert to use from the local store.&lt;/P&gt;&lt;P&gt;Am i generating machine cert rajv-test right, do i need to include server-test cert somewhere.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="raji_toor_1-1594099472302.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26627i472AE5ACEA688FB3/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="raji_toor_1-1594099472302.png" alt="raji_toor_1-1594099472302.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2020 05:24:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pre-logon-null-issue/m-p/336815#M84887</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2020-07-07T05:24:44Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Pre-Logon NULL issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pre-logon-null-issue/m-p/336911#M84908</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;I have updated the config now with actual certs that are to be used, no self generated certs, but still hitting the same issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Test PC has both root and intermediate certs from our internal PKI. Machine cert pushed by GroupPolicy with subject field populated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Portal authentication uses public cert in ssl-tls profile and none in certificate profile.&lt;/P&gt;&lt;P&gt;under agent tab root and intermediate certs from internal PKI are selected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Gateway authentication uses same public cert ssl-tls profile and cert profile with root and intermediate in it from internal PKI&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2020 17:53:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pre-logon-null-issue/m-p/336911#M84908</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2020-07-07T17:53:42Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Pre-Logon NULL issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pre-logon-null-issue/m-p/336946#M84911</link>
      <description>&lt;P&gt;This is what i have observed now.&lt;/P&gt;&lt;P&gt;Including the group that works in On-demad mode, pre-logon config fails&lt;/P&gt;&lt;P&gt;If any users is set, user gets authenticated but i still don't see any pre-logon happening&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE width="530"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="386.667px" height="57px"&gt;Portal Authentication&lt;/TD&gt;&lt;TD width="71.8519px" height="57px"&gt;Connect Method&lt;/TD&gt;&lt;TD width="71.1111px" height="57px"&gt;Working&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="386.667px" height="57px"&gt;cn=emp,ou=groups,ou=emp,dc=aaa,dc=bbbbb,dc=ca&lt;/TD&gt;&lt;TD width="71.8519px" height="57px"&gt;On-Demand&lt;/TD&gt;&lt;TD width="71.1111px" height="57px"&gt;Yes&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="386.667px" height="29px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="71.8519px" height="29px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="71.1111px" height="29px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="386.667px" height="29px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="71.8519px" height="29px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="71.1111px" height="29px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="386.667px" height="57px"&gt;Portal Authentication&lt;/TD&gt;&lt;TD width="71.8519px" height="57px"&gt;Connect Method&lt;/TD&gt;&lt;TD width="71.1111px" height="57px"&gt;Working&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="386.667px" height="111px"&gt;pre-logon&lt;/TD&gt;&lt;TD width="71.8519px" height="111px"&gt;pre-logon (always-on)&lt;/TD&gt;&lt;TD width="71.1111px" height="111px"&gt;No&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="386.667px" height="111px"&gt;cn=emp,ou=groups,ou=emp,dc=aaa,dc=bbbbb,dc=ca&lt;/TD&gt;&lt;TD width="71.8519px" height="111px"&gt;pre-logon (always-on)&lt;/TD&gt;&lt;TD width="71.1111px" height="111px"&gt;No&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="386.667px" height="29px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="71.8519px" height="29px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="71.1111px" height="29px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="386.667px" height="29px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="71.8519px" height="29px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="71.1111px" height="29px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="386.667px" height="57px"&gt;Portal Authentication&lt;/TD&gt;&lt;TD width="71.8519px" height="57px"&gt;Connect Method&lt;/TD&gt;&lt;TD width="71.1111px" height="57px"&gt;Working&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="386.667px" height="110px"&gt;pre-logon&lt;/TD&gt;&lt;TD width="71.8519px" height="110px"&gt;pre-logon (always-on)&lt;/TD&gt;&lt;TD width="71.1111px" height="110px"&gt;No&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="386.667px" height="111px"&gt;Any&lt;/TD&gt;&lt;TD width="71.8519px" height="111px"&gt;pre-logon (always-on)&lt;/TD&gt;&lt;TD width="71.1111px" height="111px"&gt;Yes&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Tue, 07 Jul 2020 18:50:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pre-logon-null-issue/m-p/336946#M84911</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2020-07-07T18:50:17Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Pre-Logon NULL issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pre-logon-null-issue/m-p/336970#M84913</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56221"&gt;@raji_toor&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Machine Cert need to be imported in both Local user and Local machine in Certificate Store - Personal on each machine.&lt;/P&gt;
&lt;P&gt;Under Portal and Gateway Authentication for SSL/TLS profile&amp;nbsp; has to be same&lt;/P&gt;
&lt;P&gt;And also the Certificate profile under&amp;nbsp; authentication in Portal and gateway has to be same&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2020 19:59:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pre-logon-null-issue/m-p/336970#M84913</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-07-07T19:59:34Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Pre-Logon NULL issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pre-logon-null-issue/m-p/336986#M84914</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;I did not need to import to Local user store, but fixing the cert config did fix the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Portal/Gateway authentication - SSL/TLS profile - This is using Public cert&lt;/P&gt;&lt;P&gt;Portal/Gateway authentication - Certificate Profile - This is using internal PKI root and intermediate certs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2020 20:34:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pre-logon-null-issue/m-p/336986#M84914</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2020-07-07T20:34:06Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Pre-Logon NULL issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pre-logon-null-issue/m-p/337044#M84919</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56221"&gt;@raji_toor&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Make sure Cert in SSL/TLS profile has CN the FQDN of the VPN url and is trusted by the PA and end user.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Portal/Gateway authentication - Certificate Profile - This is using internal PKI root and intermediate certs&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My assumption is that if you are using Cert PRofile with internal root and intermediate certs need to be same as Cert in&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;SSL/TLS profile -&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Can you please test by using either external Root or Internal Root certs and intermediate certs for both SSL/TLS and&amp;nbsp;&lt;SPAN&gt;Certificate Profile?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2020 02:10:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pre-logon-null-issue/m-p/337044#M84919</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-07-08T02:10:47Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Pre-Logon NULL issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pre-logon-null-issue/m-p/337097#M84925</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;I am pasting all the relevant screenshots of my config, and since all the documentations show config with self generated certs. This is with actual public cert and internal certs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SSL/TLS Profile used in both portal and gateway configs&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 885px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26664iCC593CA8BCE26425/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;SSL/TLS Profile config&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 546px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26665i8F03E1392C938C5D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;above ssl-tls profile refers this Public Certificate&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26654i4123CF1A9E919C83/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Portal &amp;gt; agent &amp;gt; config &amp;gt;External refers public fqdn&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26655i2ACE9ADF8AA5CD2E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;portal &amp;gt; agent &amp;gt; root and inter certs added here issued from internal certificate authority&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26656i9633C060592E425E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Certificate profile used in both portal and gateway configs&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 857px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26657i0FF925B3DE738F44/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Certificate profile config referring same internal certificates&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 903px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26658iC072EEA3B9FF58EF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Internal certs added to firewall. In case someone my wonder about 3rd IM-ROOT below, we had setup that previously for decryption.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26659iEE527675A7321561/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ROOT and ROOT-INTER and Machine cert are automatically pushed to PC by Group Policy under Local Computer. I don't know why 2 are pushed. And as per earlier mentioned KB Subject field should not be empty and refers to the PC name.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Status at login screen on reboot&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 517px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26660i3B071682246B3398/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Tunnel status on firewall before usre logs in to PC, that is the previous screenshot state. User is pre-logon&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26661i95F6DD28486F29EC/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Tunnel status after user logs in, connection is automatically established if credentials have been entered before.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26662i8CE65AC6A7C4DBDD/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2020 05:55:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pre-logon-null-issue/m-p/337097#M84925</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2020-07-08T05:55:26Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Pre-Logon NULL issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pre-logon-null-issue/m-p/337323#M84950</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56221"&gt;@raji_toor&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So As per these logs it seems pre logon is working.&lt;/P&gt;
&lt;P&gt;Does the user name pre logon to the specfic user as configured in LDAP profile?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2020 03:00:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pre-logon-null-issue/m-p/337323#M84950</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-07-09T03:00:46Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Pre-Logon NULL issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pre-logon-null-issue/m-p/337442#M84968</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;Yes it logs as the user according to the ldap profile.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2020 14:54:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pre-logon-null-issue/m-p/337442#M84968</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2020-07-09T14:54:12Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Pre-Logon NULL issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pre-logon-null-issue/m-p/337460#M84972</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56221"&gt;@raji_toor&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So seems then it is working as expected now ?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2020 15:43:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pre-logon-null-issue/m-p/337460#M84972</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-07-09T15:43:35Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Pre-Logon NULL issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pre-logon-null-issue/m-p/337646#M84982</link>
      <description>yes</description>
      <pubDate>Fri, 10 Jul 2020 04:28:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pre-logon-null-issue/m-p/337646#M84982</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2020-07-10T04:28:39Z</dc:date>
    </item>
  </channel>
</rss>

