<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect - Connecting before pre-logon in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-connecting-before-pre-logon/m-p/365200#M88541</link>
    <description>&lt;P&gt;We had a ticket open with support for some time, although the main issue that we were trying to fix was pre-logon tunnels not renaming, the problem in this post was also resolved along with the tunnel-rename issue being fixed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What it came down to was routing from the internal network to the gateways.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As we have multiple internet circuits and a gateway on each one, we had to make sure that traffic was getting routed correctly. When we looked into this we found one gateway was going into a routing loop and we needed to put a PBF in place to make the traffic bypass the default PBF rules.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's not a very detailed solution, but I hope this may point others in the right direction.&lt;/P&gt;</description>
    <pubDate>Tue, 24 Nov 2020 13:34:00 GMT</pubDate>
    <dc:creator>Geroge</dc:creator>
    <dc:date>2020-11-24T13:34:00Z</dc:date>
    <item>
      <title>GlobalProtect - Connecting before pre-logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-connecting-before-pre-logon/m-p/353291#M87309</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are experiencing an issue with some of our Windows 10 laptops where if the user connects&amp;nbsp;&lt;EM&gt;before&lt;/EM&gt; the pre-logon tunnel establishes at the Windows logon screen, then they are presented with a Global Protect error saying 'VPN Connection could not be established' once the desktop loads.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have checked the system logs during this process, and the strange thing is that the tunnel does get established and is up, even though GP says otherwise. However either the user needs to refresh the connection, or if you wait long enough GlobalProtect will auto refresh before it displays as connected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The system logs look like the following;&lt;/P&gt;&lt;P&gt;&amp;lt;user logs into Windows, before pre-logon tunnel&amp;gt;&lt;/P&gt;&lt;P&gt;1 globalprotectportal-auth-succ&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Portal&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; user authentication succeeded. User name: xxxx&lt;BR /&gt;2 globalprotectportal-config-succ&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Portal&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; client configuration generated.&lt;BR /&gt;3 globalprotectgateway-auth-succ&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Gateway&amp;nbsp; &amp;nbsp; &amp;nbsp;user authentication succeeded. User name: xxxx&lt;BR /&gt;4 globalprotectgateway-regist-succ&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Gateway&amp;nbsp; &amp;nbsp; &amp;nbsp; user login succeeded. User name: xxxx&lt;BR /&gt;5 globalprotectgateway-config-succ&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Gateway&amp;nbsp; &amp;nbsp; &amp;nbsp;client configuration generated.&lt;BR /&gt;6 globalprotectgateway-switch-succ&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Gateway&amp;nbsp; &amp;nbsp; &amp;nbsp;client switch to SSL tunnel mode succeeded.&lt;/P&gt;&lt;P&gt;&amp;lt;user see's popup saying VPN failure&amp;gt;&lt;BR /&gt;7 globalprotectgateway-auth-succ&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Gateway&amp;nbsp; &amp;nbsp; &amp;nbsp; user authentication succeeded. User name: xxxx&lt;BR /&gt;8 globalprotectgateway-regist-fail&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Gateway&amp;nbsp; &amp;nbsp; &amp;nbsp; user login failed. User name: xxxx, error: Existing user session found.&lt;BR /&gt;9 globalprotectgateway-config-release&amp;nbsp; &amp;nbsp;Gateway&amp;nbsp; &amp;nbsp; client configuration released. User name: xxxx&lt;BR /&gt;10 globalprotectgateway-logout-succ&amp;nbsp; &amp;nbsp; &amp;nbsp;Gateway&amp;nbsp; &amp;nbsp; &amp;nbsp;user logout succeeded. User name: xxxx, Reason: remove previous login.&lt;BR /&gt;11 globalprotectgateway-regist-succ&amp;nbsp; &amp;nbsp; &amp;nbsp; Gateway&amp;nbsp; &amp;nbsp; &amp;nbsp;user login succeeded. User name: xxxx&lt;BR /&gt;12 globalprotectgateway-config-succ&amp;nbsp; &amp;nbsp; &amp;nbsp;Gateway&amp;nbsp; &amp;nbsp; &amp;nbsp;client configuration generated.&lt;/P&gt;&lt;P&gt;&amp;lt;user sees VPN connected message&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the user waits for the pre-logon tunnel to establish (which sometimes its not easy to ask them to do this, you have to explain where to find the icon which shows this on the Windows logon screen) then the tunnel will establish with pre-logon user, and then rename when Windows loads - as per design.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone come across anything similar with people logging in before the pre-logon tunnel establishes?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2020 13:35:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-connecting-before-pre-logon/m-p/353291#M87309</guid>
      <dc:creator>Geroge</dc:creator>
      <dc:date>2020-10-01T13:35:07Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect - Connecting before pre-logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-connecting-before-pre-logon/m-p/353320#M87310</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/92755"&gt;@Geroge&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are Running GP 5.2.2 with Prelog on always on no issues.&lt;/P&gt;
&lt;P&gt;Our machine tunnel connects before user log on and GP shows connected.&lt;/P&gt;
&lt;P&gt;We are using windows 10 laptops.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Make sure under Portal agent single sign is configured as Yes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2020 13:56:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-connecting-before-pre-logon/m-p/353320#M87310</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-10-01T13:56:52Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect - Connecting before pre-logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-connecting-before-pre-logon/m-p/353321#M87311</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;, it works fine for us too - but only if you wait for the pre-logon tunnel to establish.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you get your credentials in before that, then there are issues once Windows loads.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2020 14:11:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-connecting-before-pre-logon/m-p/353321#M87311</guid>
      <dc:creator>Geroge</dc:creator>
      <dc:date>2020-10-01T14:11:24Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect - Connecting before pre-logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-connecting-before-pre-logon/m-p/353503#M87328</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/92755"&gt;@Geroge&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As per my understanding in our case we see user login prompt and we see sign in options.&lt;/P&gt;
&lt;P&gt;Then if i click on sign in options i see GP icon shows connected in sec or 2&lt;/P&gt;
&lt;P&gt;For prelogon always on we need to wait for few secs to get the GP machine tunnel built with user name prelogon.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will say check the client side GP logs in your case if it takes more time to built machine tunnel?&lt;/P&gt;
&lt;P&gt;Once PC is rebooted and login prompt is there then GP prelogon should connect with few secs&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Oct 2020 02:12:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-connecting-before-pre-logon/m-p/353503#M87328</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-10-02T02:12:52Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect - Connecting before pre-logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-connecting-before-pre-logon/m-p/353600#M87338</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/92755"&gt;@Geroge&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;What build of the GlobalProtect Agent do you have deployed? I can't say that I've seen this issue in recent releases, but we did see it on occasion with&amp;nbsp;&lt;EM&gt;old&amp;nbsp;&lt;/EM&gt;releases of the agent. However, post 5.0 and higher we've completely eliminated the issue getting reported within our environment.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Oct 2020 15:31:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-connecting-before-pre-logon/m-p/353600#M87338</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-10-02T15:31:24Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect - Connecting before pre-logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-connecting-before-pre-logon/m-p/353915#M87373</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have the same result with some of our users, but others seem to take a long time to connect, causing them to log into windows before the tunnel is established, causing the problems when Windows loads.&lt;/P&gt;&lt;P&gt;It's a beta deployment before we roll out to a large user base, so its very likely others will log in before the tunnel comes up.&lt;/P&gt;&lt;P&gt;On my machine I have a tunnel within about 20s, but I've seen on others it taking up to 90 seconds.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Perhaps I should be looking at why the tunnel is taking so long to come up, rather than the issues after windows loads.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2020 10:44:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-connecting-before-pre-logon/m-p/353915#M87373</guid>
      <dc:creator>Geroge</dc:creator>
      <dc:date>2020-10-05T10:44:20Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect - Connecting before pre-logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-connecting-before-pre-logon/m-p/353918#M87374</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have 5.1.5 running on the Firewall, but client side we have tried up to 5.2 with the same results.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a ticket open with support, but I'm considering now changing to Connect Before Logon, as the main purpose to deploy Pre-logon was to allow new users to connect to new laptops without having to connect to the domain first.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With the inconsistencies with Pre-logon I feel like connect before logon could be a better solution. I appreciate it works fine for others, but so far i've not had any luck and the support ticket has been going on for 6 weeks now!&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2020 10:48:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-connecting-before-pre-logon/m-p/353918#M87374</guid>
      <dc:creator>Geroge</dc:creator>
      <dc:date>2020-10-05T10:48:32Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect - Connecting before pre-logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-connecting-before-pre-logon/m-p/365200#M88541</link>
      <description>&lt;P&gt;We had a ticket open with support for some time, although the main issue that we were trying to fix was pre-logon tunnels not renaming, the problem in this post was also resolved along with the tunnel-rename issue being fixed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What it came down to was routing from the internal network to the gateways.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As we have multiple internet circuits and a gateway on each one, we had to make sure that traffic was getting routed correctly. When we looked into this we found one gateway was going into a routing loop and we needed to put a PBF in place to make the traffic bypass the default PBF rules.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's not a very detailed solution, but I hope this may point others in the right direction.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 13:34:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-connecting-before-pre-logon/m-p/365200#M88541</guid>
      <dc:creator>Geroge</dc:creator>
      <dc:date>2020-11-24T13:34:00Z</dc:date>
    </item>
  </channel>
</rss>

