<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to connect users to their domain via GlobalProtect in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-connect-users-to-their-domain-via-globalprotect/m-p/374007#M88993</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- IF computers are&amp;nbsp;&lt;SPAN&gt;already joined to the domain, cookie authentication can be used with "pre-log on (allways on)" feature without using client certificate.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- This config must be used alongside other authentication mechanisms like "LDAP". In order to client receives the cookie.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;With this config A cookie will be generated by firewall and sent to client profile folder under "%LocalAppdata%/Palo Alto Networks\GlobalProtect\" with &amp;lt;somenumerbers&amp;gt;.dat file.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;-So within the cookie lifetime client can be connect to gateway as pre-log on state and the can change their password.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I used this articale;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000boODCAY" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000boODCAY&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Have a nice day.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 12 Dec 2020 08:37:08 GMT</pubDate>
    <dc:creator>upelister</dc:creator>
    <dc:date>2020-12-12T08:37:08Z</dc:date>
    <item>
      <title>How to connect users to their domain via GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-connect-users-to-their-domain-via-globalprotect/m-p/373740#M88956</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We need a solution to join the users first to their Domain via Global Protect and after that client MUST be able to reset/change their password.&lt;/P&gt;&lt;P&gt;We were thinking of using Pre-logon, however, this requires machine certificate and customer is not willing to spend anything on this.&lt;/P&gt;&lt;P&gt;Is there a way to implement the request? Kindly provide some KBs as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2020 03:45:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-connect-users-to-their-domain-via-globalprotect/m-p/373740#M88956</guid>
      <dc:creator>FarzanaMustafa</dc:creator>
      <dc:date>2020-12-11T03:45:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to connect users to their domain via GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-connect-users-to-their-domain-via-globalprotect/m-p/373755#M88959</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/98673"&gt;@FarzanaMustafa&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;The actual computers will already be joined to the domain correct? I'm assuming that the answer to this is yes, because otherwise this really isn't going to work regardless of what you do.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If they aren't willing to pay for the time needed to do a proper pre-logon configuration, you could always use the new GlobalProtect 5.2 agent and&amp;nbsp; Connect Before Logon (CBL). Essentially this acts the same as the old SBL configuration with AnyConnect if you are familiar with that. It allows a user to manually initiate a VPN connection connection prior to logging into the system. That sounds like it would meet all of your requirements you listed.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/10-0/globalprotect-admin/globalprotect-apps/deploy-app-settings-transparently/deploy-app-settings-to-windows-endpoints/deploy-connect-before-logon-settings-in-the-windows-registry.html" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/10-0/globalprotect-admin/globalprotect-apps/deploy-app-settings-transparently/deploy-app-settings-to-windows-endpoints/deploy-connect-before-logon-settings-in-the-windows-registry.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2020 04:13:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-connect-users-to-their-domain-via-globalprotect/m-p/373755#M88959</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-12-11T04:13:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to connect users to their domain via GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-connect-users-to-their-domain-via-globalprotect/m-p/374007#M88993</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- IF computers are&amp;nbsp;&lt;SPAN&gt;already joined to the domain, cookie authentication can be used with "pre-log on (allways on)" feature without using client certificate.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- This config must be used alongside other authentication mechanisms like "LDAP". In order to client receives the cookie.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;With this config A cookie will be generated by firewall and sent to client profile folder under "%LocalAppdata%/Palo Alto Networks\GlobalProtect\" with &amp;lt;somenumerbers&amp;gt;.dat file.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;-So within the cookie lifetime client can be connect to gateway as pre-log on state and the can change their password.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I used this articale;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000boODCAY" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000boODCAY&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Have a nice day.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 12 Dec 2020 08:37:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-connect-users-to-their-domain-via-globalprotect/m-p/374007#M88993</guid>
      <dc:creator>upelister</dc:creator>
      <dc:date>2020-12-12T08:37:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to connect users to their domain via GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-connect-users-to-their-domain-via-globalprotect/m-p/374009#M88994</link>
      <description>&lt;P&gt;Hi I have trouble creating my account please help&lt;/P&gt;</description>
      <pubDate>Sat, 12 Dec 2020 12:01:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-connect-users-to-their-domain-via-globalprotect/m-p/374009#M88994</guid>
      <dc:creator>135267895</dc:creator>
      <dc:date>2020-12-12T12:01:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to connect users to their domain via GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-connect-users-to-their-domain-via-globalprotect/m-p/374013#M88997</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/98673"&gt;@FarzanaMustafa&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the user is part of a Windows Domain network, the machine is cert is FREE.&amp;nbsp; It should be deployed to the user PRIOR to even having GP on the computer.&amp;nbsp; Once a machine cert, signed by the ECA (enterprise CA), then the user can do auth with a machine cert.&amp;nbsp; No cost involved.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 12 Dec 2020 16:17:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-connect-users-to-their-domain-via-globalprotect/m-p/374013#M88997</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2020-12-12T16:17:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to connect users to their domain via GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-connect-users-to-their-domain-via-globalprotect/m-p/374332#M89042</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/165304"&gt;@135267895&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Which account? looks like you are logged into this LIVE account and posting a message.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Dec 2020 22:14:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-connect-users-to-their-domain-via-globalprotect/m-p/374332#M89042</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2020-12-14T22:14:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to connect users to their domain via GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-connect-users-to-their-domain-via-globalprotect/m-p/375117#M89150</link>
      <description>&lt;P&gt;Yes but when i want to create account it says contact support what can I do I'm lost&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2020 04:54:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-connect-users-to-their-domain-via-globalprotect/m-p/375117#M89150</guid>
      <dc:creator>135267895</dc:creator>
      <dc:date>2020-12-18T04:54:27Z</dc:date>
    </item>
  </channel>
</rss>

