<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global protect warning message upon commit in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-warning-message-upon-commit/m-p/436349#M96255</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/181759"&gt;@Ben-Price&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;If you allow authentication override it would bypass the device check that you have configured because it's just accepting the cookie and not performing the rest of the authentication process that would actually look at the device/custom checks that you have configured.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 24 Sep 2021 01:55:37 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2021-09-24T01:55:37Z</dc:date>
    <item>
      <title>Global protect warning message upon commit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-warning-message-upon-commit/m-p/436073#M96228</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A client recently updated to PAN OS 10.1.2 and is now receiving the below warning upon commit.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2021-09-19 12:18:46.350 +1000 client sslvpn reported warning: Portal config 'GP_VPN': Authentication Override and Config Seletcion Criteria -&amp;gt; Device Checks/Custom Checks are both configured, Authentication Override will be disabled.&lt;BR /&gt;(Module: sslvpn)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am just trying to understand why they are receiving this warning. Is GP portal authentication override and device/custom checks not able to be configured at the same time?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BenPrice_0-1632382640904.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36576i80096FA3DB6D521F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="BenPrice_0-1632382640904.png" alt="BenPrice_0-1632382640904.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BenPrice_2-1632382763240.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36578iE8FB1139810AA0AB/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="BenPrice_2-1632382763240.png" alt="BenPrice_2-1632382763240.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2021 07:40:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-warning-message-upon-commit/m-p/436073#M96228</guid>
      <dc:creator>Ben-Price</dc:creator>
      <dc:date>2021-09-23T07:40:00Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect warning message upon commit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-warning-message-upon-commit/m-p/436349#M96255</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/181759"&gt;@Ben-Price&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;If you allow authentication override it would bypass the device check that you have configured because it's just accepting the cookie and not performing the rest of the authentication process that would actually look at the device/custom checks that you have configured.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Sep 2021 01:55:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-warning-message-upon-commit/m-p/436349#M96255</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-09-24T01:55:37Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect warning message upon commit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-warning-message-upon-commit/m-p/436354#M96257</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;thanks for that, makes sense.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Sep 2021 02:28:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-warning-message-upon-commit/m-p/436354#M96257</guid>
      <dc:creator>Ben-Price</dc:creator>
      <dc:date>2021-09-24T02:28:55Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect warning message upon commit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-warning-message-upon-commit/m-p/528840#M109183</link>
      <description>&lt;P&gt;Sorry to drag up an old thread but I just started getting this error having enabled the cookie creation on the Portal and allowing the override on the Gateway.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The device check I have on the Portal is making sure I have a machine certificate in place, the system is a domain system.&amp;nbsp; Despite this error the cookie allows only one round of authentication whereas we were experiencing two rounds of authentication before making the cookie additions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is the a bug?&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 08:51:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-warning-message-upon-commit/m-p/528840#M109183</guid>
      <dc:creator>WilliamD</dc:creator>
      <dc:date>2023-01-27T08:51:36Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect warning message upon commit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-warning-message-upon-commit/m-p/1205186#M122997</link>
      <description>&lt;P&gt;We use exactly this configuration : device check for selecting the config with domain registry key, and cookie generation in order to pass this cookie to the gateway. We are not bypassing the authentication in the portal, we only generate the cookie.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have the same warning, but this configuration seems to work as expected.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PanOS 11.1.6.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2025 14:04:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-warning-message-upon-commit/m-p/1205186#M122997</guid>
      <dc:creator>A2SR</dc:creator>
      <dc:date>2025-01-23T14:04:54Z</dc:date>
    </item>
  </channel>
</rss>

