about global protect agent default behavior

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

about global protect agent default behavior

L4 Transporter

Hi All,

Is there any one knowing that global protect client will cash or keep user credential in the local? is the default behavior or not?

Our PA runs PanOS 4.1.10 and global protect client's version is 1.1.7.

Thanks.

Regrads,

Joy

5 REPLIES 5

L6 Presenter

Hi,

Why do you need that information and which credentials you mean ?

L5 Sessionator

If you permit to save it and client users are able to save their ID/PW, it will be save in client device.

You can decide it under Network tab > Global Protect Portal > <config name> > Agent tab > Use can save password.

This configuration is enabled by default.

Regards,WS000013.JPG

Hi All,

Thanks for feedbacks, quickly descrip my question below.

1.Use AD LDAP for sslvpn authentication

2.User-ID group-mapping is also use for after sslvpn login security policy control

3.The group-mapping -> Include group is also add groups into that would like to authenticated.

4.Two accounts in the AD who are "test_user" and "test.user".

In the beginning test_user can login sslvpn by global protect agent, and can hit correct security policy. for testing, we change user to "test.user" and do the test again, we find the user "test.user" can login sslvpn successfully, but the traffic logs we see, the user column is display "test_user" not "test.user".

We also check system logs, test.user is always try to login but authenticated fail. after several times, the system logs show user "test_user" login successfully.

After investigation, the user "test.user" is not in group-mapping include groups, so system logs display auth-fail, but it seems the GP agent brought account "test_user" to authenticae with PaloAlto firewall automatically, and auth-success.

So, we would like to know that is the global protect agent default behavior? or not?

In addition, we change another laptop and to the same again, but issue not occured.

My laptop runs windows 7 x86 and GP client's version is 1.1.7.

Regards,

if you did not see the issue on another laptop, I think you have to focus on differences between these 2 client pc.

I did not see any issue like that before and configured many global protect environments.

I did not see the issue before too, I think that should be the issue of first laptop itself, however just only a confusion, "why"?

  • 2477 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!