- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-17-2013 01:55 AM
Hi All,
Is there any one knowing that global protect client will cash or keep user credential in the local? is the default behavior or not?
Our PA runs PanOS 4.1.10 and global protect client's version is 1.1.7.
Thanks.
Regrads,
Joy
03-17-2013 06:29 AM
If you permit to save it and client users are able to save their ID/PW, it will be save in client device.
You can decide it under Network tab > Global Protect Portal > <config name> > Agent tab > Use can save password.
This configuration is enabled by default.
Regards,
03-17-2013 07:23 AM
Hi All,
Thanks for feedbacks, quickly descrip my question below.
1.Use AD LDAP for sslvpn authentication
2.User-ID group-mapping is also use for after sslvpn login security policy control
3.The group-mapping -> Include group is also add groups into that would like to authenticated.
4.Two accounts in the AD who are "test_user" and "test.user".
In the beginning test_user can login sslvpn by global protect agent, and can hit correct security policy. for testing, we change user to "test.user" and do the test again, we find the user "test.user" can login sslvpn successfully, but the traffic logs we see, the user column is display "test_user" not "test.user".
We also check system logs, test.user is always try to login but authenticated fail. after several times, the system logs show user "test_user" login successfully.
After investigation, the user "test.user" is not in group-mapping include groups, so system logs display auth-fail, but it seems the GP agent brought account "test_user" to authenticae with PaloAlto firewall automatically, and auth-success.
So, we would like to know that is the global protect agent default behavior? or not?
In addition, we change another laptop and to the same again, but issue not occured.
My laptop runs windows 7 x86 and GP client's version is 1.1.7.
Regards,
03-17-2013 08:41 AM
if you did not see the issue on another laptop, I think you have to focus on differences between these 2 client pc.
I did not see any issue like that before and configured many global protect environments.
03-17-2013 09:20 AM
I did not see the issue before too, I think that should be the issue of first laptop itself, however just only a confusion, "why"?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!