Does Pre-logon for Global Protect use the Computer certificate as a client certificate?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
Palo Alto Networks Approved
Palo Alto Networks Approved
Community Expert Verified
Community Expert Verified

Does Pre-logon for Global Protect use the Computer certificate as a client certificate?

L2 Linker

Hi;

 

Prelogon Global Protect connection, does it use the Computer certificate as opposed to the user certificate to establish the tunnel? It seems that the only way to do it.

 

Kindly

Wasfi

2 accepted solutions

Accepted Solutions

L7 Applicator

Yes it will use the certificate in the computers store, it cannot use the user cert until user logs in as GP will not have access to the user profile and how will GP know which user will be logging in.

 

is there another reason why you need user details on pre logon?

View solution in original post

sure, no problem but please note that its not a case of using a machine certificate, more using a certificate in the machine store.

 

you could import a cert for fred smiff into the machine store and it will happily use that if it matches the root cert on the palo config.

 

View solution in original post

4 REPLIES 4

L7 Applicator

Yes it will use the certificate in the computers store, it cannot use the user cert until user logs in as GP will not have access to the user profile and how will GP know which user will be logging in.

 

is there another reason why you need user details on pre logon?

Thank you Mick. 

 

There is no reason but I just wanted to understand the mechanism as one of the clients asked me about it.

 

 

 

Kindly

Wasfi

sure, no problem but please note that its not a case of using a machine certificate, more using a certificate in the machine store.

 

you could import a cert for fred smiff into the machine store and it will happily use that if it matches the root cert on the palo config.

 

L2 Linker

However GP Pre-logon from 9.0 and 9.0.1 is broken and is currently with TAC for investigation. 

  • 2 accepted solutions
  • 5860 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!