- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
04-10-2019 09:02 PM
Hi;
Prelogon Global Protect connection, does it use the Computer certificate as opposed to the user certificate to establish the tunnel? It seems that the only way to do it.
Kindly
Wasfi
04-10-2019 11:01 PM
Yes it will use the certificate in the computers store, it cannot use the user cert until user logs in as GP will not have access to the user profile and how will GP know which user will be logging in.
is there another reason why you need user details on pre logon?
04-11-2019 01:30 AM
sure, no problem but please note that its not a case of using a machine certificate, more using a certificate in the machine store.
you could import a cert for fred smiff into the machine store and it will happily use that if it matches the root cert on the palo config.
04-10-2019 11:01 PM
Yes it will use the certificate in the computers store, it cannot use the user cert until user logs in as GP will not have access to the user profile and how will GP know which user will be logging in.
is there another reason why you need user details on pre logon?
04-11-2019 01:26 AM
Thank you Mick.
There is no reason but I just wanted to understand the mechanism as one of the clients asked me about it.
Kindly
Wasfi
04-11-2019 01:30 AM
sure, no problem but please note that its not a case of using a machine certificate, more using a certificate in the machine store.
you could import a cert for fred smiff into the machine store and it will happily use that if it matches the root cert on the palo config.
04-12-2019 07:33 AM
However GP Pre-logon from 9.0 and 9.0.1 is broken and is currently with TAC for investigation.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!