Global Protect certificate auth user/device information

Showing results for 
Show  only  | Search instead for 
Did you mean: 
Please sign in to see details of an important advisory in our Customer Advisories area.

Global Protect certificate auth user/device information

L1 Bithead

Currently we have a GP vpn setup for our mobile devices.  We have are doing certificate based authentication, certificate is pushed out through an MDM.  Basically if your device has this cert, your device connects.  Is there a way to capture or pass through connected user information, for example username, email, etc.?  Right now when looking at the GP monitor logs, it displays the source user as our public IP/CN of the cert.  This would help to see who is connected or not, since the hostname field is whatever the mobile device is set to.


Cyber Elite
Cyber Elite

you would need to add the username in each certificate (as CN or SAN email) so that information can be pulled in lieu of an authentication username

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
  • 1 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!