Global Protect Setup using an external CA

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Global Protect Setup using an external CA

L2 Linker

Can anyone help with setting up GP to use certificates from an external CA ?

Ive managed to get it working using an internal CA & signing the server & client certificates defined in the portal against that - but Im struggling to get it working when I use an external CA to generate the certificates; where Im trying to get too is that we preload our laptops with certs signed against our Microsoft CA & users can then use Global Protect to connect into the LAN using Kerberos to authenticate against the our Microsoft DC & the preinstalled certificate on the laptop checked against a copy of the CA cert installed on the PA.

The Kerberos authentication is working fine, but I dont appear to be able to get the correct settings for GP portal & gateway to use externally generated certificates.

Any ideas ?

Thanks - Nick.

1 REPLY 1

L6 Presenter

This is just a shot in the dark, but are the GP clients able to check cert validity against the external CA before they are authorized on the network?

-Benjamin

  • 1868 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!