05-25-2023 05:31 PM
I'm trying to set up GlobalProtect's 'Serial Number Check' feature, but I'm having a hard time.
GlobalProtect is already being used in conjunction with LDAP.
So, when I do not use the function, I log in normally.
I want to control by matching the serial number to the LDAP user.
Is it correct that the serial number mentioned here means the device ID of Windows/Mac?
And in the firewall, there seems to be nothing to set other than changing the function to 'yes'.
I tried entering the device ID in Serial Number among the LDAP properties, but it doesn't work.
If anyone has done the above setup or knows how to do it, please let me know.
05-27-2023 05:11 PM
In looking at the help for this section.
I think it will be to tie to the device (not the user) to LDAP.
So I think GP can get confirmation that the device belongs in AD (as long as AD responds back).
I am not sure of the mechanism, but it is best to open a TAC case to get confirmation on the solution.
05-31-2023 01:19 PM
I read additional information that the Serial number check is used by the Cloud Identity Engine for registering endpoints.
If you are using GlobalProtect and you have enabled Serial Number Check, select the Endpoint Serial Number option to allow the Cloud Identity Engine to collect serial numbers from managed endpoints. This information is used by the GlobalProtect portal to check if the serial number exists in the directory for verification that the endpoint is managed by GlobalProtect.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!