I am facing a problem with pre-logon on windows 10. I have some windows 10 laptops that works fine but few of them have the problem below.
I have import the local machine certificate and change registry entries. If I sign out from windows, I can see the pre logon option and connect to my vpn. But when i restart or shutdown the laptop, when it comes to the windows login screen, I dont have any option for pre logon. That means that i have first to login with a cached user , log off and here they are the start global protect option.
Thanks a lot
Do a check on following :-
Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto Networks\GlobalProtect\PanSetup
Prelogon Value should be 1.
Check your machine certificate status.
your machine certificates it should contain private key.
Check certificate chain for machine certificate.
Troubleshooting logs what error do you see ?
Just wondering if there was a resolution with this?
From research apparently changing the Pre-Logon Tunnel Rename Timeout to 0 might help.
In case someone else is facing this issue
1. Make sure the registry's Prelogon Value is 1, as Fatboy1607 already mentioned.
2. Make sure you imported the correct certificates on the machine/user store on the endpoints
3. As per the PA doc, if you have different configs for prelogon and other users, make sure the connect method is prelogon.
And here is what fixed the same issue I had:
Checking PanGPS, I found out that PanGPS found a user session, so it skipped the pre-logon tunnel establishment, and continued with the normal user connection establishment
Once I disabled that Windows 10 feature mentioned on the link above, pre-logon tunnel was working as expected
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!