- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
05-17-2024 07:11 AM - edited 05-17-2024 08:31 AM
Looking for assistance on a GP setup. I want to have a pre-logon tunnel (certificate, always on) and a portal, which uses SAML authentication. I also need the user to have to re-authenticate any time they disable, sign-out, reboot, etc. The problem I'm running into is because the portal uses SAML auth, the portal communication during pre-logon fails and therefore the pre-logon tunnel doesn't start. I thought I should be able to set the Generate and Authenticate cookie options on the pre-logon portal agent configuration but it's not working. I thought it would flow like this:
The portal auth by cookie after reboot is apparently not happening. PanGPS.log shows the messages "Unserialized empty cookie on portal..." and there are no attempts to connect to the portal in the FW Monitor log.
For my testing, I have my cookie lifetime set to 10 minutes. My reboots, logons, reboots are all occurring within 3 minutes.
PAN-OS 10.2.9-h1
GP 6.2.3
FYI, there are no certificate issues or anything like that. This is a modification of an existing setup where the pre-logon and portal use the machine certificate. I need to be able to have different portal agent configs for different groups of people, which means I need to know the user at the portal level so I can use AD groups. User certificates are not an option.
05-18-2024 03:20 AM
Hi
if you always want prelogon with certificate auth, deactivate the authenticaten overwrite. Then you dont run into the cookie problems.
What is your portal authentication setup?
You cannot activate User Credentials And Client Certificate. With pre-logon, you can only activate User Credentials Or Client Certificate. Because you don't have a user at pre-logon.
What says your GP log on the firewall?
05-20-2024 04:44 AM
Thank you for the reply but I'm not sure you understood the question. I have a machine certificate portal and pre-logon setup today. However, now I need to know who the user is at the portal for the post logon agent config. The question basically comes down to, how do I do that without breaking the pre-logon tunnel?
05-22-2024 04:31 AM
I'm not sure I understood the question 😄 You wrote about SAML login failures at pre-logon (what is normal), but you also expect this behavior at 1.
For cookie auth you need a valid certificate oder user auth at first. This should be the reason for your unserilied cookie problem.
The user result from the SAML auth. If it was successful, you see the user in the logs and can setup different agent configs also
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!