Global Protect After Prelogin the switch to user is not changing IP networks

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Global Protect After Prelogin the switch to user is not changing IP networks

L0 Member

We are using machine and user certificates from a windows server 2016 CA. to authenticate when using Global Protect.

  • Step one is the prelogin connections and it works as intended.  The IP address is assigned on 10.1.1.0/24 network.
  • Once the user logs into the computer it is configured as always on VPN then switch to user certificate for the user VPN.  The expected behavior is the endpoint gets a new IP address in 10.1.2.0/24 network. Everything is working except that the IP address never changes. The first network is very restricted while the second one has access to the needed resources. I need to find out while the user context is showing as switched it never switches IP addresses (changes from prelogin to username@domain.local)
3 REPLIES 3

Cyber Elite
Cyber Elite

@CobaltixIT 

 

Do you want that when user login to prelogon then it has one subnet and when they login they should have different IP address?

for this you need to have IP address pool for pre log on and then you need second ip pool for actual user login.

 

also which connection method you have prelogon and always on?

 

Regards

MP

Help the community: Like helpful comments and mark solutions.

L4 Transporter

Hello @CobaltixIT 

You might be able to achieve the same result (limited access vs. more access) by filtering the user (pre-logon vs "domain\domain users" on the firwall (VPN gateway).

L7 Applicator

Thats kinda whats supposed to happen. If you require different ip pool then @MP18 has the answer with different pools via the gateway configs. One range for pre logon and another for users.

 

i prefer to keep the same address and set policies to suit the user names.  I have limited access for pre-logon and almost full access for domain\users as suggested by @JoergSchuetter . 

  • 3584 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!