Global Protect pre-logon then on-demand configuration

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Global Protect pre-logon then on-demand configuration

L2 Linker

We're using these versions (Yes, we need to upgrade, but other priorities at the moment)

PANos 8.1.14
Global Protect client 5.2.1

 

We're currently usingOn-Demand, which is working. We used this page with the only difference is we're using AD Authentication.

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClH2CAK


Now we want to use pre-logon then on-demand.

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000oM4ACAU

We used our internal PKI to create machine certs and those have been deployed using Group Policy.

 

What I'm not getting is how to configure GlobalProtect to use the machine cert for pre-logon.

Do I create a new SSL/TLS profile or certificate profile?

Can I use the PANos self-signed in conjunction with the PKI machine cert? Would the self-signed be for the portal and the machine cert be for the gateway?

 

I've gone through all the documents, as well as, the GP Admin guide.

 

Any advice or guidance is much appreciated!

9 REPLIES 9

Portal Auth

MickBall_0-1624534161830.png

Portal configs

MickBall_1-1624534775583.png

Gateway Auth

MickBall_2-1624534861980.png

Gateway conf

MickBall_3-1624534992893.png

 

And your SSL/TLS profile points to your CA?

Yes but not the same CA used for authentication.

 

 

L2 Linker

Just a followup. I switched to using a wilcard cert for the portal and internal PKI with machine certs for pre-logon. I've passed this hurdle and now just need to resolve the cookie issue I'm having with pre-login.

 

Thanks for your help!

L2 Linker

Hope y'all are well.

 

@CobaltixIT 

@MickBall 

 

Thank you both for your help. In the end we stood up an MS NPS server for RADIUS.

 

Now the portal has the wildcard.domain.com cert and the gateway has an internal PKI certificate. When a computer is joined to the domain they are issued a cert from our PKI. Then using RADIUS to authenticate Pre-Logon then Demand is working and users can change their password before logging in.

 

Since the company is allowing BYOD for remote users I have to configure GP to allow a non-domain computer to authenticate. (BYOD may change soon, but in the meantime...)

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!