- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
01-28-2026 06:39 AM
Hello,
I'm reaching out to see if anyone has configured GlobalProtect with cert+SAML authentication with multiple gateways across multiple firewalls. I've been attempting to configure this, however, whenever I use cert+SAML at the gateway and I attempt to switch gateways after logging in, the logs always show "client cert not present".
I have both the root/intermediate configured under certificate and have an accompanying certificate profile with nothing special specifying those two certs. I have both machine and user certs issued to the machine/user respectively. App configuration is basic, setup with pre-logon (always-on) and is targeted for "any".
For context, I'm able to perform cert-only authentication and if i set the subject-alt name to email in the profile, it authenticates both machine and user respectively for whichever stage its at and determines the correct user. Likewise, with SAML only, everything works fine as well when switching gateways. It's only when I combine cert with SAML that it fails.
I haven't been able to find many resources with concrete information on whether this is supported or not, most videos I've seen only specify SAML at the gateway.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

