GlobalProtect credentials for RDP

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

GlobalProtect credentials for RDP

L2 Linker

Hello Community,

 

Customer is using Global Protect with SSO and RDP and he would like to know why does Globalprotect asks for credentials (internal portal) when a user logs through RDP?

 

For example, if the user logs locally the SSO works fine and Globalprotect can connect with the user's domain credentials.

However, if the user logs in the same machine with the same credentials but using RDP, Globalprotect disconnects and asks for credentials.

 

Is it the expected behavior ?

 

I have seen  the below option in portal >> Agent >> APP :

----

User Switch Tunnel Rename Timeout (sec) : Specify the number of seconds that a remote user has to be authenticated by a GlobalProtect gateway after logging into an endpoint by using Microsoft’s Remote Desktop Protocol (RDP) (range is 0 to 600; default is 0). Requiring the remote user to authenticate within a limited amount of time maintains security.

-----

 

If we modify this setting could it help for the behavior observed ?

 

Thanks in advance for your reply.

 

Best regards.

 

 

 

 

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

This is expected behavior

it's insecure to 'give' the connected GP connection to a new user that is hijacking the system using RDP

 

if you want to be able to allow users to do this, you can indeed change the timer on "User Switch Tunnel Rename Timeout" so the tunnel is not broken immediately, but it will be broken eventually for the new user to log in

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

View solution in original post

2 REPLIES 2

L2 Linker

Hello Team,

 

Could I have any feedback on this please ?

 

Thank you and best regards.

Cyber Elite
Cyber Elite

This is expected behavior

it's insecure to 'give' the connected GP connection to a new user that is hijacking the system using RDP

 

if you want to be able to allow users to do this, you can indeed change the timer on "User Switch Tunnel Rename Timeout" so the tunnel is not broken immediately, but it will be broken eventually for the new user to log in

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
  • 1 accepted solution
  • 444 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!