- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-02-2025 06:26 PM
Hello,
Recently we had the new PANFW migration, together with the GlobalProtect VPN enabled. We are working fine with what has setup. As of our staffs we login to the GP VPN with the corporate computers pre-installed with machine certificates and also the client certificates.
Now we are going to settle the issue when the staffs trying to login with their Windows AD accounts and if the AD account was expired. Although helpdesk has settled the password for them, the problem happened to be the users still unable to login to the computer.
I have a quick search to the PAN, it should be called Pre-logon authentication. (please advise me if it is not correct)
The current environment we have is having a policy that allows GP VPN formed. A separate Subnet range is assigned for those authenticated users (in VPN_Zone).
Now I am planning to setup the Pre-logon authentication for our staffs. In this case, do I have to create a separate interface? It seems we have most of the part done, am I right to skip to Step 6 of Remote Access VPN with Pre-Logon? (create a certificate profile PrelogonCert)?
Thanks in advance. Best Regards,
Timothy
03-04-2025 02:22 PM
You didn't actually include the guide that you're following so we can't actually certify what step you can/cannot skip to. Whether or not you would need a separate interface or not would depend on how you're configuring things, generally speaking I would say a small environment has the same gateway in use for fully authenticated users and pre-logon but you don't have to.
03-05-2025 07:56 PM
@BPry Thanks for you reply.
Here is the doc that I followed.
I did not create extra interface for my testing.
Now I come to a stage that to create two Agents inside the GlobalProtect Portal.
The first agent is for PreLogon, so I setup the Config Selection Criteria to pre-logon, and the Connect Method I use is set to PreLogon then On-Demand.
The other is for normal VPN access, I set Config Selection Criteria to Any, and the Connect Method to On-Demand (Manual user initiated connection)
Timothy
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!