GlobalProtect Prelogon

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

GlobalProtect Prelogon

L0 Member

Hello,

Recently we had the new PANFW migration, together with the GlobalProtect VPN enabled. We are working fine with what has setup. As of our staffs we login to the GP VPN with the corporate computers pre-installed with machine certificates and also the client certificates. 

 

Now we are going to settle the issue when the staffs trying to login with their Windows AD accounts and if the AD account was expired. Although helpdesk has settled the password for them, the problem happened to be the users still unable to login to the computer.

I have a quick search to the PAN, it should be called Pre-logon authentication. (please advise me if it is not correct)

 

The current environment we have is having a policy that allows GP VPN formed. A separate Subnet range is assigned for those authenticated users (in VPN_Zone).

 

Now I am planning to setup the Pre-logon authentication for our staffs. In this case, do I have to create a separate interface? It seems we have most of the part done, am I right to skip to Step 6 of Remote Access VPN with Pre-Logon? (create a certificate profile PrelogonCert)?

 

Thanks in advance. Best Regards,

Timothy

2 REPLIES 2

Cyber Elite
Cyber Elite

@GroupITSvc,

You didn't actually include the guide that you're following so we can't actually certify what step you can/cannot skip to. Whether or not you would need a separate interface or not would depend on how you're configuring things, generally speaking I would say a small environment has the same gateway in use for fully authenticated users and pre-logon but you don't have to.

L0 Member

@BPry  Thanks for you reply.

https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-quick-configs...

Here is the doc that I followed.

 

I did not create extra interface for my testing.

Now I come to a stage that to create two Agents inside the GlobalProtect Portal. 

 

The first agent is for PreLogon, so I setup the Config Selection Criteria to pre-logon, and the Connect Method I use is set to PreLogon then On-Demand.

GroupITSvc_0-1741232255905.png

GroupITSvc_1-1741232291047.png

 

 

The other is for normal VPN access, I set Config Selection Criteria to Any, and the Connect Method to On-Demand (Manual user initiated connection)

GroupITSvc_2-1741232357167.png

GroupITSvc_3-1741232383159.png

Timothy

 

 

 

 

  • 244 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!