- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
12-16-2021 11:03 AM
I'm testing out pre-logon always on VPN with a pretty basic setup. My pre-logon tunnel is coming up and seems to work fine, however I am not seeing any hits on a permit any/any security policy rule that has the source users set to "pre-logon". Nothing in the traffic log either, just shows a blank user for traffic prior to successful user auth. User ID works after user auth and shows the actual user in the traffic logs / using proper matched policy rules.
I see this: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClXlCAK
But that's pretty out dated...
Is there something obvious I'm missing?
01-13-2022 06:01 AM
Thanks for the reply and yes agreed there won't be a user in the traffic logs. However there should at least hits on the rules that are made for the pre-login user.
I did end up figuring this out and forgot to post. In my environment I have the user-id agents installed and reporting user to ip mappings to the firewalls. I had to exclude the global protect IP range from this as it was overriding the pre-logon user.
01-13-2022 02:19 AM
This is normal to not see the prelogon user in the traffic logs:
Pre-logon User Does Not Appear in Traffic Logs - Knowledge Base - Palo Alto Networks
01-13-2022 06:01 AM
Thanks for the reply and yes agreed there won't be a user in the traffic logs. However there should at least hits on the rules that are made for the pre-login user.
I did end up figuring this out and forgot to post. In my environment I have the user-id agents installed and reporting user to ip mappings to the firewalls. I had to exclude the global protect IP range from this as it was overriding the pre-logon user.
09-30-2022 07:39 AM
I am having same issue with Prisma GPCS. I can see user pre-logon in globalprotect logs in Panorama but, not in the traffic logs.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!