pre-logon - not seeing "pre-logon" user in traffic logs / 0 hits on pre-logon policy rules

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

pre-logon - not seeing "pre-logon" user in traffic logs / 0 hits on pre-logon policy rules

L1 Bithead

I'm testing out pre-logon always on VPN with a pretty basic setup. My pre-logon tunnel is coming up and seems to work fine, however I am not seeing any hits on a permit any/any security policy rule that has the source users set to "pre-logon". Nothing in the traffic log either, just shows a blank user for traffic prior to successful user auth. User ID works after user auth and shows the actual user in the traffic logs / using proper matched policy rules.

 

I see this: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClXlCAK 

 But that's pretty out dated... 

 

Is there something obvious I'm missing? 

1 accepted solution

Accepted Solutions

Thanks for the reply and yes agreed there won't be a user in the traffic logs. However there should at least hits on the rules that are made for the pre-login user. 

 

I did end up figuring this out and forgot to post. In my environment I have the user-id agents installed and reporting user to ip mappings to the firewalls. I had to exclude the global protect IP range from this as it was overriding the pre-logon user. 

View solution in original post

3 REPLIES 3

L6 Presenter

This is normal to not see the prelogon user in the traffic logs:

 

 

Pre-logon User Does Not Appear in Traffic Logs - Knowledge Base - Palo Alto Networks

Thanks for the reply and yes agreed there won't be a user in the traffic logs. However there should at least hits on the rules that are made for the pre-login user. 

 

I did end up figuring this out and forgot to post. In my environment I have the user-id agents installed and reporting user to ip mappings to the firewalls. I had to exclude the global protect IP range from this as it was overriding the pre-logon user. 

L0 Member

I am having same issue with Prisma GPCS. I can see user pre-logon in globalprotect logs in Panorama but, not in the traffic logs.

 

  • 1 accepted solution
  • 4133 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!