pre-logon - not seeing "pre-logon" user in traffic logs / 0 hits on pre-logon policy rules

cancel
Showing results for 
Search instead for 
Did you mean: 

pre-logon - not seeing "pre-logon" user in traffic logs / 0 hits on pre-logon policy rules

L1 Bithead

I'm testing out pre-logon always on VPN with a pretty basic setup. My pre-logon tunnel is coming up and seems to work fine, however I am not seeing any hits on a permit any/any security policy rule that has the source users set to "pre-logon". Nothing in the traffic log either, just shows a blank user for traffic prior to successful user auth. User ID works after user auth and shows the actual user in the traffic logs / using proper matched policy rules.

 

I see this: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClXlCAK 

 But that's pretty out dated... 

 

Is there something obvious I'm missing? 

2 REPLIES 2

Cyber Elite
Cyber Elite

This is normal to not see the prelogon user in the traffic logs:

 

 

Pre-logon User Does Not Appear in Traffic Logs - Knowledge Base - Palo Alto Networks

Thanks for the reply and yes agreed there won't be a user in the traffic logs. However there should at least hits on the rules that are made for the pre-login user. 

 

I did end up figuring this out and forgot to post. In my environment I have the user-id agents installed and reporting user to ip mappings to the firewalls. I had to exclude the global protect IP range from this as it was overriding the pre-logon user. 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!