This website uses cookies essential to its operation, for analytics, and for personalized content. By continuing to browse this site, you acknowledge the use of cookies. For details on cookie usage on our site, read our Privacy Policy
@BPry Would you mind sharing with me your configuration so that I may mimic what is working in your environment without giving any sensitive information? That may help us determine if it is an issue with our workstation or Globalprotect configuration.
... View more
Thanks for sharing your experience. Yes I did verify that prelogon was passing traffic during the logon in firewall logs. Also we are using the same subnet on the gateway for prelogon and users so the tunnel only gets renamed to the user. It could be something to do with our workstation build I don't know. Palo support did see that there is a wait for network connectivity during the boot process. Maybe networking is taking a little longer to initialize? It's good to know that it's functioning for others.
... View more
Our organization has been struggling with getting MS AD security group changes to apply over VPN w/ prelogon enabled for a long period of time now. I have had support tickets in with Palo support and MS support. Palo support has determined via Globalprotect logs, prelogon appears to be functioning properly and no traffic for this function is being denied by prelogon/user firewall security policies. Sometimes we have noticed if the user reboots twice the security group changes are then reflected on the user's PC. It hasn't been a great experience. I am curious if others are having the same headaches with gpo/security group changes that apply during boot with prelogon. Is it solvable or just something we must live with? We are configured with SAML authentication prelogon always on. Prelogon authenticates via a cookie.
... View more