- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
05-27-2022 09:01 AM
Hi,
I am trying to implement URL filtering for all users on Global Protect VPN.
I have done some tests and figure it out that I need to have ssl decryption policy set, matching the URLs to be blocked. I am using self-signed cert for ssl forward proxy, have manually exported the cert and imported into my local trusted root, everything seems to be fine.
The only question is how will I deploy the cert to all users? I dont want to do it manually for everyone, we dont have on prem DC. Is there a way to push the cert to the client using global protect client?
I am using public sectigo cert to secure vpn connection.
Regards,
05-27-2022 04:09 PM - edited 05-27-2022 04:10 PM
Hi @Marcin_Jakubiec ,
Yes there is! If you navigate to Network > GlobalProtect > Portal > [edit portal] > Agent, you will see a TRUSTED ROOT CA section on the bottom. Add your CA there. If you check the INSTALL IN LOCAL ROOT CERTIFICATE STORE check box, the CA will be pushed to the client. If you click on the ? in the upper right, then GlobalProtect Portals Agent Tab hyperlink, you will read "To install (transparently) the trusted root CA certificates that are required for SSL Forward Proxy decryption in the certificate store on the client, select Install in Local Root Certificate Store."
Thanks,
Tom
05-27-2022 04:09 PM - edited 05-27-2022 04:10 PM
Hi @Marcin_Jakubiec ,
Yes there is! If you navigate to Network > GlobalProtect > Portal > [edit portal] > Agent, you will see a TRUSTED ROOT CA section on the bottom. Add your CA there. If you check the INSTALL IN LOCAL ROOT CERTIFICATE STORE check box, the CA will be pushed to the client. If you click on the ? in the upper right, then GlobalProtect Portals Agent Tab hyperlink, you will read "To install (transparently) the trusted root CA certificates that are required for SSL Forward Proxy decryption in the certificate store on the client, select Install in Local Root Certificate Store."
Thanks,
Tom
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!