Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

deploying ssl decryption cert using global protect client

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

deploying ssl decryption cert using global protect client

L0 Member

Hi,

 

I am trying to implement URL filtering for all users on Global Protect VPN.

I have done some tests and figure it out that I need to have ssl decryption policy set, matching the URLs to be blocked. I am using self-signed cert for ssl forward proxy, have manually exported the cert and imported into my local trusted root, everything seems to be fine.

The only question is how will I deploy the cert to all users? I dont want to do it manually for everyone, we dont have on prem DC. Is there a way to push the cert to the client using global protect client?

I am using public sectigo cert to secure vpn connection.

 

Regards,

 

 

 

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

Hi @Marcin_Jakubiec ,

 

Yes there is!  If you navigate to Network > GlobalProtect > Portal > [edit portal] > Agent, you will see a TRUSTED ROOT CA section on the bottom.  Add your CA there.  If you check the INSTALL IN LOCAL ROOT CERTIFICATE STORE check box, the CA will be pushed to the client.  If you click on the ? in the upper right, then GlobalProtect Portals Agent Tab hyperlink, you will read "To install (transparently) the trusted root CA certificates that are required for SSL Forward Proxy decryption in the certificate store on the client, select Install in Local Root Certificate Store."

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

View solution in original post

1 REPLY 1

Cyber Elite
Cyber Elite

Hi @Marcin_Jakubiec ,

 

Yes there is!  If you navigate to Network > GlobalProtect > Portal > [edit portal] > Agent, you will see a TRUSTED ROOT CA section on the bottom.  Add your CA there.  If you check the INSTALL IN LOCAL ROOT CERTIFICATE STORE check box, the CA will be pushed to the client.  If you click on the ? in the upper right, then GlobalProtect Portals Agent Tab hyperlink, you will read "To install (transparently) the trusted root CA certificates that are required for SSL Forward Proxy decryption in the certificate store on the client, select Install in Local Root Certificate Store."

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.
  • 1 accepted solution
  • 4518 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!