GlobalProtect Client Certificate Authentication- PAN-OS 10.0.6

แชร์
ฝัง
  • เผยแพร่เมื่อ 21 ก.ค. 2024
  • In the video, I will show you how I configure GlobalProtect to use Client Certificate Authentication on a VM-Series Palo Alto NGFW running PAN-OS 10.0.6. Make sure you check out my "How to Configure Automatic Computer Certificate Enrollment in Windows Server 2016 / 2019" so that you have a machine certificate in place. - • How to Configure Autom...
    **Check out my new blog*** - www.mbtechtalker.com
    Watch these videos first!!
    🎥 GlobalProtect Portal & Gateway Configuration PAN-OS 10.0.6 - • GlobalProtect Portal &...
    🎥 - How to Configure Automatic User Certificate Enrolment in Windows Server 2016 / 2019 - • How to Configure Autom...
    🎥 GlobalProtect Pre-logon using a machine certificate - PAN-OS 10.0.6 • GlobalProtect Pre-logo...
    🎥 How to Configure Automatic Computer Certificate Enrollment in Windows Server 2016 / 2019 - • How to Configure Autom...
    🎥 How to Install Microsoft Certificate Services - • How to Install Microso...
    🎥 Palo Alto firewall lab using VMware Workstation - • Palo Alto firewall lab...
    🎥 How to configure Palo Alto Firewall Signature Based Security Profiles in PAN-OS 9.1- • Palo Alto Firewall Sig...
    🎥 Palo Alto Firewall Active-Passive HA VMware Workstation Lab- • Palo Alto Firewall Act...
    🎥 User-ID - • Palo Alto Firewall Win...
    🎥 SSL Forward Proxy decryption - • Palo Alto NGFW SSL For...
    Subscribe for more:
    / mbtechtalker
    Share this video with a friend:
    • GlobalProtect Client C...
    🎥 Watch next
    How To Configure A Certificate For Secure PAN-OS Web GUI Access
    • How To Configure A Cer...
    🐦 Twitter - @mbtechtalker
    🌐. Blog - www.mbtechtalker.com
    ☕. buymeacoffee.com/mbtechtalker

ความคิดเห็น • 18

  • @michaelbredell
    @michaelbredell ปีที่แล้ว

    Deploying this for a customer with SAML authentication. Will update how it goes. BTW this video answered a lot of questions. Keep the Palo Alto stuff coming! :)

  • @prakashborah6989
    @prakashborah6989 2 ปีที่แล้ว

    Just Fantastic! I watched a lot of videos but your videos cover all aspects...NAT, Security Policy, and GP config.

    • @MBTechTalker
      @MBTechTalker  2 ปีที่แล้ว

      That's great to hear Prakash!

  • @thomashunt7370
    @thomashunt7370 2 ปีที่แล้ว

    Your videos are awesome. Straight to the point but goes over everything necessary/required where other videos assume you already have X done.
    Would you be able to do a video around SAML and MFA? Ex: Google + Duo or 0Auth?

    • @alvanhuynh2852
      @alvanhuynh2852 ปีที่แล้ว +1

      Just wanted to let you know you can do DUO sign-in and MFA without having to go through Google, sort of. You'd have to configure your SAML on DUO if you already synchronize Azure AD/Google IDs to DUO. For SSO related things on DUO, you'd need to have a PKI in your environment to be able to utilize this. If you don't have this, I'm not sure with Google, but with Azure AD, you can configure Conditional Access that requires MFA (MS Authenticator or DUO) after signing in. You would configure the SAML on Azure AD and import it in to your PAN FWs.
      If you have anything radius related, you can also configure Radius to have DUO MFA as well.

  • @popescusilviu9948
    @popescusilviu9948 7 หลายเดือนก่อน

    fantastic content

  • @breakingbisley
    @breakingbisley 2 ปีที่แล้ว

    Hi Matt, Really enjoy these videos. Thank you for putting them up! I am on my journey with PAs and FGTs, so these config tutorials are expanding my knowledge. A quick question, have you managed to configure RADIUS with GP, or RADIUS auth for admin with WIN2016 Server? I am having quite the tough time as you do when labbing. Cheers!

    • @MBTechTalker
      @MBTechTalker  2 ปีที่แล้ว +1

      Hey breakingbisley, Thats good hear! I have a while back. One of my customers was using LDAP authentication but had requirement for users to have the ability to change there domain user account passwords over GlobalProtect. We ended up moving over to RADIUS using Microsoft NPM. Check out out this video th-cam.com/video/1J9ZfwckUbE/w-d-xo.html there is a part that discusses/demos RADIUS authentication using NPM and VSAs. I'll add this to my list of videos to create. Hope this helps in the meantime.

    • @breakingbisley
      @breakingbisley 2 ปีที่แล้ว

      @@MBTechTalker thanks for the response..much appreciated :) I will certainly give that YT link a look, cheers!

  • @Foword1
    @Foword1 2 ปีที่แล้ว

    Hi Matt , great tutorial , but i have a question , how palo knows that SecAdmin1 user is a vaild user ?
    looks like the portal only check the certificate itself and not user ? meaning where did you tell the firewall the SecAdmin1 is a vaild user ? hope I was clear.

  • @mohammadqaseemzalmai6623
    @mohammadqaseemzalmai6623 2 ปีที่แล้ว

    Hi Matt, Enjoyed the videos. I was wondering if you tested this with macOS. I tried and keep getting keychain prompt whenever GlobalProtect tries to connect. Windows work fine.

  • @carlbaillargeon4037
    @carlbaillargeon4037 2 ปีที่แล้ว

    Nice tutorial ! Are you going to do two-factor authentication as well ? Looking forward to it !

    • @MBTechTalker
      @MBTechTalker  2 ปีที่แล้ว

      Thanks Carl, what specifically would you like to see configured?

    • @carlbaillargeon4037
      @carlbaillargeon4037 2 ปีที่แล้ว

      @@MBTechTalker I think LDAP + Certificates would be the most common.

  • @AISynthar
    @AISynthar 11 หลายเดือนก่อน

    Can someone point me in the right direction to Disable Certificate prompt during GlobalProtect login for certificate confirmation through Intune. I need to automatically accept the certificate for my users. Thanks

  • @pranayranjannayak2015
    @pranayranjannayak2015 2 ปีที่แล้ว

    @mb tech talker i am getting server certificate error , how to troubleshoot that

    • @balasubramanianwv3877
      @balasubramanianwv3877 2 ปีที่แล้ว

      keep the subject name as none in the cert profile and try

  • @YuYuHakushoForever1
    @YuYuHakushoForever1 2 ปีที่แล้ว

    shortcut??? not enough details :(