GlobalProtect Pre-logon using a machine certificate - PAN-OS 10.0.6

แชร์
ฝัง
  • เผยแพร่เมื่อ 5 ต.ค. 2024
  • In the video, I show you how I configure GlobalProtect Pre-logon using a machine certificate on a VM-Series Palo Alto NGFW running PAN-OS 10.0.6. Make sure you check out my "How to Configure Automatic Computer Certificate Enrollment in Windows Server 2016 / 2019" so that you have a machine certificate in place. - • How to Configure Autom...
    **Check out my new blog*** - www.mbtechtalker.com
    Watch these videos first!!
    🎥 GlobalProtect Portal & Gateway Configuration PAN-OS 10.0.6 - • GlobalProtect Portal &...
    🎥 How to Configure Automatic Computer Certificate Enrollment in Windows Server 2016 / 2019 - • How to Configure Autom...
    🎥 How to Install Microsoft Certificate Services - • How to Install Microso...
    🎥 Palo Alto firewall lab using VMware Workstation - • Palo Alto firewall lab...
    🎥 How to configure Palo Alto Firewall Signature Based Security Profiles in PAN-OS 9.1- • Palo Alto Firewall Sig...
    🎥 Palo Alto Firewall Active-Passive HA VMware Workstation Lab- • Palo Alto Firewall Act...
    🎥 User-ID - • Palo Alto Firewall Win...
    🎥 SSL Forward Proxy decryption - • Palo Alto NGFW SSL For...
    Subscribe for more:
    / mbtechtalker
    Share this video with a friend:
    • GlobalProtect Portal &...
    🎥 Watch next
    How To Configure A Certificate For Secure PAN-OS Web GUI Access
    • How To Configure A Cer...
    🐦 Twitter - @mbtechtalker
    🌐. Blog - www.mbtechtalker.com
    ☕. buymeacoffee.c...

ความคิดเห็น • 12

  • @ericjovanrivera660
    @ericjovanrivera660 2 ปีที่แล้ว +4

    I have had tons of issues with Pre-logon because the documentation was not that helpful. This video is great!!! Is there any way you could go more in depth on the machine certificate settings and how to configure that piece? The Portal and Gateway configs were clear but when talking about the Certs and CA' i wasnt sure if you were referring to an Internal CA or the CA that signs the Public cert used in the Portal. Maybe you could do a part 2 or in depth demo on that side of things. Thank you!!!

  • @joe618
    @joe618 5 หลายเดือนก่อน

    Thanks for sharing. I hope there will be more teachings.

  • @sachinwarad10
    @sachinwarad10 11 หลายเดือนก่อน

    Great Video. So So much better than online document. Thanks for this.
    1 Query while creating Cert Profile you selected Root CA, instead of this can I use my Local Enterprise Root CA & Intermediate CA? Bcoz machine & user cert are signed using Local Enterprise CA?

  • @bizbouk
    @bizbouk 2 ปีที่แล้ว +3

    Am I correct in saying that this is using authentication cookies and not using machine certificates?

  • @tracygarner5487
    @tracygarner5487 2 ปีที่แล้ว +2

    This works if I login, connect with the GPC, log out, then log back in. It does not work after a startup/reboot.

  • @md.mahmudhasan3507
    @md.mahmudhasan3507 2 ปีที่แล้ว

    Out of the 3 option that you mentioned, looks like you used option 2 as I think no cert were used in the portal and you need to login to the gp client for the first time to generate the cookie. Is that right?

  • @verdibahnsen
    @verdibahnsen 3 ปีที่แล้ว +1

    Can this be done without using auth cookies and just a machine cert for the pre-logon? We have a scenario where laptops are being built for new users and they need connection to the VPN to have their profiles/GPOs applied etc but can’t because they’ve never logged in. Kind of a chicken before the egg scenario. I’ve read that it’s possible but I’ve never gotten it to work

    • @MBTechTalker
      @MBTechTalker  3 ปีที่แล้ว

      Hi, If I understand correctly, your referring to "connect before logon" take a look at this link docs.paloaltonetworks.com/globalprotect/5-2/globalprotect-app-new-features/new-features-released-in-gp-app/connect-before-logon

    • @bbass2
      @bbass2 2 ปีที่แล้ว +3

      @@MBTechTalker In the beginning of the video, and in the official document from PA, it mentions the three methods that will work for pre-logon. You used option 3 which allows the use of machine certs and authentication cookies. The logs did show successful authentication with the cookie at the end of the video.
      The document leads one to believe it will work using only machine certs by following the same config you laid out with the exception of enabling the cookie generation and acceptance check boxes in the portal and gateway configs. However, when I test this in my environment GlobalProtect shows no status information at the Windows login screen so it doesn't even appear to be attempting a connection. Any ideas or perhaps clarification if I'm misinterpreting how this is supposed to function?

    • @smakersify
      @smakersify 2 ปีที่แล้ว +3

      Yeah there seems to be missing step here. Currently, this also is not working for me in my test env, as pre-logon is not able to login to VPN. The GP log before login is success, but doesn't say the pre-logon as the source user, instead its blanc.

  • @techfire1
    @techfire1 3 ปีที่แล้ว +1

    Where do you get the RootCA cert from?

    • @MBTechTalker
      @MBTechTalker  3 ปีที่แล้ว +1

      Hey techfire1, I installed Microsoft Certificate Services on my lab Windows 2016 server , check out this video - th-cam.com/video/58WQIu0VUTw/w-d-xo.html