Skip to content

GlobalProtect Pre-logon

GlobalProtect Pre-logon is a remote connection method based on machine certificate authentication. Practical use cases to deploy Pre-logon are:

  1. Domain scripts executed at login stage, VPN is established before user login, so can execute.
  2. Expired domain password – user will get prompt to change password normally like locally in the office.
  3. My Customer uses it to provision endpints in some emergency caseses when PC must be send directly to user.

Configuration steps in detail are elaborated here:

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEYCA0

Be aware of mandatory conditions to make it running, one of the following three must exist:

Portal contains ‘certificate profile’ but ‘no’ auth cookies
Portal does ‘not’ contain ‘certificate profile’ but has ‘auth cookies’
Portal contains both ‘certificate profile’ and ‘auth cookies’

I always deploy third option, certificate profile and auth cookies, to be sure that only endpoints with proper certificates can connect to GlobalProtect. With that option, endpoints without certificate cannot connect to GlobalProtect at all, so if you must support, for example external consultants, than other GP gateway is necessary.

Configuration correctness can be verify directly on ednpoint looking into registry Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto Networks\GlobalProtect\PanSetup, key Prelogon should be set to 1. Remember also that registry key will be changed after first connection.

Under Monitor -> Globalprotect you should see pre-logon as source user:

Join the conversation

Your email address will not be published. Required fields are marked *