Basic-GlobalProtect-configuration-with-Pre-Logon-then-On-Demand

Objective

This document will explain the GlobalProtect Pre-Logon then On-Demand connect method and the basic configuration required

Environment

Procedure


The Pre-logon then On-Demand is a new hybrid connect method which combines both Pre-logon capabilities to authenticate the user before they log into the endpoint, and the on-demand capability to allow users to establish a connection with external gateways manually for subsequent connections.

This is useful when users forget their password or work with their help-desk to change their password and require network access over a pre-logon VPN tunnel to log into their system.

Please follow the steps below to configure the Portal's agent configuration using the pre-logon then On-Demand connect method:
Note: This is found by navigating under Networks > GlobalProtect > Portals > ( Select Appropriate Portal(s)) > Agent > (Select/Create Appropriate Agent Config)
  1. Authentication
Note : If a certificate is selected here under the portal, the same certificate needs to be selected under Gateway's config for encrypt/decrypt cookie.

Note: One of the following 3 conditions must be met for pre-logon to work:

i.  Portal contains ‘certificate profile’ but ‘no’ auth cookies
Note : When Portal/Gateway are on the same IP, the Gateway Cert Profile will take precedence over Portal Cert Profile. If Portal Cert Profile is required, Portal/Gateway must be on different IP.

ii. Portal does ‘not’ contain ‘certificate profile’ but has ‘auth cookies’.

(In this case, the very first GP connection must be made by a user, which will create two cookies one for the ‘user’ and other for ‘pre-logon’. From then on the pre-logon will work.)

(Attempting ‘pre-logon’ in the very first time without having a user connected to GP previously will not work in this case since the ‘pre-logon’ cookie will only get generated after a user is logged in the first time.)

iii. Portal contains both ‘certificate profile’ and ‘auth cookies’.

User-added image
  1. Config Selection Criteria
User-added image
  1. External
Screenshot displaying the GlobalProtect Portal's Agent dialog box.
  1. App
User-added image
User-added image


Note: The following steps are required only if you need to add a new client configuration that differs from the one previously created.
  1. Authentication
Note: If a certificate is selected here under the portal, the same certificate needs to be selected under Gateway's config for encrypt/decrypt cookie.

User-added image
  1. Config Selection Criteria
User-added image
  1. External
Screenshot displaying the GlobalProtect Portal's Agent dialog box.
  1. App
User-added image
  1. Select OK and commit your changes

Additional Information