paloaltonetworks:configuration:globalprotect
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| paloaltonetworks:configuration:globalprotect [2020/11/11 10:27] – [GlobalProtect SSO Use Login Credentials] bstafford | paloaltonetworks:configuration:globalprotect [2025/09/11 08:00] (current) – [Cookies] bstafford | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| ====== GlobalProtect ====== | ====== GlobalProtect ====== | ||
| + | ===== SAML for GlobalProtect ===== | ||
| + | [[https:// | ||
| ===== Licence Requirements ===== | ===== Licence Requirements ===== | ||
| Palo Alto Networks list the licence requirements [[https:// | Palo Alto Networks list the licence requirements [[https:// | ||
| Line 120: | Line 122: | ||
| [HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto Networks\GlobalProtect] | [HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto Networks\GlobalProtect] | ||
| " | " | ||
| + | |||
| + | If you are installing with MSI, you can use the following install command to ensure that SSO is enabled. | ||
| + | < | ||
| ===== Dual ISP Resiliency ===== | ===== Dual ISP Resiliency ===== | ||
| If you have two active ISP links to a firewall, you can have resilient GlobalProtect. | If you have two active ISP links to a firewall, you can have resilient GlobalProtect. | ||
| Line 134: | Line 139: | ||
| < | < | ||
| ===== Cookies ===== | ===== Cookies ===== | ||
| + | User related cookies are stored in the following folders. | ||
| - | For Windows, | + | First line is for user cookies. |
| + | Second line is for pre-logon cookies (not tied to a particular user, but to a machine) | ||
| - | < | + | **For Windows** |
| - | filenames have this format: | + | < |
| - | < | + | C:\Program Files\Palo Alto Networks\GlobalProtect\</ |
| - | + | **For MacOS** | |
| - | For pre-logon cookies (not tied to a particular user, but to a machine), cookies can be found in: | + | < |
| - | < | + | / |
| - | filenames have this format: | + | **For Linux** |
| + | < | ||
| + | / | ||
| + | |||
| + | **Naming** | ||
| + | User cookie filenames have this format: | ||
| + | < | ||
| + | |||
| + | Pre-Login cookie | ||
| < | < | ||
| + | |||
| + | To delete the cookies in Windows | ||
| + | < | ||
| + | |||
| + | or Powershell: | ||
| + | < | ||
| + | ===== Portal Client Certificates ===== | ||
| + | When you go to a GlobalProtect portal that requires a client certificate be selected, you used to be able to add the site (in Internet Explorer) to the list of ' | ||
| + | ADMX is group policy for Edge. | ||
| + | ===== Linux Mint Certificates ===== | ||
| + | On Linux Mint, you may need to install the certificate being used by the GlobalProtect portal. | ||
| + | |||
| + | Copy the PEM/CRT files to ''/ | ||
| + | |||
| + | ===== Bypass Uninstall Password ===== | ||
| + | |||
| + | Edit registry '' | ||
| + | |||
| + | Set the '' | ||
| + | |||
| + | Restart the agent services or restart the machine to read the new value. | ||
| + | |||
| + | ===== Unauthenticated Downloads===== | ||
| + | < | ||
| + | < | ||
| + | If you want to create an inbound URL blocker | ||
| + | < | ||
| + | | ||
| + | |||
| + | < | ||
| + | https:// | ||
| + | https:// | ||
| + | |||
| + | https:// | ||
| + | https:// | ||
| + | https:// | ||
| + | </ | ||
| + | |||
| + | To force authentication, | ||
| + | < | ||
| + | set global-protect redirect on</ | ||
| + | If this other server doesn' | ||
| + | |||
| + | ===== Dynamic DNS ===== | ||
| + | PAN-OS doesn' | ||
| + | |||
| + | ( stage eq connected ) or ( stage eq logout ) and put $private_ip and $srcuser and $device_name as payload. Update Dynamic DNS using $deivce_name (possibly $hostname?) and $private_ip. Maybe add $srcuser as tag? Add timestamp as tag? | ||
paloaltonetworks/configuration/globalprotect.1605090422.txt.gz · Last modified: (external edit)
