Connect Before Logon configuration is not working
3937
Created On 05/05/22 15:45 PM - Last Modified 04/10/25 14:31 PM
Symptom
Connect Before Logon configuration is not working as expected
Environment
- Palo Alto Firewalls
- GlobalProtect App 5.2+
- Connect Before Logon
Cause
Connect Before Logon did not work as expected due to additional configured settings that are not supported.
Resolution
- Connect Before Logon works before the user logs into their Windows laptop.
- It has limited resources and will not support the following features:
- Pre-logon and Pre-logon then On-demand connection methods.
- Platforms other than Windows.
- SSO credential.
- Save User Credentials.
- Customized labels for username and password.
- Welcome Message.
- Internal Gateway.
- Manually-only gateway or set preferred-gateway.
- Captive Portal.
- Hip Notification.
- Application version detection and upgrade.
- System default browser for SAML for GlobalProtect versions older than 6.0.4-26.
- HTTP proxy.
- Retain Connection on Smart Card Removal.
Additional Information
Connect Before Logon supports following features:
- Auto discovery gateway.
- Platforms Windows 10 and Windows 11.
- Authentication methods like SAML, LDAP, Radius or Smart Card.
- Two-factor authentication.
- Password update via RADIUS server.
- RSA passcode with all 3 types (PINPad, Fob, and PINless).
- System default browser for SAML for GlobalProtect versions 6.0.4-26 or higher.