How to configure Certificate only authentication for GlobalProtect client on Cloud managed Prisma Access or Strata Cloud Manager
18169
Created On 05/22/23 05:35 AM - Last Modified 04/05/24 19:13 PM
Objective
- GlobalProtect Client connecting to Prisma Access gateway is configured for Always on mode with Certificate based authentication. This is achieved with authentication profile with "Local Users OR Client Certificate" option.
- When the device is rebooted, users always have to open the app and tap on the 'connect' button to initiate GP instead of GP app connecting automatically.
- When this is done, "Enter Login credentials" for portal is displayed.
- The logs indicate initial client cert access failure
- This indicates means portal is not configured as "cert only" auth before user unlocks the phone.
- When an iOS device is locked, access to the certificate store is blocked thereby causing the failure.
- To overcome this issue, configure portal as client cert only authentication.
- This article provides the guidance on configuring the certificate-based authentication for iOS devices for Cloud Managed Prisma Access or Prisma access managed through SCM (Strata Cloud Manager).
Note: The authentication method is set as "local users" because "None" option is not available. There is no need to create local users because this setting does not have significance and uses cert based authentication.
Cloud Managed Prisma Access Authentication Profile
Panorama Authentication Profile
Environment
- Cloud Managed Prisma Access
- Strata Cloud Manager
- GlobalProtect app version 5.2 and above
- Always-On connect method
- iOS version 15 and above
Procedure
- Configure Authentication profiles for all other devices than iOS devices or Change the user authentication so that no auth profile matches iOS device.
GUI: SCM > Workflows > Prisma Access setup > GlobalProtect > Infrastructure > User Authentications (For Strata cloud Manager)
GUI: Prisma Access > Setup > GlobalProtect > Infrastructure > User Authentications (For Cloud managed Prisma Access)
GUI: Prisma Access > Setup > GlobalProtect > Infrastructure > User Authentications (For Cloud managed Prisma Access)
- Add Certificate authentication profile for iOS users by clicking "Add Authentication" (This will be catch all profile) but not listed under user authentications list. This acts as cert only authentication allowing iOS GP client to connect post reboot automatically.
Additional Information
How to configure seamless authentication for iOS devices using Always-On connect method?