How to configure Certificate only authentication for GlobalProtect client on Cloud managed Prisma Access or Strata Cloud Manager

How to configure Certificate only authentication for GlobalProtect client on Cloud managed Prisma Access or Strata Cloud Manager

18169
Created On 05/22/23 05:35 AM - Last Modified 04/05/24 19:13 PM


Objective


  • GlobalProtect Client connecting to Prisma Access gateway is configured for Always on mode with Certificate based authentication. This is achieved with authentication profile with "Local Users OR Client Certificate" option.
  • When the device is rebooted, users always have to open the app and tap on the 'connect' button to initiate GP instead of GP app connecting automatically. 
  • When this is done, "Enter Login credentials" for portal is displayed.
  • The logs indicate initial client cert access failure
  • This indicates means portal is not configured as "cert only" auth before user unlocks the phone. 
  • When an iOS device is locked, access to the certificate store is blocked thereby causing the failure.
  • To overcome this issue, configure portal as client cert only authentication. 
  • This article provides the guidance on configuring the certificate-based authentication for iOS devices for Cloud Managed Prisma Access or Prisma access managed through SCM (Strata Cloud Manager).
Note: When the Always-On connect method is deployed for iOS devices, seamless authentication can only be successful with certificate-based authentication. 
Note: The authentication method is set as "local users" because "None" option is not available. There is no need to create local users because this setting does not have significance and uses cert based authentication.

Cloud Managed Prisma Access Authentication Profile

PA authentication profile


Panorama Authentication Profile
Panorama With None as option
 
 
 
 
 


Environment


  • Cloud Managed Prisma Access
  • Strata Cloud Manager
  • GlobalProtect app version 5.2 and above
  • Always-On connect method
  • iOS version 15 and above


Procedure


  1. Configure Authentication profiles for all other devices than iOS devices or Change the user authentication so that no auth profile matches iOS device.
GUI:  SCM > Workflows > Prisma Access setup > GlobalProtect > Infrastructure > User Authentications   (For Strata cloud Manager)
GUI: Prisma Access > Setup > GlobalProtect > Infrastructure > User Authentications (For Cloud managed Prisma Access)
Authentication Profiles
  1. Add Certificate authentication profile for iOS users by clicking "Add Authentication" (This will be catch all profile) but not listed under user authentications list. This acts as cert only authentication allowing iOS GP client to connect post reboot automatically.
Cert Profile.jpeg
 


Additional Information


How to configure seamless authentication for iOS devices using Always-On connect method?



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000g1tPCAQ&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language