Upon initial machine boot up, pre-logon tunnel does not establish and GlobalProtect status shows as Disconnected.

Upon initial machine boot up, pre-logon tunnel does not establish and GlobalProtect status shows as Disconnected.

18847
Created On 09/13/22 08:56 AM - Last Modified 01/28/25 21:04 PM


Symptom


Upon initial machine boot up, pre-logon tunnel does not establish and GlobalProtect status shows as Disconnected.

Environment


  • Palo Alto Firewall
  • PAN-OS 8.1 and above
  • GlobalProtect Pre-Logon setup
  • Authentication cookie


Cause


When a user turns on their client machine, they will notice that pre-logon tunnel is not connected.

  1. The user has to authenticate during user tunnel connection first, to generate authentication cookie.
  2. Two authentication cookies are generated. One for ‘user’ and other for ‘pre-logon’.
  3. Once authentication cookies are generated, they will notice GlobalProtect Pre-Logon will be connected for the following machine boot ups.
  4. Pre-Logon tunnel will stay up until the Login Lifetime timer ends.
  5. Until the cookie lifetime ends, the next pre-logon cookie won't be generated for the authentication; unless the user signs out of the GlobalProtect app.
  6. To avoid tunnel connection failure due to cookie lifetime expiration, it is recommended to use certificate based authentication


Resolution


Cookie Configuration:

  1. Both portal and gateway can generate and accept authentication cookie with either same or separate Cookie Lifetime timers on each.
  2. Portal can generate and gateway can accept authentication cookie.
  3. Portal can accept cookie whereas gateway can generate and accept authentication cookie with either same or separate Cookie Lifetime timers on each.

On Portal:

  • Network > GlobalProtect > Portals > [portal-name] > Agent > [portal-config-name] > Authentication
Portal-Cookie
 

On Gateway:

  • Network > GlobalProtect > Gateways > [gateway-name] > Agent > Client Settings > [gateway-config-name] > Authentication Override
Gateway-Cookie

Login Lifetime:
  • Timeout value can be configured under WebUI: Network > GlobalProtect > Gateways > [gateway-name] > Agent > Connection Settings.
Gateway-Connection-Settings


Additional Information




Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000wlX8CAI&lang=en_US%E2%80%A9&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail