{"id":368,"date":"2020-03-17T15:47:10","date_gmt":"2020-03-17T14:47:10","guid":{"rendered":"http:\/\/wp.12p.no\/?p=368"},"modified":"2020-03-17T15:47:10","modified_gmt":"2020-03-17T14:47:10","slug":"globalprotect-client-certificate","status":"publish","type":"post","link":"https:\/\/12p.no\/wp\/?p=368","title":{"rendered":"GlobalProtect + Client Certificate"},"content":{"rendered":"\n<p>Setup the client certificate deployment by following this guide : <a href=\"https:\/\/www.virtuallyboring.com\/setup-microsoft-active-directory-certificate-services-ad-cs\/\">https:\/\/www.virtuallyboring.com\/setup-microsoft-active-directory-certificate-services-ad-cs\/<\/a>  <\/p>\n\n\n\n<p>Start of by exporting the CA certificate:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"http:\/\/wp.12p.no\/wp-content\/uploads\/2020\/03\/image-2.png\" alt=\"\" class=\"wp-image-371\"\/><\/figure>\n\n\n\n<p>Install the certificate on you Palo Alto Firewall:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"http:\/\/wp.12p.no\/wp-content\/uploads\/2020\/03\/image-3.png\" alt=\"\" class=\"wp-image-372\"\/><\/figure>\n\n\n\n<p>the certificate should look something like this:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"http:\/\/wp.12p.no\/wp-content\/uploads\/2020\/03\/image-4.png\" alt=\"\" class=\"wp-image-373\"\/><\/figure>\n\n\n\n<p>Create a Certificate profile:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"http:\/\/wp.12p.no\/wp-content\/uploads\/2020\/03\/image-5-1024x610.png\" alt=\"\" class=\"wp-image-374\"\/><figcaption><br><\/figcaption><\/figure>\n\n\n\n<p>Add this profile to your Authentication settings on the GlobalProtect gateway:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"http:\/\/wp.12p.no\/wp-content\/uploads\/2020\/03\/image-8.png\" alt=\"\" class=\"wp-image-377\"\/><\/figure>\n\n\n\n<p>Now you can access your globalprotect vpn with the required client certificate.<\/p>\n\n\n\n<p>If you get disconnected right away you can check the debug logs undre Troubleshooting, look for this message:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"http:\/\/wp.12p.no\/wp-content\/uploads\/2020\/03\/image-9.png\" alt=\"\" class=\"wp-image-378\"\/><figcaption>indicating the client certificate is not correct or missing<br><\/figcaption><\/figure>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Setup the client certificate deployment by following this guide : https:\/\/www.virtuallyboring.com\/setup-microsoft-active-directory-certificate-services-ad-cs\/ Start of by exporting the CA certificate: Install the certificate on you Palo Alto Firewall: the certificate should look something like this: Create a Certificate profile: Add this profile to your Authentication settings on the GlobalProtect gateway: Now you can access your globalprotect vpn [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"class_list":["post-368","post","type-post","status-publish","format-standard","hentry","category-it-security"],"_links":{"self":[{"href":"https:\/\/12p.no\/wp\/index.php?rest_route=\/wp\/v2\/posts\/368","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/12p.no\/wp\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/12p.no\/wp\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/12p.no\/wp\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/12p.no\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=368"}],"version-history":[{"count":0,"href":"https:\/\/12p.no\/wp\/index.php?rest_route=\/wp\/v2\/posts\/368\/revisions"}],"wp:attachment":[{"href":"https:\/\/12p.no\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=368"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/12p.no\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=368"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/12p.no\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=368"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}