| Where Can I Use This? | What Do I Need? |
- NGFW (managed by Panorama or Strata Cloud Manager)
- Prisma Access (managed by Panorama or Strata Cloud
Manager)
|
- GlobalProtect Gateway license or Prisma Access license with
the Mobile User subscription
|
With certificate authentication, the user
must present a valid client certificate that identifies them to
the GlobalProtect portal or gateway. To verify that a client certificate
is valid, the portal or gateway checks if the client holds the private
key of the certificate by using the Certificate Verify message exchanged during
the SSL handshake. In addition, the client certificate is signed
by the certificate authority (CA) specified in the Issuer field
of the certificate chain. In addition to the certificate itself,
the portal or gateway can use a certificate profile to determine
whether the user that sent the certificate is the user to which
the certificate was issued.
When a client certificate is the
only means of authentication, the certificate that the user presents
must contain the username in one of the certificate fields; typically the
username corresponds to the common name (CN) in the Subject field
of the certificate.
Upon successful authentication, the GlobalProtect
app establishes a tunnel with the gateway and is assigned an IP
address from the IP pool in the gateway’s tunnel configuration.
To support user-based policy enforcement on sessions from the corp-vpn zone,
the username from the certificate is mapped to the IP address assigned
by the gateway. If a security policy requires a domain name in addition
to the user name, the domain value specified in the certificate profile
is appended to the username.
GlobalProtect
Client Certificate Authentication Configuration
This
quick configuration uses the same topology as
GlobalProtect
VPN for Remote Access. The only configuration difference
is that instead of authenticating users against an external authentication
server, this configuration uses client certificate authentication
only.