Pre-Logon Tunnel Rename Timeout (sec) (Windows Only) | This setting controls how GlobalProtect
handles the pre-logon tunnel that connects an endpoint to the gateway. A
value of -1 means the pre-logon tunnel does not time out after a
user logs on to the endpoint; GlobalProtect renames the tunnel to
reassign it to the user. However, the tunnel persists even if the
renaming fails or if the user does not log in to the GlobalProtect gateway. A
value of 0 means when the user logs on to the endpoint, GlobalProtect
immediately terminates the pre-logon tunnel instead of renaming
it. In this case, GlobalProtect initiates a new tunnel for the user
instead of allowing the user to connect over the pre-logon tunnel. Typically,
this setting is most useful when you set the Connect
Method to Pre-logon then On-demand, which
forces the user to manually initiate the connection after the initial
logon. A value of 1 to 7200 indicates the number of seconds
in which the pre-logon tunnel can remain active after a user logs
on to the endpoint. During this time, GlobalProtect enforces policies
on the pre-logon tunnel. If the user authenticates with the GlobalProtect
gateway within the timeout period, GlobalProtect reassigns the tunnel
to the user. If the user does not authenticate with the GlobalProtect
gateway before the timeout, GlobalProtect terminates the pre-logon
tunnel. |