<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic GP 6.0.6 - Cookie expired only from mobile phone in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-6-0-6-cookie-expired-only-from-mobile-phone/m-p/558547#M4401</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;we have PA-850 and we deployed GP 6.0.7 for desktops and 6.0.6 version for mobile phones.&lt;/P&gt;
&lt;P&gt;The authentication is based on SAML via Azure and every connection from desktops works flawlessly.&lt;/P&gt;
&lt;P&gt;Recently we started receiving complaints from users that the VPN stopped working on phones, they received an XML saying Access Denied (attached).&lt;/P&gt;
&lt;P&gt;Looking at logs I found a Cookie Expiration and the quick solution was to clean the history of the mobile browser. then, the error disappeared and SAML authentication happened as usual.&amp;nbsp;&lt;BR /&gt;It seems like the GP client on a desktop can go for SAML authentication whenever it receives a cookie expiration message.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a way to configure the mobile client to do the same? is it a bug? any setting I can configure at Paloalto level?&amp;nbsp;&lt;BR /&gt;one option would be to disable the cookie authentication but that would be my last choice.... &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 19 Sep 2023 10:49:45 GMT</pubDate>
    <dc:creator>JoseCortijo</dc:creator>
    <dc:date>2023-09-19T10:49:45Z</dc:date>
    <item>
      <title>GP 6.0.6 - Cookie expired only from mobile phone</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-6-0-6-cookie-expired-only-from-mobile-phone/m-p/558547#M4401</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;we have PA-850 and we deployed GP 6.0.7 for desktops and 6.0.6 version for mobile phones.&lt;/P&gt;
&lt;P&gt;The authentication is based on SAML via Azure and every connection from desktops works flawlessly.&lt;/P&gt;
&lt;P&gt;Recently we started receiving complaints from users that the VPN stopped working on phones, they received an XML saying Access Denied (attached).&lt;/P&gt;
&lt;P&gt;Looking at logs I found a Cookie Expiration and the quick solution was to clean the history of the mobile browser. then, the error disappeared and SAML authentication happened as usual.&amp;nbsp;&lt;BR /&gt;It seems like the GP client on a desktop can go for SAML authentication whenever it receives a cookie expiration message.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a way to configure the mobile client to do the same? is it a bug? any setting I can configure at Paloalto level?&amp;nbsp;&lt;BR /&gt;one option would be to disable the cookie authentication but that would be my last choice.... &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 10:49:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-6-0-6-cookie-expired-only-from-mobile-phone/m-p/558547#M4401</guid>
      <dc:creator>JoseCortijo</dc:creator>
      <dc:date>2023-09-19T10:49:45Z</dc:date>
    </item>
  </channel>
</rss>

