<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic GlobalProtect | External Gateway | SAML | Reconnect Issue in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-external-gateway-saml-reconnect-issue/m-p/577578#M4979</link>
    <description>&lt;P&gt;Hello,&lt;BR /&gt;I implementing GlobalProtect as our main VPN Solution and got it working so far.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;When I stress-test the GlobalProtect Client (imitating a stressed busy user who clicks on reconnect / "erneut verbinden in a short time frame) I get "no acces to site / kein zugriff auf seite" error in the integrated browser.&amp;nbsp;&lt;BR /&gt;I have to close the "kein zugriff auf seite" window because global protect awaits the window to be closed to continue working.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BilertJulian_systemo_0-1708177392123.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57698iDF4786769285635F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="BilertJulian_systemo_0-1708177392123.png" alt="BilertJulian_systemo_0-1708177392123.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;If I now close the "kein zugriff auf seite" window&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BilertJulian_systemo_2-1708177910134.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57700iA77BB316D93ACA9D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="BilertJulian_systemo_2-1708177910134.png" alt="BilertJulian_systemo_2-1708177910134.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;When I press "connect / verbinden" the windows with "kein zugriff auf seite" appears by a 50:50 chance. But mostly the connection works than...&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BilertJulian_systemo_0-1708182174749.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57702iD586362C67E46D28/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="BilertJulian_systemo_0-1708182174749.png" alt="BilertJulian_systemo_0-1708182174749.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;If I press "disconnect / trennen" and than on "connect / verbinden"&amp;nbsp; instead of "reconnect / erneut verbinden"&amp;nbsp; the same page with "kein zugriff auf seite" opens sometimes but not as often as when I try a reconnect....&lt;BR /&gt;&lt;BR /&gt;--&amp;gt; the connection itself can be established if I retry closing the windows and pressing connect once or twice thats not the big deal...&lt;BR /&gt;--&amp;gt; the big problem at all is, that global protect stops working until the Window "kein zugriff auf seite" is closed...&amp;nbsp;&lt;BR /&gt;It would be perfect to display a custom error message: please close this window and try reconnect again ... because with the "kein zugriff auf seite" error page we will get a huge and never ending load of tickets and support calls I guess&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;PS: I already changed the setting in the gateway "app ribbon" already to the "default browser" and testet it -&amp;gt; the auth site opens at least, but sometimes (in case the browser is in the background the user does not even see the auth page)&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BilertJulian_systemo_1-1708182234659.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57703i4FD5967BE0F6B297/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="BilertJulian_systemo_1-1708182234659.png" alt="BilertJulian_systemo_1-1708182234659.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Side-Notes:&lt;BR /&gt;1. For successfull connected users the whole microsoft IP ranges are split tunneled (I can confirm this when I inspect the routes on the windows clients)&lt;BR /&gt;2. in case the integrated browser of global protect runs over our infrastructure I created some policys to the FQDN login.microsoftonline.com with no IDS, URL filtering etc) and application / service any -&amp;gt; the result stays the same "no access to site / kein zugriff auf seite) when the integrated browser appears.&lt;BR /&gt;3. I stopped the PanGPS Service on a test client and deleted the folder&amp;nbsp;(C:\Users\%USERNAME%\AppData\Local\Palo Alto Networks\GlobalProtect)&amp;nbsp; -&amp;gt; error appears again if I reconnect shortly after connecting&lt;BR /&gt;4. I tested with different global protect clients (5.x, 6.2.0, but mostly i am testing with 6.2.2) -&amp;gt; same effects.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Any other ideas I can optimize the user experience ?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;and: Is there a way to edit the Design of Global Protect with company branding or the response page for the global protect saml auth ? (see the last screenshot)&lt;BR /&gt;&lt;BR /&gt;thank you very much&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 17 Feb 2024 15:04:14 GMT</pubDate>
    <dc:creator>Blyat_tschuli</dc:creator>
    <dc:date>2024-02-17T15:04:14Z</dc:date>
    <item>
      <title>GlobalProtect | External Gateway | SAML | Reconnect Issue</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-external-gateway-saml-reconnect-issue/m-p/577578#M4979</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;I implementing GlobalProtect as our main VPN Solution and got it working so far.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;When I stress-test the GlobalProtect Client (imitating a stressed busy user who clicks on reconnect / "erneut verbinden in a short time frame) I get "no acces to site / kein zugriff auf seite" error in the integrated browser.&amp;nbsp;&lt;BR /&gt;I have to close the "kein zugriff auf seite" window because global protect awaits the window to be closed to continue working.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BilertJulian_systemo_0-1708177392123.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57698iDF4786769285635F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="BilertJulian_systemo_0-1708177392123.png" alt="BilertJulian_systemo_0-1708177392123.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;If I now close the "kein zugriff auf seite" window&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BilertJulian_systemo_2-1708177910134.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57700iA77BB316D93ACA9D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="BilertJulian_systemo_2-1708177910134.png" alt="BilertJulian_systemo_2-1708177910134.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;When I press "connect / verbinden" the windows with "kein zugriff auf seite" appears by a 50:50 chance. But mostly the connection works than...&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BilertJulian_systemo_0-1708182174749.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57702iD586362C67E46D28/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="BilertJulian_systemo_0-1708182174749.png" alt="BilertJulian_systemo_0-1708182174749.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;If I press "disconnect / trennen" and than on "connect / verbinden"&amp;nbsp; instead of "reconnect / erneut verbinden"&amp;nbsp; the same page with "kein zugriff auf seite" opens sometimes but not as often as when I try a reconnect....&lt;BR /&gt;&lt;BR /&gt;--&amp;gt; the connection itself can be established if I retry closing the windows and pressing connect once or twice thats not the big deal...&lt;BR /&gt;--&amp;gt; the big problem at all is, that global protect stops working until the Window "kein zugriff auf seite" is closed...&amp;nbsp;&lt;BR /&gt;It would be perfect to display a custom error message: please close this window and try reconnect again ... because with the "kein zugriff auf seite" error page we will get a huge and never ending load of tickets and support calls I guess&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;PS: I already changed the setting in the gateway "app ribbon" already to the "default browser" and testet it -&amp;gt; the auth site opens at least, but sometimes (in case the browser is in the background the user does not even see the auth page)&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BilertJulian_systemo_1-1708182234659.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57703i4FD5967BE0F6B297/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="BilertJulian_systemo_1-1708182234659.png" alt="BilertJulian_systemo_1-1708182234659.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Side-Notes:&lt;BR /&gt;1. For successfull connected users the whole microsoft IP ranges are split tunneled (I can confirm this when I inspect the routes on the windows clients)&lt;BR /&gt;2. in case the integrated browser of global protect runs over our infrastructure I created some policys to the FQDN login.microsoftonline.com with no IDS, URL filtering etc) and application / service any -&amp;gt; the result stays the same "no access to site / kein zugriff auf seite) when the integrated browser appears.&lt;BR /&gt;3. I stopped the PanGPS Service on a test client and deleted the folder&amp;nbsp;(C:\Users\%USERNAME%\AppData\Local\Palo Alto Networks\GlobalProtect)&amp;nbsp; -&amp;gt; error appears again if I reconnect shortly after connecting&lt;BR /&gt;4. I tested with different global protect clients (5.x, 6.2.0, but mostly i am testing with 6.2.2) -&amp;gt; same effects.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Any other ideas I can optimize the user experience ?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;and: Is there a way to edit the Design of Global Protect with company branding or the response page for the global protect saml auth ? (see the last screenshot)&lt;BR /&gt;&lt;BR /&gt;thank you very much&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 17 Feb 2024 15:04:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-external-gateway-saml-reconnect-issue/m-p/577578#M4979</guid>
      <dc:creator>Blyat_tschuli</dc:creator>
      <dc:date>2024-02-17T15:04:14Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect | External Gateway | SAML | Reconnect Issue</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-external-gateway-saml-reconnect-issue/m-p/577652#M4983</link>
      <description>&lt;P&gt;If you need to account for very nervous users, you could consider enabling authentication cookies on the gateway&lt;/P&gt;
&lt;P&gt;The minimum value you can set these to is 5 minutes which should allow for nervousness but not interfere with SAML conditional access&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the SAML login page can be branded, but this needs to be done on the SAML IdP side as this page is served by the IdP instead of the palo&lt;/P&gt;
&lt;P&gt;that last page you display can't be changed I think, only the welcome, help and portal login/home pages&lt;/P&gt;</description>
      <pubDate>Mon, 19 Feb 2024 12:01:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-external-gateway-saml-reconnect-issue/m-p/577652#M4983</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2024-02-19T12:01:09Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect | External Gateway | SAML | Reconnect Issue</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-external-gateway-saml-reconnect-issue/m-p/577813#M4998</link>
      <description>&lt;P&gt;Hi, try set the TCP handshake to 60, it helped me.&amp;nbsp; (PAN-227368 bug)&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2024 23:58:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-external-gateway-saml-reconnect-issue/m-p/577813#M4998</guid>
      <dc:creator>RadekStejnar</dc:creator>
      <dc:date>2024-02-20T23:58:26Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect | External Gateway | SAML | Reconnect Issue</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-external-gateway-saml-reconnect-issue/m-p/579924#M5106</link>
      <description>&lt;P&gt;Im running into the same issue but we are still on PanOS 10.1.x and GlobalProtect 5.2.13.&lt;/P&gt;
&lt;P&gt;I first want to upgrade PanOS to 10.2.8 and GP to 6.0.8 or 6.1.4 before i start troubleshooting this issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Which PanOS are you running on Portal/Gateway Firewalls?&lt;/P&gt;
&lt;P&gt;10.2.6: Did you maybe tried already to increase the TCP Handshake to 60 like mentioned in&amp;nbsp;&lt;SPAN&gt;PAN-227368 ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2024 14:53:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-external-gateway-saml-reconnect-issue/m-p/579924#M5106</guid>
      <dc:creator>Adrian_Moechel</dc:creator>
      <dc:date>2024-03-11T14:53:40Z</dc:date>
    </item>
  </channel>
</rss>

