<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: [SOLVED] - NGFW The Connection To Global Protect On The IPads Times Out!! in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/solved-ngfw-the-connection-to-global-protect-on-the-ipads-times/m-p/1243767#M7171</link>
    <description>&lt;P&gt;Thank you for sharing&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/289674"&gt;@DanielS.Romero&lt;/a&gt;&amp;nbsp;!&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 12 Dec 2025 04:40:51 GMT</pubDate>
    <dc:creator>JayGolf</dc:creator>
    <dc:date>2025-12-12T04:40:51Z</dc:date>
    <item>
      <title>[SOLVED] - NGFW The Connection To Global Protect On The IPads Times Out!!</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/solved-ngfw-the-connection-to-global-protect-on-the-ipads-times/m-p/1243761#M7169</link>
      <description>&lt;P&gt;Hello team,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;I created this post to share my experience resolving recent issues related to GlobalProtect on iPad devices.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;We have some users with iPads who attempted to connect to GlobalProtect using SAML-based authentication; however, after the users logged in with their credentials, the GlobalProtect application displayed the following error "&lt;FONT size="4" color="#FF0000"&gt;&lt;STRONG&gt;&lt;I&gt;Connection Failed or The Connection TimeOut or Timeout Expired&lt;/I&gt;&lt;/STRONG&gt;&lt;/FONT&gt;", and the iPad lost its internet connection:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;GLOBAL PROTECT IPAD CONNECTION TIME OUT&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DanielSRomero_1-1765512275788.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70103iCA98C95EBAD0C96B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DanielSRomero_1-1765512275788.png" alt="DanielSRomero_1-1765512275788.png" /&gt;&lt;/span&gt;&lt;BR /&gt;We found the following cause for this behavior (we were using the user login mode):&lt;BR /&gt;&lt;BR /&gt;&lt;FONT size="4" color="#FF0000"&gt;&lt;STRONG&gt;&lt;FONT size="3"&gt;CAUSE&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;- GlobalProtect iOS application only supports &lt;STRONG&gt;SAML authentication&lt;/STRONG&gt; for &lt;STRONG&gt;on-demand connect method&lt;/STRONG&gt; (Manual user-initiated connection) due to Apple VPN framework limitation.&lt;BR /&gt;&lt;BR /&gt;- When &lt;STRONG&gt;Always-on mode&lt;/STRONG&gt; is deployed to iOS devices, the Apple device &lt;STRONG&gt;blocks the internet connection&lt;/STRONG&gt; and since SAML authentication requires internet, it will not work.&lt;BR /&gt;&lt;BR /&gt;- When using a VPN profile in conjunction with MDM, the onDemandEnabled option behaves the same as the GP "Always-on" mode. Thus, SAML authentication is not supported on iOS devices when a VPN profile is used with onDemandEnabled = 1. &lt;BR /&gt;As a solution we create a agent&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;RESOLUTION&lt;/FONT&gt;&lt;BR /&gt;&lt;/STRONG&gt;To allow&amp;nbsp;iOS iPhone or iPad to work with Global Protect, we need to have &lt;STRONG&gt;On-demand&lt;/STRONG&gt; as the connect method over the Portal, after that, the iPads can now connect without any issue, as shown below:&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;GLOBAL PROTECT PORTAL CONNECTION METHOD&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DanielSRomero_2-1765512424721.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70104i92A4AEB2449445EF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DanielSRomero_2-1765512424721.png" alt="DanielSRomero_2-1765512424721.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;GLOBAL PROTECT CONNECTED&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DanielSRomero_0-1765513227125.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70105i2F495EFEBB94547D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DanielSRomero_0-1765513227125.png" alt="DanielSRomero_0-1765513227125.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The best way to accomplish the same is to configure a new Agent instance only for IOS devices and move it to the top of the list,&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;With the above configuration, the new Agent will take care of iOS iPad and iPhone clients. All other clients will use the second Agent in the list and are not affected.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Thank you for your time, and I hope this information is helpful in your daily cybersecurity work. I would greatly appreciate your support by liking or accepting this answer as the solution; it would help me a lot in becoming a CyberElite!&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;Best Regards,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Daniel Romero&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Senior Network/Security Engineer&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;PANW Partner&lt;BR /&gt;&lt;LI-PRODUCT title="GlobalProtect" id="GlobalProtect"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="NGFW" id="NGFW"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="VM-Series" id="VM-Series"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Dec 2025 05:19:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/solved-ngfw-the-connection-to-global-protect-on-the-ipads-times/m-p/1243761#M7169</guid>
      <dc:creator>DanielS.Romero</dc:creator>
      <dc:date>2025-12-12T05:19:06Z</dc:date>
    </item>
    <item>
      <title>Re: [SOLVED] - NGFW The Connection To Global Protect On The IPads Times Out!!</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/solved-ngfw-the-connection-to-global-protect-on-the-ipads-times/m-p/1243767#M7171</link>
      <description>&lt;P&gt;Thank you for sharing&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/289674"&gt;@DanielS.Romero&lt;/a&gt;&amp;nbsp;!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Dec 2025 04:40:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/solved-ngfw-the-connection-to-global-protect-on-the-ipads-times/m-p/1243767#M7171</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2025-12-12T04:40:51Z</dc:date>
    </item>
  </channel>
</rss>

