<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: For user GlobalProtect client refresh in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/force-user-globalprotect-client-refresh/m-p/574335#M115440</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/227075"&gt;@Claw4609&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Ive tried editing registries under here&amp;nbsp;Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto Networks\GlobalProtect\Settings. Specifically trying adding connect-method either pre-logon or userlogon and flipped the on-demand key to no but no combination so far has gotten GP to initiate a connection. And I have restarted after each of these changes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the debug logs Im seeing: "on-demand mode, should try retrive cache again without make connection"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But Im not sure why it keeps thinking its on-demand&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a cli/powershell command we could run to tell the clients globalprotect to connect?&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;How are you connecting to these remote devices to make these registry changes if their VPN isn't enabled?&amp;nbsp; I'm not certain what the potential CLI/PS command would be to force this.&lt;/P&gt;</description>
    <pubDate>Wed, 24 Jan 2024 17:46:56 GMT</pubDate>
    <dc:creator>Brandon_Wertz</dc:creator>
    <dc:date>2024-01-24T17:46:56Z</dc:date>
    <item>
      <title>Force user GlobalProtect client refresh</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/force-user-globalprotect-client-refresh/m-p/574112#M115403</link>
      <description>&lt;P&gt;Piggy backing off of this earlier thread (&lt;A href="https://live.paloaltonetworks.com/t5/globalprotect-discussions/force-globalprotect-portal-refresh-of-connected-clients/td-p/514881#:~:text=One%20way%20is%20to%20tell,again%20and%20connect%20to%20gateway." target="_blank" rel="noopener"&gt;LIVEcommunity - Force GlobalProtect Portal refresh of connected clients? - LIVEcommunity - 514881 (paloaltonetworks.com)&lt;/A&gt;). It there a way whether by registry or whatever, to force the client to grab its new config. We are switching over from on-demand to always-on and want to have users connect without them having to interact. Is there a way to do this?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2024 14:35:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/force-user-globalprotect-client-refresh/m-p/574112#M115403</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2024-01-25T14:35:17Z</dc:date>
    </item>
    <item>
      <title>Re: For user GlobalProtect client refresh</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/force-user-globalprotect-client-refresh/m-p/574114#M115404</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/227075"&gt;@Claw4609&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Piggy backing off of this earlier thread (&lt;A href="https://live.paloaltonetworks.com/t5/globalprotect-discussions/force-globalprotect-portal-refresh-of-connected-clients/td-p/514881#:~:text=One%20way%20is%20to%20tell,again%20and%20connect%20to%20gateway." target="_blank" rel="noopener"&gt;LIVEcommunity - Force GlobalProtect Portal refresh of connected clients? - LIVEcommunity - 514881 (paloaltonetworks.com)&lt;/A&gt;). It there a way whether by registry or whatever, to force the client to grab its new config. We are switching over from on-demand to always-on and want to have users connect without them having to interact. Is there a way to do this?&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Why not just adjust this value down to 1 hour, then after a day or however long it take to get everyone connected up and received the new setting you can adjust the check-in interval back to whatever your standard is.&amp;nbsp; Trying to force the client to check in through a registry/GPO change is probably going to be more effort than worth the result given you can just change the below setting.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Brandon_Wertz_0-1706027801609.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56789i11AF9C701E2C6C99/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Brandon_Wertz_0-1706027801609.png" alt="Brandon_Wertz_0-1706027801609.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2024 16:37:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/force-user-globalprotect-client-refresh/m-p/574114#M115404</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2024-01-23T16:37:36Z</dc:date>
    </item>
    <item>
      <title>Re: For user GlobalProtect client refresh</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/force-user-globalprotect-client-refresh/m-p/574116#M115406</link>
      <description>&lt;P&gt;This would only apply to people that connect to Globalprotect correct? The main issue we have is the people who just dont connect to GP at all or havent in months. We have some internal gateways spun up in non-tunnel mode for the purpose of user-id/hip and I would like to begin retrieving this information via globalprotect from all clients.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2024 16:50:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/force-user-globalprotect-client-refresh/m-p/574116#M115406</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2024-01-23T16:50:11Z</dc:date>
    </item>
    <item>
      <title>Re: For user GlobalProtect client refresh</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/force-user-globalprotect-client-refresh/m-p/574328#M115437</link>
      <description>&lt;P&gt;Ive tried editing registries under here&amp;nbsp;Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto Networks\GlobalProtect\Settings. Specifically trying adding connect-method either pre-logon or userlogon and flipped the on-demand key to no but no combination so far has gotten GP to initiate a connection. And I have restarted after each of these changes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the debug logs Im seeing: "on-demand mode, should try retrive cache again without make connection"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But Im not sure why it keeps thinking its on-demand&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a cli/powershell command we could run to tell the clients globalprotect to connect?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jan 2024 17:22:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/force-user-globalprotect-client-refresh/m-p/574328#M115437</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2024-01-24T17:22:54Z</dc:date>
    </item>
    <item>
      <title>Re: For user GlobalProtect client refresh</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/force-user-globalprotect-client-refresh/m-p/574335#M115440</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/227075"&gt;@Claw4609&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Ive tried editing registries under here&amp;nbsp;Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto Networks\GlobalProtect\Settings. Specifically trying adding connect-method either pre-logon or userlogon and flipped the on-demand key to no but no combination so far has gotten GP to initiate a connection. And I have restarted after each of these changes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the debug logs Im seeing: "on-demand mode, should try retrive cache again without make connection"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But Im not sure why it keeps thinking its on-demand&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a cli/powershell command we could run to tell the clients globalprotect to connect?&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;How are you connecting to these remote devices to make these registry changes if their VPN isn't enabled?&amp;nbsp; I'm not certain what the potential CLI/PS command would be to force this.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jan 2024 17:46:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/force-user-globalprotect-client-refresh/m-p/574335#M115440</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2024-01-24T17:46:56Z</dc:date>
    </item>
    <item>
      <title>Re: For user GlobalProtect client refresh</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/force-user-globalprotect-client-refresh/m-p/574336#M115441</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/227075"&gt;@Claw4609&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;This would only apply to people that connect to Globalprotect correct? The main issue we have is the people who just dont connect to GP at all or havent in months. We have some internal gateways spun up in non-tunnel mode for the purpose of user-id/hip and I would like to begin retrieving this information via globalprotect from all clients.&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Yes, this setting would require the users needing to first connect to get that update.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jan 2024 17:44:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/force-user-globalprotect-client-refresh/m-p/574336#M115441</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2024-01-24T17:44:18Z</dc:date>
    </item>
    <item>
      <title>Re: For user GlobalProtect client refresh</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/force-user-globalprotect-client-refresh/m-p/574337#M115442</link>
      <description>&lt;P&gt;Im able to replicate the scenario on my machine, I connect myself to an on-demand config, flip the portal configs around so Ill hit the an always-on config the next time I connect. So the issue Im having is getting clients to connect to where they get the always-on config. But yes we've tried changing various registry settings but even with connect method set to user-logon and on-demand set to no, the client isnt auto connecting.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jan 2024 17:50:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/force-user-globalprotect-client-refresh/m-p/574337#M115442</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2024-01-24T17:50:38Z</dc:date>
    </item>
    <item>
      <title>Re: For user GlobalProtect client refresh</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/force-user-globalprotect-client-refresh/m-p/574340#M115443</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/227075"&gt;@Claw4609&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Ive tried editing registries under here&amp;nbsp;Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto Networks\GlobalProtect\Settings. Specifically trying adding connect-method either pre-logon or userlogon and flipped the on-demand key to no but no combination so far has gotten GP to initiate a connection. And I have restarted after each of these changes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the debug logs Im seeing: "on-demand mode, should try retrive cache again without make connection"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But Im not sure why it keeps thinking its on-demand&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a cli/powershell command we could run to tell the clients globalprotect to connect?&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;I think the settings you're looking for are defined here:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/globalprotect-apps/deploy-app-settings-transparently/customizable-app-settings/app-behavior-options#id51e0e000-9cce-425d-a4fd-e7fe51e1c8fb" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/globalprotect-apps/deploy-app-settings-transparently/customizable-app-settings/app-behavior-options#id51e0e000-9cce-425d-a4fd-e7fe51e1c8fb&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the endpoints are connected/managed from SCCM you can create a package to uninstall and reinstall the GP client coupled with a reboot.&amp;nbsp; When the client reboots the OS will automatically try to connect to it's defined portal to get the app config.&amp;nbsp; When it does this the machines will get the config updates you're wanting them to have.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jan 2024 18:14:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/force-user-globalprotect-client-refresh/m-p/574340#M115443</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2024-01-24T18:14:01Z</dc:date>
    </item>
    <item>
      <title>Re: For user GlobalProtect client refresh</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/force-user-globalprotect-client-refresh/m-p/574365#M115448</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/227075"&gt;@Claw4609&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;What registry changes are you making at the moment exactly, and are you trying to get them to utilize a&amp;nbsp;&lt;EM&gt;new&amp;nbsp;&lt;/EM&gt;portal or simply update the connection method on an existing portal without having them connect?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can't say that I've ever encountered any issues changing this as we go with clients. Set the registry values properly, restart PanGPS to get it to read everything, and you're good to go.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jan 2024 22:33:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/force-user-globalprotect-client-refresh/m-p/574365#M115448</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2024-01-24T22:33:45Z</dc:date>
    </item>
    <item>
      <title>Re: For user GlobalProtect client refresh</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/force-user-globalprotect-client-refresh/m-p/574472#M115461</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz&lt;/a&gt;&amp;nbsp;We do actually use SCCM and we tried something similar with some success, but this seemed to only work on about half of our roughly 100 person test group. We actually pushed it out with /norestart so wonder it that caused some issues? We also pushed it out with&amp;nbsp;CONNECTMETHOD="user-logon". The half it didnt work on it did actually install the new version fine, they just didnt auto connect, and looking through some of their GP client debug logs it still thinks its on-demand connect method.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;We're using the same portal. Even if the users dont normally connect to GP I want to initiate connections on existing users as we have some internal gateways in non-tunnel mode where I want to start obtaining user-id/hip information from these clients.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've tried various things at this point but of the two things I though would work was: I added string "connect-method" with a value of pre-logon (I also tried it with user-logon) as well as I flipped the "on-demand" string to "no". With both of them being located here:&amp;nbsp;Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto Networks\GlobalProtect\Settings&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2024 13:21:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/force-user-globalprotect-client-refresh/m-p/574472#M115461</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2024-01-25T13:21:29Z</dc:date>
    </item>
    <item>
      <title>Re: For user GlobalProtect client refresh</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/force-user-globalprotect-client-refresh/m-p/574511#M115466</link>
      <description>&lt;P&gt;We found the issue and it ended up being how the PanGPA exe was running as it didnt have application to read the registry, no nothing I was entering was even mattering.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2024 20:19:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/force-user-globalprotect-client-refresh/m-p/574511#M115466</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2024-01-25T20:19:50Z</dc:date>
    </item>
  </channel>
</rss>

