<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect authentication blocked by home firewall in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-authentication-blocked-by-home-firewall/m-p/581378#M116366</link>
    <description>&lt;P&gt;Oh gotcha, that would be related to the saml configuration used for authentication that your login relies on then and not GlobalProtect itself. You would need to work with/look at the SAML authentication you have set up and are using for authentication to see what the options are.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 22 Mar 2024 17:42:26 GMT</pubDate>
    <dc:creator>Claw4609</dc:creator>
    <dc:date>2024-03-22T17:42:26Z</dc:date>
    <item>
      <title>GlobalProtect authentication blocked by home firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-authentication-blocked-by-home-firewall/m-p/581350#M116359</link>
      <description>&lt;P&gt;I use GlobalProtect to connect to my employer's network from my home Wifi.&lt;/P&gt;
&lt;P&gt;However, the GP authentication requires port 8443, and this is not compatible with maintaining the highest security firewall settings on my Xfinity Gateway.&amp;nbsp; &amp;nbsp; &amp;nbsp;Every time I connect, therefore, I have to change the Gateway firewall to a lower security setting.&amp;nbsp; &amp;nbsp; &amp;nbsp; For personal cybersecurity reasons,&amp;nbsp; I'd like to maintain&amp;nbsp;the highest security firewall settings all the time.&amp;nbsp; &amp;nbsp; &amp;nbsp;Can PaloAlto fix this problem, for example, by using port 443 rather than 8443?&amp;nbsp; &amp;nbsp;Is there some other way of fixing this?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2024 14:10:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-authentication-blocked-by-home-firewall/m-p/581350#M116359</guid>
      <dc:creator>bfaull</dc:creator>
      <dc:date>2024-03-22T14:10:57Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect authentication blocked by home firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-authentication-blocked-by-home-firewall/m-p/581353#M116361</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What authentication is setup for GlobalProtect? GlobalProtects portal operates on port 443 and I don't believe this can be changed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also what is your personal router blocking port 8443 for? Because its a non-default port for SSL?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2024 14:24:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-authentication-blocked-by-home-firewall/m-p/581353#M116361</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2024-03-22T14:24:01Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect authentication blocked by home firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-authentication-blocked-by-home-firewall/m-p/581375#M116363</link>
      <description>&lt;P&gt;Xfinity gives very limited options. This is the Firewall IPv4 settings for the Xfinity gateway that I have.&amp;nbsp; &amp;nbsp;You ca choose High, Typical, or Low security settings.&amp;nbsp; &amp;nbsp; &amp;nbsp;Our IT support department tells me that the High setting blocks port 8443, and that this is what is causing GlobalProtect to just get stuck on the samlpost web page.&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So my personal router is NOT using 8443.&amp;nbsp; &amp;nbsp;Rather GP is trying to use it and is getting blocked.&amp;nbsp; &amp;nbsp;&amp;nbsp;That's all I know.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2024 17:24:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-authentication-blocked-by-home-firewall/m-p/581375#M116363</guid>
      <dc:creator>bfaull</dc:creator>
      <dc:date>2024-03-22T17:24:06Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect authentication blocked by home firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-authentication-blocked-by-home-firewall/m-p/581378#M116366</link>
      <description>&lt;P&gt;Oh gotcha, that would be related to the saml configuration used for authentication that your login relies on then and not GlobalProtect itself. You would need to work with/look at the SAML authentication you have set up and are using for authentication to see what the options are.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2024 17:42:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-authentication-blocked-by-home-firewall/m-p/581378#M116366</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2024-03-22T17:42:26Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect authentication blocked by home firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-authentication-blocked-by-home-firewall/m-p/581444#M116372</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1563712939"&gt;@bfaull&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;XFinity themselves don't recommend running maximum/high security for this exact reason. Unfortunately since you don't appear to be in control of the PAN side of things that you're connecting to, changing SAML to use 443 isn't going to be an option for you.&lt;/P&gt;
&lt;P&gt;You'll either need to lower your security to Typical so that SAML can complete and you can get connected, or if you have the option on your gateway set things to custom and open what you need. There's really not a way around this since your IT department isn't going to completely change their configuration because of an option you set on your home equipment.&lt;/P&gt;</description>
      <pubDate>Sat, 23 Mar 2024 03:45:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-authentication-blocked-by-home-firewall/m-p/581444#M116372</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2024-03-23T03:45:45Z</dc:date>
    </item>
  </channel>
</rss>

