<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: &amp;quot;Advanced View&amp;quot; in GlobalProtect Client won't be locked after version 1.1.6 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/quot-advanced-view-quot-in-globalprotect-client-won-t-be-locked/m-p/3831#M2808</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, sraghunandan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I got it, so, the behavior between 1.1.5 and 1.1.6 are changed to will not initiate connection with gateway automatically, right ? If yes, I think it's working as expected as you said.&lt;/P&gt;&lt;P&gt;For the workaround, could I enable both of "On Demand" mode and "SSO" mode to make it a behavior that be initiated with gateway after a reboot every time ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sample Wu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 11 Apr 2013 02:51:03 GMT</pubDate>
    <dc:creator>paloalto.netfos</dc:creator>
    <dc:date>2013-04-11T02:51:03Z</dc:date>
    <item>
      <title>"Advanced View" in GlobalProtect Client won't be locked after version 1.1.6</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quot-advanced-view-quot-in-globalprotect-client-won-t-be-locked/m-p/3827#M2804</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In normal, "Advanced View" in GlobalProtect client will be locked if I configure to cancel "Enable advanced view" option in GlobalProtect Portal, and it will check the GlobalProtect portal information automatically after rebooting, so that client user cannot modify the settings easly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But after GlobalProtect version 1.1.6, I found it won't be checked automatically after rebooting and client user can modify the settings, it must connect to GlobalPortect gateway one time then "Advanced View" will be locked. The situation is also found in version 1.2.x ( e.g. version 1.2.2 ), it's a issue of security control for my customer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it normal ? or a bug ?&lt;/P&gt;&lt;P&gt;How to fix it ? or I need to open a case to report it ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sample Wu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Apr 2013 08:13:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quot-advanced-view-quot-in-globalprotect-client-won-t-be-locked/m-p/3827#M2804</guid>
      <dc:creator>paloalto.netfos</dc:creator>
      <dc:date>2013-04-10T08:13:25Z</dc:date>
    </item>
    <item>
      <title>Re: "Advanced View" in GlobalProtect Client won't be locked after version 1.1.6</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quot-advanced-view-quot-in-globalprotect-client-won-t-be-locked/m-p/3828#M2805</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you using on-demand or SSO?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Apr 2013 21:06:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quot-advanced-view-quot-in-globalprotect-client-won-t-be-locked/m-p/3828#M2805</guid>
      <dc:creator>sraghunandan</dc:creator>
      <dc:date>2013-04-10T21:06:49Z</dc:date>
    </item>
    <item>
      <title>Re: "Advanced View" in GlobalProtect Client won't be locked after version 1.1.6</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quot-advanced-view-quot-in-globalprotect-client-won-t-be-locked/m-p/3829#M2806</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, sraghunandan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I used "On Demand" mode,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sample Wu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Apr 2013 01:20:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quot-advanced-view-quot-in-globalprotect-client-won-t-be-locked/m-p/3829#M2806</guid>
      <dc:creator>paloalto.netfos</dc:creator>
      <dc:date>2013-04-11T01:20:06Z</dc:date>
    </item>
    <item>
      <title>Re: "Advanced View" in GlobalProtect Client won't be locked after version 1.1.6</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quot-advanced-view-quot-in-globalprotect-client-won-t-be-locked/m-p/3830#M2807</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think it is working as expected now.&amp;nbsp; With On-demand GlobalProtect agent will not automatically connect to the gateway. Instead the user will have to manually connect to the gateway by clicking to connect on the agent icon.&lt;/P&gt;&lt;P&gt;So in your case after a reboot the client won't connect to pull up the config instead the user has to initiate a connection, after which we will pull up the latest config.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Apr 2013 01:42:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quot-advanced-view-quot-in-globalprotect-client-won-t-be-locked/m-p/3830#M2807</guid>
      <dc:creator>sraghunandan</dc:creator>
      <dc:date>2013-04-11T01:42:07Z</dc:date>
    </item>
    <item>
      <title>Re: "Advanced View" in GlobalProtect Client won't be locked after version 1.1.6</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quot-advanced-view-quot-in-globalprotect-client-won-t-be-locked/m-p/3831#M2808</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, sraghunandan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I got it, so, the behavior between 1.1.5 and 1.1.6 are changed to will not initiate connection with gateway automatically, right ? If yes, I think it's working as expected as you said.&lt;/P&gt;&lt;P&gt;For the workaround, could I enable both of "On Demand" mode and "SSO" mode to make it a behavior that be initiated with gateway after a reboot every time ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sample Wu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Apr 2013 02:51:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quot-advanced-view-quot-in-globalprotect-client-won-t-be-locked/m-p/3831#M2808</guid>
      <dc:creator>paloalto.netfos</dc:creator>
      <dc:date>2013-04-11T02:51:03Z</dc:date>
    </item>
    <item>
      <title>Re: "Advanced View" in GlobalProtect Client won't be locked after version 1.1.6</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quot-advanced-view-quot-in-globalprotect-client-won-t-be-locked/m-p/3832#M2809</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sraghunandan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I really, really dislike this "feature"... I expressed this in a case I had open as well because I originally thought it was a bug(Case #00107848 - "GlobalProtect advanced mode is enabled after a reboot, even though it is disabled in the portal settings"). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I realize it's "by design," but in my humble opinion 'Advanced mode' should default to disabled until the next successful port auth/VPN auth. After the auth, if 'Advanced mode' is enabled when the client refreshes its config from the server, only then should advanced mode come back on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can already forsee that rebooting and then having access to advanced mode would play havoc with a deployment of GlobalProtect for us, as we're forced to use "OnDemand mode" because we have two-factor authentication requirements that we have to enforce. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This issue and other issues we've had are collectively show-stoppers for us implementing GlobalProtect, to the point where my boss has us looking at ASAs in order to move to Cisco's AnyConnect.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Apr 2013 16:35:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quot-advanced-view-quot-in-globalprotect-client-won-t-be-locked/m-p/3832#M2809</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2013-04-11T16:35:51Z</dc:date>
    </item>
  </channel>
</rss>

