<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Globalprotect client in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/146922#M49293</link>
    <description>&lt;P&gt;I believe the client is identical. So either you installing it manually or downloading over the PA GP portal = same&lt;/P&gt;</description>
    <pubDate>Thu, 09 Mar 2017 16:41:25 GMT</pubDate>
    <dc:creator>TranceforLife</dc:creator>
    <dc:date>2017-03-09T16:41:25Z</dc:date>
    <item>
      <title>Globalprotect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/146904#M49287</link>
      <description>&lt;P&gt;I want to do some testing on new global protect clients but I don't want to make it update anyone tell I can test it, How do I get the software to test with out making it the default cleint on the firewall?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2017 16:07:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/146904#M49287</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-03-09T16:07:12Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/146914#M49288</link>
      <description>&lt;P&gt;You always can download manually from the support site (not sure if you do have enough privileges):&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GP.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8077i39CA035F84013943/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="GP.PNG" alt="GP.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2017 16:13:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/146914#M49288</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-03-09T16:13:23Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/146919#M49291</link>
      <description>&lt;P&gt;Thanks trance I found that and downloaded one of them, do you know if the client is a different version from what is offered on the firewall if it will still work&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2017 16:34:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/146919#M49291</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-03-09T16:34:22Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/146922#M49293</link>
      <description>&lt;P&gt;I believe the client is identical. So either you installing it manually or downloading over the PA GP portal = same&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2017 16:41:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/146922#M49293</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-03-09T16:41:25Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/146923#M49294</link>
      <description>&lt;P&gt;no I mean I have 2.2 offered on my firewall. If I install a new version from downloading it from the software portal will it work with my firewall if I have only downloaded and offering 2.2 and the client installed on my pc is 3?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2017 16:44:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/146923#M49294</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-03-09T16:44:44Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/146926#M49295</link>
      <description>&lt;P&gt;Good question :0 Give a go&amp;nbsp;as l am not sure really. Never test this before&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2017 16:48:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/146926#M49295</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-03-09T16:48:08Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/146931#M49298</link>
      <description>&lt;P&gt;I will let you know what I find out. I will download different GP versions and see if they can connect.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2017 17:42:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/146931#M49298</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-03-09T17:42:41Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/146937#M49299</link>
      <description>&lt;P&gt;Interesting; one would think that as long as the client falls within the usable packeges for the portal/gateway that you should be fine when you load things up manually. Please let us know if this actually works, I do this all the time on my AnyConnect clients but I've never tried on GP.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2017 18:38:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/146937#M49299</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-03-09T18:38:17Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/146964#M49301</link>
      <description>&lt;P&gt;jprovine,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One thing to consider and an option we've used for testing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First any time you are doing testing make sure you change the GlobalProtect -&amp;gt; Portal -&amp;gt; Agent -&amp;gt; App setting for "Allow User to Upgrade GlobalProtect App" to either Disallow or Allow Manually.&amp;nbsp; If you have anything else it may try to override what you are testing with the production version.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When we test a new client I set the above App setting to Disallow and Download/Activate the version I want to test.&amp;nbsp; I then download it and install from vpn.firewall.com (your DNS name) manually.&amp;nbsp; Once we have done this we just Activate the production version we are using again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Brian&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2017 19:44:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/146964#M49301</guid>
      <dc:creator>BrianRa</dc:creator>
      <dc:date>2017-03-09T19:44:12Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/146973#M49303</link>
      <description>&lt;P&gt;well so far I manually installed version&amp;nbsp;version 2.3.1-7 and I get this error "server certificate verification failure" The version enabled on the firewall is 2.2&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2017 20:06:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/146973#M49303</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-03-09T20:06:57Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/147137#M49321</link>
      <description>&lt;P&gt;So have any one else done any upgrading of their globalprotect clients? How did you do it and was there is documentation? I did find out that you can not offer more than one globalprotect client at a time from the firewall. I am waiting to see if you can connect using a different version of globalprotect that what is being offered from the firewall. My initialize testin says that you can not but I have a ticket open asking that question in case their is something I missed.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2017 17:10:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/147137#M49321</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-03-10T17:10:54Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/147406#M49389</link>
      <description>&lt;P&gt;So Brian you downloaded and set the agent on the firewall to the new one and then downloaded the agent from the firewall to your test machine and I assume that in order to do that you have to set it to upgrade manually. So if I am understanding correctly there is no way to truly block anyone else from upgrading while you are testing?&lt;/P&gt;&lt;P&gt;Does changing the active globalprotect client on the firewall affect the users who are using an older version of globalprotect from connecting? Does it prompt them to upgrade?&lt;/P&gt;&lt;P&gt;So far I have found the upgrade of the client very poorly thought out by PA&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2017 13:05:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/147406#M49389</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-03-13T13:05:48Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/147639#M49413</link>
      <description>&lt;P&gt;I found out that if you have a cert on your firewall for globalprotect that it will have issues if you download it from the PA site and it will also ask to remove the currently globalprotect client install before installing the new one. So testing the upgrade doesn't seem to be working. It appears you have to change to it on the firewall, make it active and available to everyone and then you won't have cert issue and it will upgrade a previous install&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2017 15:20:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/147639#M49413</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-03-14T15:20:21Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/147743#M49427</link>
      <description>&lt;P&gt;jprovine,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That deals with the cert being used by the site you are connecting to.&amp;nbsp; You can ignore that in the client/agent configuration in the Portal section if you want for testing.&lt;/P&gt;&lt;P&gt;Basically the certificate asociated with &lt;A href="https://vpn.yoursite.com" target="_blank"&gt;https://vpn.yoursite.com&lt;/A&gt; does not match what the client is looking for.&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="vpn_ssl_dns.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8152iAD6EA45D361BEE33/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="vpn_ssl_dns.png" alt="vpn_ssl_dns.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Brian&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2017 20:13:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/147743#M49427</guid>
      <dc:creator>BrianRa</dc:creator>
      <dc:date>2017-03-14T20:13:19Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/147745#M49428</link>
      <description>&lt;P&gt;jprovine,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can use any supported version of the GlobalProtect client.&lt;/P&gt;&lt;P&gt;Another option would be to download the clients to the firewall you want to test with.&amp;nbsp; Set them as active and download each one to your computer.&amp;nbsp; Then set the one you are currently using back to active.&lt;/P&gt;&lt;P&gt;We have not had problems playing with multiple versions of the GlobalProtect client.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Brian&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;EDIT&amp;gt;&lt;/P&gt;&lt;P&gt;I have never tried downloading the GlobalProtect client from Palo Altos web page and using it.&amp;nbsp; We have always downloaded it to the firewalls.&lt;/P&gt;&lt;P&gt;&amp;lt;/EDIT&amp;gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2017 22:03:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/147745#M49428</guid>
      <dc:creator>BrianRa</dc:creator>
      <dc:date>2017-03-14T22:03:56Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/147820#M49449</link>
      <description>&lt;P&gt;yeah Brian we only have one firewall and its the one everyone goes through so if I download the newer globalprotect client and activate it, &amp;nbsp;it would be available to all of the users not just me. &amp;nbsp;I think I have found a way on the portal to set users to disable the ability to upgrade to the version. I just have to make sure they are still able to use the client they currently have installed and see if I can create another portal and gateway for me to test with&lt;/P&gt;</description>
      <pubDate>Wed, 15 Mar 2017 13:24:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/147820#M49449</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-03-15T13:24:52Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/147843#M49462</link>
      <description>&lt;P&gt;jprovine,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes there is a way to disable their ability to upgrade.&amp;nbsp;&lt;/P&gt;&lt;P&gt;GlobalProtect -&amp;gt; Portal -&amp;gt; Agent -&amp;gt; App setting for "Allow User to Upgrade GlobalProtect App" to Disallow&lt;/P&gt;&lt;P&gt;This will not stop them from using the portal only from being able to upgrade it.&amp;nbsp; Remember this is a push when the connection is either created or updated.&amp;nbsp; This is not an immediate change, you may want to set this and wait overnight for everyone to log back in and get the updated profile from the firewall.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Mar 2017 16:05:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/147843#M49462</guid>
      <dc:creator>BrianRa</dc:creator>
      <dc:date>2017-03-15T16:05:12Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/147862#M49468</link>
      <description>&lt;P&gt;the since I am in the same group for VPN I am going to have to create another portal and allow it the rights to upgrade to order to test it effectively&lt;/P&gt;</description>
      <pubDate>Wed, 15 Mar 2017 18:29:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/147862#M49468</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-03-15T18:29:18Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/148074#M49510</link>
      <description>&lt;P&gt;You do not need to create an additional portal but a new Agent within the existing portal.&amp;nbsp; Then you can modify the settings I previously mentioned for your new group to allow download and install.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2017 16:03:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/148074#M49510</guid>
      <dc:creator>BrianRa</dc:creator>
      <dc:date>2017-03-16T16:03:20Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/148087#M49513</link>
      <description>&lt;P&gt;I can't do that because the portal in question id all of the VPN users (staff)&amp;nbsp;not just my group. The only way I can restrict it to only me is to have my own portal&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2017 16:55:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client/m-p/148087#M49513</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-03-16T16:55:10Z</dc:date>
    </item>
  </channel>
</rss>

