<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Linux GP client in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/linux-gp-client/m-p/204333#M60119</link>
    <description>That link is now 404.</description>
    <pubDate>Thu, 08 Mar 2018 15:01:03 GMT</pubDate>
    <dc:creator>BBenson-orocktech</dc:creator>
    <dc:date>2018-03-08T15:01:03Z</dc:date>
    <item>
      <title>Linux GP client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/linux-gp-client/m-p/204113#M60067</link>
      <description>&lt;P&gt;Now that there is a Linux GP client... How do we get it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Details:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/41/globalprotect/globalprotect-app-new-features/new-features-released-in-gp-agent-4_1/globalprotect-app-for-linux" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/41/globalprotect/globalprotect-app-new-features/new-features-released-in-gp-agent-4_1/globalprotect-app-for-linux&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The page Titled "Download and Install the GlobalProtect App for Linux"&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/41/globalprotect/globalprotect-app-user-guide/globalprotect-app-for-linux/download-and-install-the-globalprotect-app-for-linux#id181NC050F59" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/41/globalprotect/globalprotect-app-user-guide/globalprotect-app-for-linux/download-and-install-the-globalprotect-app-for-linux#id181NC050F59&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;Obtain the app package from your IT administrator and then copy the TGZ file to the Linux endpoint." - Well I thats me&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but...where...is...it...?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2018 15:57:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/linux-gp-client/m-p/204113#M60067</guid>
      <dc:creator>hshawn</dc:creator>
      <dc:date>2018-03-07T15:57:35Z</dc:date>
    </item>
    <item>
      <title>Re: Linux GP client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/linux-gp-client/m-p/204122#M60069</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/42784"&gt;@hshawn&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You can download the Linux GP from the&amp;nbsp;&lt;A href="https://support.paloaltonetworks.com" target="_self"&gt;https://support.paloaltonetworks.com&lt;/A&gt;&amp;nbsp;portal.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2018 16:02:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/linux-gp-client/m-p/204122#M60069</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-03-07T16:02:57Z</dc:date>
    </item>
    <item>
      <title>Re: Linux GP client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/linux-gp-client/m-p/204125#M60072</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks once again! It was waaaaaaay at the bottom of the list instead of being grouped with the other GP clients, found it!&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2018 16:05:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/linux-gp-client/m-p/204125#M60072</guid>
      <dc:creator>hshawn</dc:creator>
      <dc:date>2018-03-07T16:05:32Z</dc:date>
    </item>
    <item>
      <title>Re: Linux GP client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/linux-gp-client/m-p/204138#M60079</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Is that the beta version, I gave one of my users the beta version, I have no idea if they have tried it yet&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2018 17:08:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/linux-gp-client/m-p/204138#M60079</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-03-07T17:08:48Z</dc:date>
    </item>
    <item>
      <title>Re: Linux GP client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/linux-gp-client/m-p/204139#M60080</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I'm pretty positive that it's not the exact same build. If you have anyone running/trying 4.1 at this point I would make sure that they get the published build.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2018 17:10:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/linux-gp-client/m-p/204139#M60080</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-03-07T17:10:41Z</dc:date>
    </item>
    <item>
      <title>Re: Linux GP client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/linux-gp-client/m-p/204146#M60081</link>
      <description>&lt;P&gt;Linux version is production 4.1.0-91&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Some things I have encountered:&lt;/P&gt;&lt;P&gt;* After entering my username and pass it just sits there and never finishes the connection (not seeing a log of useful into while tailing the logs)&lt;/P&gt;&lt;P&gt;* Even after importing the certs it still complains that the certs are not valid&lt;/P&gt;&lt;P&gt;* It is logging your password when you import the certs as plain text in the PanGP log file wow c'mon!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;P13369-T176146176 Mar 07 12:00:30:688706 Info ( 221): InitConnection ...&lt;BR /&gt;P13369-T176146176 Mar 07 12:00:30:688759 Debug( 54): fd still open before connect&lt;BR /&gt;P13369-T176146176 Mar 07 12:00:30:688823 Error( 72): Failed to set nosigpipe&lt;BR /&gt;P13369-T176146176 Mar 07 12:00:30:692115 Debug( 345): CPanSocket::OnConnect - portal message sent.&lt;BR /&gt;P13369-T176146176 Mar 07 12:00:30:692134 Info ( 233): Connecting to Pan MS Service end&lt;BR /&gt;P13369-T201324288 Mar 07 12:00:31:130433 Debug( 777): Send command to Pan Service&lt;BR /&gt;P13369-T201324288 Mar 07 12:00:31:130447 Debug( 791): Command = &amp;lt;request&amp;gt;&amp;lt;type&amp;gt;portal&amp;lt;/type&amp;gt;&amp;lt;portal&amp;gt;XXXXXXXXXX&amp;lt;/portal&amp;gt;&amp;lt;pid&amp;gt;13369&amp;lt;/pid&amp;gt;&amp;lt;user&amp;gt;XXXXXXXXXX&amp;lt;/user&amp;gt;&amp;lt;passwd&amp;gt;******************&amp;lt;/passwd&amp;gt;&amp;lt;path&amp;gt;/user/.GlobalProtect&amp;lt;/path&amp;gt;&amp;lt;checkupdate&amp;gt;no&amp;lt;/checkupdate&amp;gt;&amp;lt;allow-cached-portal&amp;gt;yes&amp;lt;/allow-cached-portal&amp;gt;&amp;lt;remember-me&amp;gt;yes&amp;lt;/remember-me&amp;gt;&amp;lt;retrieve-cache-only&amp;gt;no&amp;lt;/retrieve-cache-only&amp;gt;&amp;lt;manual-select-gateway-ip&amp;gt;&amp;lt;/manual-select-gateway-ip&amp;gt;&amp;lt;portal-certificate-verification&amp;gt;yes&amp;lt;/portal-certificate-verification&amp;gt;&amp;lt;win-user&amp;gt;XXXXXXXXXX&amp;lt;/win-user&amp;gt;&amp;lt;saved-user&amp;gt;XXXXXXXXXX&amp;lt;/saved-user&amp;gt;&amp;lt;saved-passwd&amp;gt;*****************&amp;lt;/saved-passwd&amp;gt;&amp;lt;portal-2fa&amp;gt;no&amp;lt;/portal-2fa&amp;gt;&amp;lt;gid&amp;gt;0&amp;lt;/gid&amp;gt;&amp;lt;domain&amp;gt;&amp;lt;/domain&amp;gt;&amp;lt;/request&amp;gt;&lt;BR /&gt;P13369-T201324288 Mar 07 12:00:31:130499 Debug( 848): PanClient sent successful with 640 bytes&lt;BR /&gt;P13369-T192931584 Mar 07 12:00:33:2845 Info ( 256): agent ui socket closed!&lt;BR /&gt;P13369-T184538880 Mar 07 12:00:35:955884 Info ( 221): InitConnection ...&lt;BR /&gt;P13369-T184538880 Mar 07 12:00:35:955913 Debug( 54): fd still open before connect&lt;BR /&gt;P13369-T184538880 Mar 07 12:00:35:955948 Error( 72): Failed to set nosigpipe&lt;BR /&gt;P13369-T184538880 Mar 07 12:00:35:955997 Error( 75): Failed to connect to server at port:4767&lt;BR /&gt;P13369-T184538880 Mar 07 12:00:35:956003 Error( 225): Cannot connect to service, error: 111&lt;BR /&gt;P13369-T192931584 Mar 07 12:00:36:47824 Info ( 256): agent ui socket closed!&lt;BR /&gt;P13369-T176146176 Mar 07 12:00:36:693866 Info ( 221): InitConnection ...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2018 17:16:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/linux-gp-client/m-p/204146#M60081</guid>
      <dc:creator>hshawn</dc:creator>
      <dc:date>2018-03-07T17:16:43Z</dc:date>
    </item>
    <item>
      <title>Re: Linux GP client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/linux-gp-client/m-p/204151#M60082</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/42784"&gt;@hshawn&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;So few things about that, and keep in mind that I'm not by any means actually affiliated with PAN. The passwd value that you are seeing in the logs would also be present on the Windows version of the logs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The command that the log is recording is actually the command that gets sent from the PanClient to the PanGPS service. This is then securly passed to the gateway. So while they are storing the password in clear text (still bad), it doesn't actually pass it in the clear.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you want to get rid of this, and I think it's actually following the published best-practice guide, you would actually disable the option to save the password on the client options by modifying the 'Save User Credentials' to 'Save Username Only' instead of 'Yes'.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Again, not saying that PAN should be storing the password in the log file; completely agree that this should be masked or otherwise not actually recorded.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2018 17:40:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/linux-gp-client/m-p/204151#M60082</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-03-07T17:40:52Z</dc:date>
    </item>
    <item>
      <title>Re: Linux GP client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/linux-gp-client/m-p/204304#M60113</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The user's VPN PW is masked in the logs. It is the local account password used to import a cert for global protect that is in the clear. While this is not sent over the wire it would make it outside if logs are sent to support etc...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm starting to think this issue is the same I'm seeing with the 4.1 windows client since it seems to just hang when connecting. This is going to end up being a painful support call lol... "Linux? Uh.... Have you tried turning it off and on again?"&lt;/P&gt;</description>
      <pubDate>Thu, 08 Mar 2018 10:55:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/linux-gp-client/m-p/204304#M60113</guid>
      <dc:creator>hshawn</dc:creator>
      <dc:date>2018-03-08T10:55:05Z</dc:date>
    </item>
    <item>
      <title>Re: Linux GP client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/linux-gp-client/m-p/204333#M60119</link>
      <description>That link is now 404.</description>
      <pubDate>Thu, 08 Mar 2018 15:01:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/linux-gp-client/m-p/204333#M60119</guid>
      <dc:creator>BBenson-orocktech</dc:creator>
      <dc:date>2018-03-08T15:01:03Z</dc:date>
    </item>
    <item>
      <title>Re: Linux GP client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/linux-gp-client/m-p/204610#M60169</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/84530"&gt;@BBenson-orocktech&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looks like it is back now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;p.s. anyone know where the certs are stored for the GP linux client? I can validate my CA cert exists on the system I see it in the proper directories and I have imported it using the globalprotect import-certificate command but it does not see the cert when connecting. I am unable to find the details as to where it expects to find it in a Linux environment &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Mar 2018 18:46:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/linux-gp-client/m-p/204610#M60169</guid>
      <dc:creator>hshawn</dc:creator>
      <dc:date>2018-03-09T18:46:38Z</dc:date>
    </item>
    <item>
      <title>Re: Linux GP client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/linux-gp-client/m-p/204617#M60171</link>
      <description>&lt;P&gt;Looks like this was impacted by the same issue as the windows client where it would not accept passwords with &amp;lt; and/or &amp;gt; in them. After swapping those characters out the connection is established without any issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What did we learn:&lt;/P&gt;&lt;P&gt;* there is a password length limit in the 4.1 client&lt;/P&gt;&lt;P&gt;* The 4.1 client will not connect if you have a &amp;lt; or &amp;gt; in your password&lt;/P&gt;&lt;P&gt;* The OSX 4.1 client *does* work with&lt;/P&gt;&lt;P&gt;* The Linux client suffers from the same character issue as the Windows client&lt;/P&gt;&lt;P&gt;* I do not know if the Linux client suffers from the password length issue reported by someone else in the Windows client post.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Mar 2018 19:40:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/linux-gp-client/m-p/204617#M60171</guid>
      <dc:creator>hshawn</dc:creator>
      <dc:date>2018-03-09T19:40:11Z</dc:date>
    </item>
    <item>
      <title>Re: Linux GP client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/linux-gp-client/m-p/251377#M71486</link>
      <description>&lt;P&gt;I have another query with new Global Protect client for linux.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently we are using VPNC StrongSwan for VPN to our network and we have enabled X-auth, group name and password.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once we move to Globla Protect client for linux, can we remove X-auth, group name and password? I assume these configuration will be ignored.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2019 15:24:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/linux-gp-client/m-p/251377#M71486</guid>
      <dc:creator>RbadigerCY</dc:creator>
      <dc:date>2019-02-26T15:24:47Z</dc:date>
    </item>
    <item>
      <title>Re: Linux GP client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/linux-gp-client/m-p/251444#M71501</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/68064"&gt;@RbadigerCY&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;That would be correct; the GlobalProtect agent for Linux doesn't require X-Auth to be configured. If they were the only clients utilizing X-Auth you should be good to completely remove this configuration once you've moved everything to the actual GlobalProtect agent.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2019 20:46:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/linux-gp-client/m-p/251444#M71501</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-02-26T20:46:00Z</dc:date>
    </item>
  </channel>
</rss>

