- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-17-2026 05:22 AM - edited 09-17-2026 05:23 AM
Hi,
Following the recent Microsoft updates KB5124008 and KB5126052, we have observed a significant issue with GlobalProtect’s operation, manifested by the transmission of empty or invalid HIPs.
PANOS version 10.2.16-h6 (but also on 11.2.10-h13—I was in the middle of the update but rolled back to limit its impact).
GP client version—primarily 6.3.3-1121
From the client’s perspective, this appears to be repeated disconnections—there is nothing in the PA logs related to logging out of the gateway.
Narrowing it down a bit, it seems to us that the problem mainly occurs on Windows systems with MS Defender enabled (if the client uses a different antivirus, we haven’t encountered the issue). Very often, HIPs report that Defender is disabled, even though everything is fine on the client’s end.
(A temporary workaround is to disable real-time protection checks in HIP.)
Have any of you observed similar behavior?
09-18-2026 03:04 AM
Hi @JacekL ,
This behavior sounds like an OPSWAT / Host Information Profile (HIP) detection mismatch after Windows security/cumulative updates.
When Windows updates Defender's binaries, service names, or registry keys, the underlying OPSWAT engine used by the GlobalProtect client (v6.3.x) can temporarily fail to query Defender's real-time protection status. This causes GlobalProtect to generate an empty or "Real-Time Protection Disabled" HIP report, which triggers gateway policy enforcement and drops/disconnects the session.
Recommended Next Steps & Workarounds:
Check/Update GlobalProtect Data File: Ensure your Panorama/NGFW has downloaded and installed the latest GlobalProtect Data File. Palo Alto Networks regularly pushes OPSWAT definition updates to fix OS/Antivirus detection gaps.
Collect Diagnostics: On an affected client, collect the GlobalProtect logs (PanGPS.log).
Open a TAC Case: Submit the logs to Palo Alto Networks TAC so they can verify if a specific OPSWAT SDK update or updated GP Data File is required for these specific KB builds.
Temporary Mitigation: As you noted, temporarily adjusting the HIP Object criteria will prevent client disconnections until TAC releases an updated data file.
Kind regards,
09-21-2026 01:21 AM
Hi @kiwi
GlobalProtect Data File – is it still needed?
On two identical clusters (PanOS 10.2.16-h6) with a GP Gateway license, one shows no information at all about the GlobalProtect Data File (as such), while the other displays a window but without any version information.
When I set the schedule (on the cluster 2) to update every hour, the logs show:
An error occurred while processing the request. Please try again after some time or contact support.
cluster 1
cluster 2
09-21-2026 02:14 AM
Hi @JacekL ,
Yes. The GlobalProtect Data File contains the vendor definitions (OPSWAT engine definitions) used by PAN-OS to evaluate Host Information Profile (HIP) checks. If you are using HIP checks to verify antivirus status, disk encryption, or OS patch levels, keeping this file updated is required so PAN-OS can correctly interpret HIP reports from newer client/OS builds.
If one cluster show no info and the other fail with an error it usually points to a licensing or update-service connectivity issue on the firewall.
If licenses are active and connectivity is confirmed, a TAC case may be needed.
09-21-2026 02:35 AM
Yes - the license is fine, and so is the connection…
So I'll try to contact TAC.
I'll let know once I get a response.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

