Global Protect application blank screen

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Global Protect application blank screen

L1 Bithead

Hello Members,

 

Can anyone help me to solve the global protect blank screen issue on my PC, as for others it normally works fine.

 

I am using Windows 11 and I have already removed and re-installed the GP App but still it shows a blank screen and I am not getting the login page to enter credentials and login to the GP VPN.

 

Thanks in advance.

19 REPLIES 19

Cyber Elite
Cyber Elite

@SamiPTfA,

There's not much information to go off of, and this defiantly sounds like a one-off machine issue. You could try checking the PanGPA and PanGPS logs for any errors, but a display issue might not be logging anything. 

Hello BPry,

 

The issue is when I click the global protect app to connect the VPN and it redirects to a blank screen not to the login portal to enter the credentials.

 

Also, we are using the SAML DUO 2FA for two-factor authentications so it should redirect to the login portal and then enter the 2FA passcode to successfully log in to the VPN on my PC.

 

The issue is with my PC only and the rest works fine.

 

the attached is the screenshot which I get after clicking the global protect App.

 

So i need help to resolve this issue in my PC.

 

 

gp-issue.png

Hello All,

 

Can anybody support me on the above issue?

L1 Bithead

Hi , I've seen a similar issue , it related to some Internet Explorer Group Policy setting applying to the affected machine .  Are you a windows user, do you perhaps as an admin have a different IE config to your users?  I think this was the relevant post for me - https://www.reddit.com/r/paloaltonetworks/comments/qqbrcp/win10_msft_sec_baseline_conflict_w_gp_embe...

Did you ever get a fix to this issue?

I have a user getting this exact behavior, if I use my username it works fine. If I use his username I get a screen just like yours.

That means this cannot be a pc issue. as both are on the same windows session.

 

Thanks 

 


@cosmith8000 wrote:

Did you ever get a fix to this issue?

I have a user getting this exact behavior, if I use my username it works fine. If I use his username I get a screen just like yours.

That means this cannot be a pc issue. as both are on the same windows session.

 

Thanks 

 


I'm not 100% sure this is the exact cause of your issue and the OP's, @SamiPTfA , but we had an issue using SAML auth and using the "embedded browser" for authentication.  GP client versions before 6.0.10, 6.1.5 and 6.2.3 do not support TLS1.3 for authentication, as the software called the Windows OS component called "Webview."  Webview calls the legacy Internet Explorer browser.  Since IE doesn't support TLS1.3 the GP client calling this component the SAML auth intermittently fails.  So the GP client cannnot broker the TLS1.3 SAML authentication to the external provider. 

 

We had users that intermittently receive a similar GP client pop-up.  With the GP software release of 6.0.10+, 6.1.5+ and 6.2.3+ the software support "Webview2" which uses the "Edge" version of the Windows OS browser.  Because the GP client is calling edge, via Webview2, TLS1.3 is supported.  

 

Once we migrated clients to GP version 6.0.10 users no longer failed to authenticate or receive the GP window popup.

 

 

--edit-- 

If using the "default browser" for authentication the SAML auth request is handed off to whatever the Windows OS default browser is.  In this case Edge or Chrome installed in a Windows 10/11 machine of course support TLS1.3 and clients never get stuck in this auth failure.

 

This could also be masked by the local machine having TLS1.3 disabled in the advanced settings of Internet properties.  With TLS1.3 disabled on the local machine earlier GP client software versions can't call TLS1.3 and therefore the use of the legacy Webview works with "embedded browser" selected as your authentication method.

 

The setting is in the Portal app config.  With "no" it's using the embedded browser within the GP client.  If yes, the SAML auth is offloaded to the Windows OS

Brandon_Wertz_0-1718819326190.png

 


@jbusby wrote:

Hi , I've seen a similar issue , it related to some Internet Explorer Group Policy setting applying to the affected machine .  Are you a windows user, do you perhaps as an admin have a different IE config to your users?  I think this was the relevant post for me - https://www.reddit.com/r/paloaltonetworks/comments/qqbrcp/win10_msft_sec_baseline_conflict_w_gp_embe...


I think your comment months ago was probably spot on.  Sad part is with this reddit thread being as old as it was, Palo was doing nothing to fix the calling of WebView2.  It wasn't until our issue and forcing this with Palo, that they got their development team involved in recoding the GP client to call Webview2.  It wasn't something that was even on their radar, to my knowledge, of integrating into their software.

L0 Member

Sadly, this is still occurring in 6.2.7.  I have found an easy workaround though.  Simply follow the steps below:

In the search bar at the bottom, type services.msc

Open Services

Find the PanGPS service

Restart the PanGPS service.

 

This has worked 100% of the time.

L1 Bithead

In our case we're on 6.2.7 waiting for a hotfix as my leadership does not want lose 6 months of support by moving to the 6.3 build which has no preferred software release. The current work around we have is to resize the blank window. This causes the login to redraw without needed to restart the service

I am finding on Windows 10 and 11, if the user has the default browser set to anything other than Edge, this issue is occurring.

Make sure the default browser is set to Edge and test.

Setting the default to Edge does not prevent using any other browser, but it does mean that any links or automated launching will open in Edge.

L2 Linker

I've found that when this issue happens, if you maximize the embedded browser window, the page appears.

Cyber Elite
Cyber Elite

@SamiPTfA  Fix is in GP client GlobalProtectARM64-6.2.7.1-1067

We had similar issue where some connections get the blank screen.

Other way to fix this under Agent config say do not use default browser and instead use Embedded browser.

 

Regards

 

MP

Help the community: Like helpful comments and mark solutions.

Where do you make this settings adjustment, please?

 

"Other way to fix this under Agent config say do not use default browser and instead use Embedded browser."

 

We do not have an Agent Config option in our version.

L1 Bithead

I don't see a 6.2.7.1- anything under available downloads. Is this something support made available to you? Is there some way to obtain this hotfix?

  • 21617 Views
  • 19 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!