Global protect client for windows 11

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Global protect client for windows 11

L1 Bithead
11 REPLIES 11

L5 Sessionator

Targeted official support for Windows 11 appears to be GP agent 6.0. 

 

Since vendors do not get early access to new operating systems prior to release, we are still undergoing extensive testing and validation on our end. Our QA teams are still working on it at this time. 

Help the community! Add tags and mark solutions please.

Thanks for your reply.

L5 Sessionator

We've received updated guidance that they are targeting agent 5.2.10 (ish) instead for Mac 12 and Windows 11. 

 

That would be end of December / early January if true. Usual disclaimer applies of not a promise, etc. 

Help the community! Add tags and mark solutions please.

Cyber Elite
Cyber Elite

@HussainMohammed,

Non-official answer; I've been running Windows 11 since it was officially released on both my primary Windows machines and the GP agent works perfectly fine as is without any issues. While Windows 11 may not be officially reported, we have hundreds of clients running it without any issue on the 5.2 branch of GP. 

Thanks for your reply.

Thanks for reply.

GP 5.2.9.-35 (Windows) seems to work fine for the connection, but HIP does not work correctly.. some of them like Domain check and Bitlocker seems to validate correctly but, all others (Windows, registry, Av validation) does not work correctly up to now. Anybody lucky ? 

L1 Bithead

Windows 11 is according to the Palo releasenotes on GP 5.2.10 supported !!!!

 

Intel devices only on 5.2.10 & later

 

https://docs.paloaltonetworks.com/compatibility-matrix/globalprotect/where-can-i-install-the-globalp...

 

L1 Bithead

We are having a bit of trouble with GP client 5.2.10 on some test Windows 11 machines.  The client seems to install ok, service starts ok, but looking like now that the driver is failing to load.  We get this error after cycling the PanGPS service.

 

P18000-T22588)Info ( 332): 02/01/22 11:28:49:169 PanGPS service receives stop command
(P18000-T9548)Info ( 297): 02/01/22 11:28:49:170 PanGPS service exits
(P18000-T9548)Info ( 183): 02/01/22 11:28:49:170 Stop PanGPS
(P20648-T9256)Info (1787): 02/01/22 11:28:50:705 Old registry setting Prelogon is copied to new location. Old setting is deleted.
(P20648-T8344)Info ( 156): 02/01/22 11:28:50:785 DRBG selftest: PASSED
(P20648-T8344)Info ( 158): 02/01/22 11:28:51:302 ####################### Start PanGPS service (ver: 5.2.10-6) #######################
(P20648-T8344)Info (1710): 02/01/22 11:28:51:306 Enumerate session: user ########## logs in on session 1
(P20648-T8344)Debug( 985): 02/01/22 11:28:51:319 PreviousDNSInfo doesn't exist, no need to restore
(P20648-T8344)Debug(6216): 02/01/22 11:28:51:320 Proxy is not disabled before, no need to restore
(P20648-T8344)Error( 53): 02/01/22 11:28:51:320 Driver is not installed, reinstall it now!

 

gpfltdrv.inf: Failed to add driver to the system. Error 0x00000057: The parameter is incorrect.
pangpd.inf: Failed to add driver to the system. Error 0x00000057: The parameter is incorrect.

 

Any ideas? 

What endpoint AV are you running? I'm seeing some JIRAs open right now due to McAfee and Crowdstrike blocking some of these, but no exact match to what you've posted above. The errors I see are living in gpfltdrv.sys not .inf

 

Are you doing this manually? Via SCCM? Transparently from NGFW? 

Help the community! Add tags and mark solutions please.

L1 Bithead

It has to be 5.2.10 or later ( 5.2.12 is recommended ) to support Windows 11 !!

  • 30868 Views
  • 11 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!