GlobalProtect Mobile Initial SAML Authentication with ID Fails After Upgrading to PAN-OS 10.2.18-h6

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

GlobalProtect Mobile Initial SAML Authentication with ID Fails After Upgrading to PAN-OS 10.2.18-h6

L3 Networker

Hi ,

 

Observed Behavior
- Before upgrading to PAN-OS 10.2.18-h1, GlobalProtect SAML authentication using ID worked normally on all platforms.
- After upgrading to PAN-OS 10.2.18-h6, only Android, iPhone, and iPad are affected.
- Initial SAML authentication fails only on mobile clients.
- Windows clients continue to authenticate successfully using the same SAML configuration.
- Android displays net::ERR_UNKNOWN_URL_SCHEME.
- iOS displays Unsupported URL.
- As a workaround, users must first log in using the local username/password authentication profile. Once the initial local authentication is completed, subsequent logins using ID SAML authentication are successful.

- The issue started immediately after upgrading from PAN-OS 10.2.18-h1 to PAN-OS 10.2.18-h6.

Expected Behavior
GlobalProtect Mobile clients should be able to complete the initial SAML authentication using ThaiID successfully, without requiring a prior local authentication.

Request : Could you please help verify
1. Whether this is a known issue or regression introduced in PAN-OS 10.2.18-h6.
2. Whether any changes were made to the GlobalProtect Mobile initial SAML authentication flow in this release.
3. Whether there are any known issues related to mobile session initialization, portal session/cookie handling, or callback URL processing after upgrading to PAN-OS 10.2.18-h6.
4. Whether any workaround, configuration changes, or hotfix is available.

connection failed unsupported URL.jpg

connection failed ERR_UNKNOWN_URL_SCHEME.jpg

  

1 REPLY 1

L7 Applicator

Hi @Fariq_Zaidi 

 

GlobalProtect SAML authentication is failing on initial login for mobile clients (Android, iPhone, iPad) after upgrading to PAN-OS 10.2.18-h6, exhibiting net::ERR_UNKNOWN_URL_SCHEME on Android and Unsupported URL on iOS. This behavior is likely due to changes in how the GlobalProtect mobile client handles SAML redirects and callback URLs, potentially related to the default-browser setting or initial session/cookie establishment, which can be impacted by PAN-OS upgrades.


*Investigation Path**

Step 1: Is the GlobalProtect Portal configured to use the default browser for SAML authentication?*
Changes to the default browser setting for SAML authentication can cause issues on mobile clients after a PAN-OS upgrade.
GUI: Network > GlobalProtect > Portals > <Your Portal> > Authentication
• If "Use Default Browser for SAML Authentication" is enabled → Proceed to Step 2.
• If "Use Default Browser for SAML Authentication" is disabled → Proceed to Step 3.


Step 2: Does disabling "Use Default Browser for SAML Authentication" resolve the issue?
If this setting was enabled by default during the upgrade (as seen in PAN-OS 11.1.13-h1, Source: 81), it could conflict with mobile client SAML flows.
GUI: Network > GlobalProtect > Portals > <Your Portal> > Authentication
• Disable "Use Default Browser for SAML Authentication".
• If disabling the setting resolves the issue for mobile clients → Go to [Resolution A: Disable Default Browser for SAML].
• If disabling the setting does not resolve the issue for mobile clients → Proceed to Step 3.


Step 3: Are there any ERR_UNKNOWN_URL_SCHEME or Unsupported URL errors in the GlobalProtect client logs?
These specific errors indicate a problem with the mobile client's ability to handle the SAML callback URL, often related to the embedded browser or URL scheme compatibility.
File: GlobalProtect client logs (PANGPS.log, PanGPA.log on iOS/Android) — look for ERR_UNKNOWN_URL_SCHEME (Android) or unsupported URL (iOS) .
• If ERR_UNKNOWN_URL_SCHEME is observed on Android or unsupported URL on iOS → Go to [Resolution B: Address Mobile Browser/URL Scheme Compatibility].
• If auth-failed-invalid-cookie or "Cannot Decrypt Cookie" errors are observed → Go to [Resolution C: Address Cookie and Session Issues].
• If "Authentication Error" related to certificate validation is observed, or if prelogin goes to one portal and ACS to another → Go to [Resolution 😧 Review SAML Certificate and Multi-Portal Configuration].•


If none of the above patterns are observed → Escalate to support.
*Resolutions**

Resolution A: Disable Default Browser for SAML*
1.  Navigate to Network > GlobalProtect > Portals > <Your Portal> > Authentication .
2.  Uncheck the option "Use Default Browser for SAML Authentication" .
3.  Commit the changes to the firewall.
4.  Test GlobalProtect SAML authentication on mobile clients.


Resolution B: Address Mobile Browser/URL Scheme Compatibility
1.  Check GlobalProtect Client Version: Ensure the GlobalProtect mobile client is updated to a version known to address ERR_UNKNOWN_URL_SCHEME issues, such as GlobalProtect versions 6.1.7 or higher .
2.  Portal Setting for Default Browser: As a workaround, if disabling the "Use Default Browser for SAML Authentication" (Resolution A) does not fully resolve the issue, consider if changing the portal settings to explicitly use the default browser (if currently using an embedded one) helps for Android, though this might cause issues for iOS .
3.  Browser Compatibility (iOS/iPad): For iOS devices experiencing "unsupported URL" errors, especially when using specific browsers like Microsoft Edge, recommend users switch to Safari or other compatible browsers . The saml-use-default-browser MDM key may not have been correctly pre-deployed, causing issues .


Resolution C: Address Cookie and Session Issues
1.  Clear GlobalProtect Client Cookies: Instruct users to delete authentication cookies from their GlobalProtect client. On Windows, this involves deleting files starting with PUAC from C:\Users\%USERNAME%\AppData\Local\Palo Alto Networks\GlobalProtect . For mobile, this typically involves clearing app data or reinstalling the client.
2.  Review Authentication Override Settings: If "Authentication Override" cookies are enabled, ensure that all GlobalProtect Portal and Gateway firewalls run on the same PAN-OS version to avoid "Cannot Decrypt Cookie" errors .3.  IdP Username Attribute Format: If authentication fails specifically for iOS and is related to an "allow list" check, configure the username attribute in the IdP server in UPN or email format. Also, use a different certificate for the "Cookie encrypt/decrypt for GlobalProtect Gateway" "Authentication Override" setting in each agent config to invalidate old cookies .


Resolution 😧 Review SAML Certificate and Multi-Portal Configuration
1.  Certificate Validation: Investigate and resolve any certificate validation issues on the SAML server side or within the firewall's SAML configuration. Ensure the firewall recognizes the signer of the SAML assertion from the IdP .
2.  FQDN to Portal Mapping: If a single FQDN is shared by multiple portals, ensure that the prelogin and Assertion Consumer Service (ACS) requests consistently go to the same portal. Having them resolve to different portal IPs is not supported and can cause authentication failures .

 

Regards,

Sawan Jain

  • 71 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!