GlobalProtect Version 5.1.6 has Browsing Issues on MacOS 10.15.6/7!

Announcements

ATTENTION Customers, All Partners and Employees: The Customer Support Portal (CSP) will be undergoing maintenance and unavailable on Saturday, November 7, 2020, from 11 am to 11 pm PST. Please read our blog for more information.

Reply
Highlighted
L0 Member

GlobalProtect Version 5.1.6 has Browsing Issues on MacOS 10.15.6/7!

Last week I updated GP on our 5250 firewall from 5.0.4 to 5.1.6, which according to this website is the recommended version to use. 
After MacOS users updated their GP adapter on their laptop, many of them started to have connectivity & surfing/browsing issues! 
Until now, I know for sure that this problem affects MacOS versions 10.15.6 & 10.15.7 (which is the latest version)! 
I asked one of them to try version 5.2.2, but it didn't solve the problem. 
Then, I asked them to install version 5.0.10, & all the problems disappeared! 
As you may know, starting version 5.1.4 on MacOS version 10.15.4 & up, GP is using NE (Network Extensions), instead of KEXT (Kernel Extensions), so my guess would be it's the root cause of the problem! 
I just don't understand how a company in this scale releases a new version(s) without thoroughly testing it first on all platforms... 
Highlighted
Cyber Elite

@Snir_Gavriel,

Well so here's the deal, I can guarantee that 5.1.6 and 5.2.2, and 5.2.3 all work without issue on macOS 10.15.6 and 10.15.7. So to say it's not tested and that nobody can use GlobalProtect agents above 5.0 is just not correct. Now if you look at one of the machines that have stopped working, you'll likely find under the user's security preferences that macOS has stopped the new system extension from being loaded, and the user simply need to allow it for the first time to get things to function properly again. 

While this could be smother for the user, Apple doesn't make that as easy as you would think to actually prompt the user that additional permissions are required during the upgrade process. That's either something you manage from the MDM side, or communicate to users as you deploy the update if you don't manage those endpoints. It's an annoyance, but it's one that really falls under Apple. 

 

I have plenty of macOS users deployed throughout the 5.1 and 5.2 releases without issue, and PAN themselves have a very large fleet of macOS devices all running GlobalProtect. The agent when properly configured and granted the proper permissions works perfectly fine. 

Highlighted
L0 Member

Sorry, but I think I didn't explain myself correctly.

I'm already aware that starting from MacOS version 10.13, you have to allow the usage of the GP app in Security & Privacy (or during its installation), as described in the below link (in section # 8), but this is not the case here! 
https://kstate.service-now.com/kb_view.do?sysparm_article=KB14182
The GP adapter can establish a connection to the firewall, but although we're using a Split Tunnel, some users have issues reaching the Internet, while others can't reach some internal resources we configured in Domain Split Tunnel

I've asked our MacOS users to check in Security & Privacy whether there's another option to allow the new extensions, but there's nothing there! 

Highlighted
L0 Member

I am also experiencing this issue on 5.1.6 after upgrading from 5.1.5. Browsing will randomly stop or take a long time to load. Speed tests are also affected. I plan to open a case with TAC. It’s only happening on Apple computers. 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!