GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
About GlobalProtect Discussions
Welcome to the GlobalProtect discussion area! Here, you can engage in conversations about GlobalProtect, explore new insights, and stay updated on ongoing discussions. Check back regularly for the latest updates and community insights on GlobalProtect.

Discussions

Global Protect Client IP Range not able to get to internal resources

Hi All,I recently configured an HA pair of 3220s for Global Protect. I have the firewalls handing out IPs from the 192.168.124.0/22 network. The clients can connect and get the correct IPs but are not able to reach internal resources. This same IP range had been setup on a pair of 5250s and I believe I had everything setup for this to work on th...

Global Protect - Internal Detect - WIFI/LAN

hello I am testing our rollout of mobile user vpn with pre-logon and always oncurrently we are on-prem with on-demand so its complete change in user experience but with one of out test users we found today when they are at home using they are using a device that displays company wifi so they connect to this and they are detected as internal whic...

Globalprotect Azure MFA in PA-220

Hello all, I'm just new here and would like to know if Azure MFA will work in PA-220 firewall or is there any restrictions with the said firewall? We are looking to provide solution to enable Azure MFA when using Globalprotect on a PA-220 firewall. Cheers,Mark

mrosales by L0 Member
  • 2328 Views
  • 1 replies
  • 0 Likes

easiest way to move users to 2nd gateway for maintenance on 1st

We have an Azure implementation of Palo Alto/GlobalProtect.We use an Azure LoadBalancer point to 2 Palo Alto firewalls for GP portal connectivity.Then based on the received config we send the user to the direct interface address of one of the 2 firewalls for gateway connectivity.No HA, no failover. What would be the easiest way to have users con...

GlobalProtect depends on ISP

Hello all, I have a problem that has no sense for me..A customer of us has problems with speed when they used his mobile phone as Personal Hotspot, all his employees uses same mobile phone model & ISP, and also same GlobalProtect version (5.2.2). When they're conencted throught their mobile phone & GP they have 35.4 Mb/s download but 0.0...

BigPalo by L4 Transporter
  • 2342 Views
  • 1 replies
  • 0 Likes

GP 5.2.4 upgrade

Dears, I am planning to upgrade the Globalprotect version from 5.1.7 to 5.2.4. Do I need to push or reinstall SSL / TLS certificate when I am upgrading to GP 5.2.4 ? Also I am planning to push the GP software (*.msi files) from an SCCM server. May I know is this the best method. And any best practices available while pushing the GP client from ...

GlobalProtect Pre-Login with SAML + Azure MFA re-authentication issues

We currently have GlobalProtect deployed utilizing a combination of certificates (for pre-login) and SSO + SAML (to Azure AD) for user authentication. The SAML portion redirects the users to the Microsoft MFA portal for 6 digit authentication when they log in. This is working without pretty much flawlessly. The issue comes into play when a use...

Global Protect user-pre-logon from Windows domain login first time user

I'm having an issue finding an all inclusive document that can help me validate my GP portal and gw config to allow new users who receive a domain joined laptop be able to log into the domain on receipt of the laptop current gw is pre-login with on-demandall laptop have machine cert installed from our domainfor purposes of the test I have a new ...

Resolved! GLOBALPROTECT WITH AN INTERNAL IP BEHIND INTERNET DEVICE

GlobalProtect set up on a firewall with an internal IP address sitting behind an edge Internet device Internet Router (2.2.2.2/24) > Internal Network > PAN ( 192.168.0.2/24) I'm using OS 9.0.13 internally i can connect (for testing purpose), but externally I get error server certificate error. I have associated certificate with FQDN ...

spiyaa by L1 Bithead
  • 3654 Views
  • 3 replies
  • 0 Likes

Resolved! Force GP client upgrade

Hi,Is there a way to force a client to upgrade their globalprotect version? I have set the update to transparent and this works when users boot up their computers and connect. The issue comes from users that remain connected and don't disconnect. Disconnecting their gateway session does not force the upgrade. I use always on vpn setting.

ce1028 by L4 Transporter
  • 15575 Views
  • 7 replies
  • 0 Likes

GlobalProtect using IPSec and a Site-to-Site IPSec VPN

I'm running a PA-500, PANOS 8.1.15-h3 and am trying to create a site-to-site IPSec VPN tunnel. It must run alongside an already configured GlobalProtect gateway where the GlobalProtect is also configured to use IPSec. Can these two VPN types exist on the same firewall at the same time? They would both be using the same outside interface to conne...

kkrause by L2 Linker
  • 3688 Views
  • 2 replies
  • 0 Likes

Host-ID Information is not captured for some by GP Agent

Hi Team, In Global Protect logs, for some of the MAC and Windows machine Host-ID information is not captured by the Agent what will be the possible cause for this and how to resolve this . Snap for Host ID not captured for some and captured for some for the same machine itself: Please let us know if you have thoughts on this below mentioned qu...

SahulH_0-1615293902039.png
SahulH by L3 Networker
  • 6072 Views
  • 4 replies
  • 1 Likes

Pre-Logon can't get IP address from IP pool

I created two agents for my internal gateway in GlobalProtect.One is for Pre-Logon and another is for Any users. I split a big IP address pool for them two.big pool: 10.224.0.0/20Split to : 10.224.0.0/21 and 10.224.8.0/21But no matter which one I assign to Pr-Logon, it will not get IP address when I restart PC.And Any users always can use anoth...

  • 1702 Posts
  • 68 Subscriptions
Top Solution Authors
Labels