GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
About GlobalProtect Discussions
Welcome to the GlobalProtect discussion area! Here, you can engage in conversations about GlobalProtect, explore new insights, and stay updated on ongoing discussions. Check back regularly for the latest updates and community insights on GlobalProtect.

Discussions

GlobalProtect logged in user issue

Hello Mr. After changing from GlobalProtect 5.1.14 to 5.2.8 it's very noticed that added authentication user such as 'mydomain\myusername' just change it self to 'myusername' only just by itself which doesn't allow it to access the resources.Why that? Any ideas?

Resolved! Does PBF rule works for traffic originating from Global Protect Client

Hi All, We have two Global Protect portals/Gateways configured on each firewall ISP 1(Eth 1/1) and ISP 2(Eth 1/2) interfaces. We had enabled ECMP on the firewall with max path 2 and configured ISP 1 and ISP 2 as default routes. When an user is connected to GP configured on ISP 2 interface and trying to access internet the traffic from GP client ...

Resolved! Palo Alto Globalprotect app to gateway communication impact because of free hotel Wi-Fi.

Hello to All, We see issues when someone goes to a hotel and uses the fee Wi-Fi to start the Globalprotect agent application, because many hotels have SSL decryption proxy devices and the Globalprotect agent sees that the Gateway certificate is with wron CN name or if it is a newer proxy, it will be seen that the signing CA is different (simila...

Resolved! GlobalProtect client script options

I want to create a script or some other option if it is available that will present an icon on the users desk so that they can quickly disable/ enable the GP client without the reason prompt. I had a quick look but I don't see any CLI oprtions available tha I can use in a script. Is this possible?

Jamesy by L2 Linker
  • 11927 Views
  • 9 replies
  • 0 Likes

Cisco DUO MFA with Radius under Global Protect

Hi Folks, We are trying to configure MFA under Radius using Cisco DUO.We have done the configuration for MFA in firewall for the same.Now we are facing some problem such as 'Reason: Invalid username/password. auth profile \'Duo_Auth\', vsys \'vsys1\', server profile \'Duo_Radius\', server address Failed to communicate with any Active Directory s...

Resolved! GlobalProtect Certificate Profile Issue

Hello, I have a situation where I am looking for advice and help. An existing PA5050 is a portal/gateway and we have several global PAs as gateways alsoThe gateway authentication on the Portal/Gateway uses external authentication and NO certificate profileThe subordinate gateways globally use external authentication and certificate profiles. T...

GlobalProtect Uninstall Issue

We have a user who cannot connect to VPN. When trying to uninstall the app we get the message that another account on the computer uses it and are prevented from uninstalling. No one else is logged into the machine. I tried disabling it and enabling it , logging out username , deleting and adding back the VPN portal address. Made sure she cou...

GlobalProtect logged in user issue

Hello Mr. After changing from GlobalProtect 5.1.14 to 5.2.8 it's very noticed that added authentication user such as mydomain\myusername just change it self to myusername only just by itself which doesn't allow it to access the resources.Why that? Any ideas?

GlobalProtect app 5.1.9?

Hello, In the Palo Alto Networks Security Advisories / CVE-2021-3057 it refers to the issue being fixed in GlobalProtect app 5.1.9 - however, when either looking for it in the list on the firewall (after refreshing the list by 'Check Now'), or looking for it in the Support portal, I am unable to find it to download, or basically any other refere...

What if my global protect client version is 5.2.7 got affected due to vulnerability CVE-2021-3057 ?

As per client requirement, I checked that client has global protect client version 5.2.7. Now According to CVE-2021-3057 Vulnerability this version got affected. If I will update the current version from 5.2.7 to 5.2.8 then this vulnerability not affected.But according to PANOS release guidance, global protect version 5.2.8 is under monitor. So ...

Documentation for LSVPN deployments

Does anyone have access to, pointers to, or stashes of better documentation for how LSVPN works? Something along the lines of "best practices" for configuring routing for the satellites? Or with "big picture" information on how all the pieces work together? The GlobalProtect Administration Guide and the PanOS Admin Guide show you all the nitty...

fjwcash by L4 Transporter
  • 2245 Views
  • 0 replies
  • 0 Likes

Global Protect - exclude video traffic not working

Hello, Did somebody successfully implement this feature ?I'm working on GP 5.0.7 and PANOS 8.1, also we have a Global Protect Gateway license active. I want to exclude video traffic from the VPN tunnel. So I go to my external gateway, and enable exclude video traffic. The tunnel mode is enabled, and also in the agent config, the split tunneling ...

MMerlier by L1 Bithead
  • 12138 Views
  • 7 replies
  • 0 Likes

Resolved! Global Protect connection issue

Hello community,I'm having trouble connecting to the global protect VPN after assigning security profiles (AV ,Anti-spyware,Wildfaire,..) to the rules.In reality, the link became unstable. Any advice 🙂 Many thanks.

Linux CLI GlobalProtect with SAML MFA connection problems

Hi Hope someone can help. I am running into problems with Ubuntu 20.04 users that want to use CLI only. When I try to use the CLI GP client(tried version 2.4 and 2.6) on Ubuntu it opens the default browser and the MFA via Okta is successful but then nothing happens. The VPN is never setup. The last message on the CLI is "Try to launch default b...

Hendre by L0 Member
  • 7784 Views
  • 2 replies
  • 0 Likes
  • 2069 Posts
  • 68 Subscriptions
Top Solution Authors
Labels