GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
About GlobalProtect Discussions
Welcome to the GlobalProtect discussion area! Here, you can engage in conversations about GlobalProtect, explore new insights, and stay updated on ongoing discussions. Check back regularly for the latest updates and community insights on GlobalProtect.

Discussions

Hibernate message in GP logs

What does below log mean P5168-T2376)Debug(6561): 07/15/21 08:14:19:956 NetworkConnectionMonitorThread: m_state = 0, m_bOnDemand=1, m_bAgentEnabled=1, m_bJustResumed is 1,m_bHibernate is 0, m_bAgentEnabled is 1, m_bDisconnect is 0, IsConnected() is 0, IsVPNInRetry() is 0. IS PC going to hibernate or GP Adapter or Wifi NIC> Thanks in advance!

GlobalProtect gateway limit

We have a pair of PA-850 firewalls, and we are running into an error when pushing configuration from Panorama that contains 7 GP gateways (6 external and 1 internal), and 6 portals. . global-protect -> global-protect-gateway -> GlobalProtect AlwaysOn constraints failed : Maximum number of GlobalProtect gateway configuration exceeded The on...

MFA and Windows Store app

My company has allowed the use of the Windows Store app for the past few years and it has been very handy for deployments. We are moving to MFA for VPN in the near future. Just wondering if the Windows store app will ever support that or if we need to deploy the full client going forward? Currently when I try to connect to an MFA server the MS...

brimur by L0 Member
  • 2212 Views
  • 0 replies
  • 0 Likes

creating split tunnel on full tunnel enforcement

Hi We’ve recently discovered that the Mac GlobalProtect client does not terminate existing network connections after full tunnel with no access to local network is established. This is reproducible In the following procedure:Disconnect from VPNConnect to resource that you should be unable to while connected to GlobalProtect – the connection must...

Multiple Class C addresses PA setup

I’m configuring a PA3220 for three external class C addresses we own (192.168.10.0/24, 192.168.11.0/24, and 192.168.14.0/24). We have two ISP Internet connections on two different campuses. We are using trunking to carry the different VLANs, so the outside networks are on the same physical interface. The inside network is on another physical int...

Firewall Network.jpg

Send Logs from GlobalProtect App on iOS managed via Intune

Does anyone else have issues on iOS sending logs from the GlobalProtect client to email when the device is managed via Intune? We manage our devices via Intune and use the MS Outlook app for email. We are having an issue with the GlobalProtect app and are working with support and they need the logs from this iOS device. When trying to do the S...

Pre Logon then on Demand traffic flow

Hi Community, We have GP prelogon then on demand.For pre logon we are using machine cert for authentication.For on demand we are using SAML MFA. I see that prelogon works fine for few users but one they logon to PC and click on connect they get error that PCis not in intune. So need to understand that for pre logon it uses only machine cert for ...

Does GP VPN Client store Session Data on client software

This is regarding whether VPN Client store any session related information over the client software.Kindly find below comment that needs to be noted. "Check if the VPN software writes session data to the remote workstation's disk. If possible, use a connection method that keeps the data in memory only, preferably encrypted." kindly share the sup...

Retain Connection on Smart Card Removal behavior on GP

Hello, There are Smart Cards being used for the GP authentication. One of the options for Windows endpoints is to disconnect the GP as soon as Smart Card is removed and that was tested, option in the app settings: "Retain Connection on Smart Card Removal" set to No.But the result after removing the Smart Card is that prompt is shown to the user ...

nikoo by L3 Networker
  • 4596 Views
  • 4 replies
  • 0 Likes

GlobalProtect IPv6 on tunnel adapter

Hi Community, since the Covid situation, we went in a fast rollout regarding GlobalProtect and got a prelogon always on setup running - so far so good. As we enabled the users, wo work from home, we experienced lot's of issues regarding name resolution, since IPv6 an LLMNR interferes with the classical IPv4 DNS way.As a result, we deployed a scr...

Chacko42 by L4 Transporter
  • 2627 Views
  • 0 replies
  • 0 Likes

HP Remote Graphics Software freeze when accessing via global protect to internal network

Hi, Have anyone experiencing performance degradation when using remote graphic software with global protect ?During pandemic, our user using global protect then accessing their office computer with HP remote graphic software (RGS) and RDP. we have issue when user accessing remote with HP RGSwhen they using remote graphic software to access their...

ichsan11 by L0 Member
  • 2588 Views
  • 0 replies
  • 0 Likes

Network Extensions crash macOS

Hi, I'm trying to split tunnel some GlobalProtect traffic. Using macOS (catalina) I've tried multiple versions of GP but I'm currently running 5.2.7. Upon logging into GP, I get the prompt "GlobalProtect would like to add VPN configurations. All network activity on this Mac may be filtered or monitored when using VPN" As soon as I click Allow...

global protect clientless using guacamole

Hi all,Start working with global protect using MFA and try using guacamole for proxy rdp connection.after building the guacamole server (updated one using Guacamole 1.1 on Ubuntu 20.04) the server is working on the internal network but when accessing it from outside I get the following message. Access Error: 404 -- Not FoundCan't locate document...

SShnap by L3 Networker
  • 10522 Views
  • 5 replies
  • 0 Likes

Radius Auth Profile with PEAP-MsCHAPv2

Has anyone successfully integrated Radius Auth profile PEAP-MsCHAPv2 with NPS or any other Radius platform? I have configured my Radius Auth Profile and attached relevant Cert profile to it as per below knowledgebase article.https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CmkRCASHowever we are unable to establish succes...

NamalW_0-1600837232072.png
Namalw by L1 Bithead
  • 11982 Views
  • 2 replies
  • 0 Likes
  • 2062 Posts
  • 68 Subscriptions
Top Solution Authors
Top Liked Authors
Labels