GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
About GlobalProtect Discussions
Welcome to the GlobalProtect discussion area! Here, you can engage in conversations about GlobalProtect, explore new insights, and stay updated on ongoing discussions. Check back regularly for the latest updates and community insights on GlobalProtect.

Discussions

User management with Client certificates not working

Hello experts, We are trying to authenticate users connecting to GP via client certs, idea is to revoke client certs and thus prevent users from connecting to GP. Test user is still able to connect after certification has been revoked. Due to some reasons, OCSP has been disabled on the gateway, CRL does not contain revocation status, only delta ...

ksoni by L1 Bithead
  • 2442 Views
  • 1 replies
  • 0 Likes

GP assigning static IPs to clients

Trying to understand why GP is assigning static IPs to GP clients. We are running GP 5.2.5 and the clients are getting assigned with static IPs, they are able to connect fine without any problem for now but one of the employee when she is working remotely had an issue with GP not having gateway address in there. I was able to get her going by pu...

Akhil_B by L2 Linker
  • 6229 Views
  • 6 replies
  • 0 Likes

Global Protect 5.2.5 and 5.2.5 Hotfix - Allow Transparent upgrade doesn't work - what a mess.

5.2.5 has a nasty bug in which has affected a few hundred remote worker staff as we rolled it out.. Problem 1 - Hotfix now availableThe IP6 and IP4 conflict for DNS resolution when sending AAAA and A requests Problem 2 - Hotfix is seen as older version and will not auto update userswe then see the Hotfix is released to fix this issue, howev...

GlobalProtect Unstable Connection

PA-OS version: 7.1.7GlobalProtect Client version : 5.2.5I have a strange connection problem when I login GP client or open the Portal website. It noticed that I can't connect to the gateway.I test it that the 443 port has no response. It was unstable and intermittent.I don't know if my setting for GlobalProtect is correct or there is some bugs o...

Resolved! Using corporate wildcard certificate for Global Protect

To get up and running with GP I set things up with a locally generated a root cert on the PAN and then generated a server cert tied to the root cert. The server certificate used the IP address of the outside interface as the Common Name. Then I created an SSL profile which pointed to the server certificate. Everything works well although it has...

Global Protect Client IP Range not able to get to internal resources

Hi All,I recently configured an HA pair of 3220s for Global Protect. I have the firewalls handing out IPs from the 192.168.124.0/22 network. The clients can connect and get the correct IPs but are not able to reach internal resources. This same IP range had been setup on a pair of 5250s and I believe I had everything setup for this to work on th...

Global Protect Failing to Work on Xfinity Networks with PopOS 20.04

Hi there, I'm hopping to get some troubleshooting advice by the experts here. I'm using GlobalProtect 5.2.4 with a linux laptop running PopOS 20.04. At home I don't have issues connecting on a Verizon FIOS network, but when I visit family members (who all each have Xfinity) I haven't been able to get it all working. I can log in with the SSO GUI...

Global Protect - Internal Detect - WIFI/LAN

hello I am testing our rollout of mobile user vpn with pre-logon and always oncurrently we are on-prem with on-demand so its complete change in user experience but with one of out test users we found today when they are at home using they are using a device that displays company wifi so they connect to this and they are detected as internal whic...

GlobalProtect cert auth alternative

Hi all, We are using Cert authentication for identify check and make sure the device connected to GlobalProtect is a domain joined device. We are having issues with GlobalProtect Cert authentication when users travelling and connecting to a captive portal, where some captive portals represent their cert to the FW portal(man in the middle). This ...

Globalprotect Azure MFA in PA-220

Hello all, I'm just new here and would like to know if Azure MFA will work in PA-220 firewall or is there any restrictions with the said firewall? We are looking to provide solution to enable Azure MFA when using Globalprotect on a PA-220 firewall. Cheers,Mark

mrosales by L0 Member
  • 2274 Views
  • 1 replies
  • 0 Likes

easiest way to move users to 2nd gateway for maintenance on 1st

We have an Azure implementation of Palo Alto/GlobalProtect.We use an Azure LoadBalancer point to 2 Palo Alto firewalls for GP portal connectivity.Then based on the received config we send the user to the direct interface address of one of the 2 firewalls for gateway connectivity.No HA, no failover. What would be the easiest way to have users con...

GlobalProtect depends on ISP

Hello all, I have a problem that has no sense for me..A customer of us has problems with speed when they used his mobile phone as Personal Hotspot, all his employees uses same mobile phone model & ISP, and also same GlobalProtect version (5.2.2). When they're conencted throught their mobile phone & GP they have 35.4 Mb/s download but 0.0...

BigPalo by L4 Transporter
  • 2280 Views
  • 1 replies
  • 0 Likes
  • 2069 Posts
  • 68 Subscriptions
Top Solution Authors
Labels