GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
About GlobalProtect Discussions
Welcome to the GlobalProtect discussion area! Here, you can engage in conversations about GlobalProtect, explore new insights, and stay updated on ongoing discussions. Check back regularly for the latest updates and community insights on GlobalProtect.

Discussions

GlobalProtect 5.1.3 client update issue

Hello, I have downloaded and updated PA firewall to the latest 5.1.3 version from 4.1.3 and activated. However when i click on GP client to "Check for Updates" it states that i am on the latest version. And the update doesnt prompt. Even when i go to our VPN portal and installl again, its the older 4.1.3 version. Should this be instantaneous or ...

ITWinch by L0 Member
  • 5497 Views
  • 3 replies
  • 0 Likes

Clients stuck in Connecting state

Hello All, We have had a more or less stable GP environment during this pandemic. About a week ago, we started receiving calls of clients not able to connect - the GP agent stuck in the connecting state. We had recently enabled split tunneling for just a couple Microsoft networks to support teams and backed that out but at still receiving calls...

jhwarren by L1 Bithead
  • 3371 Views
  • 1 replies
  • 0 Likes

Resolved! VPN Configured. Android devices can connect, GP-Windows NOT.

Hello, Here are rare trouble. I just configured a new VPN Portal and GlobalProtect inside PaloAlto 3220 FW. I can perfectly connect using Android devices without GP client (Direct on Android VPN config) but I can't connect using a windows machine with GlobalProtect Client. Test made on Windows: 1.- I can connect to the Portal (Internet Browser) ...

Best practices for preventing GlobalProtect connections internally

We currently have GP configured as connect on demand and currently have both an internal and external gateway. I'm finding that several of our users are connecting to GlobalProtect even when they are in the office, which is causing extra overhead and perceived slowness as their Internet traffic is piped out through our corporate data center. In...

dfrancis by L1 Bithead
  • 14724 Views
  • 5 replies
  • 0 Likes

Resolved! Use DHCP relay with GlobalProtect

Hi,I've been doing some research on the option of using DHCP relay on Palo Alto for all the GlobalProtect gateways, and i'ts not clear to me if it's possible or not. The thing is, we want to enable Secure DNS records registration for the GlobalProtect IP network pools, but because currently the Palo Altos are the ones providing the IP, instead o...

MarcelST by L3 Networker
  • 10048 Views
  • 1 replies
  • 2 Likes

Certificate profile - option Block session if the certificate was not....

Basic GP setup, portal and gateway using certificate authentication only, certificates issues by internal CA, Palo Alto firewall is not involved in the certificate enrollment process. Certificate profile used is configured with Root and intermediate certificate, set for using CRL and options (block session if certificate status cannot be retriev...

Global Protect user inactivity timer

We are trying to figure out how the Global Protect inactivity timer works? We have set the inactivity timer to 3 hours but for some reason we don't see the user session log out after 3 hours of inactivity. Login Lifetime: set for 10 hoursInactivity timeout : 3 hoursDisconnect on idle: 3 hours Any suggestions on how to get this working highly app...

Globalprotect use problem

The customer uses SSLVPN made by a certificate issued by a third-party trust agency. The problems we have now are: Some customers can use domain names or public network IP addresses to log in to sslvpn, but some users can only use domain names to log in to sslvpn, not public IP addresses. Can you help me see the reason?

Resolved! Can't Uninstall GlobalProtect

After a drive failure I cannot uninstall goblaprotect. The failed drive was only used for my applications. So the install directory was lost but my main windows drive is intact so GP is still registered as an application. I have the install msi for GP 5.00 but it cannot repair or remove the existing package.Is there any way other than editing t...

Resolved! GlobalProtect Post Login Banner - SAML

We are currently using SAML w/Cisco's DUO for authentication to our Portal, with the authentication override cookies enabled. I am now being asked if we can display a "Welcome Banner" of sorts to users when they connect to the vpn. the globalprotect portal is only used once, for these users, and only then to download the Agent software. after ...

DonClick by L0 Member
  • 5514 Views
  • 1 replies
  • 0 Likes

Resolved! Global protect with IPsec

Hello,one of my customer is using global protect with IPsec.when he turn off the internet in his pc,GP disconnects from the machine as expected.but in gateway-remote users , the user is still showing as connected and able to observe the same through gateway connected users in cli.There are no logout events generated in systems logs as well.the t...

snimshad by L1 Bithead
  • 6018 Views
  • 3 replies
  • 0 Likes

Global Protect Cannot Reconnect When a Proxy is Enabled

Hey PA LIVECommunity! I have a weird issue... Global Protect Fails to Connect after Disconnecting, stating it cannot reach the gateway. However, restarting the computer with the GP Client, and reconnecting it will succeed.We've seen this on a handful of our Windows devices, and it seems to be slowly growing as first we only had four devices with...

  • 2062 Posts
  • 68 Subscriptions
Top Solution Authors
Top Liked Authors
Labels