GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
About GlobalProtect Discussions
Welcome to the GlobalProtect discussion area! Here, you can engage in conversations about GlobalProtect, explore new insights, and stay updated on ongoing discussions. Check back regularly for the latest updates and community insights on GlobalProtect.

Discussions

exclude ms update in global protect

Spoiler (Highlight to read)Spoiler (Highlight to read) We are facing the bandwith issue due to windows update and want to exclude ms-update application application in global protect vpn .2- we also seen the users are getting ip address in login session from post authentication ip pool due to this users session got stuck and need to logout fou...

Applications are not opening properly from the Clientless VPN

We have configured a clientless application on PA. It s working fine it's taking to the application, Following the Home page and other contents are accessing but from there we not able to open few the popup menu tabs from the application. Application is based on IP, not URL base. please find the details with Clientless VPN.https://XXX.XX.X.XX/ht...

Resolved! Global Protect, 1 Portal - 2 gateways - AlwaysOn users don't disconnect

We run a Solarwinds script to count panGPGWUtilizationActiveTunnels from each of our active gateways (2 different firewalls). Currently we have 900 Global Protect clients installed, but there are 1,355 active tunnels due to the fact that we use Always-On with a Login Lifetime of 5 days. Essentially, if a user connects to gateway A, then discon...

mwunder by L1 Bithead
  • 5971 Views
  • 4 replies
  • 0 Likes

GlobalProtect 5.1.3 client update issue

Hello, I have downloaded and updated PA firewall to the latest 5.1.3 version from 4.1.3 and activated. However when i click on GP client to "Check for Updates" it states that i am on the latest version. And the update doesnt prompt. Even when i go to our VPN portal and installl again, its the older 4.1.3 version. Should this be instantaneous or ...

ITWinch by L0 Member
  • 5540 Views
  • 3 replies
  • 0 Likes

Clients stuck in Connecting state

Hello All, We have had a more or less stable GP environment during this pandemic. About a week ago, we started receiving calls of clients not able to connect - the GP agent stuck in the connecting state. We had recently enabled split tunneling for just a couple Microsoft networks to support teams and backed that out but at still receiving calls...

jhwarren by L1 Bithead
  • 3389 Views
  • 1 replies
  • 0 Likes

Resolved! VPN Configured. Android devices can connect, GP-Windows NOT.

Hello, Here are rare trouble. I just configured a new VPN Portal and GlobalProtect inside PaloAlto 3220 FW. I can perfectly connect using Android devices without GP client (Direct on Android VPN config) but I can't connect using a windows machine with GlobalProtect Client. Test made on Windows: 1.- I can connect to the Portal (Internet Browser) ...

Best practices for preventing GlobalProtect connections internally

We currently have GP configured as connect on demand and currently have both an internal and external gateway. I'm finding that several of our users are connecting to GlobalProtect even when they are in the office, which is causing extra overhead and perceived slowness as their Internet traffic is piped out through our corporate data center. In...

dfrancis by L1 Bithead
  • 14928 Views
  • 5 replies
  • 0 Likes

Resolved! Use DHCP relay with GlobalProtect

Hi,I've been doing some research on the option of using DHCP relay on Palo Alto for all the GlobalProtect gateways, and i'ts not clear to me if it's possible or not. The thing is, we want to enable Secure DNS records registration for the GlobalProtect IP network pools, but because currently the Palo Altos are the ones providing the IP, instead o...

MarcelST by L3 Networker
  • 10101 Views
  • 1 replies
  • 2 Likes

Certificate profile - option Block session if the certificate was not....

Basic GP setup, portal and gateway using certificate authentication only, certificates issues by internal CA, Palo Alto firewall is not involved in the certificate enrollment process. Certificate profile used is configured with Root and intermediate certificate, set for using CRL and options (block session if certificate status cannot be retriev...

Global Protect user inactivity timer

We are trying to figure out how the Global Protect inactivity timer works? We have set the inactivity timer to 3 hours but for some reason we don't see the user session log out after 3 hours of inactivity. Login Lifetime: set for 10 hoursInactivity timeout : 3 hoursDisconnect on idle: 3 hours Any suggestions on how to get this working highly app...

  • 2069 Posts
  • 68 Subscriptions
Top Solution Authors
Labels