GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
About GlobalProtect Discussions
Welcome to the GlobalProtect discussion area! Here, you can engage in conversations about GlobalProtect, explore new insights, and stay updated on ongoing discussions. Check back regularly for the latest updates and community insights on GlobalProtect.

Discussions

Resolved! Global Protect SAML: authentication works fails on matching client config not found. Group not matching.

Hi, I am trying to configure globalprotect to use SAML authentication for the portal and gateway. The authentication seems to work but when, but i am not getting a valid client config when i use groups in allow list. I am sure it is related to group mapping and user id but don't know where exactly it is going wrong. I have the following conf...

zGomez_0-1694012059685.png
zGomez_1-1694012177202.png
zGomez_2-1694012661065.png
zGomez_3-1694012917716.png
zGomez by L3 Networker
  • 5128 Views
  • 2 replies
  • 0 Likes

IP Validation for GlobalProtect Public IP

Hi All, We are currently attempting to complete GlobalSign IP address validation for our GlobalProtect public IP address.GlobalSign's validation process requires access to a challenge file under:/.well-known/pki-validation/However, our understanding is that Palo Alto does not normally host files under this path.In addition, HTTP validation via p...

Having issues connecting to GlobalProtect VPN from laptop connected with iPhone and JiO ISP hotspot

Hello community, we are facing a strange issue with the globalprotect connectivity. where we are trying to connect vpn from laptop and its connected via iPhone hotspot having JiO sim card, its on 5G network. we have SAML configured to login the global protect but its not happening in above scenario. did someone face similar issue and hav...

Configuring GlobalProtect via Ansible

Hi,I'm working on creating an automated Ansible process through which I can configure GlobalProtect in PAN Firewall.The automaton process I try to create it based on the official Paloalto Repository containing ansible playbooks:GitHub - PaloAltoNetworks/ansible-playbooks: Sample playbooks for the Palo Alto Networks Ansible modules.Unfortunately,...

GlobalProtect Cert+SAML

Hello, I'm reaching out to see if anyone has configured GlobalProtect with cert+SAML authentication with multiple gateways across multiple firewalls. I've been attempting to configure this, however, whenever I use cert+SAML at the gateway and I attempt to switch gateways after logging in, the logs always show "client cert not present". I h...

Global Protect Android client failing with certificate error after upgrading PAN-OS

Dear all, I have a strange error after I upgraded my firewall to PAN-OS 11.1.15 to fix a GP vulnerability. (18990)06/04 17:44:57:208734 - PanKeyManager: Issuers: CN=ixxx, DC=ixxx, DC=local(18990)06/04 17:44:57:208841 - PanKeyManager: Use Cert: gp_user_new(18990)06/04 17:44:57:208883 - PanKeyManager: getPrivateKey for alias: gp_user_new(1899...

GP with Certificate base authentication and LDAP, userid not visible in global protect logs

We have setup wherein user get certificate base authentication on pre logon(machine authentication), When user logged into machine, it must shift from machine name to userid. this transition is not happening. We also don;t require GP client login window popup. It must derive userid and password from windows login. Authentication table we have LD...

Issue on Android VPN

Hello DearsI am trying to install Global protect VPN on Android device, but it is unable to processed with that since the certificate is self sign so any other way to solve that problem without replace the current certificate meaning change setting on Andriod device. Best Regards

"Your login session has expired" errors when authenticating to GP portal

Dear community! We are currently experiencing an issue where after authenticating to the globalprotect portal page with the browser, we get the following message :"“Your login session has expired and you have been logged out for security reasons...” And we cannot get to the portal page. It only works with Mozilla firefox or Edge in IE compa...

Carracido_0-1784638080115.png
Carracido by L4 Transporter
  • 294 Views
  • 1 replies
  • 1 Likes

GP Uninstallation with password

Hi,Ajay this side from India. I'm hoping you can help me with the uninstallation of Global Protect.I am an Administrator of ManageEngine Endpoint Central in my company. Recently, the latest patch of the Global Protect VPN client was installed in our environment on more than 400 machines. We now need to uninstall this version and reinstall an old...

GlobalProtect Fails During Pre-Login with WinHttpReceiveResponse Error 12152

GlobalProtect is unable to connect during the pre-login phase. Verified all required certificates are installed on the endpoint. Confirmed certificates are located in the appropriate certificate stores. Collected and reviewed: GlobalProtect logs TSF Firewall packet captures We got the following error in PanGPS.log:2 3(P5136-T8916)Debug(54...

Resolved! [SOLVED] GPUDATE /FORCE DOESN'T WORK WITH GLOBAL PROTECT

Hello LiveCommunity Team! I created this post to share my experience regarding an issue involving GlobalProtect users from Prisma Access who attempt to run gpupdate /force to update GPO policies from the DC server, and who encounter the following error:CMD ERROR GPUPDATE /FORCEC:\WINDOWS\system32>gpupdate /force Updating policy...User polic...

DanielSRomero_1-1778369596055.png
DanielSRomero_2-1778369715172.png
DanielSRomero_4-1778370034165.png

Resolved! Global Protect count current users not match statistics

Hey thereThe counts are not matching between: >show global-protect-gateway summary detail GlobalProtect Gateway: connect-gtw:Current Users: 675Previous Users: 4520current-user : 675 Also with MIB OID .1.3.6.1.4.1.25461.2.1.2.5.1.3.0 panGPGWUtilizationActive Tunnels shows 675 But >show user ip-user-mapping all type GPTotal: 225 usersi...

kuschg by L0 Member
  • 480 Views
  • 1 replies
  • 0 Likes

Can you configure clientless VPN in SCM ?

I have the license installed and dynamic updates for clientless installed. We only have the Agent Licensing for GP and Prisma. We already have Global protect configured though SCM. But I cannot find anything about clientless vpn setup in SCM. I would have to overide my config directly on the firewall ?

E.Egger by L0 Member
  • 686 Views
  • 1 replies
  • 0 Likes
  • 1700 Posts
  • 68 Subscriptions
Top Solution Authors
Labels