GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
About GlobalProtect Discussions
Welcome to the GlobalProtect discussion area! Here, you can engage in conversations about GlobalProtect, explore new insights, and stay updated on ongoing discussions. Check back regularly for the latest updates and community insights on GlobalProtect.

Discussions

GlobalProtect SAML Login Loop

Hi All, I am using CIE and EntraID with SAML to allow logins to GP. This is working very well but I am having an issue. I had a user whose name changed. When logging into GP, it just continuously asks her to log in. Inside of the GP Portal, I get the error 'username from cas sso response is different from the input' and can see where it is tryin...

HIP check Patch Management

Hello, I am trying to setup a HIP Profile for contractors accessing our network over Global Protect.This HIP Profile is checking if version of Windows is supported(allowing only 8.1 and 10), then checking if Anti-Malware and Firewall is enabled and as a last check I want to check if Windows patches are up to date.Checks for OS, Anti-Malware and ...

hip check.PNG
hip object.PNG
Henley by L1 Bithead
  • 5080 Views
  • 3 replies
  • 0 Likes

HIP Global Protect

I want to create a security policy containing a HIP profile as follows: if the connecting machine has ALL category 3 updates installed, certain traffic will be released. I'm very confused about creating this in HIP object, as it is about MISSING PATCHES.

Clientless/GP portal does not load in browser on 10.2.9-h1

We are facing an issue where the Clientless/GP Portal does not show the login page on the browser. When traffic reaches the external firewall, we see the connection being allowed. We are using the Go Daddy cert and have ensured the cert chain is complete on the firewall. The strange part is it works if we use GP Client we can connect to GP Porta...

Resolved! MacOS Sequoia & Global Protect

Hey Palo Alto, EXPLAIN WHY... "Your device doesn't meet security requirements." Then possibly there's something I can do. OR LET ME TURN OFF seeing this EVERY TIME I LOGON TO VPN. PALO ALTO controls this security check, OR my company does... EITHER WAY... the software works... ...just LET ME TURN OFF THE POPUP!

GP_SecReqPopup.jpg
GP_About.jpg
vte888 by L1 Bithead
  • 4805 Views
  • 3 replies
  • 0 Likes

Could not verify the server certificate of the gateway. If the issue persists, contact your administrator

Hello, I've a case where some users can not connect to our GP gateway. Connection through the portal seems fine but then the client won't connect to the gateway. We manually reimported the self signed root certificate into the cert store of the client. Also, this issue only happens to users using a specific ISP. All other users using another...

Costa Rica Global Protect users are automatically falling back to the Hong Kong gateway

Hello Team, We can see the user through STRATA logging services logs that user in Costa Rica regions are automatically connected to the Hong Kong gateway. Also, we got escalation from client that they have seen Hong Kong users are accessing the URL. The users are facing high latency issue if they automatically connect to Hong Kong gateway. We...

N.Madiye by L0 Member
  • 855 Views
  • 1 replies
  • 0 Likes

Pre-Logon Machine Certificate

Hello All, My issue is regarding the Machine Certificate selection in the Global Protect Agent. Background information: We are using our own internal PKI (Active Directory). Our CA root has been imported and other systems are known to be working fine (i.e. Forward Trust Cert, SSL decryption... based on this Active Directory CA root) Our curre...

Rievax_0-1729106990357.png
Rievax by L2 Linker
  • 5399 Views
  • 4 replies
  • 0 Likes

Gateway Unresponsive or unreachable.

Unable to connect to one of our global protect gateways. Debug log of PanGPS attached with its attempt to connect to the gateway. I have checked all the gateway settings, and they match the working gateway, so I am at a loss on what to look for. The working Gateway is on a HA pair of 5220 in active/passive mode, and the non working gateway is on...

M.Caudle by L0 Member
  • 1906 Views
  • 1 replies
  • 0 Likes

split tunnel

Hi Team, We are using global protectect and using split tunnel where all LAN traffic gose through global protect and internet traffic through their own ISP Is it possible to route specific traffic, such as access to https://ab.xyz.com/something/#, through our firewall rather than directly over the internet via split tunnelling?

Resolved! Global Protect User ID not showing if connected to internal GW

Hello all, we have an issue that the User ID is not shown on the Palo if the GP Client is connected to the internal network. The detection is working but in the logs I can't see any user informations of internal connected clients. For our Global Protect Clients we are using pre-auth. Settings for pre-auth and for the User Configs, both the sam...

smindorf_0-1727430224035.png
smindorf_1-1727430278567.png
smindorf_2-1727430625673.png
smindorf by L1 Bithead
  • 3247 Views
  • 2 replies
  • 0 Likes
  • 1692 Posts
  • 68 Subscriptions
Top Solution Authors
Top Liked Authors
Labels