Palo Alto Vulnerability CVE-2024-8687
Hi Team, For CVE-2024-8687 we are using PAN OS 10.2.9-H1, but our Global protect version are Vulnerability affected version in this case we need to upgrade the Global protect to unaffected the version.
Hi Team, For CVE-2024-8687 we are using PAN OS 10.2.9-H1, but our Global protect version are Vulnerability affected version in this case we need to upgrade the Global protect to unaffected the version.
I would like to limit the number of VPN sessions as 1 a user can connect to. For example, if I have already connected VPN from laptop A and attempt to connect VPN from laptop B, I want to block connection or terminate existing connection. Is it possible to do this? Regards, Sanjay S
I'm trying to setup a GlobalProtect On-Demand environment.The portal uses an LDAP server profile for authentication and has been validated to be working fine.I intend to configure the gateway to use a combination of RADIUS and certificate profile to authenticate. I've confirmed that authentication works without the certificate profile.My underst...
We have some Windows machines on GP that connect via a pre-logon tunnel which then fully connects when the user logs in. We would like to target machines for a specific package installation push only when the VPN is fully connected (i.e. not connected via pre-logon, but an actual authenticated user). My question is, are there any checks that c...
Hello folks, i have a massive issue with GLobalProtect since the MacOS Sonoma Upgrade. It does not connect to the VPN Service. It tries to connect for a minute or so, but than it just says it can not. I don't even get to the part to insert a user or password. I checked to official website, and the client my company is using is 6.0.7-372, ...
Hi, Our security team is seeing Windows defender able to probe guest wifi at hotels and see other devices like phones and laptops on the network, until Global Protect can finally connects to one of our gateways. They want the network restricted to just the captive portal for the hotel until connected to a gateway. Anyone know what can be restr...
Every time I try to connect to VPN Global Protect on my HP Envy laptop. It won't allow me to enter my credentials. It's just blank. Please look at the attachment.
So I was looking at prisma access content and came across this: If traffic is initiated from a service connection and bound for a mobile user or a remote network, Prisma Access cannot restrict the traffic. The traffic hits no security-enforcement point, because the RN-SPN and MU-SPNs enforce Security policy only on sessions ingressing into Prism...
Global Protect is showing "unable to connect gateway" intermittently. It is also observed that the PANOS network adapter not releasing the IP after we disconnect the VPN which could be the issue. Is there any one know the fix...We are using version 6.1.1-5
Does the Global Protect RADIUS implementation support Messaging Authentication? If not, how quickly will a hotfix to patch this vulnerable implementation of RADIUS be released? Background info: When configuring Global Protect we used RADIUS to integrate RSA Secure ID as a second factor to LDAP, to ensure it took more than just a password to ...
A bit of background: We are an all-Google G Suite company. We do not have internal LDAP servers. Everyone auths to Google. We are using PA 3060s as our firewalls and VPN systems. We are getting ready to turn on SAML authentication for GlobalProtect. We are using Google as our IdP. I've gotten it working, but I want to make policy decisions based...
We have been trying to migrate a client from Airwatch to Intune for MDM management. Part of this deployment was implementing certificate-based authentication for their Global Protect VPN client. We have been successful with Windows, and Android. However, we have not been able to get MacOS, iPadOs, or IOS to work successfully. all the Error logs...
I am planning to upgrade Global Protect. If I upgrade the software on the firewall, will the old clients be able to connect to the gateway? Current PAN-OS version is 10.2.9-h1 and Global Protect is 5.2.12. I would like to upgrade to 6.1.5. Thanks.
Setup: We have one GP portal and one gateway currently, used by employees and vendors. All GP users are authenticated with Entra and Duo MFA. We are using a public cert. for the FQDN and a single IP in the current setup. Vendors are assigned to a different subnet than employees when connecting to GP. Change: We want to use the Entra authentica...
We are running 10.2.2 w/ GP 6.0.3 and I am unable to figure out how to have my serial number (discovered via HIP) be required to match what is in AD. Could someone please show me which way to go? Support and my sales engineer have been unable to assist. Thank you, Andy
| User | Likes Count |
|---|---|
| 3 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |

