GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
About GlobalProtect Discussions
Welcome to the GlobalProtect discussion area! Here, you can engage in conversations about GlobalProtect, explore new insights, and stay updated on ongoing discussions. Check back regularly for the latest updates and community insights on GlobalProtect.

Discussions

How to Configure a frame-ancestors response header with a list specifying (Global Protect portal)

HelloI am reviewing that GlobalProtect (vpn.xxxxxx.com and remote.xxxxxx.com) are vulnerable as they do not have a frame-ancestors response header configured. I want to configure a frame-ancestors response header with a list specifying which URLs can embed site elements; or use the 'none' keyword to deny any site from embedding site content; or ...

Alpalo by L4 Transporter
  • 2302 Views
  • 1 replies
  • 1 Likes

Global Protect update - no auto-reconnect with transparent update

Hello,To make the next update to GP as easy as possible for users, we would like to see an automatic reconnect. At the moment, the actual upgrade works fine to 5.1.9, but requires manual intervention at the end by clicking on the "connect" button after the update is complete and the VPN disconnected. Could this be related to cookies? Currentl...

landoa by L1 Bithead
  • 2606 Views
  • 1 replies
  • 2 Likes

Hide Global Protect redirection

Hello team We have already hidden the global protect pages so that our users can only access through the client, however, we have detected that when we type the ULR or IP in a browser there is an automatic redirect that adds /global-protect/login.esp and we do not want this to be so, because we do not want that from the outside can be seen that ...

Alpalo by L4 Transporter
  • 1305 Views
  • 1 replies
  • 0 Likes

Resolved! GlobalProtect does not create gpd0 interface on installation

When I try using GlobalProtect on a ubuntu based machine (I tried with two different computers, and two different distributions of ubuntu) as soon, as it displays de message Connected, the Wireles network interface disconnects and connects constantly to whatever network it was connected Reviewing the Ifconfig.txt file resultant from collecting l...

Global Protect and ISE integration

Hello,I want to make an integration of Palo Alto and Cisco ISE in these terms:1. Global Protect users can be authenticated using Cisco ISE2. There are some dynamic ACLs that define access rights for certain group of users, so the customer would like to continue using these ACLs for Global Protect usersSo my question is, ca this integration be ma...

Global Protect and Azure SAML

Hi All PA-VM running 11.0.02 Global Protect 6.2.0 After some advise/suggestions We are rolling out Global Protect for the first time and getting some strange results Portal and Gateway Configured to use Azure SAML in addition to this I have followed this article to try and make the whole process simple for users Seamless SAML Authenticatio...

PBassett by L0 Member
  • 2822 Views
  • 1 replies
  • 0 Likes

TunnelVision Vulnerability on Prisma Access via GlobalProtect Agent?

https://security.paloaltonetworks.com/CVE-2024-3661 The advisory states Prisma Access is unaffected by the TunnelVision vulnerability. However, to use Prisma Access, it must be done through the GlobalProtect agent itself. I looked at my GlobalProtect agent configuration and we do have the affected settings but we do not use GlobalProtect its...

hgosal by L0 Member
  • 836 Views
  • 0 replies
  • 0 Likes

Deploying GlobalProtect to iOS devices via (Airwatch, Meraki, MDM)

Hi, We're looking at deploying GlobalProtect to 1000+ iOS devices and wondered if there was anyone out there that could share their experiences and provide some insights. Using our MDM tool (Meraki and Airwatch), I'd like to push out the GlobalProtect iOS app, configure VPN address, and apply any approval/config to iOS to allow this app/VPN ...

Clientless VPN only shows the top application in the stack

We're trying to setup Clientless VPN for the first time and we've run into an issue where the portal site only shows the top application in the config stack. GlobalProtect > Portals > Clientless VPN > Applications. They all seem to work when you manually enter the app URL in the menu. We're running PanOS 10.2.8.-h3 and GlobalProte...

Client cert usage check failed

I am testing client auth using certificates and the certificate is not being retrieved from the User store. It's Windows 11. The PanGPA.log file shows this error: (P23516-T9764)Debug(2744): 06/08/24 11:07:10:562 box return Valid client certificate is required, remove cache and close all handle now(P23516-T9764)Debug(5570): 06/08/24 11:07:10:56...

BBartik by L2 Linker
  • 1564 Views
  • 1 replies
  • 0 Likes

Global Protect on MacOS (TYPE65 dns queries)

While troubleshooting a failing GlobalProtect update on my own machine, I checked the DNS requests made by the Global Protect updater. And noticed that it's not making type A requests, but instead uses TYPE65 (aka HTTPS ordraft spec RFC 9460) requests. My internal DNS server don't have the option of hosting this type of record. The update fails ...

dmgeurts by L2 Linker
  • 1598 Views
  • 0 replies
  • 0 Likes
  • 2069 Posts
  • 68 Subscriptions
Top Solution Authors
Labels