GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
About GlobalProtect Discussions
Welcome to the GlobalProtect discussion area! Here, you can engage in conversations about GlobalProtect, explore new insights, and stay updated on ongoing discussions. Check back regularly for the latest updates and community insights on GlobalProtect.

Discussions

Client cert usage check failed

I am testing client auth using certificates and the certificate is not being retrieved from the User store. It's Windows 11. The PanGPA.log file shows this error: (P23516-T9764)Debug(2744): 06/08/24 11:07:10:562 box return Valid client certificate is required, remove cache and close all handle now(P23516-T9764)Debug(5570): 06/08/24 11:07:10:56...

BBartik by L2 Linker
  • 1674 Views
  • 1 replies
  • 0 Likes

Global Protect on MacOS (TYPE65 dns queries)

While troubleshooting a failing GlobalProtect update on my own machine, I checked the DNS requests made by the Global Protect updater. And noticed that it's not making type A requests, but instead uses TYPE65 (aka HTTPS ordraft spec RFC 9460) requests. My internal DNS server don't have the option of hosting this type of record. The update fails ...

dmgeurts by L2 Linker
  • 1709 Views
  • 0 replies
  • 0 Likes

Resolved! GlobalProtect VPN Issues

Hi. Can someone please help me? Thank you in advance. We are currently experiencing issues with a GlobalProtect VPN setup, it is working for users located in Australia but not in the Philippines, we have set it to allow connections from the Philippines and we're able to get to the GlobalProtect web portal to download the VPN but the VPN itself...

Global Protect Authentication Loop with Azure unable to connect but authenticate completes.

Hello Everyone, Has anyone else been facing issues connecting via GP VPN lately? When we try to connect via the agent. It prompts to authenticate via edge. Once that is complete and 2fa is verified on the webpage it states authentication complete and it opens another edge tab to authenticate again and it happens constantly. Steps Taken: ...

Udit_Das by L0 Member
  • 2706 Views
  • 1 replies
  • 0 Likes

After Endpoint Traffic Policy Enforcement, client can not be access microsoft login portal for smal auth.

Hello Everyone, I build a gp authenticaiton for azure ad saml auth in prisma access, and it works normally. After enable "Endpoint Traffic Policy Enforcement", and missing add lists of enforcer exception list, and then finished push jobs, client can not access microsoft login portal for smal auth, and can not access anywhere. Anyone knows...

GlobalProtect doesn't upgrade transparently.

In Prisma Access Mobile User, the user GP version was distributed as 6.2.0. However, due to an issue, I needed to upgrade to 6.2.3, so I set upgrade globalprotect to allow transparently in the app settings. However, there was no change for 6.2.0 users, so I installed 6.1.4 as a test and waited, and it was automatically upgraded to 6.2.3 within 5...

Resolved! certificate ca

Hi to all, I want to import a certificate which is signed and use it as trusted root ca. I saw that there was command on older versions that you could set the certificate as ca=yes. but in my version 10-1-6h7 that command at the cli does not exist. Can anyone help me?

kvagenas by L1 Bithead
  • 2763 Views
  • 1 replies
  • 0 Likes

Vulnerability Protection for CVE-2024-3400

TL;DR: ensure you are applying Vulnerability Protection to web-browsing traffic hitting your GP portal interface, if you rely on the intrazone-default allow I was responding to another case of this flu. Even though the best-practice strict VP profile was attached to the rule allowing access to the GlobalProtect interface, a test for the vuln (...

mb_equate by L3 Networker
  • 2853 Views
  • 2 replies
  • 0 Likes

Resolved! Global Protect VPN client-less web portal local account

Hi, We have a user who is traveling to a restricted location and will need to connect to our client-less Global Protect Web Portal using a local account. Is there a way to have this one user change their password after successful initial login to our client-less Global Protect Web Portal? There is the option "Require Password Change on First Log...

GP Agent Machine Certificate Check

Hello, I am trying to find out more information about a GP portal setting called Machine Certificate Check under Portal Configuration / Agent / Agent Config / Config Selection Criteria / Device Checks. I was hoping to use a machine certificate check outside of the authentication tab to allow or disallow machines based on user/user group, but I...

Unauthorized GP login attempts

Hi All – Just curious on when to get concerned about unauthorized GP login attempts. I’ve had a person from the RU making login attempts on our GP for about a year now. I speculate they are new at this, after a while they learned how to mask the ‘HOST NAME’ and use VPN, tho they do use the same IP and region, like I said, probably new at this. S...

chipabf by L0 Member
  • 17060 Views
  • 6 replies
  • 0 Likes

Duo two factor authentication challenge message not showing in GP Portal

After migrating to PA-1410 from a PA-3200, the Duo 2-FA challenge message stopped showing up on the GP portal page after the initial AD credentials authentication. The functionality is working fine as the textbox for the 2-FA options shows up and proceeds as usual after the user's input, its just that the Duo login banner text that should show u...

  • 1692 Posts
  • 68 Subscriptions
Top Solution Authors
Labels