GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
About GlobalProtect Discussions
Welcome to the GlobalProtect discussion area! Here, you can engage in conversations about GlobalProtect, explore new insights, and stay updated on ongoing discussions. Check back regularly for the latest updates and community insights on GlobalProtect.

Discussions

Resolved! Machine Certificate Check/ Not working for me

Goal: When a user connects to the Globalprotect Portal it will authenticate using the LDAP authentication profile, and check for the presence of a certificate on the device. If the device(in my case I'm only going to use Windows 10 PCs) does not have the certificate, the authentication will fail. What I've done so far: The LDAP authenticati...

asiewert_0-1716391538482.png
asiewert_1-1716391699348.png
asiewert by L1 Bithead
  • 6334 Views
  • 3 replies
  • 0 Likes

IOS and Globalprotect using Multifactor authenticator

We are facing a problem on IOS devices related to globalprotect using Multifactor Authenticator with Azure. We tried forming a certificate chain a root certificate and an intermediate certificate. We added to the root certificate an extra attribute which is "IP= "IP Address" from Subject Alternative Name (SAN) field". As for the intermediate cer...

HMahfouz by L0 Member
  • 1775 Views
  • 0 replies
  • 1 Likes

SAML authentication - How to avoud the "Open GlobalProtect ..." popup ?

Hi all, I recently integrated Azure MFA via SAML with GlobalProtect and it works flawless. The only little issue is a popup that always appears whenever the authentication process is about to be completed. I guess this is the browser communicating with the global protect app , necessary to complete the tunnel creation. Any idea about how to s...

techreg by L0 Member
  • 6162 Views
  • 3 replies
  • 1 Likes

GlobalProtect software versioning numbers do not make sense to me

Hello - new to the GlobalProtect VPN client. We are in the processing of beginning to roll out the GP VPN client via GPO to our user base. I occasionally receive emails from Palo stating that a new version of GP VPN client is available, but when I look at the software update page, the versions of GP VPN client for Windows 64-bit shown do not...

Global protect upgrade to 6.2.0-89 having disconnection issue

I want ask if anyone face issue with below error after upgrading global protect to 6.2.0-89? "The network connection is unreachable, or the gateway is unresponsive. Check the network connection and reconnect" Before upgrade it works fine and no any changes. I can see logs in PanGPS as below: (P6048-T4788)Debug( 149): 08/18/23 07:54:44:675 CP...

GP fail to connect on MAC - web browser can open a page, ping not working

It was working before but than administrator changes certificate. Now I am trying to activate GP on MAC 14 Sonoma with latest GP 6.02. I can open portal IP on web browser with my credentials and download latest GP software. Authentication with user/pass is ok, than I use token and GP returns a message "Connection Failed". Certificate is valid ...

SCR-20240514-mgwm.png
Primoz by L0 Member
  • 1665 Views
  • 2 replies
  • 0 Likes

Resolved! Is there an XML API query to find the Host-ID from Panorama logs

Is there a way to use XML API to query the Host-ID from Panorama logs? I have the XML API requests to remove a user from the VPN and to add a user's device to a quarantine list working. To add a user's device to the quarantine list requires the Host-ID. I'm trying to find a way to get the Host-ID for a specific user using API and not the GUI.

John_J by L1 Bithead
  • 2262 Views
  • 1 replies
  • 0 Likes

Global Protect agent background is invisible on some external displays

We've recently gotten reports of two different Macbook Pros running Sonoma with external displays where the GP agent background is invisible / transparent. The app seems to be working fine, but on certain external displays, it's difficult to use because it's transparent. Also the menubar globe icon itself is invisible on one system. Screensho...

image (5).png
rlarose by L2 Linker
  • 1585 Views
  • 1 replies
  • 0 Likes

Global Protect is saying it's disconnect but traffic still flows fine.

Having a strange issue since upgrading our PA450 to 10.2.8h3 whereby Global Protect users have an Always on connections the VPN connects as usual then the GP app tells us that the VPN is disconnected but actually the VPN is still connected and users can all work as usual. We were previously using version 10.2.4h4 and never saw this issue. Users ...

tatrasystemsltd_0-1715187668912.png

Resolved! Global Protect Transparent Update not working.

Good day, I was trying to update the Global Protect client via the activation from the PA Firewall [Device -> GlobalProtect Client] our users are currently the version 6.1.0-58 but, we wanted to move on into the version 6.2.2, but, it always fails the Download, in the option "Allow User to Upgrade GlobalProtect App" I set it to "Allow Transpa...

GPAgente update failed.png
R.Tudon by L1 Bithead
  • 3943 Views
  • 1 replies
  • 0 Likes

Resolved! GlobalProtect version 3 certificate

Dear Team, Among models using Android 13, kernel 5.4 or 5.15, a certificate error appears to occur when connecting to the GP. I confirmed with TAC that I need to use version 3 certificate. However, many customers are using Paloalto's own CA certificate. Is there a way to create a v3 certificate in Paloalto?

Resolved! GP portal/gateway config

hello I am trying to add a GP portal/gateway to support Radius authentication the customer has provided a public IP that I am trying to use the IP will not add --there are a list of IP in drop down that I could select what needs to happen for this new public IP x.x.x.199 to be available to select ? I created a tunnel.199 and configured the IP...

S.Byrne by L3 Networker
  • 3399 Views
  • 4 replies
  • 0 Likes

MACOS Sonoma, GlobalProtect not able to connect to the port 4767

Hi Guys, Three weeks ago I upgraded my intel MAC to the Sonoma Version, and unfortunately my GlobalProtect does not work anymore. The PANGS service is not able to set up the port 4767 anymore and the logs shows: P2503-T34311 12/15/2023 10:29:11:158 Debug( 57): fd still open before connectP2503-T34311 12/15/2023 10:29:11:158 Error( 80): CPan...

  • 2069 Posts
  • 68 Subscriptions
Top Solution Authors
Labels