GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
About GlobalProtect Discussions
Welcome to the GlobalProtect discussion area! Here, you can engage in conversations about GlobalProtect, explore new insights, and stay updated on ongoing discussions. Check back regularly for the latest updates and community insights on GlobalProtect.

Discussions

[SOLVED] - NGFW The Connection To Global Protect On The IPads Times Out!!

Hello team, I created this post to share my experience resolving recent issues related to GlobalProtect on iPad devices. We have some users with iPads who attempted to connect to GlobalProtect using SAML-based authentication; however, after the users logged in with their credentials, the GlobalProtect application displayed the following error "C...

DanielSRomero_1-1765512275788.png
DanielSRomero_2-1765512424721.png
DanielSRomero_0-1765513227125.png

SAML Authentication with Shibboleth error : idp has no assertion

Hello, We are setting up global protect with SAML SSO with a shibboleth IdP. But we post back to global protect after authentication we do have IdP has no assertion. SAML Tracer shows an encryted assertion but does not seems to handle it. Is there any way to have a more verbose / debug log of SAML Authentication ? Is there any cypher protocol r...

S.DR18 by L0 Member
  • 1224 Views
  • 1 replies
  • 0 Likes

Global Protect - ARM client

As stated with this link, a client version of GlobalProtect for ARM has been released GlobalProtect fails to connect on windows 11 ARM64 with error message: Could not connect to the GlobalProtect service. As I migrated to a new machine (ARM processor , a Mac Studio M2 Ultra) from an old one from 2015, I need this client to connect to 2 network...

ddregs by L0 Member
  • 30375 Views
  • 7 replies
  • 0 Likes

Resolved! Need a setting to change interfaceMetric 1 to a higher value

Hi Community.Every time when GP connects it sets its interfcaceMetric to 1. However, I have a nested VPN with even higher priority so every time I have to manually change the PANGP interface metric to a higher value e.g. 400. My wired connection already has metric 8500. Do you know if there's a setting for that?

[Let me know reason & workaround] Global Protect Agent ver6.3.3 “PanPUAC_xxx.dat” does not work (auto create or renew, failed to open).

- Let me know reason why “PanPUAC_xxx.dat” does not work (auto create or renew, failed to open), after Windows Update, BIOS Update. - Let me know workaround. -pan_gp_event.log Ex) -Failed to open file C:\xxx\Palo Alto Networks\GlobalProtect\PanPUAC_xxx.dat -Portal status is User authentication failed -Retry connect failed first time Best reg...

RADIUS flows for Authenticating GP with username, password and OTP

Hello, I have a working GP configuration that uses client certificate, username and password for authentication, with the username and password validated using PEAP-MSCHAPv2 against a RADIUS server. I want to add an OTP challenge as described at https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm8ICAS, for the on demand ...

Global Protect and Microsoft Teams e911

Microsoft Teams e911 calling does not display the location when connected to Global Protect. We have split tunneled the Microsoft Teams subnets (i.e. 52.112.0.0/14, 52.122.0.0/15, 52.238.119.141/32, 52.244.160.207/32) as per the Microsoft 365 URLs and IP address ranges (https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-addre...

Packaging Global Protect

Have questions regarding packaging Global Protect for distribution to both Windows and Mac. Using MSI for Windows and pkg for Mac. 1. How do we create a package to distribute Global Protect that sets the Portal and forces it to use a specified browser (Windows - Edge and for Mac - Safari) and not use the default browser that is set up on the O...

Prevent users to add new portal in Gloabal Protect App

Hello Community Members, I am looking to restrict the users from adding any additional portal in the Global Protect App. I know there is an option in Agent configuration that restricts users not to change the portal but that will limit users to only connecting to one portal. We have multiple portals in our infra and we want users to give th...

Resolved! NGFW Global Protect 6.2.7 Global Counters Negotiation Error TLS 1.3 MAC-OS

Hello Livecommunity!I'm facing an error with the Global Protect Agent 6.2.7 when an Apple Mac OS X 15.3.1 Sequoia tries to establish an SSL VPN connection with the Global Protect Portal; We see the next error on the DP CLI pcap global counters:NGFW(active)> show counter global filter packet-filter yes delta yesssl_tls13_connection_error ...

DanielSRomero_0-1741003799243.png
DanielSRomero_3-1741004715515.png
DanielSRomero_1-1741003799236.png

Resolved! GP client update fails to download, DNS record needed

We're updating from 5.2.12 to 6.2.1. The transparent update only works when testing with a DNS entry in a local hosts file. I don't think we've had a DNS entry in the past for the portal, but it seems like it's needed now. The below article talks about this, but I want to understand which address needs to be resolved. Is it the loopback interf...

Resolved! Panorama managed - Global protect SAML cert renew - IDP xml import wrong expiry

Background : Panorama version 10.2.13-h5 PA460's : 10.2.13-h5 2x PA460 active/passive HA. Managed by Panorama (9 other firewalls as well, but they don't provide GP portal / config. - SAML cert expires Jan 10th 2026. - Followed MS instruction on creating a new cert within MS admin/entra/azure/whatever they call it today. - Firewalls did not li...

GlobalProtect VPN Client windows 11 crash

Hi, I am using GlobalProtect GlobalProtect App version 6.2.8-263. It is the latest version i could download from network. When i am using connectioni got bluescreen crash whch i can reasume to: Bugcheck code: 0x1E This is MODE_EXCEPTION_NOT_HANDLED, which means that a kernel-mode component threw an exception that was not handled. Excep...

PiotrH by L0 Member
  • 1892 Views
  • 1 replies
  • 0 Likes
  • 2062 Posts
  • 68 Subscriptions
Top Solution Authors
Top Liked Authors
Labels