GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
About GlobalProtect Discussions
Welcome to the GlobalProtect discussion area! Here, you can engage in conversations about GlobalProtect, explore new insights, and stay updated on ongoing discussions. Check back regularly for the latest updates and community insights on GlobalProtect.

Discussions

Domain Split tunnel 'under the hood'

hey, can someone please explain how this feature work from the stage of open the browser and surf to www.google.com until the GP client decide it should enter the tunnel? for example 1. GP listen on the nic for dns queries 2. GP check with the split tunnel rules if there is a match 3. GP route the traffic to the tunnel on the OS network sta...

Global Protect on macOS Sonoma 14.2 (betas and now release)

I generally try to run macOS beta version to jump ahead of any issues. I've been running macOS Sonoma 14.2 beta (2 and 4, specifically). In my testing, the Global Protect VPN client successfully connects (we're using certificates on in this case) but then fails to pass any traffic. The interface has an IP address, which can be pinging, but no...

SAML Authentication - Users not prompted for password or MFA

Hi all, We've setup SAML / SSO and all works OK , however, when GlobalProtect starts, it automatically connects without asking for any creds. I'm assuming this is a result of the machine being joined to the same domain so the password is not needed. However, I'd like to configure it so that at least an MFA prompt occurs. Connecting on a non j...

GlobalProtect Logon Banner with Accept button

I'm trying to figure out if therre's a way to configure GlobalProtect to prompt the end users to accept a logon banner message when they've entered their credentials successfully in the GlobalProtect app. Cisco Anyconnect can accomplish this in the group-policy and it's nice because after a user enters their credentials, they get prompted with a...

Resolved! Strange errors with Globalprotect and PANOS 10.2.3-h2

Hello everyone, We have two strange errors with Globalprotect (v. 5.2.11) since the update to PANOS 10.2.3-h2:- For internal connections (via tunnel) the connection fails with the event gateway-hip-check with the message "Invalid tunnel end point IP address". - The external portal is suddenly no longer accessible via https but pingable via the...

Spaniel by L1 Bithead
  • 6500 Views
  • 5 replies
  • 0 Likes

PPPoE and GlobalProtect Issues

Hi everyone, Hoping someone could tell me where I'm going wrong with this. We have recently acquired a secondary ISP line which is connected to our PA's eth1/1 via PPPoE, which includes /28 available IPs. I am looking at moving one of our client's GlobalProtect portal and gateway from our primary ISP line (Which is via static IP) to the seco...

Setting up GlobalProtect Gateway in Azure VM-Series

Hi Friends, Has anybody deployed GlobalProtect Gateway in Azure VM-Series? Or is there any documentation you could share with me? I have deployed a lot of GlobalProtect in on-premise platforms, but Azure is driving me nuts! My main concern is, port 443 is already occupied on my Untrust interface for the External Load Balancer health checks (I ...

Resolved! Can't connect user group is fine but Agent Policy does not match

Hello, I'm running out of ideas to tshoot a GP connection problem. I have a user that is in an AD group uservpn (checked on the cli and it's fine). Added this group to Portal and GW configuration and I can't connect. If I live any for the config under user/user group for portal and Gateway it works. I see the user has this group on the CLI but s...

Global Protect portal entry

I'm using GP 6.1.2 and GP 5.2.11 respectively in my environment. We are in the midst of upgrading the 5.2.11 to 6.1.2. There is also a need to add/update the portal entry with a new entry.Where is the file that store the portal entry? We are using SCCM to push the GP agent to UAT laptop and would like to push portal entry as well.

KhairulNizam_0-1701658046016.png

Resolved! 2FA and certificate

Hello friends. For my workers, I am using 2FA (AD+DUO) as the authentication process. I would like to add additional to the 2FA authentication, by enforcing checking the existence of a client certificate. My goal is to eliminate using GP from laptops that don't have my PFX installed. (i will install them manually). I want the cert to be an addit...

chens by L3 Networker
  • 1809 Views
  • 1 replies
  • 0 Likes
  • 2065 Posts
  • 68 Subscriptions
Top Solution Authors
Top Liked Authors
Labels