GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
About GlobalProtect Discussions
Welcome to the GlobalProtect discussion area! Here, you can engage in conversations about GlobalProtect, explore new insights, and stay updated on ongoing discussions. Check back regularly for the latest updates and community insights on GlobalProtect.

Discussions

HELP - I have a hacker trying to use SPECIFIC users to get into my VPN service

The pattern is they try nonsense users such as "cisco" and I block their IP they come from, but they always come back. I am getting frequent attempts with various other users, but they seem to come back within an hour of me blocking their IPs.I need a rule that immediately blocks the user, potentially one that could add to a dynamic IP list disc...

Palo RAVPN connection profiles?

Hi, I'm taking my first steps in palo and trying to understand RA VPN configuration. I used to work with cisco devices where i have possibility to create different connection profiles for users and when they connect to vpn they can choose group where they want to connect. Example bellow: I thought i will be able to configure something like that...

obraz_2023-10-06_120323612.png

Resolved! How to Deactivate GP Package on the Firewall

Hello. It is known that GP Portal landing page in the browser can be easily bypassed by replacing login.esp with getsoftwarepage.esp PAN knows this, they do not see it as a security risk, which is nuts if you ask me. Don't mind the ability for someone to run a download loop and eat the bandwith downloading 200MB file infinitelly from multiple ...

Specific browser instead of default browser

Our company maintain SAML Authentication using a specific browser (edge), but it is not my default browser (brave).Each time before starting connection I have to switch default browser to Edge and after successful connection have to restore my default browser settings. Is there any way to specify the browser used for SAML Authentication?

Domino by L0 Member
  • 1876 Views
  • 1 replies
  • 0 Likes

Page to login global protect after connect not appear, and appear error AADSTS50105

By error when I tried to login to global protect, I put an email incorrect, and after when try again to login global protect not show login page, only show page error AADSTS50105. I tried everything like reinstall, delete folder palo alto, delete folder regedit, but get the same error. I want to see the login page to put the correct email. I u...

luisgue by L0 Member
  • 3088 Views
  • 2 replies
  • 0 Likes

SSL Certificate update while GP migration

Hello, I have scheduled all activities for my FW migration from ASA to PA, however I have a question about GP migration. The PA FW has its GP deployed with Public IP x.x.x.6 and gp.domain.com, whereas the ASA has Anyconnect on Public IP x.x.x.5 with asa.domain.com. Both are currently connected to the same ISP; I have disabled Anyconnect, and ...

Resolved! Setting Failed Attempts and Lockout Time

Hello, I would like to set failed attempts and lockout time on my Global Protect auth profile but I do not see where I can set this. The only place I see these settings is in the global profile but I would like to set this only for Global Protect. I am using v 10.2.4-h2 Thanks for any thoughts. MJF

GlobalProtect blocks my internet access

Hi all, I've recently started to use a GlobalProtect vpn, but every time I successfully connect to it, it blocks my internet access. I reached out to our IT departement and a firewall engineer told me he can see that I am connected and that traffic is being allowed from my location, but return traffic from them is timing out after a couple of pa...

Blank Login Page

Issue occurs both on Windows 10 & 11. Mostly see it on 10 though and when the user is off site. Rarely do we see the issue on site. User tries to connect to GlobalProtect, window pops up and it's blank - can't type in credentials. GP version: 6.0.3 We've tried uninstalling, deleting the files/folder in Program Files (and x86) and in rege...

GP.jpg

Is it possible to host a Global Protect Portal and Gateway on the same outside interface as IPSEC VPNS

I'm trying to set up a global protect gateway on an interface that already has a couple IPSEC VPN tunnels on it. But I am unable to browse to the page to download the client. After some checking I realized that I'm not even able to ping this interface from inside the network or from the public IP of the other PA. If I ping out, then I am getting...

Global Protect authentication happened twice while LDAP and Okta Auth

Recently we moved to PA-3410 software version 11.0.1-h2 from PA-850 software version 10.2.3-h4 . on both firewalls GlobalProtect Agent 6.1.1 We have selected option for authentication override On PortalsGenerate cookie for authentication override on Gateway Accept cookie for authentication override https://supportcases.paloaltonetw...

tthapa23 by L1 Bithead
  • 8362 Views
  • 8 replies
  • 0 Likes

Global Protect

Hi Friends, We have a customer who is using global protect. Two HIP profiles are configured for two different groups. One for AD users and one for Local users. The requirement is if local user tries to login he should get the hip profile banner set up for local user If the ad user login he should get the hip profile banner that is setup for A...

GlobalProtect Web Portal - Domain Validation Code (DVC) - /.well-known/pki-validation

Does anyone know how to go about performing domain validation for an IP address for the GlobalProtect Portal? This is a standard supported by most Certificate providers but I can't find anything about it when searching Palo Alto's site. With this tunnelcrack vulnerability and the need to use an IP address in the SAN of a publicly signed cert,...

  • 1684 Posts
  • 68 Subscriptions
Top Solution Authors
Top Liked Authors
Labels