GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
About GlobalProtect Discussions
Welcome to the GlobalProtect discussion area! Here, you can engage in conversations about GlobalProtect, explore new insights, and stay updated on ongoing discussions. Check back regularly for the latest updates and community insights on GlobalProtect.

Discussions

Using Hash to Bring over User VPN Passwords

Hello Everyone, I am setting up a new PA460 and have a decent amount of users I set up. I have all the users set up and gave them new passwords. I was wondering, (on my current device) if I take the Password Hash from the user section in the Firewall's config using Notepad++, couldn't I simply copy the hash and paste that in as a hash for the ...

GlobalProtect Issues with Hotspot Users

Two different users reported problems when connecting to GlobalProtect when using an iPhone as a hotspot. The users can connect to GP, but are then unable to use HTTPS or ssh to connect to internal assets via the VPN. If the user uses the same laptop and connects via wifi (not using hotspot), GP works fine. Tests with several other users usin...

peppywoll_0-1610157455136.png

[RFC5746] issue with ssl decryption: openssl3.0 unsafe legacy renegotiation disabled

Since I upgraded to the lastest fedora, all of my python/ansible script failed when they are decrypted by our palo alto ssl outbound policy. After some diging, fedora 35 was using openssl 1.1.1 and fedora 36 switched to openssl 3.0: https://fedoraproject.org/wiki/Changes/OpenSSL3.0 On the openssl 3.0 changelog, we can find this: OPENSSL chan...

Internal host detection issue

Hello, Current setup is a 440 running 10.1.10-h2. Global Protect version is 6.1.2 I have double and triple checked that it's not a reverse dns issue, following this article: GlobalProtect app fails to detect Internal Network with Interna... - Knowledge Base - Palo Alto Networks global protect tries to connect internally to the vpn it fails wi...

MNoble by • L2 Linker
  • 4066 Views
  • 4 replies
  • 0 Likes

Updating new Poral name (GW) to all existing Global Protect users

Hi,I already have almost 1500 users using Global Protect VPN Client. Currently our users are using gateway portal name (Eg :123.vpn.com.)We have implemented a new cloud VPN gateway (eg abcd.cloudvpn.com) and now we want all users to use the new cloud VPN gateway.Is there a way to push the new gateway name to all users VPN client settings so the ...

muja1913 by • L0 Member
  • 1155 Views
  • 1 replies
  • 0 Likes

Resolved! Global Protect MFA Looping

Hello, I am facing a weird issue with Global Protect where after a user authenticates via Okta Radius to the Portal and enters their MFA SMS Key the GP Agent asks for the user to enter the MFA SMS Key again with the response of ('A message was sent or a call was made to the phone in the past 30 seconds. Please try again when 30 secs have passed....

GP example script running as admin

Hi, according to the doc, to run a pre (or post) vpn script can be run as admin using the following: context admin | user I haven't been able to get this working, so I'm guessing I have the variables all wrong. Can someone give me an example of how this would be used in a script? For example my current registry entry works as local user like bel...

Dekkar by • L1 Bithead
  • 2676 Views
  • 1 replies
  • 0 Likes

Internet not working after conncted to GlobalProtect. But it is happening only for a particular network provider.

The Internet does not work once the user connects to two particular network providers. The Global Protect is in the pre-logon method and enforced connection. When disconnected from GP with an admin password, the Internet is working.With a working network provider, the internet is working, GP is connected, and the user is able to ping Google and ...

misleading IOS Notification - "Globalprotect Always-On mode is enabled. Please sign in to continue"

We are currently testing Globalprotect for IOS and we are seeing this notification in the phones - "Globalprotect Always-On mode is enabled. Please sign in to continue" Everything is working as expected in our test setup which is on-demand, using Azure SAML for authentication with client certificate - the one thing we don't understand or not m...

RREALICA by • L2 Linker
  • 2193 Views
  • 2 replies
  • 0 Likes

Global Protect with PPPoE static IP

I have a static ip on my ISP PPPoE connection, i want to configure a GP with this ISP. I am a bit confused that i don't have the gateway configured on my interface routes how to do it. My PPPoE configuration is user name & Password but my ISP is providing static IP at the backend.

HELP - I have a hacker trying to use SPECIFIC users to get into my VPN service

The pattern is they try nonsense users such as "cisco" and I block their IP they come from, but they always come back. I am getting frequent attempts with various other users, but they seem to come back within an hour of me blocking their IPs.I need a rule that immediately blocks the user, potentially one that could add to a dynamic IP list disc...

Palo RAVPN connection profiles?

Hi, I'm taking my first steps in palo and trying to understand RA VPN configuration. I used to work with cisco devices where i have possibility to create different connection profiles for users and when they connect to vpn they can choose group where they want to connect. Example bellow: I thought i will be able to configure something like that...

obraz_2023-10-06_120323612.png
  • 1711 Posts
  • 68 Subscriptions
Top Solution Authors
Labels