GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
About GlobalProtect Discussions
Welcome to the GlobalProtect discussion area! Here, you can engage in conversations about GlobalProtect, explore new insights, and stay updated on ongoing discussions. Check back regularly for the latest updates and community insights on GlobalProtect.

Discussions

Is it possible to host a Global Protect Portal and Gateway on the same outside interface as IPSEC VPNS

I'm trying to set up a global protect gateway on an interface that already has a couple IPSEC VPN tunnels on it. But I am unable to browse to the page to download the client. After some checking I realized that I'm not even able to ping this interface from inside the network or from the public IP of the other PA. If I ping out, then I am getting...

Global Protect authentication happened twice while LDAP and Okta Auth

Recently we moved to PA-3410 software version 11.0.1-h2 from PA-850 software version 10.2.3-h4 . on both firewalls GlobalProtect Agent 6.1.1 We have selected option for authentication override On PortalsGenerate cookie for authentication override on Gateway Accept cookie for authentication override https://supportcases.paloaltonetw...

tthapa23 by L1 Bithead
  • 8539 Views
  • 8 replies
  • 0 Likes

Global Protect

Hi Friends, We have a customer who is using global protect. Two HIP profiles are configured for two different groups. One for AD users and one for Local users. The requirement is if local user tries to login he should get the hip profile banner set up for local user If the ad user login he should get the hip profile banner that is setup for A...

GlobalProtect Web Portal - Domain Validation Code (DVC) - /.well-known/pki-validation

Does anyone know how to go about performing domain validation for an IP address for the GlobalProtect Portal? This is a standard supported by most Certificate providers but I can't find anything about it when searching Palo Alto's site. With this tunnelcrack vulnerability and the need to use an IP address in the SAN of a publicly signed cert,...

Resolved! GlobalProtect issues after updating firewall version to 10.2.3

Hi Team The customer recently updated one of their firewalls to version 10.2.3 and now when we try to connect to the GlobalProtect client on the end user's machines, we are prompted twice to sign in. The monitoring tab gives a failure with "Authentication failed: empty password". Adding to this, we use Cisco Duo for MFA and we are prompted twi...

Resolved! HIP profile is not working with WAN rule

Hello valued community, unfortunately, I am still seeking answers for my issue. I have an HIP profile that works when defined as an example for someone establishing a VPN connection using RDP. However, I am unable to achieve results when applied to a WAN rule. Precisely, what I want to achieve is this: If it doesn't meet the conditions specified...

Resolved! VPN user not allowed to gain access

Has anyone dealt with an issue where a vpn user is out of the country and cannot gain access? They are prompted to login, but it just continues to spin. In the GlobalProtect logs, it's saying 'success' though the portal, but not through the gateway.

How to Update the SAML Certificate When Integrated with Azure AD and SAML.”

Hello, I’m using Azure AD as the Identity Provider (IdP) and GlobalProtect as the Service Provider (SP) for SSO. I’m having difficulty updating the SAML certificate. I’ve followed these steps: 1. Issued a new SAML certificate in Azure AD.2. Imported this new certificate into GlobalProtect.3. Activated the new Azure AD SAML certificate in GlobalP...

taro1021 by L0 Member
  • 10151 Views
  • 1 replies
  • 0 Likes

GlobalProtect Random disconnects

Hello,Has anyone else have issues with random GP disconnections since recently (May/June/July 2021) on GP version 5.0.x and 5.2.x ? It started around one month ago throughout the whole company and we weren't able to figure out what's going on till now.There is no preceding events logged in the GP debug or dump level trace that would point to an ...

Resolved! Diffie-Hellman Ephemeral Key Exchange DoS Vulnerability (SSL/TLS, D(HE)ater)

Hi, Has anyone running the client version of GP successfully mittigated the Diffie-Hellman Ephemeral Key Exchange DoS Vulnerability (SSL/TLS, D(HE)ater) for the GP portals? I have only found ways to disable DHE for clientless GP configuration. We are running PANOS 10.1.10 h1 but it seems like DHE is supported on all PANOS version even though it ...

How can i apply different HIP Policy for external users?

Hello Dear Community, I have 2 SSL VPN rules assigned to my username in Palo Alto firewall. For testing purposes, I added a HIP profile to only one of them. The device I tested does not comply with the HIP profile. The VPN connection is notifyed as failed. The rule to which I applied the HIP Profile is not working because the computer I'm using ...

Global Protect client connected an able to send traffic but not replying when traffic is initiated in the Datacenter side

Hi, I am having a problem where random global protect clients are connecting and are able to send traffic through the tunnel to the Data Center when traffic is initiated in the client workstation. However if we try to RDP or send any traffic to the connected VPN client initiated from the Data Center side, we are seeing in the capture that traffi...

  • 1702 Posts
  • 68 Subscriptions
Top Solution Authors
Labels