GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
About GlobalProtect Discussions
Welcome to the GlobalProtect discussion area! Here, you can engage in conversations about GlobalProtect, explore new insights, and stay updated on ongoing discussions. Check back regularly for the latest updates and community insights on GlobalProtect.

Discussions

GlobalProtect Issues with Hotspot Users

Two different users reported problems when connecting to GlobalProtect when using an iPhone as a hotspot. The users can connect to GP, but are then unable to use HTTPS or ssh to connect to internal assets via the VPN. If the user uses the same laptop and connects via wifi (not using hotspot), GP works fine. Tests with several other users usin...

peppywoll_0-1610157455136.png

using Azure SSO for GP fails when password change dialog must be shown to user

Useing Azure SSO with Global Protect and MFA for sign in, there comes times when users must authenticate however their password must be changed, say on first login, or after X days etc. The page that displays the login etc seems to not be able to redirect to that change password dialog, and does not give the user any indication of what is wrong....

Using PAN as a DHCP Server - MAC Addresses are Case Sensitive

Hi everyone, I'm having an issue trying to tell our account representative that PAN should treat upper-case or lower-case (or even mixed) MAC addresses as one entry. I say this because I had an entry in our PAN DHCP Server all in lower-case (entered manually); later, I copied a MAC address into the system was wondering why the device didn't p...

Using pre-logon user with client certificates, how to force global protect to select a particular certificate and not prompt user?

The issue is that we are about to replace our Issuing Intermediate Root Certificate (IIRC) in our PKI chain with a new one due to expiration on December 15th. Right now we configure laptops we sent out to remote users with the special registry key settings in GlobalProtect to allow the "pre-logon" user, and to pre-define a specific portal to use...

[RFC5746] issue with ssl decryption: openssl3.0 unsafe legacy renegotiation disabled

Since I upgraded to the lastest fedora, all of my python/ansible script failed when they are decrypted by our palo alto ssl outbound policy. After some diging, fedora 35 was using openssl 1.1.1 and fedora 36 switched to openssl 3.0: https://fedoraproject.org/wiki/Changes/OpenSSL3.0 On the openssl 3.0 changelog, we can find this: OPENSSL chan...

Global Protect SAML Azure timeout

Hi, I have Global Protect setup to run authentication against Azure SAML. The users login with their credentials and are prompted with their MFA. The thing is that there seems to be a timeout timer for this in Global Protect? I tested that if the user logs in within about 30secs with user and MFA, everything works great. If it takes longer, ...

Internal host detection issue

Hello, Current setup is a 440 running 10.1.10-h2. Global Protect version is 6.1.2 I have double and triple checked that it's not a reverse dns issue, following this article: GlobalProtect app fails to detect Internal Network with Interna... - Knowledge Base - Palo Alto Networks global protect tries to connect internally to the vpn it fails wi...

MNoble by L2 Linker
  • 3584 Views
  • 4 replies
  • 0 Likes

Globalprotect: Always on doesn't always work after comming out of standby requires refresh.

Hi, I have a couple of question about Global Protect Always on. At this moment my portal and gateway are using SAML authentication and my client is set to Always On and Internal portal detection. 1. What is best practice around authentication cookie override and SAML auth. Am I correct that the process for the cookies is to ...

zGomez by L3 Networker
  • 1245 Views
  • 0 replies
  • 0 Likes

Updating new Poral name (GW) to all existing Global Protect users

Hi,I already have almost 1500 users using Global Protect VPN Client. Currently our users are using gateway portal name (Eg :123.vpn.com.)We have implemented a new cloud VPN gateway (eg abcd.cloudvpn.com) and now we want all users to use the new cloud VPN gateway.Is there a way to push the new gateway name to all users VPN client settings so the ...

muja1913 by L0 Member
  • 1013 Views
  • 1 replies
  • 0 Likes

Globalprotect not working on Lenovo X13s

HI, I am trying to use the company-provided GlobalProtect vpn app (version 5.2.11-10) to connect to our VPN. My work laptop is a Lenovo X13s running the Snapdragon (TM) 8cx Gen 3 @ 3.0 GHz 3.00 GHz ARM-based processor. I set up the VPN with the right address, but when I try to connect the app does nothing. Any help troubleshooting this would...

mmorri by L0 Member
  • 1106 Views
  • 0 replies
  • 0 Likes

Resolved! Global Protect MFA Looping

Hello, I am facing a weird issue with Global Protect where after a user authenticates via Okta Radius to the Portal and enters their MFA SMS Key the GP Agent asks for the user to enter the MFA SMS Key again with the response of ('A message was sent or a call was made to the phone in the past 30 seconds. Please try again when 30 secs have passed....

Global Protect MFA Looping

Hello, I am facing a weird issue with Global Protect where after a user authenticates via Okta Radius to the Portal and enters their MFA SMS Key the GP Agent asks for the user to enter the MFA SMS Key again with the response of ('A message was sent or a call was made to the phone in the past 30 seconds. Please try again when 30 secs have passed....

GP example script running as admin

Hi, according to the doc, to run a pre (or post) vpn script can be run as admin using the following: context admin | user I haven't been able to get this working, so I'm guessing I have the variables all wrong. Can someone give me an example of how this would be used in a script? For example my current registry entry works as local user like bel...

Dekkar by L1 Bithead
  • 2535 Views
  • 1 replies
  • 0 Likes
  • 2062 Posts
  • 68 Subscriptions
Top Solution Authors
Top Liked Authors
Labels