Global protect
GP users lifetime shows 2592000 Seconds (that means 720 hours). But we need to change this to 24 hours max (86400 seconds). Can you let me know how to do the change.
GP users lifetime shows 2592000 Seconds (that means 720 hours). But we need to change this to 24 hours max (86400 seconds). Can you let me know how to do the change.
Hi,I downloaded Global Protect for linux from Updates/Software Updates (PanGPLinux-6.0.0-c18.tgz)Now I have 2 problems here:1. Problem in CLII extract the tgz and install the package for CLI using (sudo dpkg -i GlobalProtect_deb-6.0.0.1-44.deb)When I try to connect to gateway it gives me this errorError: Gateway ExternalGateway: Could not verify...
Hello, We have a use case in which we have say example.com resolving internally(on-prem) to 10.1.1.1, this will resolve internally while you are connected to the corporate network using the corporate network DNS servers. the global protect clients are also pointed to the internal corporate DNS servers. So all the traffic for DNS comes through th...
Hi Team, We have configured GP VPN with AD authentication and MFA . The AD authentication is working but the MFA is not working which is our next level authentication. So kindly help us to resolve this issue. Also using username and password we are able to connect the network also using the 2FA we are able to connect the network but after co...
Hi looking to get some feedback. Currently we have on-demand global protect VPN connection (user inisitates the VPN connection, puts username/password). They have full access to internet via laptop (w.o any traffic inspection) if there is no VPN tunnel and they are off-prem. Our company wants to move away from that and force auto VPN connecti...
Hello, Our Palo GP is setup inside Azure - and it is working and serving its purpose. GP can reach everything, but not the other way around. We can't ping GP Clients, we can't RDP to them, any traffic destined to GP Subnet has literally no logs at all. Looking for some expert advice. Thanks in advance.
Hey community, we are currently trying to enroll iOS Devices with an always-on VPN Connection and authenticated by client certificate. A lot people turn their iPhone over night off and start it at the morning, while the iPhone is still locked WiFi is not enabled and I guess the client certificates too. So mobile data is active which is tryin...
Hi Team, We have configured GP VPN with AD authentication and MFA . The AD authentication is working but the MFA is not working which is our next level authentication. So kindly help us to resolve this issue. Also using username and password we are able to connect the network also using the 2FA we are able to connect the network but after co...
Hi Friends, We have a requirement related to global protect. Condition: User tries to connect to global protect and fails to login. If he tries for three or more times to connect to global protect and fails to login an email alert should come to my mail id. I have configured email alerts in my firewall but can we specifically customize by ab...
Hi all, Has anyone been able to configure a PA firewall to forward Radius messages to a MS Defender for Identity sensor as per Microsoft Defender for Identity VPN integration in Microsoft 365 Defender | Microsoft Docs We are using Azure AD for Global Protect authentication, so not sure that it's possible to send to Radius if not using it to au...
We have multiple gateways in our environment. Our default agent profile has always on configured. Users are balanced across the gateways. We have a troubleshooting profile that gives users the option to disconnect and choose to try and switch to a different gateway.My question is that I would like to configure a profile that is always on but giv...
I have a PA-440 running 10.2.3-h4. I have a working external GlobalProtect gateway and created an internal gateway. I have enabled "Internal Host Detection" added the internal gateway information to the config of the portal. After trying to connect, the main GlobalProtect screen shows "Not Connected" with "Select the portal to connect and sec...
Hello, We have 4 vCPU PaloAlto NGWF Firewall. We are using GlobalProtect for Remote Access VPN Service. Now we would like to enable 2FA via Azure (SAML). I tried to do configuration as it showed in Palo Alto article: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g0000008U48CAE I can login into Portal with AD Credentials, b...
Hi, I found that after March 25th, when I was connected to a VPN, I was no longer able to use bing chat. Bing chat said: "Sorry, looks like your network settings are preventing access to this feature." But if I disconnected from VPN then everything works fine. I have been tested on two different machines, macbook and windows laptop. Any idea? ...
Hi LIVECommunity, Has someone else seen this behavior on the GP Agent? All of a sudden it started showing strange characters. The agent is installed on a Windows10 with the Spanish language. By the way, the agent works fine (I can connect to the VPN), It's just an issue with the characters. We already tried re-installing it but no luck... We ...

