Resolved! HIPS to prevent windows 7 clients
How would I go about creating a HIPS profile that would deny access to machines running windows 7 that need to connect to global protect?
How would I go about creating a HIPS profile that would deny access to machines running windows 7 that need to connect to global protect?
I have questions about the Global Protect, if I need to use .bat scripts to auto login GlobalProtect and auto connect a VPN too.Does this solution support on GP? In case the PC is at the branch and no staff at the branch. GlobalProtect
This is messing up our EDR solution. This program will run cmd.exe and then whoami /groupsC:\Program Files\Palo Alto Networks\GlobalProtect\PanGpHip.exe Whoami as the Local System authority is a bad thing in our EDR world. Is there anyway to change this behaviour?
Hi all, I'm using GlobalProtect 6.0.4.1 under Ubuntu 22.10. I work with two separate organisations, both of whom use GlobalProtect. So each one has a different server that I need to connect to. After I've configured GlobalProtect with one of them, the server is listed in the window next to "Portal:". It looks like I'm unable to change it. ...
Hi, greetings. Is there a way to use the CLR to verify the machine/user certificate through globalprotect, to drop connections if the certificate is revoked?
I am testing changing our authentication for GlobalProtect from AD LDAP on premises servers to using Azure AD saml. I have the authentication working fine at the portal; the system logs show successful authentication. But then I get "Could not verify the server certificate of the gateway." on the client. The GlobalProtect logs on the firewall s...
So my company has switched VPN providers. Whenever I connect and launch Global Protect VPN it says "You must enable automatic Windows Updates in order to access the xxxx Network. In addition, all recent patches must be installed to ensure security." In terms of troubleshooting I have manually edited the policy in gpedit and various places within...
We have an issue that we have logged a PA TAC case but wanted to stick out a forum post to see if others are having this issue. It seems when the machine upgrades Sophos from 2.20.11 to 2.20.13, we get the following message: "Your AntiVirus is not updated". HIP checks then fail. The only thing changed is the version of Sophos, but the HIP checks...
Hi, I am looking for the way to integrate Global Protect MFA with Microsoft Authenticator App. Please note that I need to local user database of the firewall for the authentication and Microsoft Authenticator App for the second factor. Please help on this.
We are using SAML authentication via The Global Protect Enterprise application in Azure. E everything is functioning as expected except for the logging is incorrect. The user login logs show the OS as Windows 8 when a Windows 10 user logs in. If you go to the details. in the log entry, The =User agent details show the correct PAN GP version and ...
Hi All, We are planning to enable SAML(OKTA) authentication for GP Portal and GP GW in our environment. Below are my queries. How to use the Hostnames instead of IP address to connect from the GlobalProtect. Where is the settings to configure a domain instead of IP address. In Cisco Anyconnect we call it as Alias. Not sure what we call in Global...
Hello everyone, We have configured a new set-up for GlobalProtect which use Auzre SAML authentication and Microsoft AuthenticatorIt's all working fine with the exception of this weird behavior: - User connect to the portal with SAML authentication - A window open for the user to select an AD account to use - User select account - New window ...
Hello team, I have an issue with the exchage key ECDHE size with Global protect. Our Qualys scans show that we accept keys of insufficient size in ECDHE.The problem is that on our equipment, we obviously cannot set the size of the keys. When I checked this KB https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000CqSHCA0&am...
I have configure a security policy for global protect access. the security policy I added below app-id panos-global-protect panos-web-interface SSL From my traffic log I can see my firewall is allow port 4443 traffic for this security rules. From Application Research Center I search this few port is only allow port 80 and port 443. Why my ...
Hi team, I am using GP (build # PanGPLinux-5.2.6-c18 ) on Ubuntu 22.04 LTS. I am unable to connect to VPN and get the following error: Gateway XXXXXXXXXXXX: Could not connect to gateway. The device or feature requires a GlobalProtect subscription license. If the issue persists, contact your administrator. The same credentials work if I t...

