GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
About GlobalProtect Discussions
Welcome to the GlobalProtect discussion area! Here, you can engage in conversations about GlobalProtect, explore new insights, and stay updated on ongoing discussions. Check back regularly for the latest updates and community insights on GlobalProtect.

Discussions

Global Protect credential error for mutual domain but seperate active directory

Hi, We have mutual domain with our other site, but seperate Active Directories. When a consultant tries to connect us just after connecting to other site, GP tries to connect with other site's username (ismailt). His username in our AD is ismail.tetik. But in pop up window that GP creates for MFA, we still see his other username, which is isma...

Global Protect for Google Chrome Client connects successfully but unable to connect to the internet- assigned IP 100.115.92.2

Our Google Chrome client are not able to access any network resources including the internet after connecting to Global Protect app. I noticed that the following IP address was assigned 100.115.92.2 as opposed to the expected IP address from the configured pool subnet. It appears as though there is some kind of segregation on the Google Chrome s...

Resolved! Apple MAC devices not connecting

I just uploaded the new PKG into Jamf Pro Cloud and then installed the client onto a Mac. I went to attempt to connect and received the following error: Could not connect to the GlobalProtect services. Make sure the GlobalProtect service is running. I made zero modifications to any settings within Jamf Pro for the installation except for the...

aaronz by L0 Member
  • 2878 Views
  • 1 replies
  • 0 Likes

Resolved! GlobalProtect Security updates for non-customers?

Is there any way for a company who is not a PaloAlto partner to get GlobalProtect security updates? For example, a company who provides software support for on-premises envrionments and uses the GlobalProtect client if the customer has a Palo Alto Networks firewall, but does not own any Palo Alto Networks equipment itself? thank you

Has the inactivity logout changed?

I was reading about disconnect at idle being removed and just inactivity logout will be used in 10.1. In the past this never really worked as the tunnel was never truly "idle" unless the end user lost their internet connection or network port was powered off during a shutdown/sleep. Would like to disconnect users who are not actively using their...

Enforce GlobalProtect Connection For Network Access and Local Network Access

Hi I have enabled "Enforce GlobalProtect Connection For Network Access" on an "Always On" VPN and it works as expected but I can no longer access the Local Network for Printing even though "No Direct Access to Local Network" is disabled. I am assuming that the Enforce takes preference but is there any other way of still allowing local printing? ...

GlobalProtect idle timeout

Hello all, I would like to know your feedback with some requirements which I have to configure a GlobalProtect VPN to be used by mobile devices: 1- Split tunneling: Configured and working properly, mobile devices using this VPN are sending through the VPN only the traffic of some specific subnets. 2- Specific addressing based on SO: I’ve a...

pasp_997 by L0 Member
  • 1452 Views
  • 0 replies
  • 0 Likes

Several client authentication in a Gateway

Hi, we have a PA-850 running 10.1.8 firmware. We currently use GlobalProtect VPN using Symantec VIP authentication via RADIUS. We want to progressively migrate the authentication to Azure AD MFA (already synced with all accounts). I was wondering if I could simply add the new client authentication to the list and use it as a fall back authentica...

Global Protect multiple gateway setup

I have an existing setup of Global protect Portal and gateway on first Firewall, I have created a New gateway on another Firewall and added that gateway to the portal of first firewall under Agent---> External gateway. When I am connecting to Global protect from the app i am getting an IP address from the pool of first gateway which is the ol...

GlobalProtect Qualys: 150307 External Service interaction via Host Header Injection

Has anyone scanned their GlobalProtect Portals/Gateways with a Qualys WAS scanner? With GP running version 10.0.x, it's reporting back QID 150307 External Service interaction via Host Header Injection. The scanner injects a special FQDN in the Host header and X-Forwarded-Host header. Qualys Periscope is used to detect any subsequent DNS reque...

jmurphy by L2 Linker
  • 10906 Views
  • 8 replies
  • 1 Likes

GlobalProtect client doubled in size?

Does anyone know why the latest GlobalProtect client distribution package doubled in size? 5.2.12 103MB --> 5.2.13 232MB 6.0.3 155MB --> 6.0.5 283MB 6.1.0 124MB --> 6.1.1 250MB Was going to upgrade some GP clients, but in some cases remote internet access is limited and having people wait 30min for a VPN client download before l...

Why can I still access the company's internal network after the GP client is disconnected?

client终止GPAgent的连接后,ipconfig显示仍然获取到断开前的IP地址(在正确的IP地址池中分配的地址)。同时,仍然可以和内网服务器通信(ping的结果)。给我的感觉是虽然显示连接中断了,但是实际连接并没有中断。除非你手动切换网络信号(换wifi),或者重启电脑。我们检查了VMFW的配置,发现没有相关配置。也就是说,这种现象不是预料之中的,所以想排查原因和解决办法。

Lyman.Li by L0 Member
  • 1066 Views
  • 0 replies
  • 0 Likes

RSA SecurID Windows MFA Agent stops working when GlobalProtect is installed

We are trying to implement RSA SecurID MFA across our infrastructure, specifically to lock down VPN, cross zone traffic, and essential network assets. On the Window servers and some of the more sensitive mobile devices (Windows laptops) we are installing the RSA SecurID Windows MFA Agent. The RSA MFA works fine if GlobalProtect is not installed ...

fpascal4 by L0 Member
  • 5001 Views
  • 2 replies
  • 0 Likes
  • 2062 Posts
  • 68 Subscriptions
Top Solution Authors
Top Liked Authors
Labels