GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
About GlobalProtect Discussions
Welcome to the GlobalProtect discussion area! Here, you can engage in conversations about GlobalProtect, explore new insights, and stay updated on ongoing discussions. Check back regularly for the latest updates and community insights on GlobalProtect.

Discussions

PCI compliance ECDHE/RSA

There were a couple of discussions on this months ago with no resolution. SecureTrust's PCI scans say that we are failing. We would need to set both RSA and ECDHE to 2048 but there is no option to do so that I know of for the SSL/TLS profile. The workaround that was discussed was to disable ECDHE and RSA. However, among other possible issues, ...

11618 - TCP/IP SYN+FIN Packet Filtering Weakness resolution

VA scan flag out the below for GP Portal URL 11618 - TCP/IP SYN+FIN Packet Filtering Weakness-SynopsisIt may be possible to bypass firewall rules.DescriptionThe remote host does not discard TCP SYN packets that have the FIN flag set.Depending on the kind of firewall you are using, an attacker may use this flaw to bypass its rules. See Alsohttps:...

GlobalProtect: Using an alternative port

Good morning. I require a bit of assistance for deploying GlobalProtect with a twist. A client of ours wishes to deploy Global Protect but unfortunately, they also have a Web Facing application using SSL on the same ISP interface. This is unfortunately causing issues since GP also makes use of 443(SSL) and due to the DNAT rule in place for t...

MGiusti by L0 Member
  • 3304 Views
  • 1 replies
  • 0 Likes

Browser behavior when using SAML authentication with GlobalProtect

We recently changed from using our internal AD for authentication to GP external portal/gateway to using SAML authentication with MFA using Azure AD. The testing for company users was fairly consistent but involves a lot of browser activity (prompt for AD creds, MFA prompt and two GP prompts). After a few successful logins this process usually...

Resolved! PA-440 Global Protect VPN - no Internet after connecting, only local resources

I've recently setup Global Protect Gateway/Portal but after connecting do not have access to Internet, only local resources. A coworker and I have been going through the configuration comparing it to other working PA-220's we have at work but nothing seems to working. Using Global Protect client 6.0.3 DNS for IP Pool is configured for 9.9.9.9 an...

Global Protect Windows logon PIN/Password

Hi, I am currently on GP 5.2.10 & I logon to Windows 11 via a PIN. When I upgrade to 6.1.0 my windows 11 laptop defaults to password & I have to change it to PIN and then logon. When I revert back to 5.2.10 it defaults to PIN logon. Is there a way to set PIN as a default when I upgrade to GP 6.1.0 Thanks.

Getting connection failed

Hello all, Our laptops are seeing the issue where they are working remotely and when the user tries to vpn back in its saying Connection Failedthe network connection is unreachable or the portal is unresponsive. Check the network connection and reconnect. ive tried uninstalling / reinstalling 5.1.x, 5.2.x etc.. reboots in between. tried ever...

MNTech by L0 Member
  • 12366 Views
  • 4 replies
  • 0 Likes

IOS + User logon (Always On) + SAML is not working...

>Founf this in the release note: GPC-6663 The GlobalProtect app for iOS does not support SAML authentication when you configure GlobalProtect with the User-logon (Always On) Connect Method (NetworkGlobalProtectPortals<portal-config>Agent<agent-config>App). This limitation is due to the Apple Network Extension framework, which bloc...

rxie by L3 Networker
  • 7966 Views
  • 2 replies
  • 2 Likes

Problems connecting to Globalprotect after users install latest windows Cumulative updates

There seems to be a bit of an issue connecting to Globalprotect after our windows machines have the latest microsoft cumulative updates, KB5018410 (windows 10) and KB5018418 (windows 11). Looking in reddit it looks like other users are seeing the same problem as well, anyone got any ideas on how to fix this going forward? The only way we've been...

jclements by L1 Bithead
  • 98754 Views
  • 53 replies
  • 3 Likes

debug ssl-vpn global missing in 10.2 ?

I am trying to troubleshoot an issue with config selection in a pa3410 running panos 10.2.2H2 but cant find "debug ssl-vpn global" and have been unable to find in documentation if that command was changed or ? does anyone have an idea ?

MFA global protect

Hello, Could you please tell me why every user who connects to vpn with global protect must have a license on a MFA server? What is the point and what would happen if a user does not have a license? Thank you very much.

Resolved! Global Protect Behind NAT

I have a PA-800 with global protect configured in an internal network. A 1to1 NAT has been setup to map a public IP address to the internal IP address of the external interface of the PA. The 1to1 NAT is on a Cisco ASA5508X with direct passthrough on 443. I set the same internal IP address on the portal and the gateway. When authenticating from ...

  • 1692 Posts
  • 68 Subscriptions
Top Solution Authors
Top Liked Authors
Labels