GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
About GlobalProtect Discussions
Welcome to the GlobalProtect discussion area! Here, you can engage in conversations about GlobalProtect, explore new insights, and stay updated on ongoing discussions. Check back regularly for the latest updates and community insights on GlobalProtect.

Discussions

Resolved! pre-logon - not seeing "pre-logon" user in traffic logs / 0 hits on pre-logon policy rules

I'm testing out pre-logon always on VPN with a pretty basic setup. My pre-logon tunnel is coming up and seems to work fine, however I am not seeing any hits on a permit any/any security policy rule that has the source users set to "pre-logon". Nothing in the traffic log either, just shows a blank user for traffic prior to successful user auth. U...

Assigning a static IP to a Global Protect user

Is there a way to assign a static IP to a global protect user? I have a couple security policies that specify userids in the source, but the policies are not getting picked up. They are dropping to the default deny. I verified that the userid shown on the traffic monitor matches the rule, but it is not working. I was thinking that if I 'assi...

Global Protect HIP check severity numbers (Windows)

The Global Protect documentation for severity numbers is a little incomplete. I opened a TAC case and got the full breakdown and wanted to document it. Severity Value Rating-2 (PATCHMANAGEMENTAGENT_SEVERITY_NOTAVAILABLE) -> not available-1 (PATCHMANAGEMENTAGENT_SEVERITY_UNKNOWN) -> unkno...

staustin by L2 Linker
  • 3150 Views
  • 1 replies
  • 2 Likes

GlobalProtect "Connect Before Logon" not working with Duo SSO

We recently implemented Duo Multi-Factor Authentication (MFA) and have configured GlobalProtect to use Duo's SSO service (which in turn Duo uses Azure AD for authenticating the user). We are using SAML for authentication, so when the user clicks 'Connect', GlobalProtect does the portal connection first and is told by the Palo Alto to open it's...

jrauman by L2 Linker
  • 6160 Views
  • 1 replies
  • 1 Likes

Force GlobalProtect Portal refresh of connected clients?

Is there a way to force the refresh of the portal agent config on connected clients? We have multiple portals and multiple gateways for VPN load distribution and fail-over capabilities. When developing/testing changes to the GP VPN I will often take a gateway out of rotation by deleting it from the portal external gateway config. The following d...

GlobalProtect SAML Not working

Hi We have recently deployed SAML authentication on our existing GP environment and this is working fine on most devices. Currently we are in a migration phase, which means only that the gateway is using SAML and the portal is still using on prem AD credentials (not saml). A few users experience the following behaviour: when logging into their...

Message an error has occurred in the script on this page when trying to connect to GlobalProtect

Hello team When connecting to GlobalProtect VPN for Windows we detect this error "an error has occurred in the script on this page" We have tried to perform Clear your Internet cache. Open the Start menu and search for Control Panel. Open the Control Panel and select Internet Options. Under Browsing history, click Delete... Check all boxes ex...

BigPalo by L4 Transporter
  • 9372 Views
  • 1 replies
  • 0 Likes

GlobalProtect GW redundancy and preemption

Does anyone know if GW preemption can be achieved with GlobalProtect Agent? Meaning, that we use primary and secondary GW, whereas secondary GW should be used only in case primary is not reachable. So far, the failover to secondary GW works perfectly if the primary becomes unreachable, however, as soon the primary becomes available again it does...

GlobalProtect, Windows 11 and laptop lids

We've had issues running GlobalProtect (5.x and 6.0) on Windows 11, particularly when a person closes the lid of their laptop while they're still connected to the GP gateway. When they wake the laptop up, GP won't connect. They have to reboot the laptop and then it's fine again. Manually disconnecting GP before shutting the laptop lid seems to m...

Unable to connect Global Protect VPN

All our users are able to connect to our PA220 using Global Protect VPN except one. We've tried reinstalling the Global Protect client multiple times and also connected successfully using their account from another computer, but it just refuses to work on his.

Jason.T by L2 Linker
  • 46061 Views
  • 22 replies
  • 0 Likes

Windows365 and GlobalProtect.

We are setting up a Windows365 environment that, obviously, lives in Azure cloud. These machines are access by RDPing into them. Due to some access management controls and the systems not actually living on our network, the Windows365 machines were having issues connecting properly. One of the engineers on the project got an idea to install Glob...

  • 1683 Posts
  • 68 Subscriptions
Top Solution Authors
Labels