GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
About GlobalProtect Discussions
Welcome to the GlobalProtect discussion area! Here, you can engage in conversations about GlobalProtect, explore new insights, and stay updated on ongoing discussions. Check back regularly for the latest updates and community insights on GlobalProtect.

Discussions

Trying to install certificate on web portal page

We have been using self-signed certificates for years with no issues. However, one business partner can't access the Web portal on our firewall to download the global protect software due to the self-signed cert. I have tried to configured the firewall to use a cert issued by a signing authority. I installed the cert in our Global Protect Gat...

svanarts by • L1 Bithead
  • 4782 Views
  • 3 replies
  • 0 Likes

Gateway gw:Could not verify the server certificate of the gateway

Hello, We had PA550 , now moved to PA 440 and configuration migrated from 550 to 440 , and can able to connect with old version of global protect ; but newer version we can't able to connect . For the newer version of Global protect we are getting the following error . Gateway gw: could not verify the server certificate of the gateway. Thank Y...

Global Protect Cookies Portal Gateway

Hello good afternoon, as always thank you very much for your time and collaboration. I have a question, currently I have configured at the level of Global Protect, cookies in both Portal and Gateway. The issue is that this was configured to keep the credentials and not have to be entering these manually, twice, ie for the portal and gateway....

Metgatz by • L4 Transporter
  • 3276 Views
  • 1 replies
  • 0 Likes

Source-NAT with POOL from GlobalProtect zone to subnet behind the MPLS router

Hi community, I'm writting this post to get any ideas or suggestions in a new end-customer requirement. The main goal is that all clients connected via GlobalProtect can access to a new services acquired recently via MPLS (attached the brief topology). The point here is the MPLS's administrator share a specific IP Address that we need to NAT an...

larry2019_0-1665525816825.png

GlobalProtect integrated login

Hello, We currently have GlobalProtect setup with always-on, with certificate logon and credentials (via RADIUS via AD). Right everything is working as designed. We have a desire to remove the manual login once globalprotect launches in the user session (so one logon; just Windows). How do we enable GlobalProtect to automatically logon while usi...

mrt3385 by • L0 Member
  • 2128 Views
  • 2 replies
  • 0 Likes

Launching Global Protect from Microsoft myapps portal

We currently have our palo firewalls tied to Azure SAML for our vpn users. These users multi factor authenticate through azure. When clicking global protect from the taskbar, it opens and users are able to connect. What I would like to do is point users to the myapps.microsoft.com portal, show the palo app, users click this app and it launches t...

Does a new Split Tunnel require client restart?

We are implementing a split tunnel to separate 365 traffic. Once we configure the Split Tunnel, will the user be required to restart either the client or the PC? before this becomes effective, or should this be an automatic process... If so... how long before it kicks in ?

dgray1 by • L0 Member
  • 2381 Views
  • 2 replies
  • 0 Likes

split tunneling

I am trying to get global protect gateways set up on two PA-850s. Cant seem to get split tunneling right. wondering if i need licensing. the description for licensing states that it is needed for split tunnleing by domain, but not for doing it by IP address, which is what i am doing. anyone know if i need the licensing?

Resolved! Palo Azure SAML issue

Our AD forest is yz.abc.com We have GP working with LDAP but user has to enter creds as yz\user For the SAML profile it only configured for test portal authentication separately, no agent configuration done yet. When I access portal in browser i get this error although SAML profile allows all users SAML SSO authentication failed for user \'use...

image.png
image.png
image.png
image.png
raji_toor by • L4 Transporter
  • 4214 Views
  • 1 replies
  • 0 Likes

GlobalProtect Authentication Override

Been using Radius auth to portal with auth override to gateway for years but seems to now be playing up... Gateway is requesting radius auth and ignoring override settings. This is the same issue on both Windoze and IOS. PA 3020 9.1.14 We have no custom checks, just Radius auth (which is working fine) Many thanks in advance...

Resolved! pre-logon - not seeing "pre-logon" user in traffic logs / 0 hits on pre-logon policy rules

I'm testing out pre-logon always on VPN with a pretty basic setup. My pre-logon tunnel is coming up and seems to work fine, however I am not seeing any hits on a permit any/any security policy rule that has the source users set to "pre-logon". Nothing in the traffic log either, just shows a blank user for traffic prior to successful user auth. U...

Assigning a static IP to a Global Protect user

Is there a way to assign a static IP to a global protect user? I have a couple security policies that specify userids in the source, but the policies are not getting picked up. They are dropping to the default deny. I verified that the userid shown on the traffic monitor matches the rule, but it is not working. I was thinking that if I 'assi...

  • 1711 Posts
  • 68 Subscriptions
Top Solution Authors
Labels