GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
About GlobalProtect Discussions
Welcome to the GlobalProtect discussion area! Here, you can engage in conversations about GlobalProtect, explore new insights, and stay updated on ongoing discussions. Check back regularly for the latest updates and community insights on GlobalProtect.

Discussions

Resolved! Different agent configs Problem

Hi there, we have global protect with different agent configs based on ad groups enrolled. We have different configs for always on and always on disable on demand since the upgrade to global protect 6.0.3 some users seems to get a different config (always on instead of disable on demand) in PANOS 9.0 you could see in the system logs of t...

Softphone connect issue on GP agent 5.2.8 version when primary DNS is unreachable in GP setting

The endpoint having GP client version 5.2.8, is having an issue to connect to Secondary DNS Server for SIP traffic only. The issue is occurring on 5.2.8 when the primary DNS is not reachable. • WFH users connected to VPN gateways, were having primary DNS DC1 and secondary DNS DC2 in VPN setting.• Due to Planned activity Primary DNS DC1 server wa...

Deepak25 by L3 Networker
  • 3038 Views
  • 1 replies
  • 0 Likes

Separation of profiles for authorization and authentication in GlobalProtect

Hello friends! Help me please.I need advice on authentication and authorization when connecting to a GP.Is it possible to separate these roles? For example: authenticate using SAML.And then check this user for belonging to groups in LDAP, and depending on these groups, send him to the gateway / send him settings / apply policies. In general, aut...

GlobalProtect Always-on User Experience

Hey all - We're currently in the beta-testing phase of our GlobalProtect implementation, and I have a couple of questions around 'best practices' to ensure a good user experience. First, our setup: - PAN-OS 10.1.5-h1 - GlobalProtect client v5.2.11-10 (Mac OS (12.x) & Windows 10) - Pre-logon via machine-based certificates - User logon via Ok...

GlobalProtect License Portal or GP license Gateway?

Hi all, I need a clarify about GP Portal license and GP Gateway license. Which one is needed for clientless VPN?I have this PA-850 and running on PanOS 9.0.13, on support portal it shown that I have GP Gateway license active but GP Portal license is expired. As far as i know we only need Globalprotect license to use more features, but the suppo...

febriantofitranto_0-1643298903445.png

Global protect SAML with azure need to make the joined PC to access without going to authentication other than to ask for username password via webpa

Global protect SAML with azure need to make the joined PC to access without going to authentication other than to ask for username password via webpage. I done the SAML and enabled the Sigle sign on from agent tab to be ON so the global protect get the username password when user login but the issue when the not joined PC tried it will get the...

Resolved! Global Protect Force Gateway Selection

I am trying to set up GlobalProtect and am having issues with client gateway selection. I have a single portal and will have two gateways set up. One uses SAML auth (general users) and the other one uses DUO auth (for the IT dept). Both are set to be on-demand. I want all users to be presented with both gateways initially, and then clients ...

Recommended config for Globalprotect on Azure active-active LB sandwich architecture?

We are running two active-active VM-300s at Azure using the common firewall architecture reference doc (two Azure standard load balancer sandwich). Now looking to enable Globalprotect gateways and was wondering what best practice would be for external access - use a single address on external Azure load balancers and load balance to VM-300s with...

PanGPS consumes much power when MacBook hibernates

I'm using the GlobalProtect in my MacBook Air. When I close the laptop lid, the MacBook will enter deep sleep state, which consumes very little power. But after I installed the GlobalProtect, the MacBook will consumes a lot of power 5 days after I close my laptop lid. I checked the console, it is PanGPS initiates network connection after 5 days ...

Snipaste_2022-06-24_22-21-16.png
Snipaste_2022-06-24_22-17-10.png

Resolved! Client VPN Traffic

Hi, For security reasons, I need to ensure that all client VPN traffic is going down the VPN to the Palo Alto firewall. I need to prove that to the customer that all traffic from the mobile devices is all going down the VPN tunnel and egressing out of the firewall. How can I achieve this? Thank you.

GlobalProtect Users Unable to Reach Intranet Resources Every Hour/2hrs

Hello, We have been experiencing an interesting issue where users that connect via GlobalProtect, will all of a sudden no longer be able to access internal resources after about an hour/2hrs of initially connecting. External resources work absolutely fine during this period. The only way to remedy this is to disconnect GP/refresh the connection....

Palo_SSH_dropped_traffic.JPG
kbarton by L0 Member
  • 4144 Views
  • 1 replies
  • 0 Likes

Resolved! GlobalProtect MSI opens Microsoft Store?

Got an external user (so connecting from his own PC and not a company one) that tried to install GP downloaded from our portal today, but every time he tries to start the MSI files it just opens the Microsoft Store. I have no clue on how to avoid that and just have him install the normal GP app. He's the only one with that issue with that port...

  • 1683 Posts
  • 68 Subscriptions
Top Solution Authors
Top Liked Authors
Labels