GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
About GlobalProtect Discussions
Welcome to the GlobalProtect discussion area! Here, you can engage in conversations about GlobalProtect, explore new insights, and stay updated on ongoing discussions. Check back regularly for the latest updates and community insights on GlobalProtect.

Discussions

Separation of profiles for authorization and authentication in GlobalProtect

Hello friends! Help me please.I need advice on authentication and authorization when connecting to a GP.Is it possible to separate these roles? For example: authenticate using SAML.And then check this user for belonging to groups in LDAP, and depending on these groups, send him to the gateway / send him settings / apply policies. In general, aut...

GlobalProtect Always-on User Experience

Hey all - We're currently in the beta-testing phase of our GlobalProtect implementation, and I have a couple of questions around 'best practices' to ensure a good user experience. First, our setup: - PAN-OS 10.1.5-h1 - GlobalProtect client v5.2.11-10 (Mac OS (12.x) & Windows 10) - Pre-logon via machine-based certificates - User logon via Ok...

GlobalProtect License Portal or GP license Gateway?

Hi all, I need a clarify about GP Portal license and GP Gateway license. Which one is needed for clientless VPN?I have this PA-850 and running on PanOS 9.0.13, on support portal it shown that I have GP Gateway license active but GP Portal license is expired. As far as i know we only need Globalprotect license to use more features, but the suppo...

febriantofitranto_0-1643298903445.png

Global protect SAML with azure need to make the joined PC to access without going to authentication other than to ask for username password via webpa

Global protect SAML with azure need to make the joined PC to access without going to authentication other than to ask for username password via webpage. I done the SAML and enabled the Sigle sign on from agent tab to be ON so the global protect get the username password when user login but the issue when the not joined PC tried it will get the...

Resolved! Global Protect Force Gateway Selection

I am trying to set up GlobalProtect and am having issues with client gateway selection. I have a single portal and will have two gateways set up. One uses SAML auth (general users) and the other one uses DUO auth (for the IT dept). Both are set to be on-demand. I want all users to be presented with both gateways initially, and then clients ...

Recommended config for Globalprotect on Azure active-active LB sandwich architecture?

We are running two active-active VM-300s at Azure using the common firewall architecture reference doc (two Azure standard load balancer sandwich). Now looking to enable Globalprotect gateways and was wondering what best practice would be for external access - use a single address on external Azure load balancers and load balance to VM-300s with...

PanGPS consumes much power when MacBook hibernates

I'm using the GlobalProtect in my MacBook Air. When I close the laptop lid, the MacBook will enter deep sleep state, which consumes very little power. But after I installed the GlobalProtect, the MacBook will consumes a lot of power 5 days after I close my laptop lid. I checked the console, it is PanGPS initiates network connection after 5 days ...

Snipaste_2022-06-24_22-21-16.png
Snipaste_2022-06-24_22-17-10.png

Resolved! Client VPN Traffic

Hi, For security reasons, I need to ensure that all client VPN traffic is going down the VPN to the Palo Alto firewall. I need to prove that to the customer that all traffic from the mobile devices is all going down the VPN tunnel and egressing out of the firewall. How can I achieve this? Thank you.

GlobalProtect Users Unable to Reach Intranet Resources Every Hour/2hrs

Hello, We have been experiencing an interesting issue where users that connect via GlobalProtect, will all of a sudden no longer be able to access internal resources after about an hour/2hrs of initially connecting. External resources work absolutely fine during this period. The only way to remedy this is to disconnect GP/refresh the connection....

Palo_SSH_dropped_traffic.JPG
kbarton by L0 Member
  • 4191 Views
  • 1 replies
  • 0 Likes

Resolved! GlobalProtect MSI opens Microsoft Store?

Got an external user (so connecting from his own PC and not a company one) that tried to install GP downloaded from our portal today, but every time he tries to start the MSI files it just opens the Microsoft Store. I have no clue on how to avoid that and just have him install the normal GP app. He's the only one with that issue with that port...

Global Protect VPN Disconnects Local Network Resources After 4 Hours

Apologies if this is a simple fix / stupid question. We have a group of users who need to use the GP VPN to access certain online resources provided by another company. After about 4 hours with the VPN connected, we lose all access to local network resources i.e. network drives). Only shutting down the VPN will bring them back. Is there a ti...

Importing SSL

Hi, I'm new to importing SSL Wildcard Certificates. I'm trying to import a new ssl wildcard to replace the expired ssl wildcard cert. I was able to import new ssl wildcard cert but the firewall will not allow me to add the new ssl wildcard cert to SSL/TLS profile. The old ssl wildcard cert shows with a SSL/TLS profile.But not the new cert. Do ...

  • 1695 Posts
  • 68 Subscriptions
Top Solution Authors
Top Liked Authors
Labels