GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
About GlobalProtect Discussions
Welcome to the GlobalProtect discussion area! Here, you can engage in conversations about GlobalProtect, explore new insights, and stay updated on ongoing discussions. Check back regularly for the latest updates and community insights on GlobalProtect.

Discussions

Resolved! Global Protect mixed internal and external gateway

hi everybody, i've some questions regarding global protect client and mixed environment internal / external we have a internal campus networking infrastructure with lan and wlan (2 different subnets), so the laptop changes the ip-address if traveling around the campus, wired or unwired... so we have installed global protect client for internal u...

Odd GlobalProtect issue

Just completed an install this last weekend and received a report that a user wasn't able to connect to GlobalProtect. I started with the normal troubleshooting and quickly realized this was going to be something more detailed. The user that initially complained said that she wasn't able to connect to GP. I asked them to just try to hit the port...

Azure SAML Authentication with multiple PAs

Hey, We have a GP configuration with 8 GP Gateways and 2 of them are acting as a GP Portal for backup.We are using SAML authentication with Azure and wanted to know how to you deploy GP with SAML authentication in large scale.Currently I have configured 3 SAML apps on Azure one for each PA device but I think it is not the right configuration sin...

screenshot.png
minow by L4 Transporter
  • 13782 Views
  • 10 replies
  • 0 Likes

Split Tunnel Domain & Application Cisco Umbrella Issue

We have one GlobalProtect Portal and 3 Gateways. This one Gateway is version 9.0.9-h1, and the GlobalProtect client version is 5.2.3-22. For testing, on this one Gateway, I enabled Split tunnel Domain and Application for *.webex.com and *.zoom.us. I'm testing from home with two laptops, and both are connected to this same GP Gateway. Laptop 1 do...

Assigning the same IP to a GP client based on it's MAC address

I'm trying to connect a client computer to my corporate network via global protect, and once I'm connected, I need to print to that computer through the Linux service called CUPS. In order to print to this computer, I need to know what it's IP address is. So, once I connect the client computer to the internet, download global protect, and connec...

Jamescy by L0 Member
  • 4108 Views
  • 2 replies
  • 0 Likes

Not using AppID but GP connections are denying on apps for 10 minutes before allowing traffic to work properly

We are currently working on trying to get PA-3220s working properly and Global protect working but are running into an issue. Once a user connects, recently its starting to deny based on app ID, however in our VPN policy we have any specified. The thing is this is pretty random. In 5 to 10 minutes the VPN starts working normally and those deni...

palo-drops.jpg
palo-vpn-rules.jpg
palo-allows.jpg
ksauer507 by L3 Networker
  • 4862 Views
  • 4 replies
  • 0 Likes

Resolved! Compatibility Global Protect Client - 4.1.11 and Pan OS 9.1

Hi All, We are planning to upgrade our Pan OS from 8.1.21 to 9.1.x. Some of our Global Protect clients - still on very old version - which is 4.1.11. We are in process to upgrade them to latest 5.2.x. My query is - Once we upgrade our pan OS to 9.1 and if we miss out few clients on old version - will 9.1.x allow them to download and update t...

Resolved! You have X seconds remaining to log in and reconnect to GlobalProtect

Any idea how you can "log in" to global protect?When it switches from pre-logon to the user, it should pop the Microsoft AzureAD window to log in and saml auth to azure. But when you clickon this notification nothing happens. Same thing in v 5.2 and 6.0 of globalprotect. This does not always happen. Its intermittant across Windows 10 and 11.  

seconds-remaing-to-connect-to-gp.jpg
ksauer507 by L3 Networker
  • 3854 Views
  • 1 replies
  • 0 Likes

Resolved! GP IPsec tunnel always falling back to SSL

Hi All, A customer recently migrated for 2 x PA-3020 to 2 x PA-460 running PAN OS 10.1.1. Since migrating they are having some odd issues with Global Protect, 90% of the time GP is connecting as SSL, even though IPsec is enabled on the tunnel, and when occasionally it does connect as IPsec, after 5 mins or some times a couple of hours it will fa...

Ben-Price by L4 Transporter
  • 27173 Views
  • 13 replies
  • 0 Likes

Using GlobalProtect on multi-user server to gain User-ID visibility - possible?

We've enjoyed using globalprotect in combination with palo alto firewall policies over the past few years to allow particular policies to only apply to particular users, who are of course identified by the user signing into the globalprotect client. We were wondering if we could expand on this capability. We don't need VPN capability, we just wa...

  • 1685 Posts
  • 68 Subscriptions
Top Solution Authors
Top Liked Authors
Labels