GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
About GlobalProtect Discussions
Welcome to the GlobalProtect discussion area! Here, you can engage in conversations about GlobalProtect, explore new insights, and stay updated on ongoing discussions. Check back regularly for the latest updates and community insights on GlobalProtect.

Discussions

GlobalProtect fails connection

Hi I have just installed GlobalProtect and installation and first connect seems to work, but only a few seconds. I get this: The virtual adapter was not set up correctly due to a delay. GlobalProtect will try again soon. If the issue persists, please restart your system. Tried the following: I uninstalled / reinstalled. Stopped WMI, deleting...

Rathsach by L0 Member
  • 2681 Views
  • 2 replies
  • 0 Likes

Global Protect Choking Internet Access?

To begin with, I am not an IT person but simply an end user in a big company... I work from home and my ISP subscription is 25Mbps download and 5Mbps upload. I am using Bell Wireless Home Internet in Canada - it is a cell phone connected service. My personal computers work very well with these speeds, however... With Global Protect enabled on my...

PCI compliance ECDHE/RSA

There were a couple of discussions on this months ago with no resolution. SecureTrust's PCI scans say that we are failing. We would need to set both RSA and ECDHE to 2048 but there is no option to do so that I know of for the SSL/TLS profile. The workaround that was discussed was to disable ECDHE and RSA. However, among other possible issues, ...

Global Protect Notification before disconnect before the login timeout

Hi, We have by company policy a Global Protect VPN login timeout of 24 hours. However, with Cisco Anyconnect users got a notification at least 1 hour before they were going to be disconnected. I am checking to see if there is a way to have some sort of notification before they get disconnected? I have been trying to fine documentation and artic...

11618 - TCP/IP SYN+FIN Packet Filtering Weakness resolution

VA scan flag out the below for GP Portal URL 11618 - TCP/IP SYN+FIN Packet Filtering Weakness-SynopsisIt may be possible to bypass firewall rules.DescriptionThe remote host does not discard TCP SYN packets that have the FIN flag set.Depending on the kind of firewall you are using, an attacker may use this flaw to bypass its rules. See Alsohttps:...

How to launch GlobalProtect App with its URL scheme/deeplink on iPhone?

Hello everyone, I have a question whether or not GlobalProtect Mobile App provides a way such as Url scheme/deep linking/universal link which is able to be launched by the custom website on safari or other mobile apps. Our business background is: Users have installed GlobalProtect mobile app on iPhone. Before they logged into a custom intern...

Moiradu by L0 Member
  • 1553 Views
  • 0 replies
  • 0 Likes

GlobalProtect: Using an alternative port

Good morning. I require a bit of assistance for deploying GlobalProtect with a twist. A client of ours wishes to deploy Global Protect but unfortunately, they also have a Web Facing application using SSL on the same ISP interface. This is unfortunately causing issues since GP also makes use of 443(SSL) and due to the DNAT rule in place for t...

MGiusti by L0 Member
  • 3048 Views
  • 1 replies
  • 0 Likes

Browser behavior when using SAML authentication with GlobalProtect

We recently changed from using our internal AD for authentication to GP external portal/gateway to using SAML authentication with MFA using Azure AD. The testing for company users was fairly consistent but involves a lot of browser activity (prompt for AD creds, MFA prompt and two GP prompts). After a few successful logins this process usually...

Resolved! PA-440 Global Protect VPN - no Internet after connecting, only local resources

I've recently setup Global Protect Gateway/Portal but after connecting do not have access to Internet, only local resources. A coworker and I have been going through the configuration comparing it to other working PA-220's we have at work but nothing seems to working. Using Global Protect client 6.0.3 DNS for IP Pool is configured for 9.9.9.9 an...

Inactivity logout on missing HIP check after Windows update

We have been having an issue with a handful of random always-on GP clients (out of ~250) getting automatically logged out of the Gateway every 3 hours after monthly Windows update cycles. Looking at logging, the client stops hourly HIP check reporting and hits the Inactivity Logout timer (3 hour). On reconnect a single HIP check is sent and then...

Global Protect Windows logon PIN/Password

Hi, I am currently on GP 5.2.10 & I logon to Windows 11 via a PIN. When I upgrade to 6.1.0 my windows 11 laptop defaults to password & I have to change it to PIN and then logon. When I revert back to 5.2.10 it defaults to PIN logon. Is there a way to set PIN as a default when I upgrade to GP 6.1.0 Thanks.

Getting connection failed

Hello all, Our laptops are seeing the issue where they are working remotely and when the user tries to vpn back in its saying Connection Failedthe network connection is unreachable or the portal is unresponsive. Check the network connection and reconnect. ive tried uninstalling / reinstalling 5.1.x, 5.2.x etc.. reboots in between. tried ever...

MNTech by L0 Member
  • 10274 Views
  • 4 replies
  • 0 Likes

IOS + User logon (Always On) + SAML is not working...

>Founf this in the release note: GPC-6663 The GlobalProtect app for iOS does not support SAML authentication when you configure GlobalProtect with the User-logon (Always On) Connect Method (NetworkGlobalProtectPortals<portal-config>Agent<agent-config>App). This limitation is due to the Apple Network Extension framework, which bloc...

rxie by L3 Networker
  • 7363 Views
  • 2 replies
  • 2 Likes
  • 2062 Posts
  • 68 Subscriptions
Top Solution Authors
Top Liked Authors
Labels