- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-16-2024 05:02 AM
Good Day community
Looking for some advise and guidance.
we are running into an issue where we have random users trying to connect to Global Protect experiencing issues where they are not redirected to the SAML authentication page, but rather the imbedded authentication of the application itself. The user either needs to stop the services of Global Protect or reboot their system before they can connect.
We are not seeing the authentication attempts on the firewall when it fails only when they are making a successful connection.
08-19-2024 04:33 PM
Hi @mariuse ,
When users aren't redirected, are they connected to the correct portal configured for SAML?
08-19-2024 10:51 PM
Hi JayGolf
Yes they are as per the configuration, but not seeing anything in logs for any failed authentication, we are only seeing logs after a reboot or successful SAML authentication. All access was working, we don't know if this is due to the recent update of the client to 6.2.2.
We are waiting for the logs from the SAML team and logs from a user.
08-21-2024 07:43 PM
@mariuse Which PAN OS version are you running?
Regards
08-28-2024 02:36 AM
We are running on OS 10.1.14-h2 and we also tried running the latest GP client with still the same result.
We are currently testing forcing the clients to use only one DC and so far no issues picked up.
We are suspecting a F5 load-balance issue which they are still busy investigating.
09-05-2024 05:10 AM
Update -
We forced user to connect to DC2 and no issues picked up, they are not testing connection to DC1 and so far no issues.
Looks like a F5 DNS load-balance issue that we are facing.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!