- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-15-2024 07:52 AM
We are currently running Global Protect 5.2.1-9 and are slated to upgrade to Global Protect 6.1.4-c720. What I need to understand is that are the clients forced to upgrade when we deploy the new version or can they continue to remain on the old version. We are not sure if this is allowed when upgrading to a major version as it is with a minor version.
11-18-2024 08:31 AM
Hello @ShaunTurner2
When you upgrade the Global Protect client, you have the ability to choose how users will update their clients from five different options. For more information on this, you can visit the following link: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CllpCAC
Regards
11-19-2024 08:24 AM
As @jpomachagua points to, whether the end user is automatically/manually/not upgraded to the GlobalProtect client version on the PaloAlto is set by the "Allow User to Upgrade GlobalProtect App" in the Portal Agent App settings. If set to automatic ("Allow Transparent" or "Internal") or "Manual", the update will happen when either: 1) the end user connects and a new version is present on the PaloAlto, or 2) the Portal config refresh takes place.
If you have a large number of users and you want all clients to update automatically overnight, you should turn the "GlobalProtect App Config Refresh Interval" down to something like 4-6 hours (default 24 hours) several days before the update. That way you can tell all your users to leave their PCs on/connected overnight for the upgrade and update the GlobalProtect version on the PaloAlto that evening. The VPN clients will refresh their config, see the new version, and automatically update overnight. We have found that it sometimes takes some clients multiple refresh cycles to update properly.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!