GlobalProtect 6.3.3-1121 connects automatically despite on demand is enable

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

GlobalProtect 6.3.3-1121 connects automatically despite on demand is enable

L0 Member

Hello Team,

After upgrading GlobalProtect to 6.3.3-1121, we have noticed that Mac devices are automatically connecting to the VPN without any user intervention.

 

Is anyone else experiencing the same issue after upgrading to this version?

 

Please let us know if you have observed similar behavior

8 REPLIES 8

L0 Member

Yes, we are facing the same problem on the new version.

L0 Member

we have the same problem in the 6.3.3-1121

L0 Member

same here
we just upgraded yesterday, after testing an older 6.3.3 for a longer amount of time.... 😕

L0 Member

Has anyone here found a solution to this.  So far we've just had to roll back to older version.  Only some users however have seen this, but unfortunately too many.  All are running Tahoe and are on m1 macs.  

 

 

L0 Member

Just a quick update for anyone running into this: A clean reinstall did the trick for us.

Running the uninstaller via GlobalProtect-6.3.3-c1121.pkg, followed by a fresh install and a system reboot, resolved the issue on our end.

Worth noting: One user reported seeing a single reconnect right after the initial setup, but after manually disconnecting one more time, it stabilized completely without any further action. The client now stays disconnected as expected.

L1 Bithead

Also seeing this issue. GlobalProtect is not even trying to log in to the portal in this case, it just keeps sending pre-logins directly to the gateway - can anyone else confirm whether this exact behaviour specifically is happening for them?

 

I'm getting a gateway-prelogin with SAML Request log message on the GlobalProtect logs every few minutes for affected users (which is to say all of them on version 1121 from what I can tell)

L1 Bithead

I've had to tell users to disable GlobalProtect entirely when they don't need it. Just as a workaround (without adding further fuel to the flame by having BYOD users rollback then upgrade again later)

L1 Bithead

Also I'd greatly appreciate if anyone could confirm that this behaviour did not occur in 1046, just in case I have to rollback (as we were on 676 before)

  • 379 Views
  • 8 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!