GlobalProtect ask for password after update from 6.2.3 to 6.2.4

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

GlobalProtect ask for password after update from 6.2.3 to 6.2.4

L1 Bithead

Hello,

We are using PA-3020 with software version 9.1.19, the VPN accounts are local to the PA.

Currently we are on GlobalProtect 6.2.3 and we would like to update to 6.2.4 to protect against CVE-2024-5915. When the update is done, GloabalProtect ask for the password (the username is still filled with the correct information). The users are most of the time (95%) not aware of this password, so i can't imagine having hundred calls to obtain the password. 

Is this behivior normal ? When we updated last june from 6.1.2 to 6.2.3, everything was smooth and no credentials were asked.

Thank you very much for your answers.

 

Regards,

 

Julien 

 

Support SPOC
5 REPLIES 5

Cyber Elite
Cyber Elite

@SupportSPOC Is PAN OS version 9.1 is still supported?

When user connects then the VPN Username and password is Local on the PA?

 

Which connection method you use to connect to the GP?

 

Regards

MP

Help the community: Like helpful comments and mark solutions.

@MP18 PAN OS 9.1 end of support is 30 june 2024 😞

Correct, both VPN username and password are local on the PA

We are using On-Demand connection method.

 

I tried to update from 6.2.3 to 6.2.3-c287 (hotfix version) but same behavior. After the update, GlobalProtect is asking for the password but the username is still present.

 

Thank you for your help !

Support SPOC

@SupportSPOC what happens when you the put the password?

 

Regards

MP

Help the community: Like helpful comments and mark solutions.

@MP18 The connection is established without problem.

Support SPOC

Hi @SupportSPOC ,

As part of GlobalProtect Gateway config,  there option to tell the client to cache the username and the password (or only username or disable credetials caching).

 

As mentioned here - https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm6MCAS cached credentials are saved in the Windows Credential Manager.

 

I am only guessing that after update of the GP client, the cached credetials are no longer considered valid. For that reason user needs to enter the password again. If you haven't change the settings on the firewall, it should cache the credentials again and remember them for subsequent logins.

 

Unfortunately users will need to enter the password at least once after update

  • 151 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!