I am planning to upgrade the Globalprotect version from 5.1.7 to 5.2.4. Do I need to push or reinstall SSL / TLS certificate when I am upgrading to GP 5.2.4 ?
Also I am planning to push the GP software (*.msi files) from an SCCM server. May I know is this the best method. And any best practices available while pushing the GP client from SCCM?
the only issue I have experienced from SCCM is that when it is initiated by the user, they get the installation complete message before the service has installed and restarted, if they log off or shut down too soon after the pop up then it will cause some issues as not installed correctly.
I have started moving towards the App option of "Allow Transparently" as seems a lot smoother and less grief but that may be down to my SCCM setup. (not managed by me).
@MickBall , thank you.
For transparent installation, i believe the latest version should be available on the firewall. I am planning to test it on couple of machines first. Once all working fine, I will proceed to upgrade on firewall, then the clients. I hope there won't be any certificate issue after upgrading to 5.2.4.
We've been using both, first deployment is done by using intune.
Then I set update to transparent and for upgrading you need to activate a specific GP version at the firewall.
Sometimes I create a specific duplicate configuration in the Portal for some users to test and have them only upgrade while i have the bulk set to not upgrade.
After a while we upgrade the intune version to the recent version used so new workstations do not fall too far behind.
A new hotfix has been released containing lots of fixes touching our issues:
A hotfix for 5.2.5 has been released with a lot of fixes btw: Addressed Issues in GlobalProtect App 5.2 (paloaltonetworks.com)
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!