GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
About GlobalProtect Discussions
Welcome to the GlobalProtect discussion area! Here, you can engage in conversations about GlobalProtect, explore new insights, and stay updated on ongoing discussions. Check back regularly for the latest updates and community insights on GlobalProtect.

Discussions

iphone not able to connect to Global protect

iphone not able to connect to Global protect, however things works fine on Android, windows, Mac and other OS. I do have settings on VPN portal set to on-demand. I'm using SAML for authentication. I see that the portal authenticates the user, request reach vpn gateway before-login (gateway prelogin) SAML request is sent and later no logs logs.....

GlobalProtect Fails During Pre-Login with WinHttpReceiveResponse Error 12152

GlobalProtect is unable to connect during the pre-login phase. Verified all required certificates are installed on the endpoint. Confirmed certificates are located in the appropriate certificate stores. Collected and reviewed: GlobalProtect logs TSF Firewall packet captures We got the following error in PanGPS.log:2 3(P5136-T8916)Debug(54...

Resolved! [SOLVED] GPUDATE /FORCE DOESN'T WORK WITH GLOBAL PROTECT

Hello LiveCommunity Team! I created this post to share my experience regarding an issue involving GlobalProtect users from Prisma Access who attempt to run gpupdate /force to update GPO policies from the DC server, and who encounter the following error:CMD ERROR GPUPDATE /FORCEC:\WINDOWS\system32>gpupdate /force Updating policy...User polic...

DanielSRomero_1-1778369596055.png
DanielSRomero_2-1778369715172.png
DanielSRomero_4-1778370034165.png

Resolved! Global Protect count current users not match statistics

Hey thereThe counts are not matching between: >show global-protect-gateway summary detail GlobalProtect Gateway: connect-gtw:Current Users: 675Previous Users: 4520current-user : 675 Also with MIB OID .1.3.6.1.4.1.25461.2.1.2.5.1.3.0 panGPGWUtilizationActive Tunnels shows 675 But >show user ip-user-mapping all type GPTotal: 225 usersi...

kuschg by L0 Member
  • 327 Views
  • 1 replies
  • 0 Likes

Can you configure clientless VPN in SCM ?

I have the license installed and dynamic updates for clientless installed. We only have the Agent Licensing for GP and Prisma. We already have Global protect configured though SCM. But I cannot find anything about clientless vpn setup in SCM. I would have to overide my config directly on the firewall ?

E.Egger by L0 Member
  • 609 Views
  • 1 replies
  • 0 Likes

Important Update: GlobalProtect App 6.2.8-h12 [6.2.8-c1032] & GlobalProtect App 6.3.3-h13 [6.3.3-c1105] Release Availability

Hey Team, Please be aware that our Product Team has been notified of HIP related issues within the recently released versions of 6.2.8-h12 [6.2.8-c1032] and 6.3.3-h13 [6.3.3-c1105]. Please refer to the following document that discusses how to verify if you match the criteria to be impacted by this and the necessary steps to resolve this if so:...

Resolved! Set up a test Internal Gateway for User-ID logging

Hi everyone planning to set up an Internal Gateway so we can log User-ID and an internal host detection to automatically disable VPN when in the office. We are planning to set up an internal gateway strictly for a test OU to ensure that the changes we make won't disrupt the business. I set up a loopback address from a reservered dhcp(we use Palo...

RPerez481389_0-1783920681442.png
RPerez481389_1-1783920986077.png

"Your login session has expired" errors when authenticating to GP portal

Dear community! We are currently experiencing an issue where after authenticating to the globalprotect portal page with the browser, we get the following message :"“Your login session has expired and you have been logged out for security reasons...” And we cannot get to the portal page. It only works with Mozilla firefox or Edge in IE compa...

Carracido_0-1784638080115.png
Carracido by L4 Transporter
  • 84 Views
  • 0 replies
  • 0 Likes

GlobalProtect Linux client recreates a "GP_HTML" folder in home directory on every start

Hi all, I'm running into a persistent annoyance with the GlobalProtect Linux client. Environment:- GlobalProtect version: 6.2.9-407- OS: Ubuntu (kernel 6.17.0-35-generic, 24.04-based)- Architecture: x86_64 Issue:Every time the GlobalProtect client starts, it creates a folder named `GP_HTML` directly in my home directory (`~/GP_HTML`). This happe...

Issue on Android VPN

Hello DearsI am trying to install Global protect VPN on Android device, but it is unable to processed with that since the certificate is self sign so any other way to solve that problem without replace the current certificate meaning change setting on Andriod device. Best Regards

GP with Certificate base authentication and LDAP, userid not visible in global protect logs

We have setup wherein user get certificate base authentication on pre logon(machine authentication), When user logged into machine, it must shift from machine name to userid. this transition is not happening. We also don;t require GP client login window popup. It must derive userid and password from windows login. Authentication table we have LD...

Brand New Deployment - GlobalProtect vs Prisma Access Agent

About to deploy a set of 1410s and trying to get some feedback on using standard GP vs going w/ PAA? The firewalls will be managed by an on-prem Panorama VM and be using a cloud provider for SAML authentication. I think I've read PAA will support using Panorama as the front-end and a standard NGFW as the device the vpn connects on. Wanted t...

DJ_1924 by L2 Linker
  • 163 Views
  • 1 replies
  • 0 Likes

Unable to make GlobalProtect Changes

Hi all, We recently upgraded to 11.2 and noticed that when trying to make changes on any of our Globalprotect portals I see an "Operation Failed" and it calls out the clientless-vpn (when we don't use or have this configured). This issue is also seen at one of our branch sites, PA-1420 on same OS11.2.10-h3. Thanks

BRana_0-1783716228428.png
B.Rana by L0 Member
  • 142 Views
  • 1 replies
  • 0 Likes

GP 6.2.8-C982 causes popups on Windows, no Release Notes?

We just rolled out the latest 6.2.8 update (previous version C948), and since it's been installed, users repeatedly get certificate confirmation popups to connect the client. The previous client version never did this, the popups are not just happening on initial connection, but multiple times as users tabs around applications. Is this a known i...

M.Studte by L1 Bithead
  • 590 Views
  • 2 replies
  • 0 Likes

Global protect with LOOPBACK Interface

GlobalProtect Agent Connection Failure with Custom Port (23590) - Loopback Gateway Issue I have a Palo Alto NGFW (public IP: 80.75.164.100) connected directly to the internet with a DNS record (vpn4.example.com) pointing to this IP. I’m trying to configure GlobalProtect Agent to connect via a custom port (23590) instead of the standard port 443,...

m.waked by L0 Member
  • 293 Views
  • 1 replies
  • 0 Likes
  • 1685 Posts
  • 68 Subscriptions
Top Solution Authors
Top Liked Authors
Labels