GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
About GlobalProtect Discussions
Welcome to the GlobalProtect discussion area! Here, you can engage in conversations about GlobalProtect, explore new insights, and stay updated on ongoing discussions. Check back regularly for the latest updates and community insights on GlobalProtect.

Discussions

Does the GlobalProtect Credential Provider CLSID change between versions?

Hi all, We are considering using the Windows GPO “Assign a default credential provider” so that GlobalProtect is selected by default even on the “Other user” sign-in screen. It looks like we need to specify the CLSID (GUID) of the GlobalProtect Credential Provider in the GPO. I would like to confirm: 1. Is the GlobalProtect Credential Prov...

iphone not able to connect to Global protect

iphone not able to connect to Global protect, however things works fine on Android, windows, Mac and other OS. I do have settings on VPN portal set to on-demand. I'm using SAML for authentication. I see that the portal authenticates the user, request reach vpn gateway before-login (gateway prelogin) SAML request is sent and later no logs logs.....

Resolved! Wrapped around the axle - iOS + GP + Client Certificate generated on the Palo

I’ve got an iPad that has the GlobalProtect client installed. I’ve created self-signed certs using the PA 440 as the CA for the client auth, to enable MFA (user+pass & cert). I get this error “A valid client certificate is required for authentication. If the issue persists, contact your system administrator”. I’ve been troubleshooting ...

IMG_0623.jpeg
IMG_0620.png
IMG_0619.jpeg
IMG_0617.png

GP logs

We are using Prisma access global protect services. with SAML authentication. we have around 2000 users . we are looking a solution if any users unable to connect the global protect gateway so we can to get the email alert. XYZ users are not able to connect global protect gateway ______ reason. can anyone help to get this solution.

Endpoint Traffic Policy Enforcement on Prisma Access

Hello, I am trying out the "Endpoint Traffic Policy Enforcement" feature on GP to enforce users who are actively trying to avoid connecting to VPN (even if this is set to connect automatically). I have set this setting to "All traffic" on a small test group and it was working great. However, one of the users tried to connect to a Windows 11 ...

Globalprotect for android ver 6.1.14 issue

Hello Team, I am recently having problem with GlobalProtect agent for Android phones. previously everything was fine and no problems until version 6.1.11.x. now upgraded to Globalprotect for android version 6.1.14.x. since this version was installed o the mobiles, we are having problems connecting to the portal. as soon as yo...

Resolved! Global Protect SAML: authentication works fails on matching client config not found. Group not matching.

Hi, I am trying to configure globalprotect to use SAML authentication for the portal and gateway. The authentication seems to work but when, but i am not getting a valid client config when i use groups in allow list. I am sure it is related to group mapping and user id but don't know where exactly it is going wrong. I have the following conf...

zGomez_0-1694012059685.png
zGomez_1-1694012177202.png
zGomez_2-1694012661065.png
zGomez_3-1694012917716.png
zGomez by L3 Networker
  • 5040 Views
  • 2 replies
  • 0 Likes

IP Validation for GlobalProtect Public IP

Hi All, We are currently attempting to complete GlobalSign IP address validation for our GlobalProtect public IP address.GlobalSign's validation process requires access to a challenge file under:/.well-known/pki-validation/However, our understanding is that Palo Alto does not normally host files under this path.In addition, HTTP validation via p...

Having issues connecting to GlobalProtect VPN from laptop connected with iPhone and JiO ISP hotspot

Hello community, we are facing a strange issue with the globalprotect connectivity. where we are trying to connect vpn from laptop and its connected via iPhone hotspot having JiO sim card, its on 5G network. we have SAML configured to login the global protect but its not happening in above scenario. did someone face similar issue and hav...

Configuring GlobalProtect via Ansible

Hi,I'm working on creating an automated Ansible process through which I can configure GlobalProtect in PAN Firewall.The automaton process I try to create it based on the official Paloalto Repository containing ansible playbooks:GitHub - PaloAltoNetworks/ansible-playbooks: Sample playbooks for the Palo Alto Networks Ansible modules.Unfortunately,...

GlobalProtect Cert+SAML

Hello, I'm reaching out to see if anyone has configured GlobalProtect with cert+SAML authentication with multiple gateways across multiple firewalls. I've been attempting to configure this, however, whenever I use cert+SAML at the gateway and I attempt to switch gateways after logging in, the logs always show "client cert not present". I h...

"Your login session has expired" errors when authenticating to GP portal

Dear community! We are currently experiencing an issue where after authenticating to the globalprotect portal page with the browser, we get the following message :"“Your login session has expired and you have been logged out for security reasons...” And we cannot get to the portal page. It only works with Mozilla firefox or Edge in IE compa...

Carracido_0-1784638080115.png
Carracido by L4 Transporter
  • 233 Views
  • 2 replies
  • 1 Likes

Global Protect Android client failing with certificate error after upgrading PAN-OS

Dear all, I have a strange error after I upgraded my firewall to PAN-OS 11.1.15 to fix a GP vulnerability. (18990)06/04 17:44:57:208734 - PanKeyManager: Issuers: CN=ixxx, DC=ixxx, DC=local(18990)06/04 17:44:57:208841 - PanKeyManager: Use Cert: gp_user_new(18990)06/04 17:44:57:208883 - PanKeyManager: getPrivateKey for alias: gp_user_new(1899...

GP with Certificate base authentication and LDAP, userid not visible in global protect logs

We have setup wherein user get certificate base authentication on pre logon(machine authentication), When user logged into machine, it must shift from machine name to userid. this transition is not happening. We also don;t require GP client login window popup. It must derive userid and password from windows login. Authentication table we have LD...

  • 1692 Posts
  • 68 Subscriptions
Top Solution Authors
Top Liked Authors
Labels