Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

See the users version of Global Protect in Panorama

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Palo Alto Networks Approved
Palo Alto Networks Approved
Community Expert Verified
Community Expert Verified

See the users version of Global Protect in Panorama

L0 Member

I am getting ready to test upgrading GlobalProtect using the "Allow Transparently" option of the upgrade for a small subset of users. I want to verify the upgrade worked from Panorama without reaching out to the user for verification that it worked. I can't seem to locate where I would see the user's client version for GP in Panorama. My initial thought was in HIP or Remote User.

 

I feel like I am just missing something but haven't had any luck looking through articles so any advice or direction is appreciated. 

3 REPLIES 3

Cyber Elite
Cyber Elite

Thank you for the post @Bo_Olsen

 

Could you go in Panorama to: Monitor > Logs > GlobalProtect, then click on arrow to add: "Client Version":

PavelK_0-1639872178046.png

Your Firewall has to be configured for log forwarding under: Device > Log Settings > GlobalProtect > Forward Method > Panorama.

 

Could you please check whether the above meets your requirements?

 

Kind Regards

Pavel 

Help the community: Like helpful comments and mark solutions.

Hi Pavel, I think that might be the issue, I don't seem to have an option for either one. When I look under  Device > Log Settings > "GlobalProtect" isn't an option to set up the forward. 

Cyber Elite
Cyber Elite

Thank you for the reply @Bo_Olsen

 

I believe the reason why you do not see this option is PAN-OS version. Global Protect log was introduced in PAN-OS 9.1. If you happen to be on PAN-OS 8.1 or 9.0, I would recommend you to upgrade Panorama as well as managed Firewall to 9.1 as versions 8.1 and 9.0 will be end of life on 1st March 2022. This upgrade should resolve your issue with GlobalProtect log forwarding.

 

For the upgrade itself, the order of operation is to upgrade Panorama first, then managed Firewalls. Also watch out for changes to default behavior: https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-release-notes/pan-os-9-0-release-information/cha...

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.
  • 6393 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!