Changes to Default Behavior
Focus
Focus
GlobalProtect

Changes to Default Behavior

Table of Contents

Changes to Default Behavior

Changes to default behavior in GlobalProtect app 6.3.

Changes to Default Behavior in GlobalProtect App 6.3.3-h12 (6.3.3-c1046) Windows and Mac

  • When the endpoint's physical network interface is IPv4-only, GlobalProtect automatically suppresses both IPv6 route installation and IPv6 virtual adapter address assignment, even if the gateway provides an IPv6 address in addition to an IPv4 address.
    To force IPv6 virtual adapter provisioning, set the split-tunnel-keep-tunnel-ipv6 key to yes under GlobalProtect > Settings in the plist at /Library/Preferences/com.paloaltonetworks.GlobalProtect.settings.plist, then reboot the endpoint for the change to take effect.
  • After you successfully authenticate with a captive portal through the GlobalProtect embedded browser, the embedded browser window now closes automatically after 30 seconds. Previously, the embedded browser remained open after authentication. The embedded browser displays a countdown notification before closing. This change prevents the open browser window from being used to bypass the GlobalProtect VPN tunnel after captive portal authentication is complete.

Changes to Default Behavior in GlobalProtect App 6.3.3-h2 (6.3.3-674) Linux

There are no changes to default behavior in GlobalProtect 6.3.3-h2 (6.3.3-674) Linux.

Changes to Default Behavior in GlobalProtect App 6.3.3-h9 (6.3.3-999) Windows and macOS

There are no changes to default behavior in GlobalProtect 6.3.3-h9 (6.3.3-999) Windows and macOS.

Changes to Default Behavior in GlobalProtect App 6.3.3-h7 (6.3.3-c876)

  • Clicking the GlobalProtect icon in the Finder or Applications folder on macOS clients now opens the GlobalProtect client, mirroring the taskbar behavior. This change provides a consistent user experience by ensuring the interface is immediately visible regardless of the launch method. Previously, launching the app via the Applications folder or Spotlight provided no visual feedback if the GlobalProtect app was already running in the background.
  • macOS endpoints only When GlobalProtect cannot resolve an IPv6 address for the gateway, it no longer installs any IPv6 routes — including the ::/0 default route — even when the gateway pushes IPv6 access routes, making IPv6 destinations unreachable through the tunnel. This occurs when the endpoint has no usable global IPv6 address (macOS returns no AAAA records to the app in this state), when the gateway FQDN has no AAAA record, or when the gateway is configured by IPv4 address.
    To restore IPv6 route installation, set split-tunnel-keep-tunnel-ipv6 to yes under GlobalProtect > Settings in the plist at /Library/Preferences/com.paloaltonetworks.GlobalProtect.settings.plist, then restart the endpoint.