GlobalProtect
GlobalProtect App 6.2.5 Windows and macOS Addressed Issues
Table of Contents
Expand All
|
Collapse All
GlobalProtect Docs
-
10.1 & Later
- 10.1 & Later
- 9.1 (EoL)
-
- How Does the App Know Which Certificate to Supply?
- Set Up Cloud Identity Engine Authentication
- Configure GlobalProtect to Facilitate Multi-Factor Authentication Notifications
- Enable Delivery of VSAs to a RADIUS Server
- Enable Group Mapping
-
-
- GlobalProtect App Minimum Hardware Requirements
- Download the GlobalProtect App Software Package for Hosting on the Portal
- Host App Updates on the Portal
- Host App Updates on a Web Server
- Test the App Installation
- Download and Install the GlobalProtect Mobile App
- View and Collect GlobalProtect App Logs
-
-
- Deploy App Settings in the Windows Registry
- Deploy App Settings from Msiexec
- Deploy Scripts Using the Windows Registry
- Deploy Scripts Using Msiexec
- Deploy Connect Before Logon Settings in the Windows Registry
- Deploy GlobalProtect Credential Provider Settings in the Windows Registry
- SSO Wrapping for Third-Party Credential Providers on Windows Endpoints
- Enable SSO Wrapping for Third-Party Credentials with the Windows Registry
- Enable SSO Wrapping for Third-Party Credentials with the Windows Installer
- Deploy App Settings to Linux Endpoints
- GlobalProtect Processes to be Whitelisted on EDR Deployments
-
-
- Mobile Device Management Overview
- Set Up the MDM Integration With GlobalProtect
- Qualified MDM Vendors
-
-
- Set Up the Microsoft Intune Environment for Android Endpoints
- Deploy the GlobalProtect App on Android Endpoints Using Microsoft Intune
- Create an App Configuration on Android Endpoints Using Microsoft Intune
- Configure Lockdown Mode for Always On Connect Method on Android Endpoints Using Microsoft Intune
-
- Deploy the GlobalProtect Mobile App Using Microsoft Intune
- Configure an Always On VPN Configuration for iOS Endpoints Using Microsoft Intune
- Configure a User-Initiated Remote Access VPN Configuration for iOS Endpoints Using Microsoft Intune
- Configure a Per-App VPN Configuration for iOS Endpoints Using Microsoft Intune
-
-
-
- Create a Smart Computer Group for GlobalProtect App Deployment
- Create a Single Configuration Profile for the GlobalProtect App for macOS
- Deploy the GlobalProtect Mobile App for macOS Using Jamf Pro
-
- Enable GlobalProtect System Extensions on macOS Endpoints Using Jamf Pro
- Enable GlobalProtect Network Extensions on macOS Big Sur Endpoints Using Jamf Pro
- Add a Configuration Profile for the GlobalProtect Enforcer by Using Jamf Pro 10.26.0
- Verify Configuration Profiles Deployed by Jamf Pro
- Remove System Extensions on macOS Monterey Endpoints Using Jamf Pro
- Non-Removable System Extensions on macOS Sequoia Endpoints Using Jamf Pro
- Uninstall the GlobalProtect Mobile App Using Jamf Pro
-
- Configure HIP-Based Policy Enforcement
- Configure HIP Exceptions for Patch Management
- Collect Application and Process Data From Endpoints
- Redistribute HIP Reports
-
- Identification and Quarantine of Compromised Devices Overview and License Requirements
- View Quarantined Device Information
- Manually Add and Delete Devices From the Quarantine List
- Automatically Quarantine a Device
- Use GlobalProtect and Security Policies to Block Access to Quarantined Devices
- Redistribute Device Quarantine Information from Panorama
- Troubleshoot HIP Issues
-
-
- Enable and Verify FIPS-CC Mode on Windows Endpoints
- Enable and Verify FIPS-CC Mode on macOS Endpoints
- Enable and Verify FIPS-CC Mode Using Workspace ONE on iOS Endpoints
- Enable FIPS Mode on Linux EndPoints with Ubuntu or RHEL
- Enable and Verify FIPS-CC Mode Using Microsoft Intune on Android Endpoints
- FIPS-CC Security Functions
- Resolve FIPS-CC Mode Issues
-
-
- Remote Access VPN (Authentication Profile)
- Remote Access VPN (Certificate Profile)
- Remote Access VPN with Two-Factor Authentication
- GlobalProtect Always On VPN Configuration
- Remote Access VPN with Pre-Logon
- User-Initiated Pre-Logon Connection
- GlobalProtect Multiple Gateway Configuration
- GlobalProtect for Internal HIP Checking and User-Based Access
- Mixed Internal and External Gateway Configuration
- Captive Portal and Enforce GlobalProtect for Network Access
- GlobalProtect on Windows 365 Cloud PC
-
- About GlobalProtect Cipher Selection
- Cipher Exchange Between the GlobalProtect App and Gateway
-
- Reference: GlobalProtect App Cryptographic Functions
-
- Reference: TLS Ciphers Supported by GlobalProtect Apps on macOS Endpoints
- Reference: TLS Ciphers Supported by GlobalProtect Apps on Windows Endpoints
- Reference: TLS Ciphers Supported by GlobalProtect Apps on Android 6.0.1 Endpoints
- Reference: TLS Ciphers Supported by GlobalProtect Apps on iOS 10.2.1 Endpoints
- Reference: TLS Ciphers Supported by GlobalProtect Apps on Chromebooks
- Ciphers Used to Set Up IPsec Tunnels
- SSL APIs
-
- View a Graphical Display of GlobalProtect User Activity in PAN-OS
- View All GlobalProtect Logs on a Dedicated Page in PAN-OS
- Event Descriptions for the GlobalProtect Logs in PAN-OS
- Filter GlobalProtect Logs for Gateway Latency in PAN-OS
- Restrict Access to GlobalProtect Logs in PAN-OS
- Forward GlobalProtect Logs to an External Service in PAN-OS
- Configure Custom Reports for GlobalProtect in PAN-OS
-
6.3
- 6.3
- 6.2
- 6.1
- 6.0
- 5.1
-
- Download and Install the GlobalProtect App for Windows
- Use Connect Before Logon
- Use Single Sign-On for Smart Card Authentication
- Use the GlobalProtect App for Windows
- Report an Issue From the GlobalProtect App for Windows
- Disconnect the GlobalProtect App for Windows
- Uninstall the GlobalProtect App for Windows
- Fix a Microsoft Installer Conflict
-
- Download and Install the GlobalProtect App for macOS
- Use the GlobalProtect App for macOS
- Report an Issue From the GlobalProtect App for macOS
- Disconnect the GlobalProtect App for macOS
- Uninstall the GlobalProtect App for macOS
- Remove the GlobalProtect Enforcer Kernel Extension
- Enable the GlobalProtect App for macOS to Use Client Certificates for Authentication
-
6.1
- 6.1
- 6.0
- 5.1
-
6.2
- 6.3
- 6.2
- 6.1
- 6.0
- 5.1
- Features Introduced
- Changes to Default Behavior
- Associated Software and Content Versions
-
- GlobalProtect App 6.2.8 Windows and macOS Known Issues
- GlobalProtect App 6.2.7 Windows and macOS Known Issues
- GlobalProtect App 6.2.6-c857 Windows and macOS Known Issues
- GlobalProtect App 6.2.1-c31 Linux Known Issues
- GlobalProtect App 6.2.6 Windows and macOS Known Issues
- GlobalProtect App 6.2.5 Windows and macOS Known Issues
- GlobalProtect App 6.2.4 Windows and macOS Known Issues
- GlobalProtect App 6.2.3-c287 Windows and macOS Known Issues
- GlobalProtect App 6.2.3 Windows and macOS Known Issues
- GlobalProtect App 6.2.2 Windows and macOS Known Issues
- GlobalProtect App 6.2.1 Linux Known Issues
- GlobalProtect App 6.2.1 Windows and macOS Known Issues
- GlobalProtect App 6.2.0 Linux Known Issues
-
- GlobalProtect App 6.2.8 Windows and macOS Addressed Issues
- GlobalProtect App 6.2.7 Addressed Issues
- GlobalProtect App 6.2.6-c857 Windows and macOS Addressed Issues
- GlobalProtect App 6.2.1-c31 Linux Addressed Issues
- GlobalProtect App 6.2.6 Windows and macOS Addressed Issues
- GlobalProtect App 6.2.5 Windows and macOS Addressed Issues
- GlobalProtect App 6.2.4 Windows and macOS Addressed Issues
- GlobalProtect App 6.2.3-c287 Addressed Issues
- GlobalProtect App 6.2.3 Windows and macOS Addressed Issues
- GlobalProtect App 6.2.2 Windows and macOS Addressed Issues
- GlobalProtect App 6.2.1 Linux Addressed Issues
- GlobalProtect App 6.2.1 Windows and macOS Addressed Issues
- GlobalProtect App 6.2.0 Linux Addressed Issues
GlobalProtect App 6.2.5 Windows and macOS Addressed Issues
GlobalProtect app 6.2.5 Windows and macOS. addressed issues
The following table lists the issues that are addressed in GlobalProtect app 6.2.5
Windows and macOS.
Issue ID | Description |
---|---|
GPC-21656 | Fixed an issue where an unexpected extra string was added to the end of the MFA prompt. |
GPC-21533 | Fixed an issue where GlobalProtect connected and disconnected in a loop |
GPC-21483 | Fixed an issue where users are intermittently unable to connect to GlobalProtect and get stuck at the connecting stage. |
GPC-21465 | Fixed an issue where GlobalProtect is stuck in "Connecting... Finding the Best Available Gateway". |
GPC-21442 | Fixed an issue where there was a delay in GlobalProtect restoring connectivity after the Windows host woke up from modern standby. |
GPC-21443 | Fixed an issue where GlobalProtect crashed when the PanGPS service was stopped. |
GPC-21414 | Fixed an issue where GlobalProtect using SAML authentication gets stuck in a connecting loop upon the expiration of the authentication cookie. |
GPC-21392 | Fixed an issue where GlobalProtect is stuck in the connecting state for 2-3 minutes during Windows Pre-logon. |
GPC-21387 | Fixed an issue that prevented users from connecting to Wi-Fi networks when GlobalProtect was disconnected. |
GPC-21355 | Fixed an issue where GlobalProtect was incorrectly showing as connected during Windows pre-logon. |
GPC-21301 | Fixed an issue where after upgrading to GlobalProtect 6.2.4, users were unable to connect to GlobalProtect intermittently when Enforcer is enabled. |
GPC-21247 | Fixed an issue where HIP checks for Disk Encryption status were failing after Windows and Mac hosts were rebooted, on low power mode or were resuming from standby. |
GPC-21206 | Fixed an issue where GlobalProtect intermittently does not restore connection after the user logs back in or wakes a Windows host. |
GPC-21172 | Fixed an issue where the GlobalProtect agent gets disconnected right after successful connection when SAML embedded browser authentication is used along with "Enforce GlobalProtect for Network Access". |
GPC-21161 | Fixed an issue where the notifications prior to 'Login Lifetime Expiration' and 'Inactivity Logout' were not displayed even when enabled. |
GPC-21101 | Fixed an issue where the embedded browser pop-up with "Login Successful" was displayed for each SAML authentication. |
GPC-21057 | Fixed an issue where HIP checks for Disk Encryption status were failing on Windows during modern standby. |
GPC-21035 | Fixed an issue where GlobalProtect HIP did not identify the definition version of the SentinelOne Agent. |
GPC-21024 | Fixed an issue where a HIP notification configured as "pop-up-message" for pre-logon does not show up. The pop up window is blank. |
GPC-21005 | Fixed an issue where after submitting the SAML credentials, a blank screen was displayed and GlobalProtect got stuck in that stage. |
GPC-20991 | Fixed an issue where the 'Extended Key Usage OID' value for certificate selection was deleted during an upgrade of the GlobalProtect agent. This forces users to have to manually select the correct certificate tp be used for authentication. |
GPC-20988 | Fixed an issue where GlobalProtect failed to resolve DNS queries when the 'Allow traffic to specified FQDN when Enforce GlobalProtect Connection for Network Access is enabled and GlobalProtect Connection is not established' configuration is set. |
GPC-20983 | Fixed an issue where the GlobalProtect app remains stuck in the connecting stage when Windows computer resumes from sleep. |
GPC-20943 | Fixed an issue where the GlobalProtect enforcer blocked DHCP packets. |
GPC-20895 | Fixed an issue where GlobalProtect users on macOS were able to add and modify the portal address even when portal agent configuration was "Allow User to Change Portal Address = NO". |
GPC-20884 | Fixed an issue where users get disconnected a few seconds after logging in to VDI when GlobalProtect connects. They are unable to reconnect after that. |
GPC-20864 | Fixed an issue where the GlobalProtect embedded browser login window did not stay pinned to the front of all open windows on Windows and MAC computers. |
GPC-20839 | Fixed an issue where system extensions on MacBooks were not updated upon GlobalProtect app upgrade. |
GPC-20838 | Fixed an issue where the HIP report generation was taking longer than the 'Max Wait Time' on Windows devices when anti-malware and disk encryption checks are configured. |
GPC-20771 | Fixed an issue where GlobalProtect 6.2 users on Windows 11(ARM & Intel) devices cannot connect to GlobalProtect due to "The Parameter is incorrect" error. |
GPC-20770 | Fixed an issue where certain GlobalProtect HIP checks on Windows devices failed when there was no internet connectivity. |
GPC-20741 | Fixed an issue where the GlobalProtect app intermittently disconnects from the gateway when using the embedded browser for SAML authentication. |
GPC-20736 | Fixed an issue where users are being logged out from GlobalProtect when the device wakes up from modern standby and network discovery happens. |
GPC-20700 | Fixed an issue where macOS users had to enter the SAML username and password each time they refreshed or rebooted their computer especially when using Safari or Embedded browser. |
GPC-20692 | Fixed an issue where GlobalProtect 6.2.3 with SAML authentication (via Okta) opens the embedded browser page in the background instead of the foreground. |
GPC-20645 | Fixed an issue where GlobalProtect app in macOS is stuck in connecting state when the device wakes up from sleep. |
GPC-20626 | Fixed an issue where the GlobalProtect client overwrites valid authentication override cookie with empty authentication override cookie from portal when using cached portal configuration. |
GPC-20601 | Fixed an issue where macOS users are unable to connect to GlobalProtect after upgrading from version 6.2.2 to 6.2.3 via JAMF. |
GPC-20595 | Fixed an issue where GlobalProtect users were unable to connect after upgrading to 6.2.3-270 and received a "Your internet access is blocked" error during SAML authentication using the embedded browser. |
GPC-20550 | Fixed an issue where Zoom and Outlook apps intermittently stop connecting on macOS with an error "You are unable to connect to Zoom. Please check your network connection and try again" when the apps are excluded under both domains and applications. |
GPC-20466 | Fixed an issue where when the tunnel is broken on Windows computers in modern standby mode, the Enforcer does not work even when it is enabled. |
GPC-20442 | Fixed an issue on appliances running PanOS 10.1.11-h1 and GlobalProtect 6.0.10-811 where the tunnel status failed to update to connected immediately after establishment. This problem was specific to IPv4-only clients connecting to dual-stack (IPv4 + IPv6) GlobalProtect gateways or portals. |
GPC-20441 | Fixed an issue where HIP reports are sometimes not available on the firewall for newly connected users. |
GPC-20416 | Fixed an issue where there is no network discovery once the laptop came out of standby. |
GPC-20360 | Fixed an issue where the GlobalProtect app is stuck in the connecting status after authentication and does not connect until the app is restarted or the computer is rebooted. |
GPC-20292 | Fixed an issue where RDP to Azure VDI clients disconnects when GlobalProtect is enabled on the VDI client with SAML authentication and with 'Enforce GlobalProtect for Network Access' enabled |
GPC-20191 | Fixed an issue where PanGPA.exe crashes on Windows clients |
GPC-20114 | Fixed an issue where GlobalProtect on MacOS was incorrectly selecting client certificates without a private key for certificate authentication. |
GPC-20112 | Fixed an issue where the GlobalProtect HIP check incorrectly detected Real time protection status for Kaspersky Endpoint Security, which caused the device to fail the HIP check. |
GPC-20072 | Fixed an issue where domain-based split tunneling was not working on MAC with Edge Chromium or Google Chrome browser though it was working on Safari. |
GPC-19819 | Fixed an issue where SAML default browser IDP traffic is blocked during a refresh connection when GlobalProtect is connected to the internal network with 'Enforce GlobalProtect for Network Access' enabled. |
GPC-19269 | Fixed an issue where GlobalProtect would show as "connecting" but never actually connect until the user restarted GlobalProtect on their Windows machine. |
GPC-18943 | Fixed an issue where GlobalProtect would fail to connect on Windows hosts that were woken up from modern standby by initiating an RDP to the host. |