GlobalProtect 6.3.3-h15 (6.3.3-c1195) macOS and Windows Addressed Issues
Focus
Focus
GlobalProtect

GlobalProtect 6.3.3-h15 (6.3.3-c1195) macOS and Windows Addressed Issues

Table of Contents

GlobalProtect 6.3.3-h15 (6.3.3-c1195) macOS and Windows Addressed Issues

Lists the addressed issues in GlobalProtect 6.3.3-h15 macOS and Windows.
The following table lists the issues addressed in GlobalProtect app 6.3.3-h15 (6.3.3-cc1195) Windows and macOS.
Issue ID
Description
GPC-27555
Fixed an issue where GlobalProtect user connections were disconnecting after one hour, which occurred when the portal refresh process initiated and the client encountered an error during its network configuration update. With this fix, GlobalProtect connections now refresh as expected without interruption.
GPC-27513
Fixed an issue where GlobalProtect intermittently did not detect the Real-time Protection (RTP) state of Windows Defender, which prevented authorized users from accessing resources when Host Information Profile (HIP) policies were applied. This behavior occurred after an upgrade of Windows Defender. With this fix, GlobalProtect properly detects the RTP state of Windows Defender.
GPC-27431
Fixed an issue where the GlobalProtect app service did not start on Windows 11 (Traditional Chinese Edition), which prevented the agent from launching and displayed a memory read error. With this fix, the GlobalProtect app now starts successfully on this operating system configuration.
GPC-27408
Fixed an issue where, on Mac computers, previously configured proxy settings were not restored after a fresh installation of GlobalProtect 6.3.3-830 or 6.3.3-H14, which occurred because a necessary configuration file for proxy information was not installed during the initial setup. With this fix, previously configured proxy settings are correctly restored.
GPC-27403
(GlobalProtect client on Windows devices using SmartCard authentication) Fixed an issue where the GlobalProtect client would unexpectedly terminate and fail to establish a connection, which was caused by inter-process communication issues during the authentication process. With this fix, the client connects as expected.
GPC-27394
Fixed an issue where GlobalProtect gateway certificate verification would fail after a software upgrade, which prevented connections to the gateway. With this fix, gateway certificate verification proceeds as expected.
GPC-27342
Fixed an issue where the GlobalProtect (GlobalProtect) client on macOS would fail to connect using a client certificate after the device woke from sleep, which occurred because the client did not properly re-establish access to the client certificate. With this fix, the client properly handles certificate access issues and re-establishes the connection.
GPC-27281
Fixed an issue where GlobalProtect Host Information Profile (HIP) checks intermittently failed with an "Invalid authentication cookie" error after machines woke up from modern standby, which caused traffic to incorrectly match policies without HIP requirements or fall through to default rules. With this fix, HIP checks proceed as expected, and traffic correctly matches policies based on HIP requirements.
GPC-27149
Fixed an issue where GlobalProtect connections would intermittently stall, preventing internet access. With this fix, GlobalProtect connections establish and maintain properly.
GPC-27056
Fixed an issue where .pfx and .dat files were removed from the Native store upon reboot.
GPC-26994
Fixed an issue where Host Information Profile (HIP) reports were not sent to the gateway intermittently, which resulted in issues with user-IP mapping. With this fix, HIP reports are sent consistently, ensuring accurate user-IP mapping.
GPC-26933
(macOS endpoints only) Fixed an issue where the GlobalProtect app would not connect to the GlobalProtect service after a macOS upgrade and a sleep-wake event. With this fix, the GlobalProtect app connects as expected.
GPC-26928
Fixed an issue where the GlobalProtect client would remain in a connecting state after an initial authentication attempt failed, and would not attempt to connect to alternate gateways. With this fix, the GlobalProtect client now properly transitions out of the connecting state and attempts alternate gateways when authentication fails.
GPC-26910
Fixed an issue where the GlobalProtect embedded browser displayed a blank white screen during Security Assertion Markup Language (SAML) authentication on macOS Tahoe 26.5, which prevented users from completing authentication and connecting to the VPN.
GPC-26842
Fixed an issue where GlobalProtect Host Information Profile (HIP) checks for FileVault disk encryption produced incorrect reports on certain macOS 27 version, which led to failed HIP checks and also resulted in the macOS version being unexpectedly included in the FileVault section of the report. With this fix, Host Information Profile checks for FileVault disk encryption now populate correctly, and the macOS version is no longer included in the FileVault section of the report.
GPC-26811
(On Ubuntu 20.04 systems) Fixed an issue where the GlobalProtect App user interface would not launch after installation. With this fix, the user interface launches as expected.
GPC-26808
Fixed an issue where GlobalProtect did not detect a specific version of the Broadcom Endpoint Security Agent (ESA) on macOS endpoints. With this fix, the agent is correctly detected, and administrators can configure policies for it.
GPC-26790
(macOS devices running GlobalProtect) Fixed an issue where GlobalProtect would not connect, which caused users to encounter a "Could not connect to the GlobalProtect service" error after a macOS update or system reboot. This occurred because the GlobalProtect service would not start or would stop unexpectedly. With this fix, GlobalProtect connects successfully.
GPC-26789
(GlobalProtect 6.3.3 Linux clients only) Fixed an issue where GlobalProtect clients enforced Federal Information Processing Standard Publication 140-2 Cryptographic Module Validation Program (FIPS-CC) certificate validation despite FIPS-CC mode being disabled, which prevented clients from establishing a connection. With this fix, GlobalProtect clients correctly respect the FIPS-CC setting.
GPC-26780
(macOS devices only) Fixed an issue where GlobalProtect would get stuck in a connecting state after the device woke from sleep or reconnected to a network, which resulted from GlobalProtect attempting to resolve the gateway's fully qualified domain name (FQDN) using the tunnel's DNS instead of the local internet service provider (ISP) DNS. With this fix, GlobalProtect correctly uses the local ISP DNS for gateway FQDN resolution when disconnected.
GPC-26764
(GlobalProtect app on macOS devices) Fixed an issue where the GlobalProtect app initiated unexpected portal requests after a manual gateway selection. With this fix, the app behaves as expected after a manual gateway selection.
GPC-26699
(macOS only) Fixed an issue where the GlobalProtect user interface popover would not dismiss after a successful connection, which occurred because the GlobalProtect menu bar icon became inaccessible when hidden by the operating system. With this fix, the popover automatically dismisses after a successful connection.
GPC-26696
Fixed an issue where the GlobalProtect Linux client failed to initialize for users with high-range enterprise user IDs (UIDs), which caused the gpa.service systemd unit to drop into a failed state immediately during execution. This occurred because the client introduced a restrictive UID validation that prevented the service from starting if the UID was greater than 60000. With this fix, the GlobalProtect Linux client now supports valid non-system users regardless of their enterprise UID allocation range.
GPC-26682
Fixed an issue where internet connectivity would stop working on macOS when the GlobalProtect client was connected to certain mobile hotspots that assigned IP addresses from a specific reserved range, which occurred because the GlobalProtect client did not properly process this particular IP address range used in some mobile network environments. With this fix, internet connectivity is maintained in these scenarios.
GPC-26657
Fixed an issue where the HIP process repeatedly launched in a rapid-fire loop, which triggered alerts. With this fix, the process launches as expected.
GPC-26619
(GlobalProtect app on macOS only) Fixed an issue where the GlobalProtect app remained in a connecting state for approximately two minutes after a local network-extension or route-change event, which required a restart of the app to recover. With this fix, the GlobalProtect app now connects as expected after such events.
GPC-26618
(GlobalProtect app on macOS) Fixed an issue where the GlobalProtect app would fail to connect to gateways after a manual gateway selection. With this fix, the GlobalProtect app connects successfully to gateways after manual selection.
GPC-26560
Fixed an issue where GlobalProtect app connections experienced a delay when Autonomous Digital Experience Management (ADEM) was disabled in the portal, which occurred because the agent continued to search for the ADEM configuration file. With this fix, the agent no longer attempts to locate the ADEM configuration file when ADEM is disabled.
GPC-26558
Fixed an issue where GlobalProtect App disconnect reason text was truncated in the user interface when the GlobalProtect Portal was configured with a custom disconnect reason, which prevented the full message from being displayed. With this fix, the user interface now properly displays the complete disconnect reason.
GPC-26537
Fixed an issue where an unauthorized user could disconnect a GlobalProtect connection after interrupting Security Assertion Markup Language (SAML) authentication during a connection refresh. With this fix, the Disconnect button no longer appeared for unauthorized users in this scenario.
GPC-26224
Fixed an issue where the GlobalProtect client stole focus when a user entered a PIN for PINGID/Security Assertion Markup Language (SAML) authentication. With this fix, the GlobalProtect client no longer unexpectedly takes focus during this authentication process.
GPC-26133
Fixed an issue where the DisplayVersion registry key for GlobalProtect clients on Windows reported an incomplete version string, which led to other software misidentifying the installed GlobalProtect version. With this fix, the registry key now accurately reflects the full client version.
GPC-26088
Fixed an issue where the GlobalProtect Enforcer did not unblock network traffic after a GlobalProtect connection was established, which resulted in the blocking of traffic not explicitly excluded from enforcement. With this fix, the GlobalProtect Enforcer now correctly unblocks traffic upon successful GlobalProtect connection.
GPC-25840
Fixed an issue where applications configured for split tunneling would not function correctly after a network transition. With this fix, applications would function as expected after network changes.
GPC-25670
Fixed an issue where the GlobalProtect app would intermittently get stuck in a connecting state after a laptop woke up from standby, preventing it from establishing a connection to the gateway. With this fix, the GlobalProtect agent connects successfully.
GPC-25575
(macOS devices only) Fixed an issue where custom Host Information Profile (HIP) checks did not correctly evaluate certain system configuration parameters, which prevented macOS devices from matching the intended HIP objects. With this fix, HIP checks accurately evaluate the system configuration parameters.
GPC-25567
Fixed an issue where the GlobalProtect Client would intermittently not complete Kerberos Single Sign-On (SSO) during pre-login. This occurred when the client did not post the Kerberos token back after receiving an initial authentication challenge from the portal, which prompted users for credentials and displayed an error message indicating an unreachable network or unresponsive portal. With this fix, Kerberos SSO now succeeds consistently.
GPC-25432
(GlobalProtect client on Red Hat Enterprise Linux (RHEL) 8.10 systems) Fixed an issue where the GlobalProtect client would not update the resolv.conf file with configured Domain Name System (DNS) servers, which resulted in internal DNS resolution not functioning correctly. With this fix, the resolv.conf file updates as expected.
GPC-25419
Fixed an issue where GlobalProtect clients on Linux did not send Host Information Profile (HIP) report checks to internal gateways, which caused IP mappings to time out. With this fix, HIP report checks are sent correctly to internal gateways.
GPC-25308
Fixed an issue where the GlobalProtect app intermittently stopped transmitting Host Information Profile (HIP) reports, which caused User-ID entries to be cleared and resulted in missing user-to-IP mappings. With this fix, the GlobalProtect app now consistently transmits HIP reports, maintaining accurate user-to-IP mappings.
GPC-25219
Fixed an issue where users were unable to select the GlobalProtect icon from the status bar on macOS.