Add GP Linux issues
This commit is contained in:
@@ -0,0 +1,45 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: GlobalProtect-Linux
|
||||||
|
version: 6.2.0
|
||||||
|
---
|
||||||
|
|
||||||
|
## GPC-19792
|
||||||
|
|
||||||
|
Fixed an issue where an error message was displayed on the GlobalProtect app: **Previous authentication attempt timed out. Please select Connect to initiate authentication once again**. Despite this error, the VPN tunnel was established, and traffic was routed successfully through the tunnel.
|
||||||
|
|
||||||
|
## GPC-19748
|
||||||
|
|
||||||
|
Fixed an issue where the GlobalProtect app status was connected but no traffic was passing through. This issue occurred after the GlobalProtect Linux app was upgraded from 6.1.3 to 6.1.4 on Ubuntu Version 22.04.
|
||||||
|
|
||||||
|
## GPC-19353
|
||||||
|
|
||||||
|
Fixed an issue where GlobalProtect was stuck in Connecting stage a with **Login Successful** white page displayed on the default browser instead of the expected Microsoft SAML page.
|
||||||
|
|
||||||
|
## GPC-19143
|
||||||
|
|
||||||
|
Fixed an issue where the users were unable to choose the correct certificate for the app as the configured registry value previousCertificate did not work as expected.
|
||||||
|
|
||||||
|
## GPC-18903
|
||||||
|
|
||||||
|
Fixed an issue where when the GlobalProtect app was installed on Linux devices running on Red Hat version 9, the resolv.conf file was not getting updated with GlobalProtect DNS servers as expected.
|
||||||
|
|
||||||
|
## GPC-18820
|
||||||
|
|
||||||
|
Fixed an issue where some users were unable to connect to GlobalProtect after disconnecting the app.
|
||||||
|
|
||||||
|
## GPC-18512
|
||||||
|
|
||||||
|
Fixed an issue where, when the GlobalProtect app was installed on Linux devices running Ubuntu 22.04 or REHL 9.1, the app got disconnected periodically.
|
||||||
|
|
||||||
|
## GPC-18155
|
||||||
|
|
||||||
|
Fixed an issue where the GlobalProtect main panel was displayed on the bottom right instead of its usual location at the top right. This occurred when an NVidia Graphics GPU driver was installed in the environment,
|
||||||
|
|
||||||
|
## GPC-17598
|
||||||
|
|
||||||
|
Fixed an issue where, when the GlobalProtect app was installed on Linux devices and the GlobalProtect app was connected and the tunnel was up, the DNS requests were sent to the public DNS servers assigned to the physical interface.
|
||||||
|
|
||||||
|
## GPC-16980
|
||||||
|
|
||||||
|
Fixed an issue where users were unable to upgrade GlobalProtect app from 5.3 to 6.0.x or 6.1.x due to file conflicts between packages.
|
||||||
@@ -0,0 +1,57 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: GlobalProtect-Linux
|
||||||
|
version: 6.2.1
|
||||||
|
---
|
||||||
|
|
||||||
|
## GPC-21151
|
||||||
|
|
||||||
|
Fixed an issue where, when the option **Allow Authentication with User Credentials OR Client Certificate** was set to **Yes** in the portal configuration, and no valid client certificate was installed on the endpoint, the connection failed with the error: **Connection Failed. A valid client certificate is required for authentication** without prompting the user for their credentials.
|
||||||
|
|
||||||
|
## GPC-20945
|
||||||
|
|
||||||
|
Fixed an issue where, when the GlobalProtect app was installed on Linux endpoints, users were unable to access ephemeral URLs.
|
||||||
|
|
||||||
|
## GPC-20605
|
||||||
|
|
||||||
|
Fixed an issue where, when the GlobalProtect app was installed on Linux endpoints with the connect method pre-deployed, the connect method failed to get updated with the portal configuration after the first successful connection.
|
||||||
|
|
||||||
|
## GPC-20574
|
||||||
|
|
||||||
|
Fixed an issue where, when the GlobalProtect app was installed on Linux (Fedora 38 version) endpoints, the GlobalProtect HIP check did not detect the SentinelOne application, which caused the device to fail the HIP check.
|
||||||
|
|
||||||
|
## GPC-20544
|
||||||
|
|
||||||
|
Fixed an issue where the GlobalProtect app on Linux endpoints was displaying confusing error messages when the user would connect to manual gateways.
|
||||||
|
|
||||||
|
## GPC-20525
|
||||||
|
|
||||||
|
Fixed an issue where, when the GlobalProtect app 6.1.4 version was installed on Linux endpoints and the **Allow User to Change Portal Address** option was set to **No** in the app settings of the portal configuration, the app did not retain the portal name after a system reboot.
|
||||||
|
|
||||||
|
## GPC-20449
|
||||||
|
|
||||||
|
Fixed an issue where the GlobalProtect HIP check incorrectly detected the date for ClamAV virus definition update, which caused the endpoint to fail the HIP check.
|
||||||
|
|
||||||
|
## GPC-20398
|
||||||
|
|
||||||
|
Fixed an issue where, when the GlobalProtect app was installed on Linux endpoints, the app could not resolve the DNS queries containing capital letters.
|
||||||
|
|
||||||
|
## GPC-20340
|
||||||
|
|
||||||
|
Fixed an issue where, when the GlobalProtect app was installed on Linux endpoints, end users had to reboot the system to reconnect the app when the GlobalProtect got disconnected.
|
||||||
|
|
||||||
|
## GPC-19973
|
||||||
|
|
||||||
|
Fixed an issue where, when the GlobalProtect app was installed on Linux endpoints (Ubuntu 22.04.4 LTS) and SAML authentication was used to authenticate to the app, a blank page appeared during the first attempt at SAML authentication every time.
|
||||||
|
|
||||||
|
## GPC-19297
|
||||||
|
|
||||||
|
Fixed an issue where the GlobalProtect HIP check did not detect the Last Full Scan Time for Cortex XDR, which caused the device to fail the HIP check.
|
||||||
|
|
||||||
|
## GPC-18105
|
||||||
|
|
||||||
|
Fixed an issue where the user was unable to cancel out of SAML authentication in on-demand mode while the GlobalProtect app was in connecting state.
|
||||||
|
|
||||||
|
## GPC-17378
|
||||||
|
|
||||||
|
Fixed an issue where, when the GlobalProtect app was installed on devices running System76 coreboot BIOS, the HIP check failed when the Device ID was empty.
|
||||||
@@ -0,0 +1,79 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: GlobalProtect-Linux
|
||||||
|
version: 6.2.6
|
||||||
|
---
|
||||||
|
|
||||||
|
## GPC-22950
|
||||||
|
|
||||||
|
Fixed an intermittent issue on Linux machines that affected users' ability to perform Web searches on browsers while connected to the GlobalProtect app.
|
||||||
|
|
||||||
|
## GPC-22872
|
||||||
|
|
||||||
|
Fixed an issue while installing the GlobalProtect app version 6.2.1.1-7 on Fedora 41 x86_64 Linux machines by executing gp_install.sh script on command line interface did not work as expected.
|
||||||
|
|
||||||
|
## GPC-22774
|
||||||
|
|
||||||
|
Fixed an issue where GlobalProtect app 6.2.1-7 was installed on Linux Fedora machines, the import certificate failed due to missing /etc/ssl/private/ directory.
|
||||||
|
|
||||||
|
## GPC-22766
|
||||||
|
|
||||||
|
Fixed an issue where, when the GlobalProtect app was installed on Linux machines, hyperlink in the welcome page opened in the embedded browser instead of default browser.
|
||||||
|
|
||||||
|
## GPC-22390
|
||||||
|
|
||||||
|
Fixed an issue where the GlobalProtect app version 6.2.1 did not fetch the portal address from pre-deployed pangps.xml.
|
||||||
|
|
||||||
|
## GPC-22306
|
||||||
|
|
||||||
|
Fixed an issue where the GlobalProtect app tray icon failed to display when the app was installed on devices running Linux Ubuntu 24.04.1 LTS.
|
||||||
|
|
||||||
|
## GPC-22249
|
||||||
|
|
||||||
|
Fixed an issue where some of the third party license files were missing in the GlobalProtect app packages.
|
||||||
|
|
||||||
|
## GPC-22130
|
||||||
|
|
||||||
|
Fixed an issue where the GlobalProtect app displayed the following incorrect error message when there was no internet connectivity:
|
||||||
|
|
||||||
|
**Could not verify the server of the gateway. If the issue persists, contact your administrator.**
|
||||||
|
|
||||||
|
## GPC-22051
|
||||||
|
|
||||||
|
Fixed an issue where the GlobalProtect app displayed the following unexpected client certificate error message during portal logon: **Valid client certificate required for authentication**, when **Allow Authentication with User Credentials OR Client Certificate** option was set to **Yes**.
|
||||||
|
|
||||||
|
## GPC-21951
|
||||||
|
|
||||||
|
Fixed an issue where, when the GlobalProtect app was installed on Linux machines, the virtual adapter maintained tunnel IP even when the app was disconnected.
|
||||||
|
|
||||||
|
## GPC-21920
|
||||||
|
|
||||||
|
Fixed an issue where the GlobalProtect app web interface did not display some settings such as portal address when the user manually disconnected the app and then restarted.
|
||||||
|
|
||||||
|
## GPC-21915
|
||||||
|
|
||||||
|
Fixed an issue where, when the GlobalProtect app was installed on Linux Ubuntu LTE 20.04 machines, the GlobalProtect app did not properly display the connection status and the app was incorrectly positioned in the middle of the screen.
|
||||||
|
|
||||||
|
## GPC-21861
|
||||||
|
|
||||||
|
Fixed an issue where, when the GlobalProtect app was installed on Linux devices (Ubuntu 22.04.4 LTS), the tunnel got disconnected intermittently causing connectivity issues.
|
||||||
|
|
||||||
|
## GPC-21762
|
||||||
|
|
||||||
|
Fixed an issue where, when the GlobalProtect app is installed on Linux RHEL 8.9, PanGPA process stopped and failed to recover automatically impacting the functioning of the GlobalProtect app.
|
||||||
|
|
||||||
|
## GPC-21724
|
||||||
|
|
||||||
|
Fixed an issue where the IoT GlobalProtect app connection failed after system reboot with error: **cannot connect to local gpd service**.
|
||||||
|
|
||||||
|
## GPC-21651
|
||||||
|
|
||||||
|
Fixed an issue where, when the GlobalProtect app is installed on Linux RHEL 8.9,the app did not remove the configured DNS even after disabling the app.
|
||||||
|
|
||||||
|
## GPC-21092
|
||||||
|
|
||||||
|
Fixed an issue on Linux machines where users were unable to authenticate to the GlobalProtect app using certificate authentication. Despite the certificate being sent to the firewall, the app was defaulting to SAML authentication method.
|
||||||
|
|
||||||
|
## GPC-21478
|
||||||
|
|
||||||
|
Fixed an issue where, when the GlobalProtect app version 6.2.0-265 was installed on Linux machines running Ubuntu 24.04.1 LTS, the app got stuck and users were unable to connect to the app after system reboot.
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: GlobalProtect-Linux
|
||||||
|
version: 6.2.7
|
||||||
|
---
|
||||||
|
|
||||||
|
## GPC-23208
|
||||||
|
|
||||||
|
Fixed an issue where traffic was going through via physical interface instead of the tunnel even though GlobalProtect was connected.
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: GlobalProtect-Linux
|
||||||
|
version: 6.2.8
|
||||||
|
---
|
||||||
|
|
||||||
|
## GPC-23208
|
||||||
|
|
||||||
|
Fixed an issue where traffic was going through via physical interface instead of the tunnel even though GlobalProtect was connected.
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: GlobalProtect-Linux
|
||||||
|
version: 6.3.3-h1
|
||||||
|
---
|
||||||
|
|
||||||
|
## GPC-24173
|
||||||
|
|
||||||
|
Fixed an issue where GlobalProtect Linux clients (Redhat and Ubuntu) experienced an unresponsive or crashing embedded browser when authenticating to a GlobalProtect gateway using SAML, preventing successful connection despite successful authentication on the SAML provider side.
|
||||||
@@ -0,0 +1,33 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: GlobalProtect-Linux
|
||||||
|
version: 6.3.3
|
||||||
|
---
|
||||||
|
|
||||||
|
## GPC-23773
|
||||||
|
|
||||||
|
Fixed an issue where the disconnect password was not masked when a user attempted to disable GlobalProtect on a Linux machine, even though password protection was enabled on the GlobalProtect app.
|
||||||
|
|
||||||
|
## GPC-23647
|
||||||
|
|
||||||
|
Fixed an issue where GlobalProtect for Linux clients running Ubuntu 24.04.2 LTS did not automatically reconnect to the portal after a system reboot, even when configured to automatically connect.
|
||||||
|
|
||||||
|
## GPC-23452
|
||||||
|
|
||||||
|
Fixed an issue where GlobalProtect 6.2.7 clients on RHEL endpoints failed to generate or send Host Information Profile (HIP) reports, resulting in OPSWAT errors and the HIP notification tab missing from the GlobalProtect client.
|
||||||
|
|
||||||
|
## GPC-23447
|
||||||
|
|
||||||
|
Fixed an issue where the GlobalProtect agent tray icon did not display on Ubuntu 22.04.5 LTS with GNOME shell version 46.0 after installing the GlobalProtect agent.
|
||||||
|
|
||||||
|
## GPC-23405
|
||||||
|
|
||||||
|
Fixed an issue where GlobalProtect version 6.2.7 on Fedora 41 was unable to identify the installed antivirus software, preventing users from connecting to the VPN.
|
||||||
|
|
||||||
|
## GPC-23208
|
||||||
|
|
||||||
|
Fixed an issue where, after connecting GlobalProtect on Linux, the gpd0 tunnel interface was not created and all traffic was routed through the physical interface.
|
||||||
|
|
||||||
|
## GPC-21049
|
||||||
|
|
||||||
|
Fixed an issue where the GlobalProtect GUI icon could not be opened on Ubuntu instances running in Amazon Workspaces. This was due to the Amazon Workspace environment not allowing GlobalProtect to shut down gracefully, resulting in a corrupted state upon restart.
|
||||||
@@ -0,0 +1,89 @@
|
|||||||
|
---
|
||||||
|
type: Known
|
||||||
|
product: GlobalProtect-Linux
|
||||||
|
version: 6.2.0
|
||||||
|
---
|
||||||
|
|
||||||
|
## GPC-23149
|
||||||
|
|
||||||
|
Connection via captive portal does not work in agent proxy mode when the captive portal is hosted on a non-local network.
|
||||||
|
|
||||||
|
## GPC-21694
|
||||||
|
|
||||||
|
When the GlobalProtect app is installed on Windows, a Microsoft Defender SmartScreen warning is displayed:.
|
||||||
|
|
||||||
|
**Workaround:**Click More Info and then click Run to proceed with the installation.
|
||||||
|
|
||||||
|
## GPC-21558
|
||||||
|
|
||||||
|
When the GlobalProtect app is installed on devices running on macOS and the end user enable or disable the system extensions, the GlobalProtect Enforcer feature is not working as expected.
|
||||||
|
|
||||||
|
## GPC-21442
|
||||||
|
|
||||||
|
Users running GlobalProtect client with Enforcer enabled may see an "Internet Blocked message" when performing SAML authentication for the nth time (n>1) via embedded web browser. This happens when Webview2 or Edge browser is updated between previous successful authentication and the current unsuccessful authentication attempt..
|
||||||
|
|
||||||
|
**Workaround:**Disable webview2 auto update via the group policy. If you still see the error message, restart the device.
|
||||||
|
|
||||||
|
## GPC-20970
|
||||||
|
|
||||||
|
GlobalProtect can have intermittent connectivity issues on Prisma Access IP optimization enabled tenants.
|
||||||
|
|
||||||
|
**Workaround:** If your Prisma Access tenant is IP Optimization enabled (available starting in Prisma Access 5.0.1), upgrade to GlobalProtect 6.1.4 and later, 6.2.3 and later, or 6.3 and later.
|
||||||
|
|
||||||
|
## GPC-20840
|
||||||
|
|
||||||
|
Loading content or text on the SAML embedded browser can take longer than usual. This does not impact authentication.
|
||||||
|
|
||||||
|
## GPC-19339
|
||||||
|
|
||||||
|
When the GlobalProtect app is upgraded from version 6.1.4-c1 to 6.2.0-c4 on Linux devices, the GlobalProtect web interface displays the upgraded version only after a system reboot.
|
||||||
|
|
||||||
|
## GPC-19180
|
||||||
|
|
||||||
|
When the GlobalProtect app is installed on Linux devices and the app is upgraded or downgraded, the GlobalProtect web interface and the command-line interface display the new version only after a system reboot.
|
||||||
|
|
||||||
|
## GPC-18964
|
||||||
|
|
||||||
|
The GlobalProtect tunnel disconnects after 10 minutes on app versions 6.0.8 and 6.2.1, when SAML authentication is used and the GlobalProtect app is running on macOS devices.
|
||||||
|
|
||||||
|
## GPC-18025
|
||||||
|
|
||||||
|
In 6.2.1, after a refresh connection, the HIP patch exclusion isn't visible on the GlobalProtect UI. However, the HIP patch exclusion logs are visible on the Pangphip.log file.
|
||||||
|
|
||||||
|
## GPC-17820
|
||||||
|
|
||||||
|
Firefox is not supported for proxied traffic in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode).
|
||||||
|
|
||||||
|
## GPC-17816
|
||||||
|
|
||||||
|
After entering CIE SAML authentication credentials to refresh an expired explicit proxy token or cookie when connected in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode), the GlobalProtect app gets stuck while retrieving the portal configuration.
|
||||||
|
|
||||||
|
**Workaround:** Refresh the GlobalProtect connection or disconnect and reconnect the GlobalProtect app.
|
||||||
|
|
||||||
|
## GPC-17727
|
||||||
|
|
||||||
|
When the GlobalProtect app is connected in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode), SSH traffic cannot be sent over the proxy.
|
||||||
|
|
||||||
|
## GPC-17513
|
||||||
|
|
||||||
|
When GlobalProtect is configured in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode), if the admin-defined PAC file has an HTTP URL, the GlobalProtect app will not download the PAC content.
|
||||||
|
|
||||||
|
## GPC-17447
|
||||||
|
|
||||||
|
When the GlobalProtect app is configured in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), SSL VPN establishment over the proxy doesn't work.
|
||||||
|
|
||||||
|
## GPC-17663
|
||||||
|
|
||||||
|
In [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), the GlobalProtect agent tunnel does not work seamlessly when the GlobalProtect app and the third-party VPN are configured to use overlapping IP subnets.
|
||||||
|
|
||||||
|
**Workaround:** Use GlobalProtect in [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode) for better compatibility with third-party VPNs.
|
||||||
|
|
||||||
|
## GPC-17555
|
||||||
|
|
||||||
|
In [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), the GlobalProtect agent tunnel on macOS does not coexist well with Cisco Anyconnect VPN due to an IP forwarding table issue.
|
||||||
|
|
||||||
|
**Workaround:** Use GlobalProtect in [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode) for better compatibility with third-party VPNs.
|
||||||
|
|
||||||
|
## GPC-17854
|
||||||
|
|
||||||
|
The GlobalProtect app does not prompt the users to extend the login lifetime user session when the device woke up from sleep or hibernation mode.
|
||||||
@@ -0,0 +1,83 @@
|
|||||||
|
---
|
||||||
|
type: Known
|
||||||
|
product: GlobalProtect-Linux
|
||||||
|
version: 6.2.1
|
||||||
|
---
|
||||||
|
|
||||||
|
## GPC-23149
|
||||||
|
|
||||||
|
Connection via captive portal does not work in agent proxy mode when the captive portal is hosted on a non-local network.
|
||||||
|
|
||||||
|
## GPC-21694
|
||||||
|
|
||||||
|
When the GlobalProtect app is installed on Windows, a Microsoft Defender SmartScreen warning is displayed:.
|
||||||
|
|
||||||
|
**Workaround:**Click More Info and then click Run to proceed with the installation.
|
||||||
|
|
||||||
|
## GPC-21558
|
||||||
|
|
||||||
|
When the GlobalProtect app is installed on devices running on macOS and the end user enable or disable the system extensions, the GlobalProtect Enforcer feature is not working as expected.
|
||||||
|
|
||||||
|
## GPC-21442
|
||||||
|
|
||||||
|
Users running GlobalProtect client with Enforcer enabled may see an "Internet Blocked message" when performing SAML authentication for the nth time (n>1) via embedded web browser. This happens when Webview2 or Edge browser is updated between previous successful authentication and the current unsuccessful authentication attempt..
|
||||||
|
|
||||||
|
**Workaround:**Disable webview2 auto update via the group policy. If you still see the error message, restart the device.
|
||||||
|
|
||||||
|
## GPC-20970
|
||||||
|
|
||||||
|
GlobalProtect can have intermittent connectivity issues on Prisma Access IP optimization enabled tenants.
|
||||||
|
|
||||||
|
**Workaround:** If your Prisma Access tenant is IP Optimization enabled (available starting in Prisma Access 5.0.1), upgrade to GlobalProtect 6.1.4 and later, 6.2.3 and later, or 6.3 and later.
|
||||||
|
|
||||||
|
## GPC-20840
|
||||||
|
|
||||||
|
Loading content or text on the SAML embedded browser can take longer than usual. This does not impact authentication.
|
||||||
|
|
||||||
|
## GPC-19339
|
||||||
|
|
||||||
|
When the GlobalProtect app is upgraded from version 6.1.4-c1 to 6.2.0-c4 on Linux devices, the GlobalProtect web interface displays the upgraded version only after a system reboot.
|
||||||
|
|
||||||
|
## GPC-19180
|
||||||
|
|
||||||
|
When the GlobalProtect app is installed on Linux devices and the app is upgraded or downgraded, the GlobalProtect web interface and the command-line interface display the new version only after a system reboot.
|
||||||
|
|
||||||
|
## GPC-18964
|
||||||
|
|
||||||
|
The GlobalProtect tunnel disconnects after 10 minutes on app versions 6.0.8 and 6.2.1, when SAML authentication is used and the GlobalProtect app is running on macOS devices.
|
||||||
|
|
||||||
|
## GPC-18025
|
||||||
|
|
||||||
|
In 6.2.1, after a refresh connection, the HIP patch exclusion isn't visible on the GlobalProtect UI. However, the HIP patch exclusion logs are visible on the Pangphip.log file.
|
||||||
|
|
||||||
|
## GPC-17820
|
||||||
|
|
||||||
|
Firefox is not supported for proxied traffic in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode).
|
||||||
|
|
||||||
|
## GPC-17727
|
||||||
|
|
||||||
|
When the GlobalProtect app is connected in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode), SSH traffic cannot be sent over the proxy.
|
||||||
|
|
||||||
|
## GPC-17513
|
||||||
|
|
||||||
|
When GlobalProtect is configured in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode), if the admin-defined PAC file has an HTTP URL, the GlobalProtect app will not download the PAC content.
|
||||||
|
|
||||||
|
## GPC-17447
|
||||||
|
|
||||||
|
When the GlobalProtect app is configured in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), SSL VPN establishment over the proxy doesn't work.
|
||||||
|
|
||||||
|
## GPC-17663
|
||||||
|
|
||||||
|
In [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), the GlobalProtect agent tunnel does not work seamlessly when the GlobalProtect app and the third-party VPN are configured to use overlapping IP subnets.
|
||||||
|
|
||||||
|
**Workaround:** Use GlobalProtect in [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode) for better compatibility with third-party VPNs.
|
||||||
|
|
||||||
|
## GPC-17555
|
||||||
|
|
||||||
|
In [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), the GlobalProtect agent tunnel on macOS does not coexist well with Cisco Anyconnect VPN due to an IP forwarding table issue.
|
||||||
|
|
||||||
|
**Workaround:** Use GlobalProtect in [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode) for better compatibility with third-party VPNs.
|
||||||
|
|
||||||
|
## GPC-17854
|
||||||
|
|
||||||
|
The GlobalProtect app does not prompt the users to extend the login lifetime user session when the device woke up from sleep or hibernation mode.
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
---
|
||||||
|
type: Known
|
||||||
|
product: GlobalProtect-Linux
|
||||||
|
version: 6.2.7
|
||||||
|
---
|
||||||
|
|
||||||
|
## GPC-19339
|
||||||
|
|
||||||
|
When the GlobalProtect app is upgraded from version 6.1.4-c1 to 6.2.0-c4 on Linux devices, the GlobalProtect web interface displays the upgraded version only after a system reboot.
|
||||||
|
|
||||||
|
## GPC-19180
|
||||||
|
|
||||||
|
When the GlobalProtect app is installed on Linux devices and the app is upgraded or downgraded, the GlobalProtect web interface and the command-line interface display the new version only after a system reboot.
|
||||||
|
|
||||||
|
## GPC-17854
|
||||||
|
|
||||||
|
The GlobalProtect app does not prompt the users to extend the login lifetime user session when the device woke up from sleep or hibernation mode.
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
---
|
||||||
|
type: Known
|
||||||
|
product: GlobalProtect-Linux
|
||||||
|
version: 6.2.8
|
||||||
|
---
|
||||||
|
|
||||||
|
## GPC-19339
|
||||||
|
|
||||||
|
When the GlobalProtect app is upgraded from version 6.1.4-c1 to 6.2.0-c4 on Linux devices, the GlobalProtect web interface displays the upgraded version only after a system reboot.
|
||||||
|
|
||||||
|
## GPC-19180
|
||||||
|
|
||||||
|
When the GlobalProtect app is installed on Linux devices and the app is upgraded or downgraded, the GlobalProtect web interface and the command-line interface display the new version only after a system reboot.
|
||||||
|
|
||||||
|
## GPC-17854
|
||||||
|
|
||||||
|
The GlobalProtect app does not prompt the users to extend the login lifetime user session when the device woke up from sleep or hibernation mode.
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
---
|
||||||
|
type: Known
|
||||||
|
product: GlobalProtect-Linux
|
||||||
|
version: 6.2.9
|
||||||
|
---
|
||||||
|
|
||||||
|
## GPC-19339
|
||||||
|
|
||||||
|
When the GlobalProtect app is upgraded from version 6.1.4-c1 to 6.2.0-c4 on Linux devices, the GlobalProtect web interface displays the upgraded version only after a system reboot.
|
||||||
|
|
||||||
|
## GPC-19180
|
||||||
|
|
||||||
|
When the GlobalProtect app is installed on Linux devices and the app is upgraded or downgraded, the GlobalProtect web interface and the command-line interface display the new version only after a system reboot.
|
||||||
|
|
||||||
|
## GPC-17854
|
||||||
|
|
||||||
|
The GlobalProtect app does not prompt the users to extend the login lifetime user session when the device woke up from sleep or hibernation mode.
|
||||||
@@ -0,0 +1,21 @@
|
|||||||
|
---
|
||||||
|
type: Known
|
||||||
|
product: GlobalProtect-Linux
|
||||||
|
version: 6.3.3
|
||||||
|
---
|
||||||
|
|
||||||
|
## GPC-23912
|
||||||
|
|
||||||
|
After connecting to GlobalProtect Linux 6.3.3 client on Fedora 41 with Host Information Profile enabled, the patch management section for 'Dandified Yum' displays an empty version value.
|
||||||
|
|
||||||
|
## GPC-19339
|
||||||
|
|
||||||
|
When the GlobalProtect app is upgraded from version 6.1.4-c1 to 6.2.0-c4 on Linux devices, the GlobalProtect web interface displays the upgraded version only after a system reboot.
|
||||||
|
|
||||||
|
## GPC-19180
|
||||||
|
|
||||||
|
When the GlobalProtect app is installed on Linux devices and the app is upgraded or downgraded, the GlobalProtect web interface and the command-line interface display the new version only after a system reboot.
|
||||||
|
|
||||||
|
## GPC-17854
|
||||||
|
|
||||||
|
The GlobalProtect app does not prompt the users to extend the login lifetime user session when the device woke up from sleep or hibernation mode.
|
||||||
@@ -0,0 +1,81 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: GlobalProtect
|
||||||
|
version: 6.2.8-h1
|
||||||
|
---
|
||||||
|
|
||||||
|
## GPC-23215
|
||||||
|
|
||||||
|
Fixed an issue where, the traffic stopped passing through the GlobalProtect app on macOS devices after upgrading to GP 6.2.8 and when the computer screen was locked.
|
||||||
|
|
||||||
|
## GPC-23174
|
||||||
|
|
||||||
|
Fixed an issue where the GlobalProtect failed to detect DNS during the Network Detection stage, causing the GlobalProtect app to stop working.
|
||||||
|
|
||||||
|
## GPC-23161
|
||||||
|
|
||||||
|
Fixed an issue where the GlobalProtect app stopped working after a session change.
|
||||||
|
|
||||||
|
## GPC-23088
|
||||||
|
|
||||||
|
Fixed an issue where the portal login user authentication failed after cookie expiration.
|
||||||
|
|
||||||
|
## GPC-21982
|
||||||
|
|
||||||
|
Fixed an issue in which IPv6 traffic bypassed the valid route in the rerouting table and instead passed through the physical adapter when the GlobalProtect app was installed on Windows devices.
|
||||||
|
|
||||||
|
## GPC-23046
|
||||||
|
|
||||||
|
Fixed an issue where users experienced connectivity problems when GlobalProtect was used in a WiFi network with captive portal.
|
||||||
|
|
||||||
|
## GPC-23034
|
||||||
|
|
||||||
|
Fixed an issue where the GlobalProtect embedded browser did not display certificate selection pop-up when there were multiple client certificates available.
|
||||||
|
|
||||||
|
## GPC-23032
|
||||||
|
|
||||||
|
Fixed an issue where the GlobalProtect agent restarts when the device wakes up from Modern Standby.
|
||||||
|
|
||||||
|
## GPC-23011
|
||||||
|
|
||||||
|
Fixed an issue wherein wherein the Enforcer intermittently failed to promptly block network access as configured, thereby resulting in delays of 1 to 5 minutes before eventually blocking the traffic flow.
|
||||||
|
|
||||||
|
## GPC-22800
|
||||||
|
|
||||||
|
Fixed an issue where, when the GlobalProtect app was configured with enforcer and Captive Portal, users faced issues in connecting to Captive Portal using GlobalProtect.
|
||||||
|
|
||||||
|
## GPC-22610
|
||||||
|
|
||||||
|
Fixed an issue where, after an upgrade, GlobalProtect restarted and failed to connect to the portal
|
||||||
|
|
||||||
|
## GPC-22595
|
||||||
|
|
||||||
|
Fixed an issue where users were unable to select the correct client certificate when using the GlobalProtect app on Windows devices and connected to the internal network using SAML embedded browse
|
||||||
|
|
||||||
|
## GPC-22536
|
||||||
|
|
||||||
|
Fixed an issue where users faced connectivity issues when the GlobalProtect app version 6.2.6 was installed on devices running macOS 15.3.1
|
||||||
|
|
||||||
|
## GPC-22365
|
||||||
|
|
||||||
|
Fixed an issue where users experienced intermittent issues browsing webpages while connected to the GlobalProtect app.
|
||||||
|
|
||||||
|
## GPC-22294
|
||||||
|
|
||||||
|
. Fixed an issue where intermittent internet access problems occurred when the macOS was upgraded to 15.2 and the GlobalProtect app version to 6.2.6.
|
||||||
|
|
||||||
|
## GPC-21766
|
||||||
|
|
||||||
|
Fixed an issue where the split tunnel excluded routes go missing from routing table on Windows machine at intermittent times.
|
||||||
|
|
||||||
|
## GPC-21755
|
||||||
|
|
||||||
|
Fixed an issue where GlobalProtect users with enforcer enabled were able to access applications that were not in the enforcer exception list.
|
||||||
|
|
||||||
|
## GPC-21737
|
||||||
|
|
||||||
|
Fixed an issue where the SAML redirection page opened up on end user computers even though they did not have internet connectivity.
|
||||||
|
|
||||||
|
## GPC-19024
|
||||||
|
|
||||||
|
Fixed an issue where the GlobalProtect app incorrectly used an embedded WebView instead of the system default browser for Captive Portal logins.
|
||||||
@@ -614,6 +614,7 @@
|
|||||||
"6.2.5_2026-03-16.md",
|
"6.2.5_2026-03-16.md",
|
||||||
"6.2.6_2026-03-16.md",
|
"6.2.6_2026-03-16.md",
|
||||||
"6.2.8_2026-03-16.md",
|
"6.2.8_2026-03-16.md",
|
||||||
|
"6.2.8-h1_2026-04-02.md",
|
||||||
"6.2.8-h2_2026-03-16.md",
|
"6.2.8-h2_2026-03-16.md",
|
||||||
"6.2.8-h3_2026-03-16.md",
|
"6.2.8-h3_2026-03-16.md",
|
||||||
"6.2.8-h4_2026-03-16.md",
|
"6.2.8-h4_2026-03-16.md",
|
||||||
@@ -678,6 +679,8 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
"GlobalProtect-Linux": {
|
"GlobalProtect-Linux": {
|
||||||
|
"6": {
|
||||||
|
"6.1": {
|
||||||
"addressed": [
|
"addressed": [
|
||||||
"6.1.1_2026-03-16.md",
|
"6.1.1_2026-03-16.md",
|
||||||
"6.1.3_2026-03-16.md",
|
"6.1.3_2026-03-16.md",
|
||||||
@@ -688,6 +691,33 @@
|
|||||||
"6.1_2026-03-16.md"
|
"6.1_2026-03-16.md"
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
|
"6.2": {
|
||||||
|
"addressed": [
|
||||||
|
"6.2.0_2026-04-02.md",
|
||||||
|
"6.2.1_2026-04-02.md",
|
||||||
|
"6.2.6_2026-04-02.md",
|
||||||
|
"6.2.7_2026-04-02.md",
|
||||||
|
"6.2.8_2026-04-02.md"
|
||||||
|
],
|
||||||
|
"known": [
|
||||||
|
"6.2.0_2026-04-02.md",
|
||||||
|
"6.2.1_2026-04-02.md",
|
||||||
|
"6.2.7_2026-04-02.md",
|
||||||
|
"6.2.8_2026-04-02.md",
|
||||||
|
"6.2.9_2026-04-02.md"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"6.3": {
|
||||||
|
"addressed": [
|
||||||
|
"6.3.3_2026-04-02.md",
|
||||||
|
"6.3.3-h1_2026-04-02.md"
|
||||||
|
],
|
||||||
|
"known": [
|
||||||
|
"6.3.3_2026-04-02.md"
|
||||||
|
]
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
"Prisma Access Agent": {
|
"Prisma Access Agent": {
|
||||||
"26": {
|
"26": {
|
||||||
"addressed": [
|
"addressed": [
|
||||||
|
|||||||
Reference in New Issue
Block a user