Added rest of GP 6.3 addressed issues
This commit is contained in:
@@ -0,0 +1,117 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: GlobalProtect
|
||||
version: 6.3.3-h2
|
||||
---
|
||||
|
||||
## GPC-23654
|
||||
|
||||
Fixed an issue where the GlobalProtect client displays the error message "The virtual adapter was not set up correctly due to a delay" on Windows endpoints, preventing VPN connectivity until the system is restarted.
|
||||
|
||||
## GPC-23604
|
||||
|
||||
Fixed an issue where GlobalProtect users were not automatically prompted for authentication on public Wi-Fi networks with a captive portal
|
||||
|
||||
## GPC-23558
|
||||
|
||||
Fixed an issue where GlobalProtect clients using SAML with Ping Federate did not save the SAML token upon reboot or restart of the pangps service, requiring users to re-authenticate even when the token was not expired. This issue affected GlobalProtect client version 6.3.3 when SAML authentication was configured in Prisma Access and not in Cloud Identity Engine.
|
||||
|
||||
## GPC-23551
|
||||
|
||||
Fixed an issue where the virtual network adapter retained the static IP address assigned by GlobalProtect even after the GlobalProtect client disconnected. This caused DNS registration conflicts, making workstations unreachable by hostname even after a reboot.
|
||||
|
||||
## GPC-23520
|
||||
|
||||
Fixed an issue where new GlobalProtect users were unable to connect to the GlobalProtect app. The app got stuck in 'Connecting" stage and stopped working when redirected to the embedded browser.
|
||||
|
||||
## GPC-23519
|
||||
|
||||
Fixed an issue where GlobalProtect HIP reports on MacBooks intermittently failed with an "Invalid client IP" error, preventing users from accessing resources over the GP tunnel. This issue occurred after a system network change when GP attempted to send the HIP report to an external gateway while the tunnel was disconnected. This issue affected MacBooks running GP version 6.2.5.
|
||||
|
||||
## GPC-23496
|
||||
|
||||
Fixed an issue where the GlobalProtect app's Connect button did not work as expected preventing users from connecting or changing gateways.
|
||||
|
||||
## GPC-23440
|
||||
|
||||
Fixed an issue where Okta FastPass authentication did not work with GlobalProtect 6.3.3 on macOS 15.5 Sequoia, where the Okta Verify app did not open for the additional authentication prompt.
|
||||
|
||||
## GPC-23432
|
||||
|
||||
Fixed an issue where the GlobalProtect app version 6.3.3 intermittently got stuck on the "finding best gateway" status
|
||||
|
||||
## GPC-23404
|
||||
|
||||
Fixed an issue where the Host Information Profile (HIP) check was unable to accurately identify key details from third-party security products.
|
||||
|
||||
## GPC-23294
|
||||
|
||||
Fixed an issue where GlobalProtect app intermittently disconnected on macOS endpoints even with a stable network connection. This was due to a timeout that was too short for the route system command.
|
||||
|
||||
## GPC-23263
|
||||
|
||||
Fixed an issue where after upgrading to GlobalProtect app version 6.3.3, the app did not save the username in the embedded browser when "save username" was enabled.
|
||||
|
||||
## GPC-23218
|
||||
|
||||
Fixed an issue where, when using the GlobalProtect app with an embedded browser, interrupting or canceling the SAML authentication prompt terminated the pre-logon tunnel, potentially allowing full internet access even when enforcer was enabled for the user-logon profile. With default browser, the pre-logon tunnel remained active when the SAML authentication prompt was interrupted.
|
||||
|
||||
## GPC-23115
|
||||
|
||||
Fixed an issue where the hardware token authentication option was intermittently unavailable while using the embedded GlobalProtect browser on Windows machines.
|
||||
|
||||
## GPC-23088
|
||||
|
||||
Fixed an issue where portal login failed due to embedded browser not popping up and GlobalProtect remains in connecting state
|
||||
|
||||
## GPC-23044
|
||||
|
||||
Fixed an issue where, when a machine was in Modern standby, the GlobalProtect app repeatedly attempted to connect to gateways, even when authentication failed due to SAML timeout. This resulted in GlobalProtect connecting to non-optimal gateway
|
||||
|
||||
## GPC-22989
|
||||
|
||||
Fixed an issue where the GlobalProtect app intermittently stopped sending HIP reports while connected to the gateway.
|
||||
|
||||
## GPC-22979
|
||||
|
||||
Fixed an issue where, after upgrading to GlobalProtect app version 6.2.6, the PanGPA application got stuck in 'Connecting' state and then got terminated unexpectedly.
|
||||
|
||||
## GPC-22887
|
||||
|
||||
Fixed an issue where GlobalProtect users experienced frequent disconnections across various locations.
|
||||
|
||||
## GPC-22870
|
||||
|
||||
Fixed an issue where, when using domain-based split tunneling on GlobalProtect clients, expired DNS TTL entries were not removed from the Windows Filtering Platform filter driver. This resulted in incorrect packet routing where traffic for domains not in the exclude list, but resolving to the same IP address as excluded domains, was routed via the physical interface instead of the tunnel.
|
||||
|
||||
## GPC-22804
|
||||
|
||||
Fixed an issue where the GlobalProtect app remained in a connected state after a network disconnection. As a result, when the network connection was restored, the GlobalProtect app did not recover, and traffic failed to pass until a refresh connection was performed.
|
||||
|
||||
## GPC-22764
|
||||
|
||||
Fixed an issue where wa_3rd_party_host_xx.exe attempted to connect to Microsoft’s update servers for information and the patch information was not sent in the HIP report. This occured even though HIP Exceptions for patch management were configured to exclude Windows updates agent.
|
||||
|
||||
## GPC-22541
|
||||
|
||||
Fixed an issue on Windows 11 where the GlobalProtect app (PanGPA) would stop working when the device was locked. The crash occurred when an expired authentication triggered a persistent smartcard login dialog during sleep, leading to excessive memory swapping and a crypt32.dll failure.
|
||||
|
||||
## GPC-22365
|
||||
|
||||
Fixed an issue where users experienced intermittent issues browsing webpages while connected to the GlobalProtect app.
|
||||
|
||||
## GPC-22033
|
||||
|
||||
Fixed an issue where GlobalProtect client version 6.3.1 experienced DNS resolution failures for IPv4 addresses, specifically when applications using the io.netty library attempted DNS lookups.
|
||||
|
||||
## GPC-22029
|
||||
|
||||
Fixed an issue where Apple software downloads took longer to complete when using GlobalProtect with split tunneling enabled.
|
||||
|
||||
## GPC-21982
|
||||
|
||||
Fixed an issue in which IPv6 traffic bypassed the valid route in the rerouting table and instead passed through the physical adapter when the GlobalProtect app was installed on Windows devices.
|
||||
|
||||
## GPC-21961
|
||||
|
||||
Fixed an issue where, after upgrading to GlobalProtect version 6.2.5, the app triggered authentication and opened multiple browser tabs when the computer woke from sleep.
|
||||
@@ -0,0 +1,77 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: GlobalProtect
|
||||
version: 6.3.3-h3
|
||||
---
|
||||
|
||||
## GPC-24113
|
||||
|
||||
Fixed an issue where, on Mac OS endpoints, the agent proxy was attempting to download PAC files directly, bypassing the configured proxy settings. This resulted in download failures when the corporate network was configured to block direct traffic.
|
||||
|
||||
## GPC-23947
|
||||
|
||||
Fixed an issue where GlobalProtect agent-msg logs were not generated on Panorama when a user disconnected from the GlobalProtect gateway.
|
||||
|
||||
## GPC-23839
|
||||
|
||||
Fixed an issue that caused the GlobalProtect 6.3.3 HIP report to fail with the error Method: WAAPI_MID_GET_AGENT_STATE
|
||||
|
||||
## GPC-23760
|
||||
|
||||
GlobalProtect app version 6.3.3 using SAML with the embedded browser loses cursor focus in the password field, requiring users to click in the password field before entering their password.
|
||||
|
||||
## GPC-23753
|
||||
|
||||
Fixed an issue where the DNS registration script configured on pre-vpn-connect did not run on the first GlobalProtect connection on version 6.3.3.
|
||||
|
||||
## GPC-23752
|
||||
|
||||
Fixed an issue where the GlobalProtect app failed to authenticate to the portal and gateway after a machine certificate was renewed by Intune MDM. A reboot was required to restore the connection.
|
||||
|
||||
## GPC-23746
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP check incorrectly detected status for Symantec Endpoint Protection, which caused the device to fail the
|
||||
|
||||
HIP check.
|
||||
|
||||
## GPC-23616
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on devices running macOS, the following error
|
||||
|
||||
"TransparentProxy: openWithLocalEndpoint failed" occurred in PanNExt.log when using an IPv6 address.
|
||||
|
||||
## GPC-23488
|
||||
|
||||
Fixed an issue where the HIP report intermittently detected MacOS XProtect "Real Time Protection" status as disabled.
|
||||
|
||||
## GPC-23468
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP check failed to detect the correct version of Forticlient Antivirus, which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-23417
|
||||
|
||||
Fixed an issue where SAML authentication with Azure AD, using Cisco Duo EAM, failed after upgrading to GlobalProtect version 6.2.8
|
||||
|
||||
## GPC-23403
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP report failed to detect the status of SentinelOne, causing the device to fail the HIP check
|
||||
|
||||
## GPC-23361
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP report did not detect the Status for Zoho corporation - ManageEngine Patch Manager Plus Agent, which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-23283
|
||||
|
||||
Fixed an issue where GlobalProtect was unable to set [exclude/include] 0.0.0.0/netmask routes on Mac endpoint
|
||||
|
||||
## GPC-23095
|
||||
|
||||
Fixed and issue where the GlobalProtect HIP report failed to detect the Symantec DLP software, which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-22156
|
||||
|
||||
Fixed an issue where the GlobalProtect application displayed unexpected characters on the user interface after installing the GlobalProtect client on Windows 11 machines. This issue was observed with GlobalProtect client versions 6.3.1-c383 and 6.2.6-838, where the Lato font appeared to be the cause.
|
||||
|
||||
## GPC-21745
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP check failed to detect Workspace ONE status, which caused the device to fail the HIP check.
|
||||
@@ -0,0 +1,109 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: GlobalProtect
|
||||
version: 6.3.3-h4
|
||||
---
|
||||
|
||||
## GPC-24332
|
||||
|
||||
Fixed an issue where users on trusted networks were incorrectly receiving a captive portal detection message and being redirected to a separate browser tab. This occurred because the GlobalProtect app was not properly handling captive portal detection response.
|
||||
|
||||
## GPC-24330
|
||||
|
||||
Fixed an issue where GlobalProtect app got stuck in a connecting state when using GlobalProtect version 6.2.8-h4. The issue was seen when saml-logout and enforcer was enabled.
|
||||
|
||||
## GPC-24235
|
||||
|
||||
Fixed an issue where, after upgrading to GlobalProtect agent 6.2.8 on macOS, users were unable to select a different portal. Clicking "Change Portal" would initiate a reconnection attempt instead of displaying the portal selection menu.
|
||||
|
||||
## GPC-24166
|
||||
|
||||
Fixed an issue where GlobalProtect agents in proxy-only mode would intermittently get stuck in a connecting state after upgrading from version 6.2.8 to 6.3.3-676. The agent would become stuck in the "Discovering external network" phase, and restarting the GlobalProtect process would temporarily resolve the issue.
|
||||
|
||||
## GPC-24086
|
||||
|
||||
Fixed an issue where, when Endpoint Traffic Policy Enforcement was enabled with "No Direct Access to Local Network" on GlobalProtect, Xcode running on macOS was unable to recognize iPhones connected via USB-C. This issue occurred because traffic enforcement blocked communication between Xcode and the iPhone.
|
||||
|
||||
## GPC-24050
|
||||
|
||||
Fixed an issue where GlobalProtect clients prompted a window to select a certificate with the error "The parameter is incorrect" because the client certificate request originated from a portal or gateway Access Control Server (ACS) and was not required.
|
||||
|
||||
## GPC-24048
|
||||
|
||||
Fixed an issue where GlobalProtect apps installed on on Dell Vostro 15 3515 laptops were unable to connect to the GlobalProtect service with the following error: "Could not connect to the GlobalProtect service. If the issue persists, contact your administrator."
|
||||
|
||||
## GPC-24036
|
||||
|
||||
Fixed an issue where the HIP check did not correctly detect the status of the ESET firewall on Windows hosts.
|
||||
|
||||
## GPC-23990
|
||||
|
||||
Fixed an issue where the captive portal opened in the embedded browser, but when the user tried to connect to the internet, it redirected to the default browser and was blocked.
|
||||
|
||||
## GPC-23913
|
||||
|
||||
Fixed an issue where the GlobalProtect app would become unresponsive when system extensions and a PAC file were enabled simultaneously.
|
||||
|
||||
## GPC-23906
|
||||
|
||||
Fixed an issue where GlobalProtect app displayed a "No Network Connectivity" error and failed to initiate a network connection, preventing access to applications.
|
||||
|
||||
## GPC-23730
|
||||
|
||||
Fixed an issue where IPv6 traffic on Windows 11 24H2 did not work as expected with GlobalProtect app.
|
||||
|
||||
## GPC-23689
|
||||
|
||||
Fixed an issue where the GlobalProtect app running on macOS devices would stuck in a connecting loop indefinitely if the user did not complete authentication, requiring manual cancellation of the connection.
|
||||
|
||||
## GPC-23650
|
||||
|
||||
Fixed an issue where the GlobalProtect enforcer blocked network traffic on Windows endpoints even after the tunnel was successfully connected.
|
||||
|
||||
## GPC-23549
|
||||
|
||||
Fixed an issue where the GlobalProtect (GP) agent briefly disconnected when a user logged on to Windows, even when the 'Pre-Logon Tunnel Rename Timeout (sec) (Windows Only)' setting was set to -1, with the error "server cert verification failed".
|
||||
|
||||
## GPC-23546
|
||||
|
||||
Fixed an issue where the SAML authentication window in the GlobalProtect client on macOS devices running version 6.2.6 or higher would sometimes display an incomplete or blank screen after the device woke up from sleep mode. This issue affects devices using the embedded browser for SAML authentication and with GlobalProtect set to always-on mode with enforcer enabled.
|
||||
|
||||
## GPC-23525
|
||||
|
||||
Fixed an issue where on macOS Ventura and Sequoia, manually changing the portal address using the GlobalProtect app UI would fail and revert back to the last connected portal. This issue occurred even when "Allow User to Change Portal Address" was enabled in the agent configuration.
|
||||
|
||||
## GPC-23466
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on devices running Windows OS and macOS, the Captive Portal detection message briefly appeared and disappeared when the Captive Portal exception timeout was set to 0.
|
||||
|
||||
## GPC-23336
|
||||
|
||||
Fixed an issue where agent disable logs were not being logged to Gateway System Logs on the firewall. The GlobalProtect agent reset the authentication code, which falsely indicated that the gateway was not fully authenticated, and the agent did not send the message.
|
||||
|
||||
## GPC-22683
|
||||
|
||||
Fixed an issue where tool tips were not available for the Add, Edit, and Delete buttons on the GlobalProtect application's settings page on Windows devices.
|
||||
|
||||
## GPC-22572
|
||||
|
||||
Fixed an issue where the hamburger menu button was disabled in the Refresh connection screen, which made it inaccessible when using a keyboard.
|
||||
|
||||
## GPC-22522
|
||||
|
||||
Fixed an issue where, after upgrading the GlobalProtect app, external users on Windows 11 computers with multiple Azure Entra accounts were unable to authenticate to the portal using SAML with Azure Entra as the Identity Provider (IdP). The new WebView2 embedded browser automatically used the user's default Windows credential for Single Sign-On (SSO), preventing them from selecting the correct account for authentication.
|
||||
|
||||
To resolve this issue a new registry key 'entra-sso' has been introduced. You can add the registry key using two methods and set it to no to disable SSO.
|
||||
|
||||
1. For pre-deployment, use 'msiexec.exe /i globalprotect64.msi ENTRASSO="no"
|
||||
|
||||
or
|
||||
|
||||
2. Add key "entra-sso" and set it to "no" under HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto Networks\GlobalProtect\Settings. If the "entra-sso" key does not exist under this path, the GlobalProtect agent's default behavior is to 'Allow' Entra SSO.
|
||||
|
||||
## GPC-22148
|
||||
|
||||
(GP App 6.3.1 enabled with FIPS-CC only) Fixed an issue where the OCSP request did not send the Host header, causing the X509v3 certificate validation to fail when accessing the OCSP or CRL.
|
||||
|
||||
## GPC-22021
|
||||
|
||||
Fixed an issue where, when using conditional-connect on macOS Sequoia with GlobalProtect client version 6.2.6, manually switching gateways caused the client to display a "Not connected" status for approximately 10 seconds while establishing a connection to the second gateway.
|
||||
@@ -0,0 +1,45 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: GlobalProtect
|
||||
version: 6.3.3-h6
|
||||
---
|
||||
|
||||
## GPC-24683
|
||||
|
||||
Fixed an issue where Host Information Profile (HIP) matching failed for Anti-Malware criteria on macOS endpoints due to GlobalProtect failing to detect the virus definition version for Kaspersky Anti-Virus.
|
||||
|
||||
## GPC-24579
|
||||
|
||||
Fixed an issue where GlobalProtect clients were unable to authenticate to internal gateways when multiple internal gateways were configured. This issue occured because the GlobalProtect client did not properly reset the SAML login flag, causing subsequent SAML pre-login requests to be ignored.
|
||||
|
||||
## GPC-24548
|
||||
|
||||
Fixed an issue where macOS GlobalProtect (GP) clients connected to an internal gateway with the enforcer enabled were unable to access the internet via a proxy. This occurred because the tunnel_connected flag remained set to 1 after the gateway disconnected, even though the gateway configuration was cleared.
|
||||
|
||||
## GPC-24261
|
||||
|
||||
Fixed an issue where GlobalProtect app running on macOS Sequoia 15.6.1 running GP 6.2.8 -c263 that receive both IPv4 and IPv6 addresses were not receiving packets back from the Network Load Balancer (NLB) instances.
|
||||
|
||||
## GPC-24221
|
||||
|
||||
Fixed an issue where the GlobalProtect app experienced a continuous connect-disconnect loop when used on flights. This issue occurred because rapid network wake-ups left network interfaces in an inconsistent state, causing GlobalProtect to attempt tunnel establishment on an unstable network foundation.
|
||||
|
||||
## GPC-24103
|
||||
|
||||
Fixed an issue where the GlobalProtect app running on macOS allowed users to modify or add a new portal address after each device reboot, even when the "Allow users to change portal" setting was configured as "No" in the GlobalProtect app.
|
||||
|
||||
## GPC-24037
|
||||
|
||||
Fixed an issue where GlobalProtect app prompted users to log in with SAML through the embedded browser even when the GlobalProtect app was already connected. This occurred when users logged off and then back onto their Cloud PC (Windows Azure PC), and closing the prompt disconnected and reconnected the VPN session.
|
||||
|
||||
## GPC-23929
|
||||
|
||||
Fixed an issue where, when GlobalProtect app was configured with Enforcer, users could bypass Enforcer restrictions by repeatedly canceling authentication prompts after logging into Windows. This occurred because the cached portal configuration, which contains Enforcer settings, was not loaded when a pre-logon tunnel failed to establish due to a quick user login. This fix ensures that the cached portal configuration is loaded as soon as PanGPA starts and PanGPS learns the username, preventing unrestricted access in scenarios where Enforcer is intended to lockdown the endpoint.
|
||||
|
||||
## GPC-23394
|
||||
|
||||
Fixed an issue where GlobalProtect app version 6.2.8-183. running on macOS 15.5 was unable to accurately report the disk encryption status of FileVault, resulting in an "unknown" status in HIP checks.
|
||||
|
||||
## GPC-22797
|
||||
|
||||
Fixed an issue where the MAC address generated for the DHCP feature changed on every GlobalProtect client restart. The MAC address should remain static after initial generation to allow static IP assignment on the DHCP server side for a specific GlobalProtect client. Additionally, the generated MAC address was not always marked as unicast and locally administered.
|
||||
@@ -0,0 +1,93 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: GlobalProtect
|
||||
version: 6.3.3-h7
|
||||
---
|
||||
|
||||
## GPC-25370
|
||||
|
||||
Fixed an issue where GlobalProtect clients (versions 6.3.3-h2-6.3.3-h4) intermittently failed to honor enforcer bypass rules for FQDNs and IP addresses after the client machine woke up from sleep. This resulted in connections to bypassed URLs being blocked, including GlobalProtect's own SAML authentication requests, and required a manual restart of the PanGPS service to restore connectivity.
|
||||
|
||||
## GPC-25172
|
||||
|
||||
Fixed an issue where, on macOS GlobalProtect clients, exclude routes were not properly removed from the system routing table after a PanGPS (GlobalProtect client) crash. This occurred because the routes remained in the macOS kernel, and upon reconnection, the client's `checkExistingExRts()` function only validated the destination and netmask, not the gateway. As a result, these stale routes, pointing to an old or unreachable gateway, were marked as existing and skipped during the reconnection process, leading to a corrupted routing state and preventing correct route injection, especially after a network change.
|
||||
|
||||
## GPC-25063
|
||||
|
||||
Fixed an issue where, in the GlobalProtect app on macOS, keyboard focus did not automatically move to the required "Enter portal Address" field when a user attempted to add a new portal without entering an address. This accessibility issue impacted keyboard-dependent users.
|
||||
|
||||
## GPC-24961
|
||||
|
||||
Fixed an issue where the firewall, when configured to obtain IP addresses from a DHCP server for GlobalProtect clients, sent a MAC address of '00' to the DHCP server specifically for MacOS 26 (Tahoe) clients running GlobalProtect App versions 6.2 or 6.3, which resulted in IP address collisions on the DHCP server.
|
||||
|
||||
## GPC-24897
|
||||
|
||||
Fixed an issue where the GlobalProtect Connect Before Logon tunnel disconnected for new users on their first logon. This issue affected GP client versions 6.2.8-hx and 6.3.3-hx.
|
||||
|
||||
## GPC-24892
|
||||
|
||||
Fixed an issue where the GlobalProtect Portal welcome page, when displayed in German, incorrectly presented a button labeled 'Genau' instead of 'Zustimmen' (Accept).
|
||||
|
||||
## GPC-24880
|
||||
|
||||
Fixed an issue where GlobalProtect clients, after upgrading to versions 6.2.8-263, 6.3.3-h2, or 6.3.3-h3, would get stuck in a connecting loop and fail to connect to the portal or gateways. This occurred because the GlobalProtect app crashed when attempting to delete previous SAML user data, specifically when the user data folder path contained non-ANSI characters that the app could not convert to a UTF-16 path.
|
||||
|
||||
## GPC-24842
|
||||
|
||||
(macOS only) GlobalProtect crashed when you clicked Change Portal on setups that included two or more portal entries and had a preferred gateway marked.
|
||||
|
||||
## GPC-24835
|
||||
|
||||
Fixed an issue where split tunneling domain exclusions on GlobalProtect App version 6.3.3-C711 for Windows clients failed to function as expected after the application disconnected and reconnected. This resulted in traffic for domains configured for exclusion being incorrectly routed through the VPN tunnel instead of directly, because the TTLMap for split tunneling domain rules was not properly cleared when the GlobalProtect App re-established its connection.
|
||||
|
||||
## GPC-24804
|
||||
|
||||
Fixed an issue where GlobalProtect clients running version 6.3.3-711 would randomly get stuck in a 'connecting' status, preventing them from establishing a successful VPN connection.
|
||||
|
||||
## GPC-24796
|
||||
|
||||
Fixed an issue where GlobalProtect HIP reports on macOS devices intermittently failed with an "Invalid client IP" error. This occurred on GlobalProtect client version 6.2.8-h4 (c317) due to a race condition where the HIP report thread sent the report during the VPN disconnect transition, causing the client to use a stale tunnel IP address instead of the physical IP address.
|
||||
|
||||
## GPC-24755
|
||||
|
||||
Fixed an issue where the GlobalProtect client on Windows machines truncated the Proxy Auto-Configuration file URL (autoConfigURL) at 104 characters when configured through the GlobalProtect Portal, preventing the full URL (up to 256 characters) from being correctly set in the Windows registry due to an insufficient internal buffer size.
|
||||
|
||||
## GPC-24515
|
||||
|
||||
Fixed an issue where GlobalProtect clients on macOS devices, specifically version 6.3.3-h2, were unable to resolve internal IPv6 domains when split tunneling was enabled and the operating system lacked native IPv6 connectivity. This occurred because the client's logic, which was designed to apply IPv6 configuration only when the OS already had native IPv6 connectivity, prevented the GlobalProtect tunnel from properly handling IPv6 traffic, resulting in "Err name not resolved" errors for internal FQDNs.
|
||||
|
||||
## GPC-24242
|
||||
|
||||
Fixed an issue where GlobalProtect portal authentication failed for some macOS users when attempting to use saved credentials. This issue, observed on GlobalProtect client versions 6.2.8 and 6.3.3, resulted in an immediate authentication failure on the client and firewall logs indicating an invalid username or password, even though the credentials were valid for other macOS clients.
|
||||
|
||||
## GPC-24216
|
||||
|
||||
Fixed an issue where the Host Information Profile (HIP) banner was not displayed on Windows 11 client machines running GlobalProtect client versions 6.2.8-h7 and 6.3.3. This occurred due to a timing or race condition where the GlobalProtect client (PanGPA) received an outdated status, preventing the visual display of HIP match or not-match notifications, even though the messages were recorded in the client logs.
|
||||
|
||||
## GPC-23963
|
||||
|
||||
Fixed an issue where GlobalProtect Client version 6.2.8 running in Windows 365 environments, would experience PanGPA getting stuck during the tunnel rename process. This prevented successful gateway authentication and registration after users closed and re-opened their Windows 365 session, leading to a pop-up message prompting users to re-authenticate.
|
||||
|
||||
## GPC-23787
|
||||
|
||||
Fixed an issue where GlobalProtect clients on macOS devices, after upgrading to version 6.2.8-h2, were unable to connect to the authentication server. This occurred because incorrect logic in the GlobalProtect Agent code prevented the Webview Process ID from syncing with the Network Extension process, causing the Network Extension to block SAML authentication traffic, resulting in a "Could not connect to the authentication server" error and a blank embedded browser during SAML authentication.
|
||||
|
||||
## GPC-23723
|
||||
|
||||
Fixed an issue where GlobalProtect clients running version 6.2.8-h1 (6.2.8-c223) experienced intermittent connection failures and disconnections, with the client agent getting stuck in a 'connecting' state even when backend logs indicated a successful connection. This occurred because, when conditional connect mode was enabled, the client attempted to impersonate a user and write On-Demand settings to the user's registry hive (HKEY_CURRENT_USER) during pre-logon. As no user was logged in at that stage, user impersonation failed, leading to incorrect registry access or failed registry operations, which caused service instability or misconfiguration.
|
||||
|
||||
## GPC-23090
|
||||
|
||||
Fixed an issue where the GlobalProtect app experienced connectivity issues after the host computer resumed from sleep mode due to a missing self-pointed route. This issue resulted in a delay of 5 to 10 minutes for the GlobalProtect connection to get stabilized.
|
||||
|
||||
## GPC-21852
|
||||
|
||||
Fixed an issue where the GlobalProtect Agent incorrectly displayed "N/A" in the "Last Scan Time" field for the Trend Micro Deep Security Agent within the Host Information Profile (HIP) report.
|
||||
|
||||
## GPC-20621
|
||||
|
||||
Fixed an issue where users from overseas locations were disconnected from GlobalProtect due to the HIP report not being sent with manual gateway selection.
|
||||
|
||||
## GPC-18976
|
||||
|
||||
Fixed an issue where GlobalProtect client 6.1.1-5 would select the incorrect Windows tile by default after locking the screen when using Single Sign-On for Smart Card PIN (Windows) with the Yubikey Smart Card Minidriver. When multiple smart cards were present, GlobalProtect incorrectly selected the last enumerated card instead of the currently active one.
|
||||
@@ -0,0 +1,25 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: GlobalProtect
|
||||
version: 6.3.3-h8
|
||||
---
|
||||
|
||||
## GPC-25300
|
||||
|
||||
Fixed an issue where GlobalProtect clients experienced frequent disconnections from GlobalProtect gateways. After being disconnected, users were often unable to reconnect for extended periods, and connection attempts to designated gateways, including those manually selected or identified as 'Best Available', would incorrectly redirect to other gateways.
|
||||
|
||||
## GPC-25222
|
||||
|
||||
Fixed an issue where GlobalProtect clients failed to detect captive portals on public Wi-Fi networks, even when the captive portal responded with an HTTP 302 Redirect. This occurred because the GlobalProtect agent expected the HTTP response to be terminated by `\r\n\r\n` as per RFC, but some captive portals did not adhere to this, causing the agent to incorrectly report that no data was received from the captive portal server and thus fail to detect the portal.
|
||||
|
||||
## GPC-25173
|
||||
|
||||
Fixed an issue where GlobalProtect clients on macOS devices, when configured in tunnel-proxy mode, intermittently displayed an "A valid PAC file is required" notification after waking up from modern standby, particularly when the PAC file contained a placeholder statement instead of the actual EP-FQDN.
|
||||
|
||||
## GPC-24992
|
||||
|
||||
Fixed an issue where GlobalProtect users experienced significant login delays after a system reboot or shutdown, such as after a weekend. This delay was caused by a shared memory issue that disrupted communication between the GlobalProtect agent and GlobalProtect service.
|
||||
|
||||
## GPC-23301
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app 6.2.7 and later, was installed on Windows 10 devices, the app deleted the predefined proxy PAC file configuration whenever the app got disconnected regardless of whether the disconnection was initiated manually or occurred automatically due to a timeout.
|
||||
Reference in New Issue
Block a user