Added GP 6.2 addressed issues
This commit is contained in:
@@ -0,0 +1,201 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: GlobalProtect
|
||||
version: 6.2.1
|
||||
---
|
||||
|
||||
## GPC-18789
|
||||
|
||||
Fixed an issue where the GlobalProtect app took a long time to connect to the gateway when the include domain list was used, while the enhanced split-tunnel feature was not used.
|
||||
|
||||
## GPC-18788
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP check did not detect McAfee Total Protection as an anti-malware application, which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-18594
|
||||
|
||||
Fixed an issue where the GlobalProtect app was unable to send HIP reports when the app was connected using IPv6.
|
||||
|
||||
## GPC-18566
|
||||
|
||||
Fixed an issue where the GlobalProtect app incorrectly displayed the gateway as internal when it was connected to an external gateway.
|
||||
|
||||
## GPC-18528
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP check incorrectly detected the version for KES 12 (Kaspersky Endpoint Security), which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-18509
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was configured with the Internal Host Detection and Conditional Connect method, the app did not connect to the internal network when the network was changed from external to internal as it should have with the Conditional Connect method enabled.
|
||||
|
||||
## GPC-18452
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on Windows devices the app did not start right away after a system reboot.
|
||||
|
||||
## GPC-18426
|
||||
|
||||
Fixed an issue where when the GlobalProtect app was configured with the Disable GlobalProtect set to Allow with Ticket, the app did not display the correct Disable Duration time.
|
||||
|
||||
## GPC-18336
|
||||
|
||||
Fixed an issue where the GlobalProtect app got automatically connected after a system reboot even though the connection method configured was On-Demand.
|
||||
|
||||
## GPC-18318
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was connected to the internal gateway, the app displayed the message as Connected - Inter.... instead of Connected - Internal.
|
||||
|
||||
## GPC-18281
|
||||
|
||||
Fixed an issue where the MSI install logs showed mutiple messages for Autonomous DEM installation.
|
||||
|
||||
## GPC-18251
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP check did not detect McAfee LiveSafe as an anti-malware application, which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-18230
|
||||
|
||||
Fixed an issue where, when the user entered credentials during SAML authentication after the set internal login timer, the app displayed an authentication failed message without providing the reason. The Retry button on the app web interface did not work properly when using an embedded browser for authentication. The Retry button was not fully visible on the embedded browser.
|
||||
|
||||
## GPC-18175
|
||||
|
||||
Fixed an issue where users were prompted to enter their credentials even when the GlobalProtect app was configured for authenticating with either Authentication Profile /Cookie or Client Certificate.
|
||||
|
||||
## GPC-18173
|
||||
|
||||
Fixed an issue where the vertical scroll bar on the GlobalProtect app web interface did not work properly when users tried to select the certificate from the drop-down.
|
||||
|
||||
## GPC-18171
|
||||
|
||||
Fixed an issue where users were unable to select the external gateway manually when connected to the internal network. The GlobalProtect stayed in Connecting state and users had to manually disconnect the connection and connect to the internal network to exit the Connecting state.
|
||||
|
||||
## GPC-18167
|
||||
|
||||
Fixed an issue where the GlobalProtect app displayed the Prisma Access gateways that are not set for manual selection.
|
||||
|
||||
## GPC-18146
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on Windows devices, the GlobalProtect HIP check did not detect the correct details for Cortex XDR, which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-18135
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on devices running macOS, the GlobalProtect HIP check detected the WithSecure antivirus software as XProtect, which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-18107
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP check did not detect McAfee LiveSafe – Internet Security, which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-18092
|
||||
|
||||
Fixed an issue where GlobalProtect connected to an internal gateway got automatically disconnected after a certain period of time.
|
||||
|
||||
## GPC-18073
|
||||
|
||||
Fixed an issue where the GlobalProtect app selected an unexpected gateway due to a latency discrepancy seen between PanGPS and packet capture.
|
||||
|
||||
## GPC-18060
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP check did not detect McAfee Total Protection, which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-18036
|
||||
|
||||
Fixed an issue where, when the No direct access to local network option was enabled on the GlobalProtect app with access routes excluded from the GlobalProtect VPN tunnel, the feature did not work as expected when Endpoint Traffic Policy Enforcement was enabled.
|
||||
|
||||
## GPC-17936
|
||||
|
||||
Fixed an issue where the Conditional Connect method did not work as expected and users had to manually connect the app when they changed their network.
|
||||
|
||||
## GPC-17921
|
||||
|
||||
Fixed an issue where, when the language was set to Japanese, the time to connect was not displayed properly when Disconnect Timeout for the app was configured.
|
||||
|
||||
## GPC-17896
|
||||
|
||||
Fixed an issue where users were unable to connect to GlobalProtect gateway when only one external gateway was added due to the following error: Cannot Verify Server Certificate of Gateway.
|
||||
|
||||
## GPC-17816
|
||||
|
||||
Fixed an issue ehere after entering CIE SAML authentication credentials to refresh an expired explicit proxy token or cookie when connected in Tunnel and Proxy mode or proxy mode, the GlobalProtect app got stuck while retrieving the portal configuration.
|
||||
|
||||
## GPC-17795
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP check did not detect the Xcitium Enterprise, the Endpoint Protection Platform by COMODO, which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-17776
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on devices running macOS and GlobalProtect enforcer was configured with allowed FQDNs, users were still able to access the internet and other public domains.
|
||||
|
||||
## GPC-17762
|
||||
|
||||
Fixed an issue when the GlobalProtect app was configured with the option Allow User to Disable GlobalProtect App with comment, the option did not work as expected.
|
||||
|
||||
## GPC-17748
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP check did not detect the Real-Time Protection status correctly for the CrowdStrike Falcon application, which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-17740
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was connected through the Prisma Access gateway, the upload speed of the internet was reduced to 2 Mbps.
|
||||
|
||||
## GPC-17728
|
||||
|
||||
Fixed an issue where users were unable to connect to GlobalProtect gateway when only one external gateway was added due to the following error: Cannot Verify Server Certificate of Gateway.
|
||||
|
||||
## GPC-17460
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on Windows 10 or 11 devices, and when the user tried to authenticate using SAML authentication, the app did not display the Term of Use pop-up on the Welcome page properly.
|
||||
|
||||
## GPC-17398
|
||||
|
||||
Fixed an issue where the GlobalProtect app SettingsConnection tab did not display the Assigned IP Address(es) and Gateway IP Address properly.
|
||||
|
||||
## GPC-17206
|
||||
|
||||
Fixed an issue where, when Internal Host Detection (IHD) was enabled but failed to detect the internal network properly, the app failed to switch to the external gateway when users switched from an internal network to an external network.
|
||||
|
||||
## GPC-17161
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on devices running macOS, the GlobalProtect app failed to reconnect and continued to stay in the Connecting state after the device woke up from Modern Standby mode.
|
||||
|
||||
## GPC-17099
|
||||
|
||||
When the GlobalProtect app for Windows is upgraded to version 6.0.5, devices with Driver Verifier enabled and configured to monitor the PAN virtual adapter driver (pangpd.sys) display the DRIVER_VERIFIER_DETECTED_VIOLATION Blue Screen error.
|
||||
|
||||
## GPC-17001
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on devices running on macOS, the app did not display the Connect button and Refresh Connection button properly.
|
||||
|
||||
## GPC-16978
|
||||
|
||||
Fixed an issue where the GlobalProtect app took a long time to establish a connection due to an erroneous packet capture process.
|
||||
|
||||
## GPC-16851
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on devices running macOS, the app did not try to auto-connect to the gateway after exceeding the Disable Timeout Value.
|
||||
|
||||
## GPC-16397
|
||||
|
||||
Fixed an issue where the GlobalProtect app was installed on devices running macOS, a blank GlobalProtect app user interface was displayed instead of the correct page.
|
||||
|
||||
## GPC-16126
|
||||
|
||||
Fixed an issue where the GlobalProtect app did not display the certificate name in the Client Certificate selection field properly.
|
||||
|
||||
## GPC-16003
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on devices running macOS, the app was not connected when the proxy was configured for Safari or Chrome.
|
||||
|
||||
## GPC-15968
|
||||
|
||||
Fixed an issue where the GlobalProtect app was stuck in Connecting state when users failed to authenticate with SAML and using an embedded browser. Users were unable to disconnect the app and had to reboot the device.
|
||||
|
||||
## GPC-15262
|
||||
|
||||
Fixed an issue where when single sign-on (SSO) for Smart Cards was used for authentication, users were prompted to enter a PIN instead of a password on the Windows login screen.
|
||||
|
||||
## GPC-15234
|
||||
|
||||
Fixed an issue where the app would get stuck at Connecting state while trying to connect to a gateway.
|
||||
|
||||
## GPC-15080
|
||||
|
||||
Fixed an issue where when the split tunnel was configured based on the destination domain, split tunneling did not work as expected when IPv6 traffic exclusion was configured.
|
||||
@@ -0,0 +1,37 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: GlobalProtect
|
||||
version: 6.2.2
|
||||
---
|
||||
|
||||
## GPC-19116
|
||||
|
||||
Fixed an issue where the user faced authentication issues while the GlobalProtect app was attempting to refresh the explicit proxy token.
|
||||
|
||||
## GPC-19049
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was configured in hybrid mode with internal host detection, the app failed to connect and continued to stay in the Connecting state when users tried to connect using SAML authentication.
|
||||
|
||||
## GPC-19007
|
||||
|
||||
Fixed an issue where users were unable to connect to the GlobalProtect portal and gateway after upgrading the app version to 6.2.1.
|
||||
|
||||
## GPC-19002
|
||||
|
||||
Fixed an issue where the GlobalProtect app did not display the Connect button when the user clicked the Get Started button after the app installation through Jamf.
|
||||
|
||||
## GPC-18991
|
||||
|
||||
Fixed an issue where the proxy auto-configuration (PAC) files were not restored as expected after a system reboot or when the user disconnected the GlobalProtect app.
|
||||
|
||||
## GPC-18964
|
||||
|
||||
Fixed an issue where the GlobalProtect tunnel got disconnected after 10 minutes on the app versions 6.0.8 and 6.2.1, when the GlobalProtect app was running on macOS devices and SAML authentication was used to authenticate.
|
||||
|
||||
## GPC-18861
|
||||
|
||||
Fixed an issue where the GlobalProtect MSI download was getting stuck at 27%.
|
||||
|
||||
## GPC-18471
|
||||
|
||||
Fixed an issue where, when multiple wa_3rd_party_host_64.exe processes persisted even after the HIP check, the GlobalProtect app stopped working.
|
||||
@@ -0,0 +1,21 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: GlobalProtect
|
||||
version: 6.2.3-c287
|
||||
---
|
||||
|
||||
## GPC-20243
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was used with an embedded browser, the browser displayed ‘can't reach page’ due to a Windows filter driver issue.
|
||||
|
||||
## GPC-20157
|
||||
|
||||
Fixed an issue where the gateway location was not correctly displayed in the Connections panel.
|
||||
|
||||
## GPC-20143
|
||||
|
||||
Fixed an issue where the user was redirected to the Authentication page twice on the default browser for both portal and gateway authentication when SAML was configured.
|
||||
|
||||
## GPC-19991
|
||||
|
||||
Fixed an issue where client certificate authentication between embedded browser and IdP (SAML) failed.
|
||||
@@ -0,0 +1,309 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: GlobalProtect
|
||||
version: 6.2.3
|
||||
---
|
||||
|
||||
## GPC-20970
|
||||
|
||||
Fixed an issue where GlobalProtect had intermittent connectivity issues on Prisma Access IP optimization enabled tenants.
|
||||
|
||||
## GPC-19968
|
||||
|
||||
Fixed an issue where the GlobalProtect agent failed to detect Bitdefender Antivirus Plus on the Windows ARM64 platform during the HIP check.
|
||||
|
||||
## GPC-19924
|
||||
|
||||
Resolved intermittent connection issues for users accessing GlobalProtect via an embedded browser.
|
||||
|
||||
## GPC-19901
|
||||
|
||||
Fixed an issue where the GlobalProtect client for Mac users was intermittently disconnecting and reconnecting.
|
||||
|
||||
## GPC-19840
|
||||
|
||||
Fixed an issue where Mac computers did not display all gateways in the Search Gateway tab.
|
||||
|
||||
## GPC-19818
|
||||
|
||||
Fixed an issue where when the Enforcer was enabled, Jamf connect was not working after the MacBook was rebooted. Users had to log in manually.
|
||||
|
||||
## GPC-19784
|
||||
|
||||
Fixed an issue where the HIP check did not detect McAfee Premium individual.
|
||||
|
||||
## GPC-19753
|
||||
|
||||
Fixed an issue where the GlobalProtect icon could not be selected using the keyboard.
|
||||
|
||||
## GPC-19712
|
||||
|
||||
Fixed an issue where PanGPS crashed on 6.0.4 caused by invalid memory reference. GlobalProtect did not run correctly after the system was rebooted.
|
||||
|
||||
## GPC-19686
|
||||
|
||||
Fixed an issue where translation errors were observed in the GlobalProtect app for French localization.
|
||||
|
||||
## GPC-19664
|
||||
|
||||
Fixed an issue where users were able to deploy GlobalProtect from JAMF on Mac Sonoma, but the connection to the portal was stuck.
|
||||
|
||||
## GPC-19659
|
||||
|
||||
Fixed an issue where macOS users were connected to the GlobalProtect app before they agreed to their company’s terms of service.
|
||||
|
||||
## GPC-19656
|
||||
|
||||
Resolved an issue where connecting to a GlobalProtect gateway with IPv6 from macOS resulted in the tunnel connection dropping every 45 seconds when Endpoint Traffic Policy Enforcement was set to All Traffic.
|
||||
|
||||
## GPC-19630
|
||||
|
||||
Fixed an issue where the prelogon connect method failed on the gateway prelogin stage.
|
||||
|
||||
## GPC-19587
|
||||
|
||||
Fixed an issue where the user could not login with Okta on macOS when Endpoint Traffic Policy Enforcement was set to All traffic .
|
||||
|
||||
## GPC-19581
|
||||
|
||||
Fixed an issue where GlobalProtect indicated that Windows firewall was not enabled in the HIP report even though it was enabled.
|
||||
|
||||
## GPC-19545
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on devices running macOS, users were unable to connect to the GlobalProtect app when they used T-Mobile iPhone hotspot.
|
||||
|
||||
## GPC-19524
|
||||
|
||||
Fixed an issue where the GlobalProtect app connection failed when the user used CAS authentication to authenticate to the app. The app displayed the error message, "Username from CAS SSO response is different from the input".
|
||||
|
||||
## GPC-19513
|
||||
|
||||
Fixed an issue where the GlobalProtect client was trying to use the old portal's authorization cookie to login instead of the newly migrated portal. This happened when the user changed from secondary portal to primary portal or vice versa without signing out.
|
||||
|
||||
## GPC-19475
|
||||
|
||||
Fixed an issue where users got connection errors in an embedded browser after the computer woke up from sleep or when the user switched gateways.
|
||||
|
||||
## GPC-19449
|
||||
|
||||
Fixed an issue where the GlobalProtect client was trying to use the old portal's authorization cookie to login instead of the newly migrated portal. This happened when the user changed the portal from secondary to primary or vice versa without signing out.
|
||||
|
||||
## GPC-19433
|
||||
|
||||
Fixed an issue where a small white blank page randomly popped up on the user's screen and the focus shifted to this blank page. This issue occurs while the computer is connected to Global Protect.
|
||||
|
||||
## GPC-19431
|
||||
|
||||
Fixed an issue where interactive components in the session tray on Windows did not receive keyboard focus and were not keyboard operable.
|
||||
|
||||
## GPC-19418
|
||||
|
||||
Fixed an issue where GlobalProtect users randomly experienced issues connecting to the gateway after their computer woke up. This occurred when Enforce GlobalProtect for Network Access was enabled and Tunnel and Proxy was set to agent mode.
|
||||
|
||||
## GPC-19416
|
||||
|
||||
Fixed a GlobalProtect redirection issue in embedded browser. When a user tried to connect to GlobalProtect, an error was displayed while waiting for the SAML response instead of being redirected to the embedded browser.
|
||||
|
||||
## GPC-19414
|
||||
|
||||
Fixed an issue where GlobalProtect Always-On connect method was not triggered after a reboot when the connect-method setting was set to on-demand in the Windows Registry.
|
||||
|
||||
## GPC-19403
|
||||
|
||||
Fixed an issue where OPSWAT was unable to detect Kaspersky after an upgrade from 21.3.10.391 to 21.15.8.493.
|
||||
|
||||
## GPC-19400
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP check did not detect the Definition Date for Bitdefender Virus Scanner, which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-19391
|
||||
|
||||
Fixed an issue where GlobalProtect stayed disconnected even after being unlocked.
|
||||
|
||||
## GPC-19387
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on devices running macOS, the app displayed text incorrectly when the system language was German.
|
||||
|
||||
## GPC-19374
|
||||
|
||||
Fixed an issue where the GlobalProtect debug logs displayed information, which was not supposed to display in the logs.
|
||||
|
||||
## GPC-19359
|
||||
|
||||
Fixed an issue where system extensions on MacBook were not updated after the GlobalProtect client was upgraded.
|
||||
|
||||
## GPC-19340
|
||||
|
||||
Fixed an issue where the GlobalProtect app failed to send HIP reports hourly.
|
||||
|
||||
## GPC-19337
|
||||
|
||||
Fixed an issue where the Captive Portal functionality of the GlobalProtect app did not work as expected when the users used public Wi-Fi hotspots.
|
||||
|
||||
## GPC-19331
|
||||
|
||||
Fixed an issue where, when SAML authentication was used to authenticate to the GlobalProtect app, the app used an unknown username ‘SAMLUser’ which was not configured instead of the actual username of the user, which caused an authentication failure.
|
||||
|
||||
## GPC-19314
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app is installed on devices running macOS, the app displayed the message, ‘Downloading in progress’ when the GlobalProtect app was upgraded to 6.0.x using the option ‘Allow Transparently.’ The app should not display the message when upgraded using the transparent method.
|
||||
|
||||
## GPC-19284
|
||||
|
||||
Fixed an issue where GlobalProtect was unable to extend user session.
|
||||
|
||||
## GPC-19280
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app transitioned from pre-logon to user-logon tunnel, the app did not display the list of gateways for the users to change the gateway. The gateway list was displayed only when the app was refreshed.
|
||||
|
||||
## GPC-19262
|
||||
|
||||
Fixed an issue where GlobalProtect 6.2.1 tried to connect automatically after the user restarted their computer even though the connect method was set to On-Demand.
|
||||
|
||||
## GPC-19193
|
||||
|
||||
Fixed an issue where the GlobalProtect app was unable to fetch Windows firewall and antimalware information correctly.
|
||||
|
||||
## GPC-19162
|
||||
|
||||
Fixed an issue where, when the user upgraded the GlobalProtect version to 5.2.13 or later, the HIP report displayed the DLP ‘Digital Guardian Agent’ as disabled.
|
||||
|
||||
## GPC-19107
|
||||
|
||||
Fixed an issue where some log files were missing from the GlobalProtect bundle when downloaded from the Explore app.
|
||||
|
||||
## GPC-19104
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP report failed to detect the Real Time Protection status for Cortex XDR, which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-19083
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on devices running macOS, the Connection tab under app Settings did not display the connection status and refresh connection did not work when the Settings window was opened.
|
||||
|
||||
## GPC-19074
|
||||
|
||||
Fixed an issue where Login Lifetime was incorrectly translated on the French version of the GlobalProtect 6.2.1 app.
|
||||
|
||||
## GPC-19060
|
||||
|
||||
Fixed an issue where the app Settings -> Connection tab did not display the connection status when the app was changed from a non-tunneled gateway to a tunneled gateway.
|
||||
|
||||
## GPC-19044
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on Windows devices and the user changed the network from wired to wireless within the organization, the device displayed a blue screen.
|
||||
|
||||
## GPC-19023
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app version 5.2.13 was installed on devices running macOS, the users were unable to connect to the Zoom application.
|
||||
|
||||
## GPC-19009
|
||||
|
||||
Fixed an issue where, when SAML authentication was used to authenticate to the GlobalProtect app and the user changed the gateway to a manual gateway, the app stayed in the ‘Connecting’ stage.
|
||||
|
||||
## GPC-18992
|
||||
|
||||
Fixed an issue where internet via WiFi connection was unavailable for GlobalProtect users after their computer woke up from sleep because the client WiFi adapter was unable to obtain a DHCP IP address. This issue occurred on computers where Enforce GlobalProtect for Network Access was enabled.
|
||||
|
||||
## GPC-18983
|
||||
|
||||
Fixed an issue where the Central Authentication Service (CAS) authentication did not work when the GlobalProtect app was connected to an internal gateway and the app repeatedly opened the SAML authentication page.
|
||||
|
||||
## GPC-18913
|
||||
|
||||
Fixed an issue where the GlobalProtect app displayed the connection status as ‘Not Connected’ even though the app was connected to the internal gateway.
|
||||
|
||||
## GPC-18907
|
||||
|
||||
Fixed an issue where the GlobalProtect app running on macOS endpoints did not query the secondary DNS (when primary DNS is not responding) when the domain was part of the exclude domain list (both network and DNS).
|
||||
|
||||
## GPC-18854
|
||||
|
||||
Fixed an issue where users were prompted twice to authenticate using SAML authentication when used with CAS authentication and authentication override cookie, the GlobalProtect app got stuck in the 'Connecting' stage while trying to connect.
|
||||
|
||||
## GPC-18845
|
||||
|
||||
Fixed an issue, where the GlobalProtect app was installed manually and the user clicked the ‘Get Started’ button, the app displayed the incorrect message, "Oops! Slow or No Network Connection" instead of the actual message "Not Connected" window where they can input their portal address.
|
||||
|
||||
## GPC-18828
|
||||
|
||||
Fixed an issue where split tunnel CNAME records were created before the GlobalProtect tunnel was established.
|
||||
|
||||
## GPC-18822
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on Windows devices and the device was reset using the Microsoft Recovery tool, the GlobalProtect app was not properly displayed.
|
||||
|
||||
## GPC-18815
|
||||
|
||||
Fixed an issue where the Logon button on the GlobalProtect login screen stopped working after receiving the Microsoft Edge WebView2 runtime, 117.0.2045.36 update on the devices.
|
||||
|
||||
## GPC-18750
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on devices running macOS, the GlobalProtect HIP check did not detect the Total Defense antivirus application, which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-18733
|
||||
|
||||
Fixed an issue where the hyperlinks with the URLs containing the "=" character in the HIP notification message did not work as expected and the page did not open when the user clicked the URL.
|
||||
|
||||
## GPC-18720
|
||||
|
||||
Fixed an issue where the GlobalProtect app became unresponsive when the user clicked the ESCbutton during authentication using a hard token.
|
||||
|
||||
## GPC-18703
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP check did not detect the Trellix Endpoint Security application, which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-18598
|
||||
|
||||
Fixed an issue where the GlobalProtect SSO tile was selected instead of the Windows Password tile in the Windows Login screen even though the registry key MakeGPCPDefault was set to No.
|
||||
|
||||
## GPC-18384
|
||||
|
||||
Fixed an issue where GlobalProtect did not connect while Netskope was connected and vice-versa.
|
||||
|
||||
## GPC-18379
|
||||
|
||||
Fixed an issue where, when the IP address type was set to IPv4 and IPv6, the GlobalProtect app could connect only to the manual gateway instead of connecting to the best available gateway.
|
||||
|
||||
## GPC-18223
|
||||
|
||||
Fixed an issue where GlobalProtect experienced a prolonged connection time when IPv6 was disabled on Windows devices.
|
||||
|
||||
## GPC-18157
|
||||
|
||||
Fixed an issue where the GlobalProtect app displayed the Credential Provider language in English when the system language was German.
|
||||
|
||||
## GPC-18039
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP check did not detect the Definition Date correctly for the CrowdStrike application, which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-18025
|
||||
|
||||
In 6.2.1, after a refresh connection, the HIP patch exclusion isn't visible on the GlobalProtect UI. However, the HIP patch exclusion logs are visible on the Pangphip.log file.
|
||||
|
||||
## GPC-17640
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP check did not detect the Definition Date correctly for the CrowdStrike application, which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-17518
|
||||
|
||||
Fixed an issue where the GlobalProtect app displayed the status as 'Connected-Internal' even when the app was not connected.
|
||||
|
||||
## GPC-17436
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on devices running macOS, the upload speed of the internet was reduced after a version upgrade.
|
||||
|
||||
## GPC-17204
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on devices running macOS, the certificate information was not accessible even though the GlobalProtect app had full access to the certificate store.
|
||||
|
||||
## GPC-16975
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on devices running macOS, the screen reader did not announce the name of the GlobalProtect gateway when the gateway was marked with the star symbol.
|
||||
|
||||
## GPC-16584
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP check did not detect the CrowdStrike antivirus software correctly, causing the device to fail the HIP check.
|
||||
|
||||
## GPC-15123
|
||||
|
||||
Fixed an issue where users were unable to collapse the Change Portal and Change Gateway menus using the Escape key.
|
||||
@@ -0,0 +1,301 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: GlobalProtect
|
||||
version: 6.2.4
|
||||
---
|
||||
|
||||
## GPC-20741
|
||||
|
||||
Fixed an issue where the GlobalProtect app intermittently disconnected from the gateway when the user was using the embedded browser for SAML authentication.
|
||||
|
||||
## GPC-20640
|
||||
|
||||
Fixed an issue where the GP App graphical interface on macOS does not close on pressing the ESC key.
|
||||
|
||||
## GPC-20585
|
||||
|
||||
Fixed an issue where the GlobalProtect app could not connect to the GlobalProtect portal when configured with certificate authentication and SAML authentication using an embedded browser
|
||||
|
||||
## GPC-20571
|
||||
|
||||
Fixed an issue where the Report an Issue option was not visible in the GlobalProtect app version 6.2.3.
|
||||
|
||||
## GPC-20542
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on Windows devices, the GlobalProtect logs did not display the username correctly.
|
||||
|
||||
## GPC-20537
|
||||
|
||||
Fixed an issue where the Login page got redirected twice and opened two separate tabs for GlobalProtect portal and gateway, when the user tried to connect the GlobalProtect app using the SAML authentication method.
|
||||
|
||||
## GPC-20531
|
||||
|
||||
Fixed an issue where, when the user was using Remote Desktop with GlobalProtect, the RDP sessions got disconnected because the GlobalProtect on RDP station got disconnected with a grace period end message.
|
||||
|
||||
## GPC-20527
|
||||
|
||||
Fixed an issue where the Conditional Connect method configured for the GlobalProtect app did not work as expected when the user shifted from external network (home) to an internal network (office). Users had to reboot the system to resolve this issue.
|
||||
|
||||
## GPC-20514
|
||||
|
||||
Fixed an issue where the remote users using GlobalProtect with Connect Before Logon (CBL) were unable to reset their password when using the app with an embedded browser.
|
||||
|
||||
## GPC-20455
|
||||
|
||||
Fixed an issue where the GlobalProtect app intermittently got stuck on the 'Connecting' status when the computer resumed from sleep and a new authentication was needed or authentication cookies had expired.
|
||||
|
||||
## GPC-20445
|
||||
|
||||
Fixed an issue where the GlobalProtect app got stuck in Connecting state after upgrading from PAN-OS 10.1.11-h5 version to PAN-OS 10.1.13
|
||||
|
||||
## GPC-20444
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was used with the SAML authentication method, the app displayed two pop-up messages; one with a successful authentication message and the other with an authentication failure message.
|
||||
|
||||
## GPC-20426
|
||||
|
||||
Fixed an issue where a new HIP report was not generated when the user disabled AV on an end-user device.
|
||||
|
||||
## GPC-20381
|
||||
|
||||
Fixed an issue where the Windows defender Real Time Protection state and agent version is incorrectly identified in GlobalProtect app version 6.0.8 and 6.2.3.
|
||||
|
||||
## GPC-20378
|
||||
|
||||
Fixed an issue where the GlobalProtect app was used with the SAML authentication method with the embedded browser, the app got stuck while redirecting to the SAML authentication page.
|
||||
|
||||
## GPC-20374
|
||||
|
||||
Fixed an issue where users were unable to connect to GlobalProtect if they accidentally clicked decline on the Terms of Service page.
|
||||
|
||||
## GPC-20370
|
||||
|
||||
Fixed an issue where the Real Time Protection state from SentinelOne was displayed as true even when the app was disabled.
|
||||
|
||||
## GPC-20366
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on Windows devices and the users tried to authenticate to the app, the screen displayed both authentication success and failed message even when the authentication was successful.
|
||||
|
||||
## GPC-20320
|
||||
|
||||
GlobalProtect unable to authenticate with SAML IdP using embedded browser (webview2) when "Enforce GlobalProtect for Network Access" is enabled
|
||||
|
||||
## GPC-20279
|
||||
|
||||
Fixed an issue where users were presented with suggested user names during SAML authentication after upgrading to GlobalProtect 6.2.3.
|
||||
|
||||
## GPC-20263
|
||||
|
||||
Fixed an issue where the correct label was not associated with the GlobalProtect icon so voice over was unable to read the icon name.
|
||||
|
||||
## GPC-20262
|
||||
|
||||
Fixed an issue where users were unable to select the GlobalProtect icon from the status bar on macOS.
|
||||
|
||||
## GPC-20243
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was used with an embedded browser, the browser displayed ‘can't reach page’ due to a Windows filter driver issue.
|
||||
|
||||
## GPC-20242
|
||||
|
||||
Fixed an issue where the GlobalProtect app displayed gibberish text on the app.
|
||||
|
||||
## GPC-20241
|
||||
|
||||
Resolved an issue where the GlobalProtect app did not detect HIP information for HP Wolf Security software.
|
||||
|
||||
## GPC-20178
|
||||
|
||||
Resolved an issue where the Certificate Revocation List was sent to a URI that was not an exact match with the URI in the certificate.
|
||||
|
||||
## GPC-20163
|
||||
|
||||
Fixed an issue where the GlobalProtect app was unable to connect to the gateway via IPv6.
|
||||
|
||||
## GPC-20162
|
||||
|
||||
Fixed an issue where the GlobalProtect enforcer blocked some DHCPv6 packets on Windows computers.
|
||||
|
||||
## GPC-20157
|
||||
|
||||
Fixed an issue where the gateway location was not correctly displayed in the Connections panel.
|
||||
|
||||
## GPC-20143
|
||||
|
||||
Fixed an issue where the user was redirected to the Authentication page twice on the default browser for both portal and gateway authentication when SAML was configured.
|
||||
|
||||
## GPC-20091
|
||||
|
||||
Fixed an issue where pre-logon failed when the computer was rebooted, when the machine store had an expired and active certificate.
|
||||
|
||||
## GPC-20080
|
||||
|
||||
Fixed an issue where the GlobalProtect logs displayed different event messages for Windows and macOS devices when the Allow User to Disable GlobalProtect App was set to Allow with Passcode for the GlobalProtect app.
|
||||
|
||||
## GPC-20060
|
||||
|
||||
Fixed an issue where it was possible for the GlobalProtect enforcer to be disabled when there was a network change during portal authentication.
|
||||
|
||||
## GPC-20040
|
||||
|
||||
Resolved an issue where GlobalProtect did not re-check for internal gateways when using cached portal configuration and an external network was previously detected.
|
||||
|
||||
## GPC-20028
|
||||
|
||||
Fixed an issue where macOS users, despite having 'Allow User to Change Portal Address' set to No, were able to choose a different portal from the existing list.
|
||||
|
||||
## GPC-20005
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on Windows devices, users were able to select the manual gateway and connect to the app even when the regional or global fall back gateway was not configured.
|
||||
|
||||
## GPC-20004
|
||||
|
||||
Fixed an issue where both certificates with and without the specified OID were incorrectly being selected as potential machine certificates.
|
||||
|
||||
## GPC-20003
|
||||
|
||||
Fixed an issue where GlobalProtect users with certificates were unable to connect a gateway on version 6.0.9.
|
||||
|
||||
## GPC-19991
|
||||
|
||||
Fixed an issue where client certificate authentication between embedded browser and IdP (SAML) failed.
|
||||
|
||||
## GPC-19972
|
||||
|
||||
Fixed an issue where users were unable to connect to Prisma Access after a break and had to reboot their computer.
|
||||
|
||||
## GPC-19961
|
||||
|
||||
Fixed an issue where the hamburger menu on the GlobalProtect app was disabled and end users were unable to click on the Report an Issue option when the GlobalProtect app was disabled in Alway-On mode.
|
||||
|
||||
## GPC-19930
|
||||
|
||||
Fixed an issue where the HIP check did not detect the BitLocker disk encryption correctly during windows update, causing the device to fail the HIP check.
|
||||
|
||||
## GPC-19918
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on devices running macOS, the HIP check did not detect CrowdStrike antivirus software correctly, causing the device to fail the HIP check.
|
||||
|
||||
## GPC-19889
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on Windows machine and Connect Before Logon (CBL) was configured for the app, the app did not start properly when the user logged on to the device.
|
||||
|
||||
## GPC-19878
|
||||
|
||||
Fixed an issue where a typo in the IP address exclusion list was not marked as invalid by the GlobalProtect enforcer, resulting in all IP addresses in the range being allowed.
|
||||
|
||||
## GPC-19833
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on Windows devices, the Smart card (Yubikey) authentication did not work when the device woke up from sleep mode.
|
||||
|
||||
## GPC-19829
|
||||
|
||||
Fixed an issue where the manual gateway login failed when users tried to login using their user name and password.
|
||||
|
||||
## GPC-19751
|
||||
|
||||
Fixed an issue where the programmatic and visual label for the GlobalProtect form field was not announced.
|
||||
|
||||
## GPC-19740
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on VDI devices running Windows OS, the GlobalProtect app got disconnected without displaying any message.
|
||||
|
||||
## GPC-19696
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on endpoints running macOS and the split tunnel was configured based on the application for Zoom, users were unable to access any sites when the split tunnel was disabled for Zoom and moved to full tunnel.
|
||||
|
||||
## GPC-19660
|
||||
|
||||
Fixed an issue where the "Check for Updates" button on GlobalProtect app version 6.2.2 did not work when the activated GlobalProtect version on the firewall was earlier than 6.2.2.
|
||||
|
||||
## GPC-19652
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on devices running macOS, users were unable to access the applications and websites when the app got disconnected and reconnected while switching the medium from wired to wireless and vice versa.
|
||||
|
||||
## GPC-19629
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on devices running macOS, the split tunnel feature did not work as expected when Jamf was used to push the configuration policy rules.
|
||||
|
||||
## GPC-19610
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on devices running macOS, end users were not prompted to enter a password and the app got stuck in Restoring VPN connection state until the cookie was deleted.
|
||||
|
||||
## GPC-19603
|
||||
|
||||
Fixed an issue where the GlobalProtect app displayed a generic SAML login page and not the actual login page for authentication and the connection was not established when cached portal configuration was used.
|
||||
|
||||
## GPC-19436
|
||||
|
||||
Fixed an issue where the screen reader could not identify the image in the GlobalProtect app tray on the devices running macOS causing accessibility issues.
|
||||
|
||||
## GPC-19532
|
||||
|
||||
Fixed an issue where, after upgrading GlobalProtect via the portal prompt, all traffic except DNS was being dropped because the new GlobalProtect extensions were not being loaded.
|
||||
|
||||
## GPC-19373
|
||||
|
||||
Fixed an issue where the HIP remediation pop up is displayed even when the user is disconnected.
|
||||
|
||||
## GPC-19373
|
||||
|
||||
Fixed an issue where the HIP remediation pop up is displayed even when the user is disconnected.
|
||||
|
||||
## GPC-19336
|
||||
|
||||
Fixed an issue where the ADEM portal did not display user information such as User-ID when the ADEM portal was changed from on-premises to Prisma Access.
|
||||
|
||||
## GPC-19279
|
||||
|
||||
Fixed an issue where the GlobalProtect client was not displayed during the upgrade from version 6.0.5-35 to 6.0.8-601.
|
||||
|
||||
## GPC-19237
|
||||
|
||||
Fixed an issue where the GlobalProtect app did not disconnect when the user used the Disable option on the hamburger menu. The tunnel was still up and connected even when the user disconnected the GlobalProtect app.
|
||||
|
||||
## GPC-19138
|
||||
|
||||
Resolved an issue where the exclude for google application was not working for users.
|
||||
|
||||
## GPC-19098
|
||||
|
||||
Resolved an issue where pre-logon setup was not working when GlobalProtect 6.2.1 was deployed via Microsoft Intune.
|
||||
|
||||
## GPC-19043
|
||||
|
||||
Fixed an issue where the GlobalProtect app did not add all routes configured in the access route to the route table.
|
||||
|
||||
## GPC-19011
|
||||
|
||||
Fixed an issue where the GlobalProtect app on a Windows computer was unable to connect to an IPv4 gateway behind a NAT64 device.
|
||||
|
||||
## GPC-18933
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP check incorrectly detected Real Time Protection for Cortex XDR, which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-18778
|
||||
|
||||
Resolved an issue where devices supporting Modern Standby (Microsoft Learn) crashed when they entered sleep mode while the VPN plugin had an active connection and was sending data over its tunnel.
|
||||
|
||||
## GPC-18728
|
||||
|
||||
Fixed an issue where the ‘I Agree’ option on the GlobalProtect app Welcome page did not work as expected when the user selected the option using a keyboard.
|
||||
|
||||
## GPC-18702
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on Windows devices, the “Allow Manually upgrade failed when the user tried to upgrade the GlobalProtect app version from 6.0.5 to 6.0.7
|
||||
|
||||
## GPC-18625
|
||||
|
||||
Fixed an issue where the Zoom app intermittently stopped connecting on macOS and displayed an error message.
|
||||
|
||||
## GPC-18385
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app got reconnected after the user changed the network access from Wi-Fi (IPv4 only) to Ethernet connection (Dual Stack IPv4 + IPv6), the IPv6 ip-user mapping was missing on the firewall and only IPv6 ip-user mapping was available. The user had to refresh the connection to resolve this issue.
|
||||
|
||||
## GPC-15750
|
||||
|
||||
Fixed an issue where a hyperlink in a HIP notification opened in the GPO-disabled Internet Explorer 11 browser instead of the default browser.
|
||||
|
||||
## GPC-14714
|
||||
|
||||
Fixed an error where the screen reader does the announce the status when the radio button is selected for Network configuration, Routing table, Sockets, and "Logs".
|
||||
@@ -0,0 +1,217 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: GlobalProtect
|
||||
version: 6.2.5
|
||||
---
|
||||
|
||||
## GPC-21656
|
||||
|
||||
Fixed an issue where an unexpected extra string was added to the end of the MFA prompt.
|
||||
|
||||
## GPC-21533
|
||||
|
||||
Fixed an issue where GlobalProtect connected and disconnected in a loop
|
||||
|
||||
## GPC-21483
|
||||
|
||||
Fixed an issue where users are intermittently unable to connect to GlobalProtect and get stuck at the connecting stage.
|
||||
|
||||
## GPC-21465
|
||||
|
||||
Fixed an issue where GlobalProtect is stuck in "Connecting... Finding the Best Available Gateway".
|
||||
|
||||
## GPC-21442
|
||||
|
||||
Fixed an issue where there was a delay in GlobalProtect restoring connectivity after the Windows host woke up from modern standby.
|
||||
|
||||
## GPC-21443
|
||||
|
||||
Fixed an issue where GlobalProtect crashed when the PanGPS service was stopped.
|
||||
|
||||
## GPC-21414
|
||||
|
||||
Fixed an issue where GlobalProtect using SAML authentication gets stuck in a connecting loop upon the expiration of the authentication cookie.
|
||||
|
||||
## GPC-21392
|
||||
|
||||
Fixed an issue where GlobalProtect is stuck in the connecting state for 2-3 minutes during Windows Pre-logon.
|
||||
|
||||
## GPC-21387
|
||||
|
||||
Fixed an issue that prevented users from connecting to Wi-Fi networks when GlobalProtect was disconnected.
|
||||
|
||||
## GPC-21355
|
||||
|
||||
Fixed an issue where GlobalProtect was incorrectly showing as connected during Windows pre-logon.
|
||||
|
||||
## GPC-21301
|
||||
|
||||
Fixed an issue where after upgrading to GlobalProtect 6.2.4, users were unable to connect to GlobalProtect intermittently when Enforcer is enabled.
|
||||
|
||||
## GPC-21247
|
||||
|
||||
Fixed an issue where HIP checks for Disk Encryption status were failing after Windows and Mac hosts were rebooted, on low power mode or were resuming from standby.
|
||||
|
||||
## GPC-21206
|
||||
|
||||
Fixed an issue where GlobalProtect intermittently does not restore connection after the user logs back in or wakes a Windows host.
|
||||
|
||||
## GPC-21172
|
||||
|
||||
Fixed an issue where the GlobalProtect agent gets disconnected right after successful connection when SAML embedded browser authentication is used along with "Enforce GlobalProtect for Network Access".
|
||||
|
||||
## GPC-21161
|
||||
|
||||
Fixed an issue where the notifications prior to 'Login Lifetime Expiration' and 'Inactivity Logout' were not displayed even when enabled.
|
||||
|
||||
## GPC-21101
|
||||
|
||||
Fixed an issue where the embedded browser pop-up with "Login Successful" was displayed for each SAML authentication.
|
||||
|
||||
## GPC-21057
|
||||
|
||||
Fixed an issue where HIP checks for Disk Encryption status were failing on Windows during modern standby.
|
||||
|
||||
## GPC-21035
|
||||
|
||||
Fixed an issue where GlobalProtect HIP did not identify the definition version of the SentinelOne Agent.
|
||||
|
||||
## GPC-21024
|
||||
|
||||
Fixed an issue where a HIP notification configured as "pop-up-message" for pre-logon does not show up. The pop up window is blank.
|
||||
|
||||
## GPC-21005
|
||||
|
||||
Fixed an issue where after submitting the SAML credentials, a blank screen was displayed and GlobalProtect got stuck in that stage.
|
||||
|
||||
## GPC-20991
|
||||
|
||||
Fixed an issue where the 'Extended Key Usage OID' value for certificate selection was deleted during an upgrade of the GlobalProtect agent. This forces users to have to manually select the correct certificate tp be used for authentication.
|
||||
|
||||
## GPC-20988
|
||||
|
||||
Fixed an issue where GlobalProtect failed to resolve DNS queries when the 'Allow traffic to specified FQDN when Enforce GlobalProtect Connection for Network Access is enabled and GlobalProtect Connection is not established' configuration is set.
|
||||
|
||||
## GPC-20983
|
||||
|
||||
Fixed an issue where the GlobalProtect app remains stuck in the connecting stage when Windows computer resumes from sleep.
|
||||
|
||||
## GPC-20943
|
||||
|
||||
Fixed an issue where the GlobalProtect enforcer blocked DHCP packets.
|
||||
|
||||
## GPC-20895
|
||||
|
||||
Fixed an issue where GlobalProtect users on macOS were able to add and modify the portal address even when portal agent configuration was "Allow User to Change Portal Address = NO".
|
||||
|
||||
## GPC-20884
|
||||
|
||||
Fixed an issue where users get disconnected a few seconds after logging in to VDI when GlobalProtect connects. They are unable to reconnect after that.
|
||||
|
||||
## GPC-20864
|
||||
|
||||
Fixed an issue where the GlobalProtect embedded browser login window did not stay pinned to the front of all open windows on Windows and MAC computers.
|
||||
|
||||
## GPC-20839
|
||||
|
||||
Fixed an issue where system extensions on MacBooks were not updated upon GlobalProtect app upgrade.
|
||||
|
||||
## GPC-20838
|
||||
|
||||
Fixed an issue where the HIP report generation was taking longer than the 'Max Wait Time' on Windows devices when anti-malware and disk encryption checks are configured.
|
||||
|
||||
## GPC-20771
|
||||
|
||||
Fixed an issue where GlobalProtect 6.2 users on Windows 11(ARM & Intel) devices cannot connect to GlobalProtect due to "The Parameter is incorrect" error.
|
||||
|
||||
## GPC-20770
|
||||
|
||||
Fixed an issue where certain GlobalProtect HIP checks on Windows devices failed when there was no internet connectivity.
|
||||
|
||||
## GPC-20741
|
||||
|
||||
Fixed an issue where the GlobalProtect app intermittently disconnects from the gateway when using the embedded browser for SAML authentication.
|
||||
|
||||
## GPC-20736
|
||||
|
||||
Fixed an issue where users are being logged out from GlobalProtect when the device wakes up from modern standby and network discovery happens.
|
||||
|
||||
## GPC-20700
|
||||
|
||||
Fixed an issue where macOS users had to enter the SAML username and password each time they refreshed or rebooted their computer especially when using Safari or Embedded browser.
|
||||
|
||||
## GPC-20692
|
||||
|
||||
Fixed an issue where GlobalProtect 6.2.3 with SAML authentication (via Okta) opens the embedded browser page in the background instead of the foreground.
|
||||
|
||||
## GPC-20645
|
||||
|
||||
Fixed an issue where GlobalProtect app in macOS is stuck in connecting state when the device wakes up from sleep.
|
||||
|
||||
## GPC-20626
|
||||
|
||||
Fixed an issue where the GlobalProtect client overwrites valid authentication override cookie with empty authentication override cookie from portal when using cached portal configuration.
|
||||
|
||||
## GPC-20601
|
||||
|
||||
Fixed an issue where macOS users are unable to connect to GlobalProtect after upgrading from version 6.2.2 to 6.2.3 via JAMF.
|
||||
|
||||
## GPC-20595
|
||||
|
||||
Fixed an issue where GlobalProtect users were unable to connect after upgrading to 6.2.3-270 and received a "Your internet access is blocked" error during SAML authentication using the embedded browser.
|
||||
|
||||
## GPC-20550
|
||||
|
||||
Fixed an issue where Zoom and Outlook apps intermittently stop connecting on macOS with an error "You are unable to connect to Zoom. Please check your network connection and try again" when the apps are excluded under both domains and applications.
|
||||
|
||||
## GPC-20466
|
||||
|
||||
Fixed an issue where when the tunnel is broken on Windows computers in modern standby mode, the Enforcer does not work even when it is enabled.
|
||||
|
||||
## GPC-20442
|
||||
|
||||
Fixed an issue on appliances running PanOS 10.1.11-h1 and GlobalProtect 6.0.10-811 where the tunnel status failed to update to connected immediately after establishment. This problem was specific to IPv4-only clients connecting to dual-stack (IPv4 + IPv6) GlobalProtect gateways or portals.
|
||||
|
||||
## GPC-20441
|
||||
|
||||
Fixed an issue where HIP reports are sometimes not available on the firewall for newly connected users.
|
||||
|
||||
## GPC-20416
|
||||
|
||||
Fixed an issue where there is no network discovery once the laptop came out of standby.
|
||||
|
||||
## GPC-20360
|
||||
|
||||
Fixed an issue where the GlobalProtect app is stuck in the connecting status after authentication and does not connect until the app is restarted or the computer is rebooted.
|
||||
|
||||
## GPC-20292
|
||||
|
||||
Fixed an issue where RDP to Azure VDI clients disconnects when GlobalProtect is enabled on the VDI client with SAML authentication and with 'Enforce GlobalProtect for Network Access' enabled
|
||||
|
||||
## GPC-20191
|
||||
|
||||
Fixed an issue where PanGPA.exe crashes on Windows clients
|
||||
|
||||
## GPC-20114
|
||||
|
||||
Fixed an issue where GlobalProtect on MacOS was incorrectly selecting client certificates without a private key for certificate authentication.
|
||||
|
||||
## GPC-20112
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP check incorrectly detected Real time protection status for Kaspersky Endpoint Security, which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-20072
|
||||
|
||||
Fixed an issue where domain-based split tunneling was not working on MAC with Edge Chromium or Google Chrome browser though it was working on Safari.
|
||||
|
||||
## GPC-19819
|
||||
|
||||
Fixed an issue where SAML default browser IDP traffic is blocked during a refresh connection when GlobalProtect is connected to the internal network with 'Enforce GlobalProtect for Network Access' enabled.
|
||||
|
||||
## GPC-19269
|
||||
|
||||
Fixed an issue where GlobalProtect would show as "connecting" but never actually connect until the user restarted GlobalProtect on their Windows machine.
|
||||
|
||||
## GPC-18943
|
||||
|
||||
Fixed an issue where GlobalProtect would fail to connect on Windows hosts that were woken up from modern standby by initiating an RDP to the host.
|
||||
@@ -0,0 +1,45 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: GlobalProtect
|
||||
version: 6.2.6-c857
|
||||
---
|
||||
|
||||
## GPC-22107
|
||||
|
||||
Fixed an issue where the GlobalProtect agent was unable to validate the server certificate after the CVE-2024-5921 remediation was applied.
|
||||
|
||||
## GPC-22104
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP report failed to detect the Seqrite Endpoint Protection application, when the application was upgraded to a higher version 18.00 (14.0.0.1)
|
||||
|
||||
## GPC-22082
|
||||
|
||||
Fixed an issue where GlobaProtect did not validate certificates with 3rd parties or PKI and displayed a FIPS error.
|
||||
|
||||
## GPC-22079
|
||||
|
||||
Fixed an issue where users were unable to connect to the GlobalProtect app due to Captive Portal connectivity issues.
|
||||
|
||||
## GPC-22046
|
||||
|
||||
Fixed an issue where when the GlobalProtect app was installed on devices running macOS and the app version was upgraded to 6.2.5, end users were unable to connect the app. The app got stuck in the Connecting state and displayed the following message, “You are redirected to an embedded browser to authenticate and connect.”
|
||||
|
||||
## GPC-22010
|
||||
|
||||
Fixed an issue where loopback connection did not work when Endpoint Traffic Policy Enforcement was enabled.
|
||||
|
||||
## GPC-21950
|
||||
|
||||
Fixed an issue where the GlobalProtect connection on MacOS Sequoia 15+ was unstable.
|
||||
|
||||
## GPC-21778
|
||||
|
||||
Fixed an issue where the GlobalProtect IPSec tunnel got disconnected on GlobalProtect app version 6.2.5 when the gpupdate /force command was used to update a policy.
|
||||
|
||||
## GPC-21284
|
||||
|
||||
Fixed an issue where the GlobalProtect gateway did not receive the HIP reports from the user correctly due to which the end users were unable to access the resources even when the sessions were active.
|
||||
|
||||
## GPC-20592
|
||||
|
||||
Fixed an issue where the GlobalProtect app could not establish the tunnel and the app got stuck in the tunnel creation stage. The app displayed the following error, “ The virtual adapter was not set up correctly due to a delay.”
|
||||
@@ -0,0 +1,97 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: GlobalProtect
|
||||
version: 6.2.6
|
||||
---
|
||||
|
||||
## GPC-21774
|
||||
|
||||
Fixed an issue where the GlobalProtect ARM64 installers for 6.2.5 version did not display Digital Signatures tab.
|
||||
|
||||
## GPC-21721
|
||||
|
||||
Fixed an issue, where the GlobalProtect app got stuck in Connecting status when the device woke up from sleep mode.
|
||||
|
||||
## GPC-21731
|
||||
|
||||
Fixed an issue where the GlobalProtect app is stuck in the Connecting status when upgraded to 6.2.5-788 version and the users had to reboot the system to resolve the issue.
|
||||
|
||||
## GPC-21665
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on devices running macOS and the app was used with Trellix Proxy Agent, the web browser displayed the following error, ERR_SOCKET_NOT_CONNECTED.
|
||||
|
||||
## GPC-21636
|
||||
|
||||
Fixed an issue where the users were unable to login Windows 11 using the User Principal Name (UPN) when GPCP was selected with GlobalProtect app version 6.2.4 and Interactive logon: Don't display last signed-in was enabled in their Entra ID - group policy.
|
||||
|
||||
## GPC-21604
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on devices running macOS and were connected to the internal gateway, the app did not display the Disconnect option under Settings.
|
||||
|
||||
## GPC-21413
|
||||
|
||||
Fixed an issue where the GlobalProtect Credential Provider did not reset focus on the password field when the user entered the wrong password.
|
||||
|
||||
## GPC-21375
|
||||
|
||||
Fixed an issue where the Windows SSO did not work when the SAML authentication method was used to authenticate to the app. The username retrieved from SAML was not matching configuration selection criteria causing authentication issues.
|
||||
|
||||
## GPC-21332
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP check incorrectly detected Real Time Protection status for Avast and XProtect, which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-21320
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP check did not detect Kaspersky Endpoint Security antimalware application which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-21281
|
||||
|
||||
Fixed an issue where the GlobalProtect app got stuck in the Connecting status when the user refreshed the connection.
|
||||
|
||||
## GPC-21267
|
||||
|
||||
Fixed an issue where, when the user installed the GlobalProtectARM installer from the Customer Support Portal (CSP) and the user opened GlobalProtect using the Start menu, the icon file (PanGPA.ico) was opened instead of the executable (PanGPA.exe) file.
|
||||
|
||||
## GPC-21247
|
||||
|
||||
Fixed an issue where GlobalProtect HIP set the Filevault encryption status to unencrypted on macOS running devices, which denied access to the end-point machines.
|
||||
|
||||
## GPC-21240
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on devices running macOS Sonoma 14.5, the app used the old FQDN names and got stuck in the Connecting status instead of prompting the user to enter the portal FQDN name.
|
||||
|
||||
## GPC-21222
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP check incorrectly detected the Real Time Protection Status and Last Full Scan for Avast application, which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-21811
|
||||
|
||||
Fixed an issue where the PanGPS stopped working soon after the GlobalProtect was installed on the endpoint and the GlobalProtect app got stuck in the Connecting stage.
|
||||
|
||||
## GPC-21174
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP check did not detect Real time protection status for Acronis Cyber Protection Agent, which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-21131
|
||||
|
||||
Fixed an issue where the users were unable to access the Advanced Logging Settings screen of the GlobalProtect app using the ctrl + tab key combination on the keyboard. The screen reader did not announce the keyboard options correctly.
|
||||
|
||||
## GPC-21106
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP check did not detect 'Real Time Protection' status for Malwarebytes anti-malware application, which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-20783
|
||||
|
||||
Fixed an issue where the password field was not automatically selected for typing when using the embedded browser, requiring users to click inside the field before entering their password
|
||||
|
||||
## GPC-20779
|
||||
|
||||
Fixed an issue where Windows regional settings are not respected by Webview 2 on SAML embedded browser resulting in regional language(French, German, Chinese, Spanish, and Japanese) not loading properly in embedded browser.
|
||||
|
||||
## GPC-20674
|
||||
|
||||
Fixed an issue where all GlobalProtect portals except for the currently connected portal were deleted during the upgrade from 6.2.2 to 6.2.3 or from 6.2.3 to 6.3.0.
|
||||
|
||||
## GPC-18647
|
||||
|
||||
Fixed an issue with GlobalProtect App Log Collection feature where the user reported an issue using Report an Issue option on the GlobalProtect app and the issue was not reported as expected.
|
||||
@@ -0,0 +1,81 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: GlobalProtect
|
||||
version: 6.2.8-c223
|
||||
---
|
||||
|
||||
## GPC-23215
|
||||
|
||||
Fixed an issue where, the traffic stopped passing through the GlobalProtect app on macOS devices after upgrading to GP 6.2.8 and when the computer screen was locked.
|
||||
|
||||
## GPC-23174
|
||||
|
||||
Fixed an issue where the GlobalProtect failed to detect DNS during the Network Detection stage, causing the GlobalProtect app to stop working.
|
||||
|
||||
## GPC-23161
|
||||
|
||||
Fixed an issue where the GlobalProtect app stopped working after a session change.
|
||||
|
||||
## GPC-23088
|
||||
|
||||
Fixed an issue where the portal login user authentication failed after cookie expiration.
|
||||
|
||||
## GPC-21982
|
||||
|
||||
Fixed an issue in which IPv6 traffic bypassed the valid route in the rerouting table and instead passed through the physical adapter when the GlobalProtect app was installed on Windows devices.
|
||||
|
||||
## GPC-23046
|
||||
|
||||
Fixed an issue where users experienced connectivity problems when GlobalProtect was used in a WiFi network with captive portal.
|
||||
|
||||
## GPC-23034
|
||||
|
||||
Fixed an issue where the GlobalProtect embedded browser did not display certificate selection pop-up when there were multiple client certificates available.
|
||||
|
||||
## GPC-23032
|
||||
|
||||
Fixed an issue where the GlobalProtect agent restarts when the device wakes up from Modern Standby.
|
||||
|
||||
## GPC-23011
|
||||
|
||||
Fixed an issue wherein wherein the Enforcer intermittently failed to promptly block network access as configured, thereby resulting in delays of 1 to 5 minutes before eventually blocking the traffic flow.
|
||||
|
||||
## GPC-22800
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was configured with enforcer and Captive Portal, users faced issues in connecting to Captive Portal using GlobalProtect.
|
||||
|
||||
## GPC-22610
|
||||
|
||||
Fixed an issue where, after an upgrade, GlobalProtect restarted and failed to connect to the portal
|
||||
|
||||
## GPC-22595
|
||||
|
||||
Fixed an issue where users were unable to select the correct client certificate when using the GlobalProtect app on Windows devices and connected to the internal network using SAML embedded browse
|
||||
|
||||
## GPC-22536
|
||||
|
||||
Fixed an issue where users faced connectivity issues when the GlobalProtect app version 6.2.6 was installed on devices running macOS 15.3.1
|
||||
|
||||
## GPC-22365
|
||||
|
||||
Fixed an issue where users experienced intermittent issues browsing webpages while connected to the GlobalProtect app.
|
||||
|
||||
## GPC-22294
|
||||
|
||||
. Fixed an issue where intermittent internet access problems occurred when the macOS was upgraded to 15.2 and the GlobalProtect app version to 6.2.6.
|
||||
|
||||
## GPC-21766
|
||||
|
||||
Fixed an issue where the split tunnel excluded routes go missing from routing table on Windows machine at intermittent times.
|
||||
|
||||
## GPC-21755
|
||||
|
||||
Fixed an issue where GlobalProtect users with enforcer enabled were able to access applications that were not in the enforcer exception list.
|
||||
|
||||
## GPC-21737
|
||||
|
||||
Fixed an issue where the SAML redirection page opened up on end user computers even though they did not have internet connectivity.
|
||||
|
||||
## GPC-19024
|
||||
|
||||
Fixed an issue where the GlobalProtect app incorrectly used an embedded WebView instead of the system default browser for Captive Portal logins.
|
||||
@@ -0,0 +1,47 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: GlobalProtect
|
||||
version: 6.2.8-h2
|
||||
---
|
||||
|
||||
## GPC-23294
|
||||
|
||||
Fixed an issue where GlobalProtect app intermittently disconnected on macOS endpoints even with a stable network connection. This was due to a timeout that was too short for the route system command.
|
||||
|
||||
## GPC-23270
|
||||
|
||||
Fixed an issue where GlobalProtect app version 6.3.3 using SAML with the embedded browser would lose cursor focus in the password field, requiring users to click in the password field before entering their password.
|
||||
|
||||
## GPC-23191
|
||||
|
||||
Fixed an issue where GlobalProtect took almost 2 minutes to reconnect to an already connected gateway after a host reboot.
|
||||
|
||||
## GPC-23115
|
||||
|
||||
Fixed an issue where the hardware token authentication option was intermittently unavailable while using the embedded GlobalProtect browser on Windows machines.
|
||||
|
||||
## GPC-23044
|
||||
|
||||
Fixed an issue where, when a machine was in Modern standby, the GlobalProtect app repeatedly attempted to connect to gateways, even when authentication failed due to SAML timeout. This resulted in GlobalProtect connecting to non-optimal gateway
|
||||
|
||||
## GPC-22763
|
||||
|
||||
Fixed an issue where GlobalProtect prompted for credentials instead of using authoverride cookie when authenticating to the best available gateway.
|
||||
|
||||
## GPC-22522
|
||||
|
||||
Fixed an issue where, after upgrading from GlobalProtect app version 6.1.2 to 6.2.6, external users on Windows 11 computers with multiple Azure Entra accounts were unable to authenticate to the portal using SAML with Azure Entra as the Identity Provider (IdP). The new WebView2 embedded browser automatically used the user's default Windows credential for Single Sign-On (SSO), preventing them from selecting the correct account for authentication.To resolve this issue a new registry key 'entra-sso' has been introduced. You can add the registry key using two methods and set it to no to disable SSO.For pre-deployment, use msiexec.exe /i globalprotect64.msi ENTRASSO="no"Add key entra-sso and set it to nounder HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto Networks\GlobalProtect\Settings.
|
||||
|
||||
For pre-deployment, use msiexec.exe /i globalprotect64.msi ENTRASSO="no"
|
||||
|
||||
Add key entra-sso and set it to nounder HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto Networks\GlobalProtect\Settings.
|
||||
|
||||
If the entra-sso key does not exist under the above path, the GlobalProtect app's default behavior is to Allow Entra SSO.
|
||||
|
||||
## GPC-22066
|
||||
|
||||
Fixed an issue where the HIP check detected an incorrect real-time protection status for Windows Defender ATP and CrowdStrike Falcon anti-malware software, which could incorrectly mark non-compliant devices as compliant.
|
||||
|
||||
## GPC-22029
|
||||
|
||||
Fixed an issue where Apple software downloads took longer to complete when using GlobalProtect with split tunneling enabled.
|
||||
@@ -0,0 +1,61 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: GlobalProtect
|
||||
version: 6.2.8-h3
|
||||
---
|
||||
|
||||
## GPC-23604
|
||||
|
||||
Fixed an issue where GlobalProtect users were not automatically prompted for authentication on public Wi-Fi networks with a captive portal.
|
||||
|
||||
## GPC-23520
|
||||
|
||||
Fixed an issue where new GlobalProtect users were unable to connect to the GlobalProtect app. The app got stuck in Connecting stage and stopped working when redirected to the embedded browser.
|
||||
|
||||
## GPC-23496
|
||||
|
||||
Fixed an issue where the GlobalProtect app's Connect button did not work as expected preventing users from connecting or changing gateways.
|
||||
|
||||
## GPC-23440
|
||||
|
||||
Fixed an issue where Okta FastPass authentication did not work with GlobalProtect 6.3.3 on macOS 15.5 Sequoia, where the Okta Verify app did not open for the additional authentication prompt.
|
||||
|
||||
## GPC-23466
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on devices running Windows OS and macOS, the Captive Portal detection message briefly appeared and disappeared when the Captive Portal exception timeout was set to 0.
|
||||
|
||||
## GPC-23432
|
||||
|
||||
Fixed an issue where the GlobalProtect app version 6.3.3 intermittently got stuck on the finding best gateway status
|
||||
|
||||
## GPC-23365
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on Windows machines, the app intermittently disconnected and then reconnected with the error message Failed to create exclude route.
|
||||
|
||||
## GPC-23301
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app 6.2.7 and later, was installed on Windows 10 devices, the app deleted the predefined proxy PAC file configuration whenever the app got disconnected regardless of whether the disconnection was initiated manually or occurred automatically due to a timeout.
|
||||
|
||||
## GPC-23263
|
||||
|
||||
Fixed an issue where after upgrading to GlobalProtect app version 6.3.3, the app did not save the username in the embedded browser when "Save Username was enabled.
|
||||
|
||||
## GPC-23218
|
||||
|
||||
Fixed an issue where, when using the GlobalProtect app with an embedded browser, interrupting or canceling the SAML authentication prompt terminated the pre-logon tunnel, potentially allowing full internet access even when enforcer was enabled for the user-logon profile. With default browser, the pre-logon tunnel remained active when the SAML authentication prompt was interrupted.
|
||||
|
||||
## GPC-23125
|
||||
|
||||
Fixed an issue where GlobalProtect did not remove older versions of the WebView2 component from the %LOCALAPPDATA%\Palo Alto Networks\GlobalProtect\GPAEdge directory, which led to unnecessary disk space consumption over time.
|
||||
|
||||
## GPC-22989
|
||||
|
||||
Fixed an issue where the GlobalProtect app intermittently stopped sending HIP reports while connected to the gateway.
|
||||
|
||||
## GPC-22979
|
||||
|
||||
Fixed an issue where, after upgrading to GlobalProtect app version 6.2.6, the PanGPA application got stuck in Connecting 'state and then got terminated unexpectedly.
|
||||
|
||||
## GPC-22541
|
||||
|
||||
Fixed an issue on Windows 11 where the GlobalProtect app (PanGPA) would stop working when the device was locked. The crash occurred when an expired authentication triggered a persistent smartcard login dialog during sleep, leading to excessive memory swapping and a crypt32.dll failure.
|
||||
@@ -0,0 +1,105 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: GlobalProtect
|
||||
version: 6.2.8-h4
|
||||
---
|
||||
|
||||
## GPC-23839
|
||||
|
||||
Fixed an issue that caused the GlobalProtect 6.3.3 HIP report to fail with the error Method: WAAPI_MID_GET_AGENT_STATE.
|
||||
|
||||
## GPC-23786
|
||||
|
||||
Fixed an issue where the agent-msg log (PanoramaMonitorGlobalProtect) was not generated when a user disabled the GlobalProtect app and logged out of the gateway.
|
||||
|
||||
## GPC-23760
|
||||
|
||||
GlobalProtect app version 6.3.3 using SAML with the embedded browser loses cursor focus in the password field, requiring users to click in the password field before entering their password.
|
||||
|
||||
## GPC-23752
|
||||
|
||||
Fixed an issue where the GlobalProtect app failed to authenticate to the portal and gateway after a machine certificate was renewed by Intune MDM. A reboot was required to restore the connection.
|
||||
|
||||
## GPC-23746
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP check incorrectly detected status for Symantec Endpoint Protection, which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-23646
|
||||
|
||||
Fixed an issue where the GlobalProtect app ignores the new gateway-generated authentication override cookie and continues to use the old, expired portal cookie when using the cached portal configuration. As a result, the authentication override cookie generated by a successful SAML authentication to a gateway is replaced by the old, expired portal cookie during successive authentications, causing the gateway to prompt for SAML authentication repeatedly.
|
||||
|
||||
## GPC-23616
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on devices running macOS, the following error TransparentProxy: openWithLocalEndpoint failed occurred in PanNExt.log when using an IPv6 address.
|
||||
|
||||
## GPC-23583
|
||||
|
||||
Fixed an issue where the pre-login tunnel rename timeout notification would overlay other system tray icons, preventing users from accessing them
|
||||
|
||||
## GPC-23558
|
||||
|
||||
Fixed an issue where GlobalProtect clients using SAML with Ping Federate did not save the SAML token upon reboot or restart of the pangps service, requiring users to re-authenticate even when the token was not expired. This issue affected GlobalProtect app version 6.3.3 when SAML authentication was configured in Prisma Access and not in Cloud Identity Engine.
|
||||
|
||||
## GPC-23519
|
||||
|
||||
Fixed an issue where GlobalProtect HIP reports on MacBooks intermittently failed with an Invalid client IP error, preventing users from accessing resources over the GlobalProtect tunnel. This issue occurred after a system network change when GlobalProtect attempted to send the HIP report to an external gateway while the tunnel was disconnected. This issue affected MacBooks running GlobalProtect version 6.2.5.
|
||||
|
||||
## GPC-23514
|
||||
|
||||
Fixed an issue where, when using a screen reader on Windows or macOS, the GlobalProtect app's Settings button did not announce the available options for the end users.
|
||||
|
||||
## GPC-23488
|
||||
|
||||
Fixed an issue where the HIP report intermittently detected MacOS XProtect Real Time Protection status as disabled.
|
||||
|
||||
## GPC-23468
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP check failed to detect the correct version of Forticlient Antivirus, which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-23441
|
||||
|
||||
Fixed an issue where the GlobalProtect installation failed after a transparent upgrade automatically uninstalled the previous version.
|
||||
|
||||
## GPC-23428
|
||||
|
||||
Fixed an issue where the username and password fields in the GlobalProtect app had incorrect labels.
|
||||
|
||||
## GPC-23417
|
||||
|
||||
Fixed an issue where SAML authentication with Azure AD, using Cisco Duo EAM, failed after upgrading to GlobalProtect version 6.2.8
|
||||
|
||||
## GPC-23404
|
||||
|
||||
Fixed an issue where the Host Information Profile (HIP) check was unable to accurately identify key details from third-party security products.
|
||||
|
||||
## GPC-23403
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP report failed to detect the status of SentinelOne, causing the device to fail the HIP check
|
||||
|
||||
## GPC-23361
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP report did not detect the Status for Zoho corporation - ManageEngine Patch Manager Plus Agent, which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-23283
|
||||
|
||||
Fixed an issue where GlobalProtect was unable to set [exclude/include] 0.0.0.0/netmask routes on Mac endpoint.
|
||||
|
||||
## GPC-23142
|
||||
|
||||
Fixed an issue where an Explicit Proxy token refresh would fail with the message EP TOKEN configuration is NULL, causing the GlobalProtect app to get stuck in a Connecting state.
|
||||
|
||||
## GPC-23095
|
||||
|
||||
Fixed and issue where the GlobalProtect HIP report failed to detect the Symantec DLP software, which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-22353
|
||||
|
||||
Fixed an issue where a comment was not visible in the GlobalProtect logs when GlobalProtect was disabled with-comment.
|
||||
|
||||
## GPC-21745
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP check failed to detect Workspace ONE status, which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-20617
|
||||
|
||||
Fixed an issue where a notification appeared on the GlobalProtect app every 10 seconds asking the end-user to re-authenticate. This notification appeared during the pre-logon tunnel rename timeout period.
|
||||
@@ -0,0 +1,89 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: GlobalProtect
|
||||
version: 6.2.8-h5
|
||||
---
|
||||
|
||||
## GPC-24581
|
||||
|
||||
Fixed an issue where GlobalProtect disable agent messages were not reported to firewall when machine certificate authentication with full chain certificate validation was enabled.
|
||||
|
||||
## GPC-24332
|
||||
|
||||
Fixed an issue where users on trusted networks were incorrectly receiving a captive portal detection message and being redirected to a separate browser tab. This occurred because the GlobalProtect app was not properly handling captive portal detection response.
|
||||
|
||||
## GPC-24330
|
||||
|
||||
Fixed an issue where GlobalProtect app got stuck in a connecting state when using GlobalProtect version 6.2.8-h4. The issue was seen when saml-logout and enforcer was enabled.
|
||||
|
||||
## GPC-24261
|
||||
|
||||
Fixed an issue where GlobalProtect app running on macOS Sequoia 15.6.1 running GP 6.2.8 -c263 that receive both IPv4 and IPv6 addresses were not receiving packets back from the Network Load Balancer (NLB) instances.
|
||||
|
||||
## GPC-24221
|
||||
|
||||
Fixed an issue where the GlobalProtect app experienced a continuous connect-disconnect loop when used on flights. This issue occurred because rapid network wake-ups left network interfaces in an inconsistent state, causing GlobalProtect to attempt tunnel establishment on an unstable network foundation.
|
||||
|
||||
## GPC-24103
|
||||
|
||||
Fixed an issue where the GlobalProtect app running on macOS allowed users to modify or add a new portal address after each device reboot, even when the Allow users to change portal setting was configured as No in the GlobalProtect app.
|
||||
|
||||
## GPC-24048
|
||||
|
||||
Fixed an issue where GlobalProtect apps installed on on Dell Vostro 15 3515 laptops were unable to connect to the GlobalProtect service with the following error: Could not connect to the GlobalProtect service. If the issue persists, contact your administrator.
|
||||
|
||||
## GPC-24037
|
||||
|
||||
Fixed an issue where GlobalProtect app prompted users to log in with SAML through the embedded browser even when the GlobalProtect app was already connected. This occurred when users logged off and then back onto their Cloud PC (Windows Azure PC), and closing the prompt disconnected and reconnected the VPN session.
|
||||
|
||||
## GPC-24036
|
||||
|
||||
Fixed an issue where the HIP check did not correctly detect the status of the ESET firewall on Windows hosts.
|
||||
|
||||
## GPC-23990
|
||||
|
||||
Fixed an issue where the captive portal opened in the embedded browser, but when the user tried to connect to the internet, it redirected to the default browser and was blocked.
|
||||
|
||||
## GPC-23929
|
||||
|
||||
Fixed an issue where, when GlobalProtect app was configured with Enforcer, users could bypass Enforcer restrictions by repeatedly canceling authentication prompts after logging into Windows. This occurred because the cached portal configuration, which contains Enforcer settings, was not loaded when a pre-logon tunnel failed to establish due to a quick user login. This fix ensures that the cached portal configuration is loaded as soon as PanGPA starts and PanGPS learns the username, preventing unrestricted access in scenarios where Enforcer is intended to lockdown the endpoint.
|
||||
|
||||
## GPC-23730
|
||||
|
||||
Fixed an issue where IPv6 traffic on Windows 11 24H2 did not work as expected with GlobalProtect app.
|
||||
|
||||
## GPC-23689
|
||||
|
||||
Fixed an issue where the GlobalProtect app running on macOS devices would stuck in a connecting loop indefinitely if the user did not complete authentication, requiring manual cancellation of the connection.
|
||||
|
||||
## GPC-23650
|
||||
|
||||
Fixed an issue where the GlobalProtect enforcer blocked network traffic on Windows endpoints even after the tunnel was successfully connected.
|
||||
|
||||
## GPC-23525
|
||||
|
||||
Fixed an issue where on macOS Ventura and Sequoia, GlobalProtect app versions 6.2.6-838, 6.2.7-1047, 6.2.8, and 6.3.3, manually changing the portal address using the GlobalProtect app UI would fail and revert back to the last connected portal. This issue occurred even when Allow User to Change Portal Address was enabled in the agent configuration.
|
||||
|
||||
## GPC-23394
|
||||
|
||||
Fixed an issue where GlobalProtect app version 6.2.8-183. running on macOS 15.5 was unable to accurately report the disk encryption status of FileVault, resulting in an Unknown status in HIP checks.
|
||||
|
||||
## GPC-23336
|
||||
|
||||
Fixed an issue where agent disable logs were not being logged to Gateway System Logs on the firewall. The GlobalProtect agent reset the authentication code, which falsely indicated that the gateway was not fully authenticated, and the agent did not send the message.
|
||||
|
||||
## GPC-22683
|
||||
|
||||
Fixed an issue where tool tips were not available for the Add, Edit, and Delete buttons on the GlobalProtect application's settings page on Windows devices.
|
||||
|
||||
## GPC-22572
|
||||
|
||||
Fixed an issue where the hamburger menu button was disabled in the Refresh connection screen, which made it inaccessible when using a keyboard.
|
||||
|
||||
## GPC-22021
|
||||
|
||||
Fixed an issue where, when using conditional-connect on macOS Sequoia with GlobalProtect app version 6.2.6, manually switching gateways caused the app to display a Not Connected status for approximately 10 seconds while establishing a connection to the second gateway.
|
||||
|
||||
## GPC-22010
|
||||
|
||||
Fixed an issue where loopback connection did not work when Endpoint Traffic Policy Enforcement was enabled.
|
||||
@@ -0,0 +1,21 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: GlobalProtect
|
||||
version: 6.2.8-h6
|
||||
---
|
||||
|
||||
## GPC-24859
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP check did not detect the Kaspersky signature information which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-24827
|
||||
|
||||
Fixed an issue where, on GlobalProtect client version 6.2.8-h3, HIP checks for CrowdStrike Falcon or Microsoft/Windows Defender intermittently took longer than expected to complete, sometimes exceeding the default 20-second limit. This resulted in partial HIP reports being sent to the gateway, causing connectivity issues for users accessing internal resources or the internet.
|
||||
|
||||
## GPC-24683
|
||||
|
||||
Fixed an issue where Host Information Profile (HIP) matching failed for Anti-Malware criteria on macOS endpoints due to GlobalProtect failing to detect the virus definition version for Kaspersky Anti-Virus.
|
||||
|
||||
## GPC-23090
|
||||
|
||||
Fixed an issue where the GlobalProtect app experienced connectivity issues after the host computer resumed from sleep mode due to a missing self-pointed route. This issue resulted in a delay of 5 to 10 minutes for the GlobalProtect connection to get stabilized.
|
||||
@@ -0,0 +1,81 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: GlobalProtect
|
||||
version: 6.2.8-h7
|
||||
---
|
||||
|
||||
## GPC-25063
|
||||
|
||||
Fixed an issue where, in the GlobalProtect app on macOS, keyboard focus did not automatically move to the required "Enter portal Address" field when a user attempted to add a new portal without entering an address. This accessibility issue impacted keyboard-dependent users.
|
||||
|
||||
## GPC-24961
|
||||
|
||||
Fixed an issue where the firewall, when configured to obtain IP addresses from a DHCP server for GlobalProtect clients, sent a MAC address of '00' to the DHCP server specifically for MacOS 26 (Tahoe) clients running GlobalProtect App versions 6.2 or 6.3, which resulted in IP address collisions on the DHCP server.
|
||||
|
||||
## GPC-24897
|
||||
|
||||
Fixed an issue where the GlobalProtect Connect Before Logon tunnel disconnected for new users on their first logon. This issue affected GP client versions 6.2.8-hx and 6.3.3-hx.
|
||||
|
||||
## GPC-24892
|
||||
|
||||
Fixed an issue where the GlobalProtect Portal welcome page, when displayed in German, incorrectly presented a button labeled 'Genau' instead of 'Zustimmen' (Accept).
|
||||
|
||||
## GPC-24880
|
||||
|
||||
Fixed an issue where GlobalProtect clients, after upgrading to versions 6.2.8-263, 6.3.3-h2, or 6.3.3-h3, would get stuck in a connecting loop and fail to connect to the portal or gateways. This occurred because the GlobalProtect app crashed when attempting to delete previous SAML user data, specifically when the user data folder path contained non-ANSI characters that the app could not convert to a UTF-16 path.
|
||||
|
||||
## GPC-24842
|
||||
|
||||
(macOS only) GlobalProtect crashed when you clicked Change Portal on setups that included two or more portal entries and had a preferred gateway marked.
|
||||
|
||||
## GPC-24835
|
||||
|
||||
Fixed an issue where split tunneling domain exclusions on GlobalProtect App version 6.3.3-C711 for Windows clients failed to function as expected after the application disconnected and reconnected. This resulted in traffic for domains configured for exclusion being incorrectly routed through the VPN tunnel instead of directly, because the TTLMap for split tunneling domain rules was not properly cleared when the GlobalProtect App re-established its connection.
|
||||
|
||||
## GPC-24515
|
||||
|
||||
Fixed an issue where GlobalProtect clients on macOS devices, specifically version 6.3.3-h2, were unable to resolve internal IPv6 domains when split tunneling was enabled and the operating system lacked native IPv6 connectivity. This occurred because the client's logic, which was designed to apply IPv6 configuration only when the OS already had native IPv6 connectivity, prevented the GlobalProtect tunnel from properly handling IPv6 traffic, resulting in "Err name not resolved" errors for internal FQDNs.
|
||||
|
||||
## GPC-24242
|
||||
|
||||
Fixed an issue where GlobalProtect portal authentication failed for some macOS users when attempting to use saved credentials. This issue, observed on GlobalProtect client versions 6.2.8 and 6.3.3, resulted in an immediate authentication failure on the client and firewall logs indicating an invalid username or password, even though the credentials were valid for other macOS clients.
|
||||
|
||||
## GPC-24216
|
||||
|
||||
Fixed an issue where the Host Information Profile (HIP) banner was not displayed on Windows 11 client machines running GlobalProtect client versions 6.2.8-h7 and 6.3.3. This occurred due to a timing or race condition where the GlobalProtect client (PanGPA) received an outdated status, preventing the visual display of HIP match or not-match notifications, even though the messages were recorded in the client logs.
|
||||
|
||||
## GPC-24144
|
||||
|
||||
Fixed an issue where, after a client machine regained internet access, Network Discovery was skipped due to the fed-mandate-accept setting, preventing automatic reconnection to the Prisma Access gateway. This occurred when the device switched from a non-internet-accessible Ethernet connection to a 5G connection.
|
||||
|
||||
## GPC-24083
|
||||
|
||||
Fixed an issue where GlobalProtect clients intermittently failed RADIUS authentication due to treating the portal challenge response as a gateway challenge response. This resulted in incorrect handling of the OTP response back to the server.
|
||||
|
||||
## GPC-23963
|
||||
|
||||
Fixed an issue where GlobalProtect Client version 6.2.8 running in Windows 365 environments, would experience PanGPA getting stuck during the tunnel rename process. This prevented successful gateway authentication and registration after users closed and re-opened their Windows 365 session, leading to a pop-up message prompting users to re-authenticate.
|
||||
|
||||
## GPC-23960
|
||||
|
||||
Fixed an issue where the GlobalProtect agent on macOS devices entered a connecting loop when attempting to connect to an IPv6 gateway due to a missing gateway preservation in the original script. This resulted in the tunnel interface capturing the route to the gateway and an infinite retry loop.
|
||||
|
||||
## GPC-23909
|
||||
|
||||
Fixed an issue where AAAA DNS records were not working when connected to GlobalProtect client versions 6.2.8-c243 or 6.2.8-c263, preventing successful IPv6 connections. This issue occurred when split tunnel is not configured, causing the IPv6 DNS settings to be incorrectly set.
|
||||
|
||||
## GPC-23787
|
||||
|
||||
Fixed an issue where GlobalProtect clients on macOS devices, after upgrading to version 6.2.8-h2, were unable to connect to the authentication server. This occurred because incorrect logic in the GlobalProtect Agent code prevented the Webview Process ID from syncing with the Network Extension process, causing the Network Extension to block SAML authentication traffic, resulting in a "Could not connect to the authentication server" error and a blank embedded browser during SAML authentication.
|
||||
|
||||
## GPC-23723
|
||||
|
||||
Fixed an issue where GlobalProtect clients running version 6.2.8-h1 (6.2.8-c223) experienced intermittent connection failures and disconnections, with the client agent getting stuck in a 'connecting' state even when backend logs indicated a successful connection. This occurred because, when conditional connect mode was enabled, the client attempted to impersonate a user and write On-Demand settings to the user's registry hive (HKEY_CURRENT_USER) during pre-logon. As no user was logged in at that stage, user impersonation failed, leading to incorrect registry access or failed registry operations, which caused service instability or misconfiguration.
|
||||
|
||||
## GPC-22424
|
||||
|
||||
Fixed an issue where, on Windows endpoints running GlobalProtect, roaming user profile data was not written or sent to the server shared folder over SMB (TCP/445) during user logoff or system reboot when the GlobalProtect client was connected to the internal corporate network.
|
||||
|
||||
## GPC-18976
|
||||
|
||||
Fixed an issue where GlobalProtect client 6.1.1-5 would select the incorrect Windows tile by default after locking the screen when using Single Sign-On for Smart Card PIN (Windows) with the Yubikey Smart Card Minidriver. When multiple smart cards were present, GlobalProtect incorrectly selected the last enumerated card instead of the currently active one.
|
||||
@@ -0,0 +1,229 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: GlobalProtect
|
||||
version: 6.2.8
|
||||
---
|
||||
|
||||
## GPC-22894
|
||||
|
||||
Fixed an issue where GlobapProtect did not detect the correct version of Kaspersky Endpoint Security.
|
||||
|
||||
## GPC-22847
|
||||
|
||||
Fixed an issue where GlobalProtect did not detect Qualys for patch management.
|
||||
|
||||
## GPC-22764
|
||||
|
||||
Fixed an issue where wa_3rd_party_host_xx.exe attempted to connect to Microsoft’s update servers for information and the patch information was not sent in the HIP report. This occured even though HIP Exceptions for patch management were configured to exclude Windows updates agent.
|
||||
|
||||
## GPC-22740
|
||||
|
||||
Fixed an issue where macOS computers displayed both the new and old versions of the GlobalProtect welcome page.
|
||||
|
||||
## GPC-22688
|
||||
|
||||
Fixed an issue for proxy-only mode where customers were unable to access websites when the computer woke up from sleep.
|
||||
|
||||
## GPC-22638
|
||||
|
||||
Fixed an issue where Global Protect HIP did not detect the drive state when using Trellix Drive Encryption 8.0.
|
||||
|
||||
## GPC-22620
|
||||
|
||||
Fixed an issue where GlobalProtect was not working correctly and blocked internet access.
|
||||
|
||||
## GPC-22589
|
||||
|
||||
Fixed an issue where the Report an Issue functionality did not send the troubleshooting log to the administrator’s Strata Logging Service instance.
|
||||
|
||||
## GPC-22544
|
||||
|
||||
Fixed an issue where the GlobalProtect client did not send the HIP report causing user-IP mapping to be cleared and resulting in traffic drop.
|
||||
|
||||
## GPC-22542
|
||||
|
||||
Fixed an issue where the embedded browser shown as part of SAML authentication was blank.
|
||||
|
||||
## GPC-22487
|
||||
|
||||
Fixed an issue where Norton 360 was not compatible with GlobalProtect causing the device to fail the HIP check.
|
||||
|
||||
## GPC-22443
|
||||
|
||||
Fixed an issue where the GlobalProtect agent showed as connected even when the virtual adapter was down.
|
||||
|
||||
## GPC-22437
|
||||
|
||||
Fixed an issue where the GlobalProtect macOS client experienced a keep-alive timeout, preventing the tunnel from connecting.
|
||||
|
||||
## GPC-22412
|
||||
|
||||
Fixed an error where virtual adapter is not set correctly during tunnel creation.
|
||||
|
||||
## GPC-22297
|
||||
|
||||
Fixed an issue where the Customer was getting "A valid client certificate is required for authentication" even though they had a valid client certificate installed. In order to access the fix, you must do one of the following:uninstall the previous release (to remove all registry entries).manually delete the registry value "ext-key-usage-oid-for-client-cert" under "HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto Networks\GlobalProtect\Settings" as it may contain a corrupted value.
|
||||
|
||||
uninstall the previous release (to remove all registry entries).
|
||||
|
||||
manually delete the registry value "ext-key-usage-oid-for-client-cert" under "HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto Networks\GlobalProtect\Settings" as it may contain a corrupted value.
|
||||
|
||||
## GPC-22264
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP report did not detect the last full scan time for Avast antivirus software.
|
||||
|
||||
## GPC-22245
|
||||
|
||||
Fixed an issue where transparent upgrade from GlobalProtect version 6.2.4 or 6.2.5 to version 6.2.6 failed on some Windows endpoints with error 1618.
|
||||
|
||||
## GPC-22237
|
||||
|
||||
Fixed an issue where GlobalProtect shut down unexpectedly on Windows 11 devices running multiple versions of GlobalProtect 6.3. The issue was caused by the firewall sending invalid IPv6 packets to GlobalProtect, which did not have a validation method before processing.
|
||||
|
||||
## GPC-22235
|
||||
|
||||
Fixed an issue where users were unable to connect to the app after the system woke up from sleep mode.
|
||||
|
||||
## GPC-22233
|
||||
|
||||
Fixed an issue where the users were unable to connect the GlobalProtect app after performing the resolution of CVE-2024-5921. The app displayed the following error, “The certificate CN name mismatch.”
|
||||
|
||||
## GPC-22126
|
||||
|
||||
Fixed an issue where GlobalProtect version 6.2.6-838 was stuck intermittently during the connection process.
|
||||
|
||||
## GPC-22123
|
||||
|
||||
Fixed an issue where the GlobalProtect app got stuck and users faced connection issues after the system woke up from sleep mode even though the internet connection was stable.
|
||||
|
||||
## GPC-22092
|
||||
|
||||
Fixed an issue where the GlobalProtect app failed to validate the server certificate when the portal or gateway sent only the leaf certificate.
|
||||
|
||||
## GPC-22061
|
||||
|
||||
Fixed an issue where the GlobalProtect client displayed an error when using an ECDSA certificate with explicit EC parameters in FIPS mode.
|
||||
|
||||
## GPC-22043
|
||||
|
||||
Fixed an issue where Okta push notification shows incorrect Windows OS, when Okta SAML authentication is enabled in GlobalProtect.
|
||||
|
||||
## GPC-22036
|
||||
|
||||
Resolved an issue where GlobalProtect did not populate the internal routes in the user's routing table.
|
||||
|
||||
## GPC-22028
|
||||
|
||||
Fixed an issue where the disconnect reason for macOS users was getting cached.
|
||||
|
||||
## GPC-21988
|
||||
|
||||
Fixed an issue where the GlobalProtect Client displayed a download prompt or was updated even with an "upgrade disallow" configuration.
|
||||
|
||||
## GPC-21979
|
||||
|
||||
Fixed an issue where the included domain traffic was routed through the physical interface when split tunnel was configured.
|
||||
|
||||
## GPC-21961
|
||||
|
||||
Fixed an issue where, after upgrading to GlobalProtect version 6.2.5, the app triggered authentication and opened multiple browser tabs when the computer woke from sleep.
|
||||
|
||||
## GPC-21960
|
||||
|
||||
Fixed an issue where the HIP check failed to detect the Norton anti-malware version 24.11.9615.0.
|
||||
|
||||
## GPC-21955
|
||||
|
||||
Fixed an issue where the HIP notification pop-up on macOS looked different from that on Windows.
|
||||
|
||||
## GPC-21938
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app version 6.3.x was installed on devices running macOS, the HIP check failed to detect ESET Endpoint Security version 8.
|
||||
|
||||
## GPC-21918
|
||||
|
||||
Fixed an issue where, when the patch management category was excluded for HIP checks, HIP checks were still happening for missing patches which consumed CPU resources on users' machine.
|
||||
|
||||
## GPC-21938
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app version 6.3.x was installed on devices running macOS, the HIP check failed to detect ESET Endpoint Security version 8.
|
||||
|
||||
## GPC-21775
|
||||
|
||||
Fixed an issue where GlobalProtect users on macOS were disconnected immediately after sending the HIP report.
|
||||
|
||||
## GPC-21771
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP check incorrectly detected Malware Definition Date for Trend Micro Deep Security Agent, which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-21743
|
||||
|
||||
Fixed an issue where a user was randomly prompted with a \"Login Successful\" message when connecting to GlobalProtect (GP), even though GP was not connected.
|
||||
|
||||
## GPC-21695
|
||||
|
||||
Fixed an issue where the GlobalProtect embedded browser could not utilize a new PIV certificate for SAML authentication if multiple certificates were available.
|
||||
|
||||
## GPC-21677
|
||||
|
||||
Fixed an issue where GlobalProtect configured for Always-on Pre-logon may not display the captive portal page if there is a delay with network access or Internet connectivity.
|
||||
|
||||
## GPC-21653
|
||||
|
||||
Fixed an issue where the GlobalProtect virtual adapter was not set up correctly.
|
||||
|
||||
## GPC-21639
|
||||
|
||||
Fixed an issue where the GlobalProtect macOS client did not extend the session even though the user clicked the Extend Session button.
|
||||
|
||||
## GPC-21627
|
||||
|
||||
Fixed an issue where the Report an Issue feature failed to work for a specific user whose username contained Japanese character.
|
||||
|
||||
## GPC-21615
|
||||
|
||||
Fixed an issue where the GlobalProtect agent (wa_3rd_party_host_64.exe) modified the __PSLockDownPolicy registry key from 4 (secure language mode) to 0 (full language mode) after a reboot.
|
||||
|
||||
## GPC-21571
|
||||
|
||||
Fixed an issue where the hyperlink in HIP notification opened up in Webview2 instead of the default browser.
|
||||
|
||||
## GPC-21565
|
||||
|
||||
Fixed an issue where the SAML embedded browser did not remember the username after sign-out, even when the user had selected the check box “Remember Me" on the SAML embedded browser,
|
||||
|
||||
## GPC-21527
|
||||
|
||||
Fixed an issue where the firewall did not exclude the APIPA (169.254.0.0/16) range from GlobalProtect when the Endpoint Traffic Policy Enforcement feature was enabled with the exclude option. As a result, traffic to the APIPA range was sent over GlobalProtect instead of the local interface.
|
||||
|
||||
## GPC-21467
|
||||
|
||||
Fixed an issue where the Transparent Upgrade with Proxy only mode did not work as expected and no tunnel was established with the gateway.
|
||||
|
||||
## GPC-21453
|
||||
|
||||
Fixed an issue where the GlobalProtect app window displayed "static" instead of the connected gateway name.
|
||||
|
||||
## GPC-21222
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP check incorrectly detected the Real Time Protection Status and Last Full Scan for Avast application, which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-21090
|
||||
|
||||
Fixed an issue where GlobalProtect only displayed ADEM information for approximately 120 users even though more than 600 ADEM users were connected to GlobalProtect.
|
||||
|
||||
## GPC-20967
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed with the Conditional Connect method, users had to click the Connect button twice to connect to an external gateway after a system reboot.
|
||||
|
||||
## GPC-20632
|
||||
|
||||
Fixed an issue where GLobalProtect was stuck in connecting mode after the customer manually selected a gateway that hit the maximum user limit. This was a multi-gateway environment with SAML/CAS authentication method.
|
||||
|
||||
## GPC-20621
|
||||
|
||||
Fixed an issue where users from overseas locations were disconnected from GlobalProtect due to the HIP report not being sent with manual gateway selection.
|
||||
|
||||
## GPC-18587
|
||||
|
||||
Fixed an issue where, when the GlobalProtect was installed on Windows devices and Connect Before Logon was deployed, users were unable to log in to the device using the User Principal Name (UPN). This issue occurred when the GlobalProtect credential provider was selected and the device was offline.
|
||||
+18
-1
@@ -148,7 +148,24 @@
|
||||
]
|
||||
},
|
||||
"6.2": {
|
||||
"addressed": [],
|
||||
"addressed": [
|
||||
"6.2.3-c287_2026-03-16.md",
|
||||
"6.2.6-c857_2026-03-16.md",
|
||||
"6.2.8-c223_2026-03-16.md",
|
||||
"6.2.1_2026-03-16.md",
|
||||
"6.2.2_2026-03-16.md",
|
||||
"6.2.3_2026-03-16.md",
|
||||
"6.2.4_2026-03-16.md",
|
||||
"6.2.5_2026-03-16.md",
|
||||
"6.2.6_2026-03-16.md",
|
||||
"6.2.8_2026-03-16.md",
|
||||
"6.2.8-h2_2026-03-16.md",
|
||||
"6.2.8-h3_2026-03-16.md",
|
||||
"6.2.8-h4_2026-03-16.md",
|
||||
"6.2.8-h5_2026-03-16.md",
|
||||
"6.2.8-h6_2026-03-16.md",
|
||||
"6.2.8-h7_2026-03-16.md"
|
||||
],
|
||||
"known": []
|
||||
},
|
||||
"6.1": {
|
||||
|
||||
Reference in New Issue
Block a user