diff --git a/reference/GlobalProtect/addressed/6.3.3-h1.html b/reference/GlobalProtect/addressed/6.3.3-h1.html new file mode 100644 index 0000000..3510a1a --- /dev/null +++ b/reference/GlobalProtect/addressed/6.3.3-h1.html @@ -0,0 +1,123 @@ +
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ GPC-23277
+ |
+
+
+ Fixed an issue where the GlobalProtect macOS client intermittently
+ experienced connection timeouts while browsing the internet in proxy
+ mode (when disconnected from the VPN tunnel). Ping operations were
+ successful, but website access through a browser was slow or failed.
+
+ |
+
|
+ GPC-23237
+ |
+
+
+ Fixed an issue where the GlobalProtect macOS client restarted on
+ opening a zoom session in transparent proxy mode.
+
+ |
+
|
+ GPC-23215
+ |
+
+
+ Fixed an issue where the traffic stopped passing through the
+ GlobalProtect app on macOS devices after upgrading to GP 6.2.8 and
+ when the computer screen was locked.
+
+ |
+
|
+ GPC-23161
+ |
+
+
+ Fixed an issue where the GlobalProtect app stopped working after a
+ session change.
+
+ |
+
|
+ GPC-23139
+ |
+
+
+ Fixed an issue where, after a disconnection event, the GlobalProtect
+ agent could not connect to either the transparent proxy or the IPsec
+ tunnel until the client device was rebooted.
+
+ |
+
|
+ GPC-23117
+ |
+
+
+ Fixed an issue where after installing GlobalProtect on macOS devices,
+ the host ID displayed the device's MAC address instead of the UID, and
+ the GlobalProtect agent icon flickered.
+
+ |
+
|
+ GPC-23077
+ |
+
+
+ Fixed an issue where HIP reports were not sent to the GlobalProtect
+ gateway when transparent proxy is enabled, resulting in rules not
+ being matched.
+
+ |
+
|
+ GPC-22777
+ |
+
+
+ Fixed an issue where GlobalProtect entered proxy mode after the
+ computer woke from sleep but failed to apply the configured proxy
+ settings, resulting in a lost proxy connection.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ GPC-23654
+ |
+
+
+ Fixed an issue where the GlobalProtect client displays the error
+ message "The virtual adapter was not set up correctly due to a delay"
+ on Windows endpoints, preventing VPN connectivity until the system is
+ restarted.
+
+ |
+
|
+ GPC-23604
+ |
+
+
+ Fixed an issue where GlobalProtect users were not automatically
+ prompted for authentication on public Wi-Fi networks with a captive
+ portal
+
+ |
+
|
+ GPC-23558
+ |
+
+
+ Fixed an issue where GlobalProtect clients using SAML with Ping
+ Federate did not save the SAML token upon reboot or restart of the
+ pangps service, requiring users to re-authenticate even when the token
+ was not expired. This issue affected GlobalProtect client version
+ 6.3.3 when SAML authentication was configured in Prisma Access and not
+ in Cloud Identity Engine.
+
+ |
+
|
+ GPC-23551
+ |
+
+
+ Fixed an issue where the virtual network adapter retained the static
+ IP address assigned by GlobalProtect even after the GlobalProtect
+ client disconnected. This caused DNS registration conflicts, making
+ workstations unreachable by hostname even after a reboot.
+
+ |
+
|
+ GPC-23520
+ |
+
+
+ Fixed an issue where new GlobalProtect users were unable to connect to
+ the GlobalProtect app. The app got stuck in 'Connecting" stage and
+ stopped working when redirected to the embedded browser.
+
+ |
+
|
+ GPC-23519
+ |
+
+
+ Fixed an issue where GlobalProtect HIP reports on MacBooks
+ intermittently failed with an "Invalid client IP" error, preventing
+ users from accessing resources over the GP tunnel. This issue occurred
+ after a system network change when GP attempted to send the HIP report
+ to an external gateway while the tunnel was disconnected. This issue
+ affected MacBooks running GP version 6.2.5.
+
+ |
+
|
+ GPC-23496
+ |
+
+
+ Fixed an issue where the GlobalProtect app's Connect button did not
+ work as expected preventing users from connecting or changing
+ gateways.
+
+ |
+
|
+ GPC-23440
+ |
+
+
+ Fixed an issue where Okta FastPass authentication did not work with
+ GlobalProtect 6.3.3 on macOS 15.5 Sequoia, where the Okta Verify app
+ did not open for the additional authentication prompt.
+
+ |
+
|
+ GPC-23432
+ |
+
+
+ Fixed an issue where the GlobalProtect app version 6.3.3
+ intermittently got stuck on the "finding best gateway" status
+
+ |
+
|
+ GPC-23404
+ |
+
+
+ Fixed an issue where the Host Information Profile (HIP) check was
+ unable to accurately identify key details from third-party security
+ products.
+
+ |
+
|
+ GPC-23294
+ |
+
+
+ Fixed an issue where GlobalProtect app intermittently disconnected on
+ macOS endpoints even with a stable network connection. This was due to
+ a timeout that was too short for the route system command.
+
+ |
+
|
+ GPC-23263
+ |
+
+
+ Fixed an issue where after upgrading to GlobalProtect app version
+ 6.3.3, the app did not save the username in the embedded browser when
+ "save username" was enabled.
+
+ |
+
|
+ GPC-23218
+ |
+
+
+ Fixed an issue where, when using the GlobalProtect app with an
+ embedded browser, interrupting or canceling the SAML authentication
+ prompt terminated the pre-logon tunnel, potentially allowing full
+ internet access even when enforcer was enabled for the user-logon
+ profile. With default browser, the pre-logon tunnel remained active
+ when the SAML authentication prompt was interrupted.
+
+ |
+
|
+ GPC-23115
+ |
+
+
+ Fixed an issue where the hardware token authentication option was
+ intermittently unavailable while using the embedded GlobalProtect
+ browser on Windows machines.
+
+ |
+
|
+ GPC-23088
+ |
+
+
+ Fixed an issue where portal login failed due to embedded browser not
+ popping up and GlobalProtect remains in connecting state
+
+ |
+
|
+ GPC-23044
+ |
+
+
+ Fixed an issue where, when a machine was in Modern standby, the
+ GlobalProtect app repeatedly attempted to connect to gateways, even
+ when authentication failed due to SAML timeout. This resulted in
+ GlobalProtect connecting to non-optimal gateway
+
+ |
+
|
+ GPC-22989
+ |
+
+
+ Fixed an issue where the GlobalProtect app intermittently stopped
+ sending HIP reports while connected to the gateway.
+
+ |
+
|
+ GPC-22979
+ |
+
+
+ Fixed an issue where, after upgrading to GlobalProtect app version
+ 6.2.6, the PanGPA application got stuck in 'Connecting' state and then
+ got terminated unexpectedly.
+
+ |
+
|
+ GPC-22887
+ |
+
+
+ Fixed an issue where GlobalProtect users experienced frequent
+ disconnections across various locations.
+
+ |
+
|
+ GPC-22870
+ |
+
+
+ Fixed an issue where, when using domain-based split tunneling on
+ GlobalProtect clients, expired DNS TTL entries were not removed from
+ the Windows Filtering Platform filter driver. This resulted in
+ incorrect packet routing where traffic for domains not in the exclude
+ list, but resolving to the same IP address as excluded domains, was
+ routed via the physical interface instead of the tunnel.
+
+ |
+
|
+ GPC-22804
+ |
+ + Fixed an issue where the GlobalProtect app remained in a connected state + after a network disconnection. As a result, when the network connection + was restored, the GlobalProtect app did not recover, and traffic failed + to pass until a refresh connection was performed. + | +
|
+ GPC-22764
+ |
+
+
+ Fixed an issue where wa_3rd_party_host_xx.exe attempted to connect to
+ Microsoft’s update servers for information and the patch information
+ was not sent in the HIP report. This occured even though HIP
+ Exceptions for patch management were configured to exclude Windows
+ updates agent.
+
+ |
+
|
+ GPC-22541
+ |
+
+
+ Fixed an issue on Windows 11 where the GlobalProtect app (PanGPA)
+ would stop working when the device was locked. The crash occurred when
+ an expired authentication triggered a persistent smartcard login
+ dialog during sleep, leading to excessive memory swapping and a
+ crypt32.dll failure.
+
+ |
+
|
+ GPC-22365
+ |
+
+
+ Fixed an issue where users experienced intermittent issues browsing
+ webpages while connected to the GlobalProtect app.
+
+ |
+
|
+ GPC-22033
+ |
+
+
+ Fixed an issue where GlobalProtect client version 6.3.1 experienced
+ DNS resolution failures for IPv4 addresses, specifically when
+ applications using the io.netty library attempted DNS lookups.
+
+ |
+
|
+ GPC-22029
+ |
+
+
+ Fixed an issue where Apple software downloads took longer to complete
+ when using GlobalProtect with split tunneling enabled.
+
+ |
+
|
+ GPC-21982
+ |
+
+
+ Fixed an issue in which IPv6 traffic bypassed the valid route in the
+ rerouting table and instead passed through the physical adapter when
+ the GlobalProtect app was installed on Windows devices.
+
+ |
+
|
+ GPC-21961
+ |
+
+
+ Fixed an issue where, after upgrading to GlobalProtect version 6.2.5,
+ the app triggered authentication and opened multiple browser tabs when
+ the computer woke from sleep.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ GPC-24113
+ |
+
+
+ Fixed an issue where, on Mac OS endpoints, the agent proxy was
+ attempting to download PAC files directly, bypassing the configured
+ proxy settings. This resulted in download failures when the corporate
+ network was configured to block direct traffic.
+
+ |
+
|
+ GPC-23947
+ |
+
+
+ Fixed an issue where GlobalProtect agent-msg logs were not generated
+ on Panorama when a user disconnected from the GlobalProtect gateway.
+
+ |
+
|
+ GPC-23839
+ |
+
+
+ Fixed an issue that caused the GlobalProtect 6.3.3 HIP report to fail
+ with the error Method: WAAPI_MID_GET_AGENT_STATE
+
+ |
+
|
+ GPC-23760
+ |
+
+
+ GlobalProtect app version 6.3.3 using SAML with the embedded browser
+ loses cursor focus in the password field, requiring users to click in
+ the password field before entering their password.
+
+ |
+
|
+ GPC-23753
+ |
+
+
+ Fixed an issue where the DNS registration script configured on
+ pre-vpn-connect did not run on the first GlobalProtect connection on
+ version 6.3.3.
+
+ |
+
|
+ GPC-23752
+ |
+
+
+ Fixed an issue where the GlobalProtect app failed to authenticate to
+ the portal and gateway after a machine certificate was renewed by
+ Intune MDM. A reboot was required to restore the connection.
+
+ |
+
|
+ GPC-23746
+ |
+
+
+ Fixed an issue where the GlobalProtect HIP check incorrectly detected
+ status for Symantec Endpoint Protection, which caused the device to
+ fail the
+
+ HIP check.
+ |
+
|
+ GPC-23616
+ |
+
+
+ Fixed an issue where, when the GlobalProtect app was installed on
+ devices running macOS, the following error
+
+
+ "TransparentProxy: openWithLocalEndpoint failed" occurred in
+ PanNExt.log when using an IPv6 address.
+
+ |
+
|
+ GPC-23488
+ |
+
+
+ Fixed an issue where the HIP report intermittently detected MacOS
+ XProtect "Real Time Protection" status as disabled.
+
+ |
+
|
+ GPC-23468
+ |
+
+
+ Fixed an issue where the GlobalProtect HIP check failed to detect the
+ correct version of Forticlient Antivirus, which caused the device to
+ fail the HIP check.
+
+ |
+
|
+ GPC-23417
+ |
+
+
+ Fixed an issue where SAML authentication with Azure AD, using Cisco
+ Duo EAM, failed after upgrading to GlobalProtect version 6.2.8
+
+ |
+
|
+ GPC-23403
+ |
+
+
+ Fixed an issue where the GlobalProtect HIP report failed to detect the
+ status of SentinelOne, causing the device to fail the HIP check
+
+ |
+
|
+ GPC-23361
+ |
+
+
+ Fixed an issue where the GlobalProtect HIP report did not detect the
+ Status for Zoho corporation - ManageEngine Patch Manager Plus Agent,
+ which caused the device to fail the HIP check.
+
+ |
+
|
+ GPC-23283
+ |
+
+
+ Fixed an issue where GlobalProtect was unable to set [exclude/include]
+ 0.0.0.0/netmask routes on Mac endpoint
+
+ |
+
|
+ GPC-23095
+ |
+
+
+ Fixed and issue where the GlobalProtect HIP report failed to detect
+ the Symantec DLP software, which caused the device to fail the HIP
+ check.
+
+ |
+
|
+ GPC-22156
+ |
+
+
+ Fixed an issue where the GlobalProtect application displayed
+ unexpected characters on the user interface after installing the
+ GlobalProtect client on Windows 11 machines. This issue was observed
+ with GlobalProtect client versions 6.3.1-c383 and 6.2.6-838, where the
+ Lato font appeared to be the cause.
+
+ |
+
|
+ GPC-21745
+ |
+
+
+ Fixed an issue where the GlobalProtect HIP check failed to detect
+ Workspace ONE status, which caused the device to fail the HIP check.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ GPC-24332
+ |
+
+
+ Fixed an issue where users on trusted networks were incorrectly
+ receiving a captive portal detection message and being redirected to a
+ separate browser tab. This occurred because the GlobalProtect app was
+ not properly handling captive portal detection response.
+
+ |
+
|
+ GPC-24330
+ |
+
+
+ Fixed an issue where GlobalProtect app got stuck in a connecting state
+ when using GlobalProtect version 6.2.8-h4. The issue was seen when
+ saml-logout and enforcer was enabled.
+
+ |
+
|
+ GPC-24235
+ |
+
+
+ Fixed an issue where, after upgrading to GlobalProtect agent 6.2.8 on
+ macOS, users were unable to select a different portal. Clicking
+ "Change Portal" would initiate a reconnection attempt instead of
+ displaying the portal selection menu.
+
+ |
+
|
+ GPC-24166
+ |
+
+
+ Fixed an issue where GlobalProtect agents in proxy-only mode would
+ intermittently get stuck in a connecting state after upgrading from
+ version 6.2.8 to 6.3.3-676. The agent would become stuck in the
+ "Discovering external network" phase, and restarting the GlobalProtect
+ process would temporarily resolve the issue.
+
+ |
+
|
+ GPC-24086
+ |
+
+
+ Fixed an issue where, when Endpoint Traffic Policy Enforcement was
+ enabled with "No Direct Access to Local Network" on GlobalProtect,
+ Xcode running on macOS was unable to recognize iPhones connected via
+ USB-C. This issue occurred because traffic enforcement blocked
+ communication between Xcode and the iPhone.
+
+ |
+
|
+ GPC-24050
+ |
+
+
+ Fixed an issue where GlobalProtect clients prompted a window to select
+ a certificate with the error "The parameter is incorrect" because the
+ client certificate request originated from a portal or gateway Access
+ Control Server (ACS) and was not required.
+
+ |
+
|
+ GPC-24048
+ |
+
+
+ Fixed an issue where GlobalProtect apps installed on on Dell Vostro 15
+ 3515 laptops were unable to connect to the GlobalProtect service with
+ the following error: "Could not connect to the GlobalProtect service.
+ If the issue persists, contact your administrator."
+
+ |
+
|
+ GPC-24036
+ |
+
+
+ Fixed an issue where the HIP check did not correctly detect the status
+ of the ESET firewall on Windows hosts.
+
+ |
+
|
+ GPC-23990
+ |
+
+
+ Fixed an issue where the captive portal opened in the embedded
+ browser, but when the user tried to connect to the internet, it
+ redirected to the default browser and was blocked.
+
+ |
+
|
+ GPC-23913
+ |
+
+
+ Fixed an issue where the GlobalProtect app would become unresponsive
+ when system extensions and a PAC file were enabled simultaneously.
+
+ |
+
|
+ GPC-23906
+ |
+
+
+ Fixed an issue where GlobalProtect app displayed a "No Network
+ Connectivity" error and failed to initiate a network connection,
+ preventing access to applications.
+
+ |
+
|
+ GPC-23730
+ |
+
+
+ Fixed an issue where IPv6 traffic on Windows 11 24H2 did not work as
+ expected with GlobalProtect app.
+
+ |
+
|
+ GPC-23689
+ |
+
+
+ Fixed an issue where the GlobalProtect app running on macOS devices
+ would stuck in a connecting loop indefinitely if the user did not
+ complete authentication, requiring manual cancellation of the
+ connection.
+
+ |
+
|
+ GPC-23650
+ |
+
+
+ Fixed an issue where the GlobalProtect enforcer blocked network
+ traffic on Windows endpoints even after the tunnel was successfully
+ connected.
+
+ |
+
|
+ GPC-23549
+ |
+
+
+ Fixed an issue where the GlobalProtect (GP) agent briefly disconnected
+ when a user logged on to Windows, even when the 'Pre-Logon Tunnel
+ Rename Timeout (sec) (Windows Only)' setting was set to -1, with the
+ error "server cert verification failed".
+
+ |
+
|
+ GPC-23546
+ |
+
+
+ Fixed an issue where the SAML authentication window in the
+ GlobalProtect client on macOS devices running version 6.2.6 or higher
+ would sometimes display an incomplete or blank screen after the device
+ woke up from sleep mode. This issue affects devices using the embedded
+ browser for SAML authentication and with GlobalProtect set to
+ always-on mode with enforcer enabled.
+
+ |
+
|
+ GPC-23525
+ |
+
+
+ Fixed an issue where on macOS Ventura and Sequoia, manually changing
+ the portal address using the GlobalProtect app UI would fail and
+ revert back to the last connected portal. This issue occurred even
+ when "Allow User to Change Portal Address" was enabled in the agent
+ configuration.
+
+ |
+
|
+ GPC-23466
+ |
+
+
+ Fixed an issue where, when the GlobalProtect app was installed on
+ devices running Windows OS and macOS, the Captive Portal detection
+ message briefly appeared and disappeared when the Captive Portal
+ exception timeout was set to 0.
+
+ |
+
|
+ GPC-23336
+ |
+
+
+ Fixed an issue where agent disable logs were not being logged to
+ Gateway System Logs on the firewall. The GlobalProtect agent reset the
+ authentication code, which falsely indicated that the gateway was not
+ fully authenticated, and the agent did not send the message.
+
+ |
+
|
+ GPC-22683
+ |
+
+
+ Fixed an issue where tool tips were not available for the Add, Edit,
+ and Delete buttons on the GlobalProtect application's settings page on
+ Windows devices.
+
+ |
+
|
+ GPC-22572
+ |
+
+
+ Fixed an issue where the hamburger menu button was disabled in the
+ Refresh connection screen, which made it inaccessible when using a
+ keyboard.
+
+ |
+
|
+ GPC-22522
+ |
+
+
+ Fixed an issue where, after upgrading the GlobalProtect app, external
+ users on Windows 11 computers with multiple Azure Entra accounts were
+ unable to authenticate to the portal using SAML with Azure Entra as
+ the Identity Provider (IdP). The new WebView2 embedded browser
+ automatically used the user's default Windows credential for Single
+ Sign-On (SSO), preventing them from selecting the correct account for
+ authentication.
+
+
+ To resolve this issue a new registry key 'entra-sso' has been
+ introduced. You can add the registry key using two methods and set it
+ to no to disable SSO.
+
+
+ 1. For pre-deployment, use 'msiexec.exe /i globalprotect64.msi
+ ENTRASSO="no"
+
+ or
+
+ 2. Add key "entra-sso" and set it to "no" under
+ HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto Networks\GlobalProtect\Settings.
+ If the "entra-sso" key does not exist under this path, the
+ GlobalProtect agent's default behavior is to 'Allow' Entra SSO.
+
+ |
+
|
+ GPC-22148
+ |
+
+
+ (GP App 6.3.1 enabled with FIPS-CC only) Fixed an issue where the OCSP
+ request did not send the Host header, causing the X509v3 certificate
+ validation to fail when accessing the OCSP or CRL.
+
+ |
+
|
+ GPC-22021
+ |
+
+
+ Fixed an issue where, when using conditional-connect on macOS Sequoia
+ with GlobalProtect client version 6.2.6, manually switching gateways
+ caused the client to display a "Not connected" status for
+ approximately 10 seconds while establishing a connection to the second
+ gateway.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ GPC-24683
+ |
+
+
+ Fixed an issue where Host Information Profile (HIP) matching failed
+ for Anti-Malware criteria on macOS endpoints due to GlobalProtect
+ failing to detect the virus definition version for Kaspersky
+ Anti-Virus.
+
+ |
+
|
+ GPC-24579
+ |
+
+
+ Fixed an issue where GlobalProtect clients were unable to authenticate
+ to internal gateways when multiple internal gateways were configured.
+ This issue occured because the GlobalProtect client did not properly
+ reset the SAML login flag, causing subsequent SAML pre-login requests
+ to be ignored.
+
+ |
+
|
+ GPC-24548
+ |
+
+
+ Fixed an issue where macOS GlobalProtect (GP) clients connected to an
+ internal gateway with the enforcer enabled were unable to access the
+ internet via a proxy. This occurred because the tunnel_connected flag
+ remained set to 1 after the gateway disconnected, even though the
+ gateway configuration was cleared.
+
+ |
+
|
+ GPC-24261
+ |
+
+
+ Fixed an issue where GlobalProtect app running on macOS Sequoia 15.6.1
+ running GP 6.2.8 -c263 that receive both IPv4 and IPv6 addresses were
+ not receiving packets back from the Network Load Balancer (NLB)
+ instances.
+
+ |
+
|
+ GPC-24221
+ |
+
+
+ Fixed an issue where the GlobalProtect app experienced a continuous
+ connect-disconnect loop when used on flights. This issue occurred
+ because rapid network wake-ups left network interfaces in an
+ inconsistent state, causing GlobalProtect to attempt tunnel
+ establishment on an unstable network foundation.
+
+ |
+
|
+ GPC-24103
+ |
+
+
+ Fixed an issue where the GlobalProtect app running on macOS allowed
+ users to modify or add a new portal address after each device reboot,
+ even when the "Allow users to change portal" setting was configured as
+ "No" in the GlobalProtect app.
+
+ |
+
|
+ GPC-24037
+ |
+
+
+ Fixed an issue where GlobalProtect app prompted users to log in with
+ SAML through the embedded browser even when the GlobalProtect app was
+ already connected. This occurred when users logged off and then back
+ onto their Cloud PC (Windows Azure PC), and closing the prompt
+ disconnected and reconnected the VPN session.
+
+ |
+
|
+ GPC-23929
+ |
+
+
+ Fixed an issue where, when GlobalProtect app was configured with
+ Enforcer, users could bypass Enforcer restrictions by repeatedly
+ canceling authentication prompts after logging into Windows. This
+ occurred because the cached portal configuration, which contains
+ Enforcer settings, was not loaded when a pre-logon tunnel failed to
+ establish due to a quick user login. This fix ensures that the cached
+ portal configuration is loaded as soon as PanGPA starts and PanGPS
+ learns the username, preventing unrestricted access in scenarios where
+ Enforcer is intended to lockdown the endpoint.
+
+ |
+
|
+ GPC-23394
+ |
+
+
+ Fixed an issue where GlobalProtect app version 6.2.8-183. running on
+ macOS 15.5 was unable to accurately report the disk encryption status
+ of FileVault, resulting in an "unknown" status in HIP checks.
+
+ |
+
|
+ GPC-22797
+ |
+
+
+ Fixed an issue where the MAC address generated for the DHCP feature
+ changed on every GlobalProtect client restart. The MAC address should
+ remain static after initial generation to allow static IP assignment
+ on the DHCP server side for a specific GlobalProtect client.
+ Additionally, the generated MAC address was not always marked as
+ unicast and locally administered.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ GPC-25370
+ |
+
+
+ Fixed an issue where GlobalProtect clients (versions
+ 6.3.3-h2-6.3.3-h4) intermittently failed to honor enforcer bypass
+ rules for FQDNs and IP addresses after the client machine woke up from
+ sleep. This resulted in connections to bypassed URLs being blocked,
+ including GlobalProtect's own SAML authentication requests, and
+ required a manual restart of the PanGPS service to restore
+ connectivity.
+
+ |
+
|
+ GPC-25172
+ |
+
+
+ Fixed an issue where, on macOS GlobalProtect clients, exclude routes
+ were not properly removed from the system routing table after a PanGPS
+ (GlobalProtect client) crash. This occurred because the routes
+ remained in the macOS kernel, and upon reconnection, the client's
+ `checkExistingExRts()` function only validated the destination and
+ netmask, not the gateway. As a result, these stale routes, pointing to
+ an old or unreachable gateway, were marked as existing and skipped
+ during the reconnection process, leading to a corrupted routing state
+ and preventing correct route injection, especially after a network
+ change.
+
+ |
+
|
+ GPC-25063
+ |
+
+
+ Fixed an issue where, in the GlobalProtect app on macOS, keyboard
+ focus did not automatically move to the required "Enter portal
+ Address" field when a user attempted to add a new portal without
+ entering an address. This accessibility issue impacted
+ keyboard-dependent users.
+
+ |
+
|
+ GPC-24961
+ |
+
+
+ Fixed an issue where the firewall, when configured to obtain IP
+ addresses from a DHCP server for GlobalProtect clients, sent a MAC
+ address of '00' to the DHCP server specifically for MacOS 26 (Tahoe)
+ clients running GlobalProtect App versions 6.2 or 6.3, which resulted
+ in IP address collisions on the DHCP server.
+
+ |
+
|
+ GPC-24897
+ |
+
+
+ Fixed an issue where the GlobalProtect Connect Before Logon tunnel
+ disconnected for new users on their first logon. This issue affected
+ GP client versions 6.2.8-hx and 6.3.3-hx.
+
+ |
+
|
+ GPC-24892
+ |
+
+
+ Fixed an issue where the GlobalProtect Portal welcome page, when
+ displayed in German, incorrectly presented a button labeled 'Genau'
+ instead of 'Zustimmen' (Accept).
+
+ |
+
|
+ GPC-24880
+ |
+
+
+ Fixed an issue where GlobalProtect clients, after upgrading to
+ versions 6.2.8-263, 6.3.3-h2, or 6.3.3-h3, would get stuck in a
+ connecting loop and fail to connect to the portal or gateways. This
+ occurred because the GlobalProtect app crashed when attempting to
+ delete previous SAML user data, specifically when the user data folder
+ path contained non-ANSI characters that the app could not convert to a
+ UTF-16 path.
+
+ |
+
|
+ GPC-24842
+ |
+
+
+ (macOS only) GlobalProtect crashed when you clicked
+ Change Portal on setups that
+ included two or more portal entries and had a preferred gateway
+ marked.
+
+ |
+
|
+ GPC-24835
+ |
+
+
+ Fixed an issue where split tunneling domain exclusions on
+ GlobalProtect App version 6.3.3-C711 for Windows clients failed to
+ function as expected after the application disconnected and
+ reconnected. This resulted in traffic for domains configured for
+ exclusion being incorrectly routed through the VPN tunnel instead of
+ directly, because the TTLMap for split tunneling domain rules was not
+ properly cleared when the GlobalProtect App re-established its
+ connection.
+
+ |
+
|
+ GPC-24804
+ |
+
+
+ Fixed an issue where GlobalProtect clients running version 6.3.3-711
+ would randomly get stuck in a 'connecting' status, preventing them
+ from establishing a successful VPN connection.
+
+ |
+
|
+ GPC-24796
+ |
+
+
+ Fixed an issue where GlobalProtect HIP reports on macOS devices
+ intermittently failed with an "Invalid client IP" error. This occurred
+ on GlobalProtect client version 6.2.8-h4 (c317) due to a race
+ condition where the HIP report thread sent the report during the VPN
+ disconnect transition, causing the client to use a stale tunnel IP
+ address instead of the physical IP address.
+
+ |
+
|
+ GPC-24755
+ |
+
+
+ Fixed an issue where the GlobalProtect client on Windows machines
+ truncated the Proxy Auto-Configuration file URL (autoConfigURL) at 104
+ characters when configured through the GlobalProtect Portal,
+ preventing the full URL (up to 256 characters) from being correctly
+ set in the Windows registry due to an insufficient internal buffer
+ size.
+
+ |
+
|
+ GPC-24515
+ |
+
+
+ Fixed an issue where GlobalProtect clients on macOS devices,
+ specifically version 6.3.3-h2, were unable to resolve internal IPv6
+ domains when split tunneling was enabled and the operating system
+ lacked native IPv6 connectivity. This occurred because the client's
+ logic, which was designed to apply IPv6 configuration only when the OS
+ already had native IPv6 connectivity, prevented the GlobalProtect
+ tunnel from properly handling IPv6 traffic, resulting in "Err name not
+ resolved" errors for internal FQDNs.
+
+ |
+
|
+ GPC-24242
+ |
+
+
+ Fixed an issue where GlobalProtect portal authentication failed for
+ some macOS users when attempting to use saved credentials. This issue,
+ observed on GlobalProtect client versions 6.2.8 and 6.3.3, resulted in
+ an immediate authentication failure on the client and firewall logs
+ indicating an invalid username or password, even though the
+ credentials were valid for other macOS clients.
+
+ |
+
|
+ GPC-24216
+ |
+
+
+ Fixed an issue where the Host Information Profile (HIP) banner was not
+ displayed on Windows 11 client machines running GlobalProtect client
+ versions 6.2.8-h7 and 6.3.3. This occurred due to a timing or race
+ condition where the GlobalProtect client (PanGPA) received an outdated
+ status, preventing the visual display of HIP match or not-match
+ notifications, even though the messages were recorded in the client
+ logs.
+
+ |
+
|
+ GPC-23963
+ |
+
+
+ Fixed an issue where GlobalProtect Client version 6.2.8 running in
+ Windows 365 environments, would experience PanGPA getting stuck during
+ the tunnel rename process. This prevented successful gateway
+ authentication and registration after users closed and re-opened their
+ Windows 365 session, leading to a pop-up message prompting users to
+ re-authenticate.
+
+ |
+
|
+ GPC-23787
+ |
+
+
+ Fixed an issue where GlobalProtect clients on macOS devices, after
+ upgrading to version 6.2.8-h2, were unable to connect to the
+ authentication server. This occurred because incorrect logic in the
+ GlobalProtect Agent code prevented the Webview Process ID from syncing
+ with the Network Extension process, causing the Network Extension to
+ block SAML authentication traffic, resulting in a "Could not connect
+ to the authentication server" error and a blank embedded browser
+ during SAML authentication.
+
+ |
+
|
+ GPC-23723
+ |
+
+
+ Fixed an issue where GlobalProtect clients running version 6.2.8-h1
+ (6.2.8-c223) experienced intermittent connection failures and
+ disconnections, with the client agent getting stuck in a 'connecting'
+ state even when backend logs indicated a successful connection. This
+ occurred because, when conditional connect mode was enabled, the
+ client attempted to impersonate a user and write On-Demand settings to
+ the user's registry hive (HKEY_CURRENT_USER) during pre-logon. As no
+ user was logged in at that stage, user impersonation failed, leading
+ to incorrect registry access or failed registry operations, which
+ caused service instability or misconfiguration.
+
+ |
+
|
+ GPC-23090
+ |
+
+
+ Fixed an issue where the GlobalProtect app experienced connectivity
+ issues after the host computer resumed from sleep mode due to a
+ missing self-pointed route. This issue resulted in a delay of 5 to 10
+ minutes for the GlobalProtect connection to get stabilized.
+
+ |
+
|
+ GPC-21852
+ |
+
+
+ Fixed an issue where the GlobalProtect Agent incorrectly displayed
+ "N/A" in the "Last Scan Time" field for the Trend Micro Deep Security
+ Agent within the Host Information Profile (HIP) report.
+
+ |
+
|
+ GPC-20621
+ |
+
+
+ Fixed an issue where users from overseas locations were disconnected
+ from GlobalProtect due to the HIP report not being sent with manual
+ gateway selection.
+
+ |
+
|
+ GPC-18976
+ |
+
+
+ Fixed an issue where GlobalProtect client 6.1.1-5 would select the
+ incorrect Windows tile by default after locking the screen when using
+ Single Sign-On for Smart Card PIN (Windows) with the Yubikey Smart
+ Card Minidriver. When multiple smart cards were present, GlobalProtect
+ incorrectly selected the last enumerated card instead of the currently
+ active one.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ GPC-25300
+ |
+
+
+ Fixed an issue where GlobalProtect clients experienced frequent
+ disconnections from GlobalProtect gateways. After being disconnected,
+ users were often unable to reconnect for extended periods, and
+ connection attempts to designated gateways, including those manually
+ selected or identified as 'Best Available', would incorrectly redirect
+ to other gateways.
+
+ |
+
|
+ GPC-25222
+ |
+
+
+ Fixed an issue where GlobalProtect clients failed to detect captive
+ portals on public Wi-Fi networks, even when the captive portal
+ responded with an HTTP 302 Redirect. This occurred because the
+ GlobalProtect agent expected the HTTP response to be terminated by
+ `\r\n\r\n` as per RFC, but some captive portals did not adhere to
+ this, causing the agent to incorrectly report that no data was
+ received from the captive portal server and thus fail to detect the
+ portal.
+
+ |
+
|
+ GPC-25173
+ |
+
+
+ Fixed an issue where GlobalProtect clients on macOS devices, when
+ configured in tunnel-proxy mode, intermittently displayed an "A valid
+ PAC file is required" notification after waking up from modern
+ standby, particularly when the PAC file contained a placeholder
+ statement instead of the actual EP-FQDN.
+
+ |
+
|
+ GPC-24992
+ |
+
+
+ Fixed an issue where GlobalProtect users experienced significant login
+ delays after a system reboot or shutdown, such as after a weekend.
+ This delay was caused by a shared memory issue that disrupted
+ communication between the GlobalProtect agent and GlobalProtect
+ service.
+
+ |
+
|
+ GPC-23301
+ |
+
+
+ Fixed an issue where, when the GlobalProtect app 6.2.7 and later, was
+ installed on Windows 10 devices, the app deleted the predefined proxy
+ PAC file configuration whenever the app got disconnected regardless of
+ whether the disconnection was initiated manually or occurred
+ automatically due to a timeout.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ GPC-25889
+ |
+
+
+ Fixed an issue where GlobalProtect clients, particularly when
+ connected to Prisma Access, were unable to extend their VPN session.
+ When the 'Extend Session' or 'Refresh connection' option was selected,
+ the client would disconnect and immediately reconnect, but the session
+ countdown timer would not reset. This was due to a race condition that
+ caused the `GetCurrentGateway()` function to return a null value
+ during the session extension thread, preventing the session from being
+ properly prolonged.
+
+ |
+
|
+ GPC-25828
+ |
+
+
+ Fixed an issue where on macOS devices running GlobalProtect Agent
+ version 6.3.3-h6, the GlobalProtect Agent was unable to communicate
+ with the GlobalProtect Service, resulting in the error "Could not
+ connect to the GlobalProtect service." This occurred because when
+ prelogon was disabled, the PanGPS LaunchDaemon would exit prematurely
+ after boot, and the subsequent LaunchAgent failed to properly restart
+ PanGPS as a user-session agent, leaving no service listening on port
+ 4767 for PanGPA to connect to.
+
+ |
+
|
+ GPC-25702
+ |
+
+
+ Fixed an issue where the GlobalProtect service (PanGPS) failed to
+ start on macOS 26.3.1 after a system upgrade, preventing GlobalProtect
+ client version 6.2.8-814 from connecting. This was due to a regression
+ where `SetCurrentGateway` was set to `NULL` during `disconnectVPN`
+ operations.
+
+ |
+
|
+ GPC-24033
+ |
+
+
+ Fixed an issue where GlobalProtect Client 6.3.3-676 on Windows
+ endpoints would hang or freeze. This occurred when the client
+ connected to a GlobalProtect portal or gateway that initiated a client
+ certificate request, even if the certificate was not strictly required
+ for authentication. The client's certificate selection dialog would
+ appear briefly and then disappear, causing the GlobalProtect client
+ application to become unresponsive.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ GPC-23046
+ |
+
+
+ Fixed an issue where users experienced connectivity problems when
+ GlobalProtect was used in a WiFi network with captive portal.
+
+ |
+
|
+ GPC-23010
+ |
+
+
+ Fixed an issue where HIP checks incorrectly detected the macOS
+ built-in firewall as disabled, causing HIP checks to fail.
+
+ |
+
|
+ GPC-22847
+ |
+
+
+ Fixed an issue where GlobalProtect did not detect Qualys for patch
+ management.
+
+ |
+
|
+ GPC-22771
+ |
+
+
+ Fixed an issue where the Host Information Profile (HIP) check failed
+ to detect the installed version of Norton anti-malware.
+
+ |
+
|
+ GPC-22763
+ |
+
+
+ Fixed an issue where GlobalProtect prompted for credentials instead of
+ using authoverride cookie when authenticating to the best available
+ gateway.
+
+ |
+
|
+ GPC-22740
+ |
+
+
+ Fixed an issue where macOS computers displayed both the new and old
+ versions of the GlobalProtect welcome page.
+
+ |
+
|
+ GPC-22688
+ |
+
+
+ Fixed an issue for proxy-only mode where customers were unable to
+ access websites when the computer woke up from sleep
+
+ |
+
|
+ GPC-22638
+ |
+
+
+ Fixed an issue where Global Protect HIP did not detect the drive state
+ when using Trellix Drive Encryption 8.0.
+
+ |
+
|
+ GPC-22616
+ |
+
+
+ Fixed an issue where the Digital Guardian Agent was not detected by
+ the GlobalProtect client, causing DLP HIP checks to fail.
+
+ |
+
|
+ GPC-22610
+ |
+
+
+ Fixed an issue where, after an upgrade, GlobalProtect restarted and
+ failed to connect to the portal
+
+ |
+
|
+ GPC-22589
+ |
+
+
+ Fixed an issue where the Report an Issue functionality did not send
+ the troubleshooting log to the administrator’s Strata Logging Service
+ instance.
+
+ |
+
|
+ GPC-22547
+ |
+
+
+ Fixed an issue where the installed OWSPAT version was not supported
+ with the CrowdStrike Falcon version, resulting in HIP object match
+ failures.
+
+ |
+
|
+ GPC-22544
+ |
+
+
+ Fixed an issue where the GlobalProtect client did not send the HIP
+ report causing user-IP mapping to be cleared and resulting in traffic
+ drop.
+
+ |
+
|
+ GPC-22542
+ |
+
+
+ Fixed an issue where the embedded browser shown as part of SAML
+ authentication was blank.
+
+ |
+
|
+ GPC-22487
+ |
+
+
+ Fixed an issue where Norton 360 was not compatible with GlobalProtect
+ causing the device to fail the HIP check.
+
+ |
+
|
+ GPC-22450
+ |
+
+
+ Fixed an issue where users were unable to use smartcard authentication
+ with embedded browser.
+
+ |
+
|
+ GPC-22448
+ |
+
+
+ Fixed an issue where the GlobalProtect client could crash after it was
+ connected to a gateway.
+
+ |
+
|
+ GPC-22443
+ |
+
+
+ Fixed an issue where the GlobalProtect agent showed as connected even
+ when the virtual adapter was down.
+
+ |
+
|
+ GPC-22406
+ |
+
+
+ Fixed an issue where the GlobalProtect credential provider was not set
+ as the default after installation and reboot.
+
+ |
+
|
+ GPC-22381
+ |
+
+
+ Fixed an issue where the GlobalProtect HIP report did not include
+ Cortex XDR installed on the client machine.
+
+ |
+
|
+ GPC-22353
+ |
+
+
+ Fixed an issue where a comment was not visible in the GlobalProtect
+ logs when GlobalProtect was disabled with-comment.
+
+ |
+
|
+ GPC-22297
+ |
+
+
+ Fixed an issue where the Customer was getting "A valid client
+ certificate is required for authentication" even though they had a
+ valid client certificate installed.
+
+ |
+
|
+ GPC-22295
+ |
+
+
+ Fixed an issue where GlobalProtect client for macOS could not navigate
+ away from a hyperlink on the welcome page when the welcome page was
+ opened in the embedded browser.
+
+ |
+
|
+ GPC-22264
+ |
+
+
+ Fixed an issue where the GlobalProtect HIP report did not detect the
+ last full scan time for Avast antivirus software.
+
+ |
+
|
+ GPC-22245
+ |
+
+
+ Fixed an issue where transparent upgrade from GlobalProtect version
+ 6.2.4 or 6.2.5 to version 6.2.6 failed on some Windows endpoints with
+ error 1618.
+
+ |
+
|
+ GPC-22237
+ |
+
+
+ Fixed an issue where GlobalProtect shut down unexpectedly on Windows
+ 11 devices running multiple versions of GlobalProtect 6.3. The issue
+ was caused by the firewall sending invalid IPv6 packets to
+ GlobalProtect, which did not have a validation method before
+ processing.
+
+ |
+
|
+ GPC-22235
+ |
+
+
+ Fixed an issue where users were unable to connect to the app after the
+ system woke up from sleep mode.
+
+ |
+
|
+ GPC-22233
+ |
+
+
+ Fixed an issue where the users were unable to connect the
+ GlobalProtect app after performing the resolution of CVE-2024-5921.
+ The app displayed the following error, “The certificate CN name
+ mismatch.”
+
+ |
+
|
+ GPC-22155
+ |
+
+
+ Fixed an issue where the GlobalProtect app got stuck in the Connecting
+ stage when the app was upgraded to 6.3.2-525 version. Users had to
+ reboot the system to resolve this issue.
+
+ |
+
|
+ GPC-22126
+ |
+
+
+ Fixed an issue where GlobalProtect version 6.2.6-838 was stuck
+ intermittently during the connection process.
+
+ |
+
|
+ GPC-22123
+ |
+
+
+ Fixed an issue where the GlobalProtect app got stuck and users faced
+ connection issues after the system woke up from sleep mode even though
+ the internet connection was stable.
+
+ |
+
|
+ GPC-22092
+ |
+
+
+ Fixed an issue where the GlobalProtect app failed to validate the
+ server certificate when the portal or gateway sent only the leaf
+ certificate.
+
+ |
+
|
+ GPC-22061
+ |
+
+
+ Fixed an issue where the GlobalProtect client displayed an error when
+ using an ECDSA certificate with explicit EC parameters in FIPS mode.
+
+ |
+
|
+ GPC-22054
+ |
+
+
+ Fixed an issue where after GlobalProtect was upgraded from version
+ 6.3.0 to 6.3.1, users were stuck in connecting state.
+
+ |
+
|
+ GPC-22046
+ |
+
+
+ Fixed an issue where when the GlobalProtect app was installed on
+ devices running macOS and the app version was upgraded to 6.2.5, end
+ users were unable to connect the app. The app got stuck in the
+ Connecting state and displayed the following message, “You are
+ redirected to an embedded browser to authenticate and connect.”
+
+ |
+
|
+ GPC-22043
+ |
+
+
+ Fixed an issue where Okta push notification shows incorrect Windows
+ OS, when Okta SAML authentication is enabled in GlobalProtect.
+
+ |
+
|
+ GPC-22028
+ |
+
+
+ Fixed an issue where the disconnect reason for macOS users was getting
+ cached.
+
+ |
+
|
+ GPC-21988
+ |
+
+
+ Fixed an issue where the GlobalProtect Client displayed a download
+ prompt or was updated even with an "upgrade disallow" configuration.
+
+ |
+
|
+ GPC-21960
+ |
+
+
+ Fixed an issue where the HIP check failed to detect the Norton
+ anti-malware version 24.11.9615.0.
+
+ |
+
|
+ GPC-21955
+ |
+
+
+ Fixed an issue where the HIP notification pop-up on macOS looked
+ different from that on Windows.
+
+ |
+
|
+ GPC-21950
+ |
+
+
+ Fixed an issue where the GlobalProtect connection on MacOS Sequoia 15+
+ was unstable.
+
+ |
+
|
+ GPC-21857
+ |
+
+
+ Fixed an issue where, when the GlobalProtect debug build was installed
+ on the device, the device was immediately locked and users were unable
+ to enter their login credentials in the Window Login screen. Users had
+ to reboot their system to resolve this issue.
+
+ |
+
|
+ GPC-21775
+ |
+
+
+ Fixed an issue where GlobalProtect users on macOS were disconnected
+ immediately after sending the HIP report.
+
+ |
+
|
+ GPC-21755
+ |
+
+
+ Fixed an issue where GlobalProtect users with enforcer enabled were
+ able to access applications that were not in the enforcer exception
+ list.
+
+ |
+
|
+ GPC-21743
+ |
+
+
+ Fixed an issue where a user was randomly prompted with a \"Login
+ Successful\" message when connecting to GlobalProtect (GP), even
+ though GP was not connected.
+
+ |
+
|
+ GPC-21737
+ |
+
+
+ Fixed an issue where the SAML redirection page opened up on end user
+
+
+ computers even though they did not have internet connectivity.
+
+ |
+
|
+ GPC-21721
+ |
+
+
+ Fixed an issue, where the GlobalProtect app got stuck in Connecting
+ status when the device woke up from sleep mode.
+
+ |
+
|
+ GPC-21695
+ |
+
+
+ Fixed an issue where the GlobalProtect embedded browser could not
+ utilize a new PIV certificate for SAML authentication if multiple
+ certificates were available.
+
+ |
+
|
+ GPC-21677
+ |
+
+
+ Fixed an issue where GlobalProtect configured for Always-on Pre-logon
+ may not display the captive portal page if there is a delay with
+ network access or Internet connectivity.
+
+ |
+
|
+ GPC-21653
+ |
+
+
+ Fixed an issue where the GlobalProtect virtual adapter was not set up
+ correctly.
+
+ |
+
|
+ GPC-21639
+ |
+
+
+ Fixed an issue where the GlobalProtect macOS client did not extend the
+ session even though the user clicked the Extend Session button.
+
+ |
+
|
+ GPC-21636
+ |
+
+
+ Fixed an issue where the users were unable to login Windows 11 using
+ the User Principal Name (UPN) when GPCP was selected with
+ GlobalProtect app version 6.2.4 and 'Interactive logon: Don't display
+ last signed-in' was enabled in their Entra ID - group policy.
+
+ |
+
|
+ GPC-21627
+ |
+
+
+ Fixed an issue where the Report an Issue feature failed to work for a
+ specific user whose username contained Japanese character.
+
+ |
+
|
+ GPC-21615
+ |
+
+
+ Fixed an issue where the GlobalProtect agent
+ (wa_3rd_party_host_64.exe) modified the __PSLockDownPolicy registry
+ key from 4 (secure language mode) to 0 (full language mode) after a
+ reboot.
+
+ |
+
|
+ GPC-21583
+ |
+
+
+ Fixed an issue where the change password message was truncated in the
+ GlobalProtect agent UI.
+
+ |
+
|
+ GPC-21527
+ |
+
+
+ Fixed an issue where the firewall did not exclude the APIPA
+ (169.254.0.0/16) range from GlobalProtect when the Endpoint Traffic
+ Policy Enforcement feature was enabled with the exclude option. As a
+ result, traffic to the APIPA range was sent over GlobalProtect instead
+ of the local interface.
+
+ |
+
|
+ GPC-21482
+ |
+
+
+ Fixed an issue where some users were unable to connect to portal
+ access, the PANGPA did not work as expected and multiple GlobalProtect
+ instances were opened.
+
+ |
+
|
+ GPC-21468
+ |
+
+
+ Fixed an issue where HIP reports were not sent during modern standby
+ mode.
+
+ |
+
|
+ GPC-21467
+ |
+
+
+ Fixed an issue where the Transparent Upgrade with Proxy only mode did
+ not work as expected and no tunnel was established with the gateway.
+
+ |
+
|
+ GPC-21454
+ |
+
+
+ Fixed an issue where GlobalProtect Connect Before Logon connection
+ allowed GlobalProtect to be disconnected on first time login.
+
+ |
+
|
+ GPC-21453
+ |
+
+
+ Fixed an issue where the GlobalProtect app window displayed "static"
+ instead of the connected gateway name.
+
+ |
+
|
+ GPC-21437
+ |
+
+
+ Fixed an issue where users were unable to connect to Prisma Access via
+ GlobalProtect.
+
+ |
+
|
+ GPC-21413
+ |
+
+
+ Fixed an issue where the GlobalProtect Credential Provider did not
+ reset focus on the password field when the user entered the wrong
+ password
+
+ |
+
|
+ GPC-21375
+ |
+
+
+ Fixed an issue where username from SAML assertion did not match the
+ config selection criteria because the Windows SSO username was used
+ instead of the SAML username.
+
+ |
+
|
+ GPC-21355
+ |
+
+
+ Fixed an issue GlobalProtect pre-logon was stuck in connecting state
+ after a reboot.
+
+ |
+
|
+ GPC-21284
+ |
+
+
+ Fixed an issue where the GlobalProtect gateway did not receive the HIP
+ reports from the user correctly due to which the end users were unable
+ to access the resources even when the sessions were active.
+
+ |
+
|
+ GPC-21267
+ |
+
+
+ Fixed an issue where, when the user installed the GlobalProtectARM
+ installer from the Customer Support Portal (CSP) and the user opened
+ GlobalProtect using the Start menu, the icon file (PanGPA.ico) was
+ opened instead of the executable (PanGPA.exe) file.
+
+ |
+
|
+ GPC-21240
+ |
+
+
+ Fixed an issue where, when the GlobalProtect app was installed on
+ devices running macOS Sonoma 14.5, the app used the old FQDN names and
+ got stuck in the "Connecting" status instead of prompting the user to
+ enter the portal FQDN name.
+
+ |
+
|
+ GPC-21161
+ |
+
+
+ Fixed an issue where the notifications for the feature "Login Lifetime
+ Expiration" and "Notify Before Lifetime Expires" were not displayed on
+ the GlobalProtect client running version 6.2.4.
+
+ |
+
|
+ GPC-21131
+ |
+
+
+ Fixed an issue where the users were unable to access the Advanced
+ Logging Settings screen of the GlobalProtect app using the ctrl + tab
+ key combination on the keyboard. The screen reader did not announce
+ the Keyboard options correctly.
+
+ |
+
|
+ GPC-21090
+ |
+
+
+ Fixed an issue where GlobalProtect only displayed ADEM information for
+ approximately 120 users even though more than 600 ADEM users were
+ connected to GlobalProtect.
+
+ |
+
|
+ GPC-21024
+ |
+
+
+ Fixed an issue where a HIP notification configured as "pop-up-message"
+ for pre-logon does not show up. The pop up window is blank.
+
+ |
+
|
+ GPC-21005
+ |
+
+
+ Fixed an issue where after submitting the SAML credentials, a blank
+ screen was displayed and GlobalProtect got stuck in that stage.
+
+ |
+
|
+ GPC-20992
+ |
+
+
+ Fixed an issue where the Teams application does not connect to the
+ server for macOS.
+
+ |
+
|
+ GPC-20991
+ |
+
+
+ Fixed an issue where the Windows Registry value
+ (ext-key-usage-oid-for-client-cert) on
+ \HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto Networks\GlobalProtect\Settings
+ was deleted during the upgrade from GlobalProtect version 6.2.2 to
+ version 6.2.4. This makes the GlobalProtect client unable to select a
+ certificate by itself.
+
+ |
+
|
+ GPC-20977
+ |
+
+
+ Fixed an issue where conditional connect was not set and GlobalProtect
+ connected to an external gateway on the internal network instead of
+ connecting to an internal gateway on the internal network.
+
+ |
+
|
+ GPC-20813
+ |
+
+
+ Fixed an issue where GlobalProtect 6.3.0 on macOS was blocking
+ multicast traffic on the local network interface.
+
+ |
+
|
+ GPC-20783
+ |
+
+
+ Fixed an issue where, when the embedded browser was used, the password
+ field did not work as expected when users typed their passwords in the
+ field. Users had to click inside the password field before entering
+ their password.
+
+ |
+
|
+ GPC-20736
+ |
+
+
+ Fixed an issue where users are being logged out from GlobalProtect
+ when the device wakes up from modern standby and network discovery
+ happens.
+
+ |
+
|
+ GPC-20632
+ |
+
+
+ Fixed an issue where GLobalProtect was stuck in connecting mode after
+ the customer manually selected a gateway that hit the maximum user
+ limit. This was a multi-gateway environment with SAML/CAS
+ authentication method.
+
+ |
+
|
+ GPC-20550
+ |
+
+
+ Fixed an issue where Zoom and Outlook apps intermittently stop
+ connecting on macOS with an error "You are unable to connect to Zoom.
+ Please check your network connection and try again" when the apps are
+ excluded under both domains and applications
+
+ |
+
|
+ GPC-20514
+ |
+
+
+ Fixed an issue where the remote users using GlobalProtect with Connect
+ Before Logon (CBL) were unable to reset their password when using the
+ app with an embedded browser.
+
+ |
+
|
+ GPC-20461
+ |
+
+
+ Fixed an issue where the GlobalProtect agent version 6.1.4 would only
+ establish a connection via SSL to an IPv6 gateway. The IPSec tunnel
+ was not established or connected.
+
+ |
+
|
+ GPC-20416
+ |
+
+
+ Fixed an issue where there is no network discovery once the laptop
+ came out of standby.
+
+ |
+
|
+ GPC-20386
+ |
+
+
+ Fixed an issue where Windows users experienced a blue screen of death
+ issue due to a race condition between Microsoft IPSEC extension and
+ GlobalProtect. The issue happens only when IKE extensions are enabled
+ via IPSEC GPO on the endpoint along with GlobalProtect.
+
+ |
+
|
+ GPC-20292
+ |
+
+
+ Fixed an issue where the Azure VDI RDP connection disconnects when
+ using enforcer.
+
+ |
+
|
+ GPC-20168
+ |
+
+
+ Fixed an issue where it was possible to do a privilege escalation
+ and\or login bypass when using a 3rd party credential provider with
+ GlobalProtect
+
+ |
+
|
+ GPC-18106
+ |
+
+
+ Fixed an issue where the GlobalProtect app intermittently did not send
+ the HIP report to the Prisma Access gateway due to a timeout issue.
+
+ |
+