diff --git a/reference/GlobalProtect/addressed/6.3.3-h1.html b/reference/GlobalProtect/addressed/6.3.3-h1.html new file mode 100644 index 0000000..3510a1a --- /dev/null +++ b/reference/GlobalProtect/addressed/6.3.3-h1.html @@ -0,0 +1,123 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
GPC-23277
+
+
+ Fixed an issue where the GlobalProtect macOS client intermittently + experienced connection timeouts while browsing the internet in proxy + mode (when disconnected from the VPN tunnel). Ping operations were + successful, but website access through a browser was slow or failed. +
+
+
GPC-23237
+
+
+ Fixed an issue where the GlobalProtect macOS client restarted on + opening a zoom session in transparent proxy mode. +
+
+
GPC-23215
+
+
+ Fixed an issue where the traffic stopped passing through the + GlobalProtect app on macOS devices after upgrading to GP 6.2.8 and + when the computer screen was locked. +
+
+
GPC-23161
+
+
+ Fixed an issue where the GlobalProtect app stopped working after a + session change. +
+
+
GPC-23139
+
+
+ Fixed an issue where, after a disconnection event, the GlobalProtect + agent could not connect to either the transparent proxy or the IPsec + tunnel until the client device was rebooted. +
+
+
GPC-23117
+
+
+ Fixed an issue where after installing GlobalProtect on macOS devices, + the host ID displayed the device's MAC address instead of the UID, and + the GlobalProtect agent icon flickered. +
+
+
GPC-23077
+
+
+ Fixed an issue where HIP reports were not sent to the GlobalProtect + gateway when transparent proxy is enabled, resulting in rules not + being matched. +
+
+
GPC-22777
+
+
+ Fixed an issue where GlobalProtect entered proxy mode after the + computer woke from sleep but failed to apply the configured proxy + settings, resulting in a lost proxy connection. +
+
diff --git a/reference/GlobalProtect/addressed/6.3.3-h2.html b/reference/GlobalProtect/addressed/6.3.3-h2.html new file mode 100644 index 0000000..b40f48a --- /dev/null +++ b/reference/GlobalProtect/addressed/6.3.3-h2.html @@ -0,0 +1,396 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
GPC-23654
+
+
+ Fixed an issue where the GlobalProtect client displays the error + message "The virtual adapter was not set up correctly due to a delay" + on Windows endpoints, preventing VPN connectivity until the system is + restarted. +
+
+
GPC-23604
+
+
+ Fixed an issue where GlobalProtect users were not automatically + prompted for authentication on public Wi-Fi networks with a captive + portal +
+
+
GPC-23558
+
+
+ Fixed an issue where GlobalProtect clients using SAML with Ping + Federate did not save the SAML token upon reboot or restart of the + pangps service, requiring users to re-authenticate even when the token + was not expired. This issue affected GlobalProtect client version + 6.3.3 when SAML authentication was configured in Prisma Access and not + in Cloud Identity Engine. +
+
+
GPC-23551
+
+
+ Fixed an issue where the virtual network adapter retained the static + IP address assigned by GlobalProtect even after the GlobalProtect + client disconnected. This caused DNS registration conflicts, making + workstations unreachable by hostname even after a reboot. +
+
+
GPC-23520
+
+
+ Fixed an issue where new GlobalProtect users were unable to connect to + the GlobalProtect app. The app got stuck in 'Connecting" stage and + stopped working when redirected to the embedded browser. +
+
+
GPC-23519
+
+
+ Fixed an issue where GlobalProtect HIP reports on MacBooks + intermittently failed with an "Invalid client IP" error, preventing + users from accessing resources over the GP tunnel. This issue occurred + after a system network change when GP attempted to send the HIP report + to an external gateway while the tunnel was disconnected. This issue + affected MacBooks running GP version 6.2.5. +
+
+
GPC-23496
+
+
+ Fixed an issue where the GlobalProtect app's Connect button did not + work as expected preventing users from connecting or changing + gateways. +
+
+
GPC-23440
+
+
+ Fixed an issue where Okta FastPass authentication did not work with + GlobalProtect 6.3.3 on macOS 15.5 Sequoia, where the Okta Verify app + did not open for the additional authentication prompt. +
+
+
GPC-23432
+
+
+ Fixed an issue where the GlobalProtect app version 6.3.3 + intermittently got stuck on the "finding best gateway" status +
+
+
GPC-23404
+
+
+ Fixed an issue where the Host Information Profile (HIP) check was + unable to accurately identify key details from third-party security + products. +
+
+
GPC-23294
+
+
+ Fixed an issue where GlobalProtect app intermittently disconnected on + macOS endpoints even with a stable network connection. This was due to + a timeout that was too short for the route system command. +
+
+
GPC-23263
+
+
+ Fixed an issue where after upgrading to GlobalProtect app version + 6.3.3, the app did not save the username in the embedded browser when + "save username" was enabled. +
+
+
GPC-23218
+
+
+ Fixed an issue where, when using the GlobalProtect app with an + embedded browser, interrupting or canceling the SAML authentication + prompt terminated the pre-logon tunnel, potentially allowing full + internet access even when enforcer was enabled for the user-logon + profile. With default browser, the pre-logon tunnel remained active + when the SAML authentication prompt was interrupted. +
+
+
GPC-23115
+
+
+ Fixed an issue where the hardware token authentication option was + intermittently unavailable while using the embedded GlobalProtect + browser on Windows machines. +
+
+
GPC-23088
+
+
+ Fixed an issue where portal login failed due to embedded browser not + popping up and GlobalProtect remains in connecting state +
+
+
GPC-23044
+
+
+ Fixed an issue where, when a machine was in Modern standby, the + GlobalProtect app repeatedly attempted to connect to gateways, even + when authentication failed due to SAML timeout. This resulted in + GlobalProtect connecting to non-optimal gateway +
+
+
GPC-22989
+
+
+ Fixed an issue where the GlobalProtect app intermittently stopped + sending HIP reports while connected to the gateway. +
+
+
GPC-22979
+
+
+ Fixed an issue where, after upgrading to GlobalProtect app version + 6.2.6, the PanGPA application got stuck in 'Connecting' state and then + got terminated unexpectedly. +
+
+
GPC-22887
+
+
+ Fixed an issue where GlobalProtect users experienced frequent + disconnections across various locations. +
+
+
GPC-22870
+
+
+ Fixed an issue where, when using domain-based split tunneling on + GlobalProtect clients, expired DNS TTL entries were not removed from + the Windows Filtering Platform filter driver. This resulted in + incorrect packet routing where traffic for domains not in the exclude + list, but resolving to the same IP address as excluded domains, was + routed via the physical interface instead of the tunnel. +
+
+
GPC-22804
+
+ Fixed an issue where the GlobalProtect app remained in a connected state + after a network disconnection. As a result, when the network connection + was restored, the GlobalProtect app did not recover, and traffic failed + to pass until a refresh connection was performed. +
+
GPC-22764
+
+
+ Fixed an issue where wa_3rd_party_host_xx.exe attempted to connect to + Microsoft’s update servers for information and the patch information + was not sent in the HIP report. This occured even though HIP + Exceptions for patch management were configured to exclude Windows + updates agent. +
+
+
GPC-22541
+
+
+ Fixed an issue on Windows 11 where the GlobalProtect app (PanGPA) + would stop working when the device was locked. The crash occurred when + an expired authentication triggered a persistent smartcard login + dialog during sleep, leading to excessive memory swapping and a + crypt32.dll failure. +
+
+
GPC-22365
+
+
+ Fixed an issue where users experienced intermittent issues browsing + webpages while connected to the GlobalProtect app. +
+
+
GPC-22033
+
+
+ Fixed an issue where GlobalProtect client version 6.3.1 experienced + DNS resolution failures for IPv4 addresses, specifically when + applications using the io.netty library attempted DNS lookups. +
+
+
GPC-22029
+
+
+ Fixed an issue where Apple software downloads took longer to complete + when using GlobalProtect with split tunneling enabled. +
+
+
GPC-21982
+
+
+ Fixed an issue in which IPv6 traffic bypassed the valid route in the + rerouting table and instead passed through the physical adapter when + the GlobalProtect app was installed on Windows devices. +
+
+
GPC-21961
+
+
+ Fixed an issue where, after upgrading to GlobalProtect version 6.2.5, + the app triggered authentication and opened multiple browser tabs when + the computer woke from sleep. +
+
diff --git a/reference/GlobalProtect/addressed/6.3.3-h3.html b/reference/GlobalProtect/addressed/6.3.3-h3.html new file mode 100644 index 0000000..dbf0b7c --- /dev/null +++ b/reference/GlobalProtect/addressed/6.3.3-h3.html @@ -0,0 +1,241 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
GPC-24113
+
+
+ Fixed an issue where, on Mac OS endpoints, the agent proxy was + attempting to download PAC files directly, bypassing the configured + proxy settings. This resulted in download failures when the corporate + network was configured to block direct traffic. +
+
+
GPC-23947
+
+
+ Fixed an issue where GlobalProtect agent-msg logs were not generated + on Panorama when a user disconnected from the GlobalProtect gateway. +
+
+
GPC-23839
+
+
+ Fixed an issue that caused the GlobalProtect 6.3.3 HIP report to fail + with the error Method: WAAPI_MID_GET_AGENT_STATE +
+
+
GPC-23760
+
+
+ GlobalProtect app version 6.3.3 using SAML with the embedded browser + loses cursor focus in the password field, requiring users to click in + the password field before entering their password. +
+
+
GPC-23753
+
+
+ Fixed an issue where the DNS registration script configured on + pre-vpn-connect did not run on the first GlobalProtect connection on + version 6.3.3. +
+
+
GPC-23752
+
+
+ Fixed an issue where the GlobalProtect app failed to authenticate to + the portal and gateway after a machine certificate was renewed by + Intune MDM. A reboot was required to restore the connection. +
+
+
GPC-23746
+
+
+ Fixed an issue where the GlobalProtect HIP check incorrectly detected + status for Symantec Endpoint Protection, which caused the device to + fail the +
+
HIP check.
+
+
GPC-23616
+
+
+ Fixed an issue where, when the GlobalProtect app was installed on + devices running macOS, the following error +
+
+ "TransparentProxy: openWithLocalEndpoint failed" occurred in + PanNExt.log when using an IPv6 address. +
+
+
GPC-23488
+
+
+ Fixed an issue where the HIP report intermittently detected MacOS + XProtect "Real Time Protection" status as disabled. +
+
+
GPC-23468
+
+
+ Fixed an issue where the GlobalProtect HIP check failed to detect the + correct version of Forticlient Antivirus, which caused the device to + fail the HIP check. +
+
+
GPC-23417
+
+
+ Fixed an issue where SAML authentication with Azure AD, using Cisco + Duo EAM, failed after upgrading to GlobalProtect version 6.2.8 +
+
+
GPC-23403
+
+
+ Fixed an issue where the GlobalProtect HIP report failed to detect the + status of SentinelOne, causing the device to fail the HIP check +
+
+
GPC-23361
+
+
+ Fixed an issue where the GlobalProtect HIP report did not detect the + Status for Zoho corporation - ManageEngine Patch Manager Plus Agent, + which caused the device to fail the HIP check. +
+
+
GPC-23283
+
+
+ Fixed an issue where GlobalProtect was unable to set [exclude/include] + 0.0.0.0/netmask routes on Mac endpoint +
+
+
GPC-23095
+
+
+ Fixed and issue where the GlobalProtect HIP report failed to detect + the Symantec DLP software, which caused the device to fail the HIP + check. +
+
+
GPC-22156
+
+
+ Fixed an issue where the GlobalProtect application displayed + unexpected characters on the user interface after installing the + GlobalProtect client on Windows 11 machines. This issue was observed + with GlobalProtect client versions 6.3.1-c383 and 6.2.6-838, where the + Lato font appeared to be the cause. +
+
+
GPC-21745
+
+
+ Fixed an issue where the GlobalProtect HIP check failed to detect + Workspace ONE status, which caused the device to fail the HIP check. +
+
diff --git a/reference/GlobalProtect/addressed/6.3.3-h4.html b/reference/GlobalProtect/addressed/6.3.3-h4.html new file mode 100644 index 0000000..a0e284e --- /dev/null +++ b/reference/GlobalProtect/addressed/6.3.3-h4.html @@ -0,0 +1,368 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
GPC-24332
+
+
+ Fixed an issue where users on trusted networks were incorrectly + receiving a captive portal detection message and being redirected to a + separate browser tab. This occurred because the GlobalProtect app was + not properly handling captive portal detection response. +
+
+
GPC-24330
+
+
+ Fixed an issue where GlobalProtect app got stuck in a connecting state + when using GlobalProtect version 6.2.8-h4. The issue was seen when + saml-logout and enforcer was enabled. +
+
+
GPC-24235
+
+
+ Fixed an issue where, after upgrading to GlobalProtect agent 6.2.8 on + macOS, users were unable to select a different portal. Clicking + "Change Portal" would initiate a reconnection attempt instead of + displaying the portal selection menu. +
+
+
GPC-24166
+
+
+ Fixed an issue where GlobalProtect agents in proxy-only mode would + intermittently get stuck in a connecting state after upgrading from + version 6.2.8 to 6.3.3-676. The agent would become stuck in the + "Discovering external network" phase, and restarting the GlobalProtect + process would temporarily resolve the issue. +
+
+
GPC-24086
+
+
+ Fixed an issue where, when Endpoint Traffic Policy Enforcement was + enabled with "No Direct Access to Local Network" on GlobalProtect, + Xcode running on macOS was unable to recognize iPhones connected via + USB-C. This issue occurred because traffic enforcement blocked + communication between Xcode and the iPhone. +
+
+
GPC-24050
+
+
+ Fixed an issue where GlobalProtect clients prompted a window to select + a certificate with the error "The parameter is incorrect" because the + client certificate request originated from a portal or gateway Access + Control Server (ACS) and was not required. +
+
+
GPC-24048
+
+
+ Fixed an issue where GlobalProtect apps installed on on Dell Vostro 15 + 3515 laptops were unable to connect to the GlobalProtect service with + the following error: "Could not connect to the GlobalProtect service. + If the issue persists, contact your administrator." +
+
+
GPC-24036
+
+
+ Fixed an issue where the HIP check did not correctly detect the status + of the ESET firewall on Windows hosts. +
+
+
GPC-23990
+
+
+ Fixed an issue where the captive portal opened in the embedded + browser, but when the user tried to connect to the internet, it + redirected to the default browser and was blocked. +
+
+
GPC-23913
+
+
+ Fixed an issue where the GlobalProtect app would become unresponsive + when system extensions and a PAC file were enabled simultaneously. +
+
+
GPC-23906
+
+
+ Fixed an issue where GlobalProtect app displayed a "No Network + Connectivity" error and failed to initiate a network connection, + preventing access to applications. +
+
+
GPC-23730
+
+
+ Fixed an issue where IPv6 traffic on Windows 11 24H2 did not work as + expected with GlobalProtect app. +
+
+
GPC-23689
+
+
+ Fixed an issue where the GlobalProtect app running on macOS devices + would stuck in a connecting loop indefinitely if the user did not + complete authentication, requiring manual cancellation of the + connection. +
+
+
GPC-23650
+
+
+ Fixed an issue where the GlobalProtect enforcer blocked network + traffic on Windows endpoints even after the tunnel was successfully + connected. +
+
+
GPC-23549
+
+
+ Fixed an issue where the GlobalProtect (GP) agent briefly disconnected + when a user logged on to Windows, even when the 'Pre-Logon Tunnel + Rename Timeout (sec) (Windows Only)' setting was set to -1, with the + error "server cert verification failed". +
+
+
GPC-23546
+
+
+ Fixed an issue where the SAML authentication window in the + GlobalProtect client on macOS devices running version 6.2.6 or higher + would sometimes display an incomplete or blank screen after the device + woke up from sleep mode. This issue affects devices using the embedded + browser for SAML authentication and with GlobalProtect set to + always-on mode with enforcer enabled. +
+
+
GPC-23525
+
+
+ Fixed an issue where on macOS Ventura and Sequoia, manually changing + the portal address using the GlobalProtect app UI would fail and + revert back to the last connected portal. This issue occurred even + when "Allow User to Change Portal Address" was enabled in the agent + configuration. +
+
+
GPC-23466
+
+
+ Fixed an issue where, when the GlobalProtect app was installed on + devices running Windows OS and macOS, the Captive Portal detection + message briefly appeared and disappeared when the Captive Portal + exception timeout was set to 0. +
+
+
GPC-23336
+
+
+ Fixed an issue where agent disable logs were not being logged to + Gateway System Logs on the firewall. The GlobalProtect agent reset the + authentication code, which falsely indicated that the gateway was not + fully authenticated, and the agent did not send the message. +
+
+
GPC-22683
+
+
+ Fixed an issue where tool tips were not available for the Add, Edit, + and Delete buttons on the GlobalProtect application's settings page on + Windows devices. +
+
+
GPC-22572
+
+
+ Fixed an issue where the hamburger menu button was disabled in the + Refresh connection screen, which made it inaccessible when using a + keyboard. +
+
+
GPC-22522
+
+
+ Fixed an issue where, after upgrading the GlobalProtect app, external + users on Windows 11 computers with multiple Azure Entra accounts were + unable to authenticate to the portal using SAML with Azure Entra as + the Identity Provider (IdP). The new WebView2 embedded browser + automatically used the user's default Windows credential for Single + Sign-On (SSO), preventing them from selecting the correct account for + authentication. +
+
+ To resolve this issue a new registry key 'entra-sso' has been + introduced. You can add the registry key using two methods and set it + to no to disable SSO. +
+
+ 1. For pre-deployment, use 'msiexec.exe /i globalprotect64.msi + ENTRASSO="no" +
+
or
+
+ 2. Add key "entra-sso" and set it to "no" under + HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto Networks\GlobalProtect\Settings. + If the "entra-sso" key does not exist under this path, the + GlobalProtect agent's default behavior is to 'Allow' Entra SSO. +
+
+
GPC-22148
+
+
+ (GP App 6.3.1 enabled with FIPS-CC only) Fixed an issue where the OCSP + request did not send the Host header, causing the X509v3 certificate + validation to fail when accessing the OCSP or CRL. +
+
+
GPC-22021
+
+
+ Fixed an issue where, when using conditional-connect on macOS Sequoia + with GlobalProtect client version 6.2.6, manually switching gateways + caused the client to display a "Not connected" status for + approximately 10 seconds while establishing a connection to the second + gateway. +
+
diff --git a/reference/GlobalProtect/addressed/6.3.3-h6.html b/reference/GlobalProtect/addressed/6.3.3-h6.html new file mode 100644 index 0000000..d3356bc --- /dev/null +++ b/reference/GlobalProtect/addressed/6.3.3-h6.html @@ -0,0 +1,170 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
GPC-24683
+
+
+ Fixed an issue where Host Information Profile (HIP) matching failed + for Anti-Malware criteria on macOS endpoints due to GlobalProtect + failing to detect the virus definition version for Kaspersky + Anti-Virus. +
+
+
GPC-24579
+
+
+ Fixed an issue where GlobalProtect clients were unable to authenticate + to internal gateways when multiple internal gateways were configured. + This issue occured because the GlobalProtect client did not properly + reset the SAML login flag, causing subsequent SAML pre-login requests + to be ignored. +
+
+
GPC-24548
+
+
+ Fixed an issue where macOS GlobalProtect (GP) clients connected to an + internal gateway with the enforcer enabled were unable to access the + internet via a proxy. This occurred because the tunnel_connected flag + remained set to 1 after the gateway disconnected, even though the + gateway configuration was cleared. +
+
+
GPC-24261
+
+
+ Fixed an issue where GlobalProtect app running on macOS Sequoia 15.6.1 + running GP 6.2.8 -c263 that receive both IPv4 and IPv6 addresses were + not receiving packets back from the Network Load Balancer (NLB) + instances. +
+
+
GPC-24221
+
+
+ Fixed an issue where the GlobalProtect app experienced a continuous + connect-disconnect loop when used on flights. This issue occurred + because rapid network wake-ups left network interfaces in an + inconsistent state, causing GlobalProtect to attempt tunnel + establishment on an unstable network foundation. +
+
+
GPC-24103
+
+
+ Fixed an issue where the GlobalProtect app running on macOS allowed + users to modify or add a new portal address after each device reboot, + even when the "Allow users to change portal" setting was configured as + "No" in the GlobalProtect app. +
+
+
GPC-24037
+
+
+ Fixed an issue where GlobalProtect app prompted users to log in with + SAML through the embedded browser even when the GlobalProtect app was + already connected. This occurred when users logged off and then back + onto their Cloud PC (Windows Azure PC), and closing the prompt + disconnected and reconnected the VPN session. +
+
+
GPC-23929
+
+
+ Fixed an issue where, when GlobalProtect app was configured with + Enforcer, users could bypass Enforcer restrictions by repeatedly + canceling authentication prompts after logging into Windows. This + occurred because the cached portal configuration, which contains + Enforcer settings, was not loaded when a pre-logon tunnel failed to + establish due to a quick user login. This fix ensures that the cached + portal configuration is loaded as soon as PanGPA starts and PanGPS + learns the username, preventing unrestricted access in scenarios where + Enforcer is intended to lockdown the endpoint. +
+
+
GPC-23394
+
+
+ Fixed an issue where GlobalProtect app version 6.2.8-183. running on + macOS 15.5 was unable to accurately report the disk encryption status + of FileVault, resulting in an "unknown" status in HIP checks. +
+
+
GPC-22797
+
+
+ Fixed an issue where the MAC address generated for the DHCP feature + changed on every GlobalProtect client restart. The MAC address should + remain static after initial generation to allow static IP assignment + on the DHCP server side for a specific GlobalProtect client. + Additionally, the generated MAC address was not always marked as + unicast and locally administered. +
+
diff --git a/reference/GlobalProtect/addressed/6.3.3-h7.html b/reference/GlobalProtect/addressed/6.3.3-h7.html new file mode 100644 index 0000000..16a8ecd --- /dev/null +++ b/reference/GlobalProtect/addressed/6.3.3-h7.html @@ -0,0 +1,368 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
GPC-25370
+
+
+ Fixed an issue where GlobalProtect clients (versions + 6.3.3-h2-6.3.3-h4) intermittently failed to honor enforcer bypass + rules for FQDNs and IP addresses after the client machine woke up from + sleep. This resulted in connections to bypassed URLs being blocked, + including GlobalProtect's own SAML authentication requests, and + required a manual restart of the PanGPS service to restore + connectivity. +
+
+
GPC-25172
+
+
+ Fixed an issue where, on macOS GlobalProtect clients, exclude routes + were not properly removed from the system routing table after a PanGPS + (GlobalProtect client) crash. This occurred because the routes + remained in the macOS kernel, and upon reconnection, the client's + `checkExistingExRts()` function only validated the destination and + netmask, not the gateway. As a result, these stale routes, pointing to + an old or unreachable gateway, were marked as existing and skipped + during the reconnection process, leading to a corrupted routing state + and preventing correct route injection, especially after a network + change. +
+
+
GPC-25063
+
+
+ Fixed an issue where, in the GlobalProtect app on macOS, keyboard + focus did not automatically move to the required "Enter portal + Address" field when a user attempted to add a new portal without + entering an address. This accessibility issue impacted + keyboard-dependent users. +
+
+
GPC-24961
+
+
+ Fixed an issue where the firewall, when configured to obtain IP + addresses from a DHCP server for GlobalProtect clients, sent a MAC + address of '00' to the DHCP server specifically for MacOS 26 (Tahoe) + clients running GlobalProtect App versions 6.2 or 6.3, which resulted + in IP address collisions on the DHCP server. +
+
+
GPC-24897
+
+
+ Fixed an issue where the GlobalProtect Connect Before Logon tunnel + disconnected for new users on their first logon. This issue affected + GP client versions 6.2.8-hx and 6.3.3-hx. +
+
+
GPC-24892
+
+
+ Fixed an issue where the GlobalProtect Portal welcome page, when + displayed in German, incorrectly presented a button labeled 'Genau' + instead of 'Zustimmen' (Accept). +
+
+
GPC-24880
+
+
+ Fixed an issue where GlobalProtect clients, after upgrading to + versions 6.2.8-263, 6.3.3-h2, or 6.3.3-h3, would get stuck in a + connecting loop and fail to connect to the portal or gateways. This + occurred because the GlobalProtect app crashed when attempting to + delete previous SAML user data, specifically when the user data folder + path contained non-ANSI characters that the app could not convert to a + UTF-16 path. +
+
+
GPC-24842
+
+
+ (macOS only) GlobalProtect crashed when you clicked + Change Portal on setups that + included two or more portal entries and had a preferred gateway + marked. +
+
+
GPC-24835
+
+
+ Fixed an issue where split tunneling domain exclusions on + GlobalProtect App version 6.3.3-C711 for Windows clients failed to + function as expected after the application disconnected and + reconnected. This resulted in traffic for domains configured for + exclusion being incorrectly routed through the VPN tunnel instead of + directly, because the TTLMap for split tunneling domain rules was not + properly cleared when the GlobalProtect App re-established its + connection. +
+
+
GPC-24804
+
+
+ Fixed an issue where GlobalProtect clients running version 6.3.3-711 + would randomly get stuck in a 'connecting' status, preventing them + from establishing a successful VPN connection. +
+
+
GPC-24796
+
+
+ Fixed an issue where GlobalProtect HIP reports on macOS devices + intermittently failed with an "Invalid client IP" error. This occurred + on GlobalProtect client version 6.2.8-h4 (c317) due to a race + condition where the HIP report thread sent the report during the VPN + disconnect transition, causing the client to use a stale tunnel IP + address instead of the physical IP address. +
+
+
GPC-24755
+
+
+ Fixed an issue where the GlobalProtect client on Windows machines + truncated the Proxy Auto-Configuration file URL (autoConfigURL) at 104 + characters when configured through the GlobalProtect Portal, + preventing the full URL (up to 256 characters) from being correctly + set in the Windows registry due to an insufficient internal buffer + size. +
+
+
GPC-24515
+
+
+ Fixed an issue where GlobalProtect clients on macOS devices, + specifically version 6.3.3-h2, were unable to resolve internal IPv6 + domains when split tunneling was enabled and the operating system + lacked native IPv6 connectivity. This occurred because the client's + logic, which was designed to apply IPv6 configuration only when the OS + already had native IPv6 connectivity, prevented the GlobalProtect + tunnel from properly handling IPv6 traffic, resulting in "Err name not + resolved" errors for internal FQDNs. +
+
+
GPC-24242
+
+
+ Fixed an issue where GlobalProtect portal authentication failed for + some macOS users when attempting to use saved credentials. This issue, + observed on GlobalProtect client versions 6.2.8 and 6.3.3, resulted in + an immediate authentication failure on the client and firewall logs + indicating an invalid username or password, even though the + credentials were valid for other macOS clients. +
+
+
GPC-24216
+
+
+ Fixed an issue where the Host Information Profile (HIP) banner was not + displayed on Windows 11 client machines running GlobalProtect client + versions 6.2.8-h7 and 6.3.3. This occurred due to a timing or race + condition where the GlobalProtect client (PanGPA) received an outdated + status, preventing the visual display of HIP match or not-match + notifications, even though the messages were recorded in the client + logs. +
+
+
GPC-23963
+
+
+ Fixed an issue where GlobalProtect Client version 6.2.8 running in + Windows 365 environments, would experience PanGPA getting stuck during + the tunnel rename process. This prevented successful gateway + authentication and registration after users closed and re-opened their + Windows 365 session, leading to a pop-up message prompting users to + re-authenticate. +
+
+
GPC-23787
+
+
+ Fixed an issue where GlobalProtect clients on macOS devices, after + upgrading to version 6.2.8-h2, were unable to connect to the + authentication server. This occurred because incorrect logic in the + GlobalProtect Agent code prevented the Webview Process ID from syncing + with the Network Extension process, causing the Network Extension to + block SAML authentication traffic, resulting in a "Could not connect + to the authentication server" error and a blank embedded browser + during SAML authentication. +
+
+
GPC-23723
+
+
+ Fixed an issue where GlobalProtect clients running version 6.2.8-h1 + (6.2.8-c223) experienced intermittent connection failures and + disconnections, with the client agent getting stuck in a 'connecting' + state even when backend logs indicated a successful connection. This + occurred because, when conditional connect mode was enabled, the + client attempted to impersonate a user and write On-Demand settings to + the user's registry hive (HKEY_CURRENT_USER) during pre-logon. As no + user was logged in at that stage, user impersonation failed, leading + to incorrect registry access or failed registry operations, which + caused service instability or misconfiguration. +
+
+
GPC-23090
+
+
+ Fixed an issue where the GlobalProtect app experienced connectivity + issues after the host computer resumed from sleep mode due to a + missing self-pointed route. This issue resulted in a delay of 5 to 10 + minutes for the GlobalProtect connection to get stabilized. +
+
+
GPC-21852
+
+
+ Fixed an issue where the GlobalProtect Agent incorrectly displayed + "N/A" in the "Last Scan Time" field for the Trend Micro Deep Security + Agent within the Host Information Profile (HIP) report. +
+
+
GPC-20621
+
+
+ Fixed an issue where users from overseas locations were disconnected + from GlobalProtect due to the HIP report not being sent with manual + gateway selection. +
+
+
GPC-18976
+
+
+ Fixed an issue where GlobalProtect client 6.1.1-5 would select the + incorrect Windows tile by default after locking the screen when using + Single Sign-On for Smart Card PIN (Windows) with the Yubikey Smart + Card Minidriver. When multiple smart cards were present, GlobalProtect + incorrectly selected the last enumerated card instead of the currently + active one. +
+
diff --git a/reference/GlobalProtect/addressed/6.3.3-h8.html b/reference/GlobalProtect/addressed/6.3.3-h8.html new file mode 100644 index 0000000..5a56787 --- /dev/null +++ b/reference/GlobalProtect/addressed/6.3.3-h8.html @@ -0,0 +1,99 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
GPC-25300
+
+
+ Fixed an issue where GlobalProtect clients experienced frequent + disconnections from GlobalProtect gateways. After being disconnected, + users were often unable to reconnect for extended periods, and + connection attempts to designated gateways, including those manually + selected or identified as 'Best Available', would incorrectly redirect + to other gateways. +
+
+
GPC-25222
+
+
+ Fixed an issue where GlobalProtect clients failed to detect captive + portals on public Wi-Fi networks, even when the captive portal + responded with an HTTP 302 Redirect. This occurred because the + GlobalProtect agent expected the HTTP response to be terminated by + `\r\n\r\n` as per RFC, but some captive portals did not adhere to + this, causing the agent to incorrectly report that no data was + received from the captive portal server and thus fail to detect the + portal. +
+
+
GPC-25173
+
+
+ Fixed an issue where GlobalProtect clients on macOS devices, when + configured in tunnel-proxy mode, intermittently displayed an "A valid + PAC file is required" notification after waking up from modern + standby, particularly when the PAC file contained a placeholder + statement instead of the actual EP-FQDN. +
+
+
GPC-24992
+
+
+ Fixed an issue where GlobalProtect users experienced significant login + delays after a system reboot or shutdown, such as after a weekend. + This delay was caused by a shared memory issue that disrupted + communication between the GlobalProtect agent and GlobalProtect + service. +
+
+
GPC-23301
+
+
+ Fixed an issue where, when the GlobalProtect app 6.2.7 and later, was + installed on Windows 10 devices, the app deleted the predefined proxy + PAC file configuration whenever the app got disconnected regardless of + whether the disconnection was initiated manually or occurred + automatically due to a timeout. +
+
diff --git a/reference/GlobalProtect/addressed/6.3.3-h9.html b/reference/GlobalProtect/addressed/6.3.3-h9.html new file mode 100644 index 0000000..61c89df --- /dev/null +++ b/reference/GlobalProtect/addressed/6.3.3-h9.html @@ -0,0 +1,88 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
GPC-25889
+
+
+ Fixed an issue where GlobalProtect clients, particularly when + connected to Prisma Access, were unable to extend their VPN session. + When the 'Extend Session' or 'Refresh connection' option was selected, + the client would disconnect and immediately reconnect, but the session + countdown timer would not reset. This was due to a race condition that + caused the `GetCurrentGateway()` function to return a null value + during the session extension thread, preventing the session from being + properly prolonged. +
+
+
GPC-25828
+
+
+ Fixed an issue where on macOS devices running GlobalProtect Agent + version 6.3.3-h6, the GlobalProtect Agent was unable to communicate + with the GlobalProtect Service, resulting in the error "Could not + connect to the GlobalProtect service." This occurred because when + prelogon was disabled, the PanGPS LaunchDaemon would exit prematurely + after boot, and the subsequent LaunchAgent failed to properly restart + PanGPS as a user-session agent, leaving no service listening on port + 4767 for PanGPA to connect to. +
+
+
GPC-25702
+
+
+ Fixed an issue where the GlobalProtect service (PanGPS) failed to + start on macOS 26.3.1 after a system upgrade, preventing GlobalProtect + client version 6.2.8-814 from connecting. This was due to a regression + where `SetCurrentGateway` was set to `NULL` during `disconnectVPN` + operations. +
+
+
GPC-24033
+
+
+ Fixed an issue where GlobalProtect Client 6.3.3-676 on Windows + endpoints would hang or freeze. This occurred when the client + connected to a GlobalProtect portal or gateway that initiated a client + certificate request, even if the certificate was not strictly required + for authentication. The client's certificate selection dialog would + appear briefly and then disappear, causing the GlobalProtect client + application to become unresponsive. +
+
diff --git a/reference/GlobalProtect/addressed/6.3.3.html b/reference/GlobalProtect/addressed/6.3.3.html new file mode 100644 index 0000000..c992620 --- /dev/null +++ b/reference/GlobalProtect/addressed/6.3.3.html @@ -0,0 +1,1138 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
GPC-23046
+
+
+ Fixed an issue where users experienced connectivity problems when + GlobalProtect was used in a WiFi network with captive portal. +
+
+
GPC-23010
+
+
+ Fixed an issue where HIP checks incorrectly detected the macOS + built-in firewall as disabled, causing HIP checks to fail. +
+
+
GPC-22847
+
+
+ Fixed an issue where GlobalProtect did not detect Qualys for patch + management. +
+
+
GPC-22771
+
+
+ Fixed an issue where the Host Information Profile (HIP) check failed + to detect the installed version of Norton anti-malware. +
+
+
GPC-22763
+
+
+ Fixed an issue where GlobalProtect prompted for credentials instead of + using authoverride cookie when authenticating to the best available + gateway. +
+
+
GPC-22740
+
+
+ Fixed an issue where macOS computers displayed both the new and old + versions of the GlobalProtect welcome page. +
+
+
GPC-22688
+
+
+ Fixed an issue for proxy-only mode where customers were unable to + access websites when the computer woke up from sleep +
+
+
GPC-22638
+
+
+ Fixed an issue where Global Protect HIP did not detect the drive state + when using Trellix Drive Encryption 8.0. +
+
+
GPC-22616
+
+
+ Fixed an issue where the Digital Guardian Agent was not detected by + the GlobalProtect client, causing DLP HIP checks to fail. +
+
+
GPC-22610
+
+
+ Fixed an issue where, after an upgrade, GlobalProtect restarted and + failed to connect to the portal +
+
+
GPC-22589
+
+
+ Fixed an issue where the Report an Issue functionality did not send + the troubleshooting log to the administrator’s Strata Logging Service + instance. +
+
+
GPC-22547
+
+
+ Fixed an issue where the installed OWSPAT version was not supported + with the CrowdStrike Falcon version, resulting in HIP object match + failures. +
+
+
GPC-22544
+
+
+ Fixed an issue where the GlobalProtect client did not send the HIP + report causing user-IP mapping to be cleared and resulting in traffic + drop. +
+
+
GPC-22542
+
+
+ Fixed an issue where the embedded browser shown as part of SAML + authentication was blank. +
+
+
GPC-22487
+
+
+ Fixed an issue where Norton 360 was not compatible with GlobalProtect + causing the device to fail the HIP check. +
+
+
GPC-22450
+
+
+ Fixed an issue where users were unable to use smartcard authentication + with embedded browser. +
+
+
GPC-22448
+
+
+ Fixed an issue where the GlobalProtect client could crash after it was + connected to a gateway. +
+
+
GPC-22443
+
+
+ Fixed an issue where the GlobalProtect agent showed as connected even + when the virtual adapter was down. +
+
+
GPC-22406
+
+
+ Fixed an issue where the GlobalProtect credential provider was not set + as the default after installation and reboot. +
+
+
GPC-22381
+
+
+ Fixed an issue where the GlobalProtect HIP report did not include + Cortex XDR installed on the client machine. +
+
+
GPC-22353
+
+
+ Fixed an issue where a comment was not visible in the GlobalProtect + logs when GlobalProtect was disabled with-comment. +
+
+
GPC-22297
+
+
+ Fixed an issue where the Customer was getting "A valid client + certificate is required for authentication" even though they had a + valid client certificate installed. +
+
+
GPC-22295
+
+
+ Fixed an issue where GlobalProtect client for macOS could not navigate + away from a hyperlink on the welcome page when the welcome page was + opened in the embedded browser. +
+
+
GPC-22264
+
+
+ Fixed an issue where the GlobalProtect HIP report did not detect the + last full scan time for Avast antivirus software. +
+
+
GPC-22245
+
+
+ Fixed an issue where transparent upgrade from GlobalProtect version + 6.2.4 or 6.2.5 to version 6.2.6 failed on some Windows endpoints with + error 1618. +
+
+
GPC-22237
+
+
+ Fixed an issue where GlobalProtect shut down unexpectedly on Windows + 11 devices running multiple versions of GlobalProtect 6.3. The issue + was caused by the firewall sending invalid IPv6 packets to + GlobalProtect, which did not have a validation method before + processing. +
+
+
GPC-22235
+
+
+ Fixed an issue where users were unable to connect to the app after the + system woke up from sleep mode. +
+
+
GPC-22233
+
+
+ Fixed an issue where the users were unable to connect the + GlobalProtect app after performing the resolution of CVE-2024-5921. + The app displayed the following error, “The certificate CN name + mismatch.” +
+
+
GPC-22155
+
+
+ Fixed an issue where the GlobalProtect app got stuck in the Connecting + stage when the app was upgraded to 6.3.2-525 version. Users had to + reboot the system to resolve this issue. +
+
+
GPC-22126
+
+
+ Fixed an issue where GlobalProtect version 6.2.6-838 was stuck + intermittently during the connection process. +
+
+
GPC-22123
+
+
+ Fixed an issue where the GlobalProtect app got stuck and users faced + connection issues after the system woke up from sleep mode even though + the internet connection was stable. +
+
+
GPC-22092
+
+
+ Fixed an issue where the GlobalProtect app failed to validate the + server certificate when the portal or gateway sent only the leaf + certificate. +
+
+
GPC-22061
+
+
+ Fixed an issue where the GlobalProtect client displayed an error when + using an ECDSA certificate with explicit EC parameters in FIPS mode. +
+
+
GPC-22054
+
+
+ Fixed an issue where after GlobalProtect was upgraded from version + 6.3.0 to 6.3.1, users were stuck in connecting state. +
+
+
GPC-22046
+
+
+ Fixed an issue where when the GlobalProtect app was installed on + devices running macOS and the app version was upgraded to 6.2.5, end + users were unable to connect the app. The app got stuck in the + Connecting state and displayed the following message, “You are + redirected to an embedded browser to authenticate and connect.” +
+
+
GPC-22043
+
+
+ Fixed an issue where Okta push notification shows incorrect Windows + OS, when Okta SAML authentication is enabled in GlobalProtect. +
+
+
GPC-22028
+
+
+ Fixed an issue where the disconnect reason for macOS users was getting + cached. +
+
+
GPC-21988
+
+
+ Fixed an issue where the GlobalProtect Client displayed a download + prompt or was updated even with an "upgrade disallow" configuration. +
+
+
GPC-21960
+
+
+ Fixed an issue where the HIP check failed to detect the Norton + anti-malware version 24.11.9615.0. +
+
+
GPC-21955
+
+
+ Fixed an issue where the HIP notification pop-up on macOS looked + different from that on Windows. +
+
+
GPC-21950
+
+
+ Fixed an issue where the GlobalProtect connection on MacOS Sequoia 15+ + was unstable. +
+
+
GPC-21857
+
+
+ Fixed an issue where, when the GlobalProtect debug build was installed + on the device, the device was immediately locked and users were unable + to enter their login credentials in the Window Login screen. Users had + to reboot their system to resolve this issue. +
+
+
GPC-21775
+
+
+ Fixed an issue where GlobalProtect users on macOS were disconnected + immediately after sending the HIP report. +
+
+
GPC-21755
+
+
+ Fixed an issue where GlobalProtect users with enforcer enabled were + able to access applications that were not in the enforcer exception + list. +
+
+
GPC-21743
+
+
+ Fixed an issue where a user was randomly prompted with a \"Login + Successful\" message when connecting to GlobalProtect (GP), even + though GP was not connected. +
+
+
GPC-21737
+
+
+ Fixed an issue where the SAML redirection page opened up on end user +
+
+ computers even though they did not have internet connectivity. +
+
+
GPC-21721
+
+
+ Fixed an issue, where the GlobalProtect app got stuck in Connecting + status when the device woke up from sleep mode. +
+
+
GPC-21695
+
+
+ Fixed an issue where the GlobalProtect embedded browser could not + utilize a new PIV certificate for SAML authentication if multiple + certificates were available. +
+
+
GPC-21677
+
+
+ Fixed an issue where GlobalProtect configured for Always-on Pre-logon + may not display the captive portal page if there is a delay with + network access or Internet connectivity. +
+
+
GPC-21653
+
+
+ Fixed an issue where the GlobalProtect virtual adapter was not set up + correctly. +
+
+
GPC-21639
+
+
+ Fixed an issue where the GlobalProtect macOS client did not extend the + session even though the user clicked the Extend Session button. +
+
+
GPC-21636
+
+
+ Fixed an issue where the users were unable to login Windows 11 using + the User Principal Name (UPN) when GPCP was selected with + GlobalProtect app version 6.2.4 and 'Interactive logon: Don't display + last signed-in' was enabled in their Entra ID - group policy. +
+
+
GPC-21627
+
+
+ Fixed an issue where the Report an Issue feature failed to work for a + specific user whose username contained Japanese character. +
+
+
GPC-21615
+
+
+ Fixed an issue where the GlobalProtect agent + (wa_3rd_party_host_64.exe) modified the __PSLockDownPolicy registry + key from 4 (secure language mode) to 0 (full language mode) after a + reboot. +
+
+
GPC-21583
+
+
+ Fixed an issue where the change password message was truncated in the + GlobalProtect agent UI. +
+
+
GPC-21527
+
+
+ Fixed an issue where the firewall did not exclude the APIPA + (169.254.0.0/16) range from GlobalProtect when the Endpoint Traffic + Policy Enforcement feature was enabled with the exclude option. As a + result, traffic to the APIPA range was sent over GlobalProtect instead + of the local interface. +
+
+
GPC-21482
+
+
+ Fixed an issue where some users were unable to connect to portal + access, the PANGPA did not work as expected and multiple GlobalProtect + instances were opened. +
+
+
GPC-21468
+
+
+ Fixed an issue where HIP reports were not sent during modern standby + mode. +
+
+
GPC-21467
+
+
+ Fixed an issue where the Transparent Upgrade with Proxy only mode did + not work as expected and no tunnel was established with the gateway. +
+
+
GPC-21454
+
+
+ Fixed an issue where GlobalProtect Connect Before Logon connection + allowed GlobalProtect to be disconnected on first time login. +
+
+
GPC-21453
+
+
+ Fixed an issue where the GlobalProtect app window displayed "static" + instead of the connected gateway name. +
+
+
GPC-21437
+
+
+ Fixed an issue where users were unable to connect to Prisma Access via + GlobalProtect. +
+
+
GPC-21413
+
+
+ Fixed an issue where the GlobalProtect Credential Provider did not + reset focus on the password field when the user entered the wrong + password +
+
+
GPC-21375
+
+
+ Fixed an issue where username from SAML assertion did not match the + config selection criteria because the Windows SSO username was used + instead of the SAML username. +
+
+
GPC-21355
+
+
+ Fixed an issue GlobalProtect pre-logon was stuck in connecting state + after a reboot. +
+
+
GPC-21284
+
+
+ Fixed an issue where the GlobalProtect gateway did not receive the HIP + reports from the user correctly due to which the end users were unable + to access the resources even when the sessions were active. +
+
+
GPC-21267
+
+
+ Fixed an issue where, when the user installed the GlobalProtectARM + installer from the Customer Support Portal (CSP) and the user opened + GlobalProtect using the Start menu, the icon file (PanGPA.ico) was + opened instead of the executable (PanGPA.exe) file. +
+
+
GPC-21240
+
+
+ Fixed an issue where, when the GlobalProtect app was installed on + devices running macOS Sonoma 14.5, the app used the old FQDN names and + got stuck in the "Connecting" status instead of prompting the user to + enter the portal FQDN name. +
+
+
GPC-21161
+
+
+ Fixed an issue where the notifications for the feature "Login Lifetime + Expiration" and "Notify Before Lifetime Expires" were not displayed on + the GlobalProtect client running version 6.2.4. +
+
+
GPC-21131
+
+
+ Fixed an issue where the users were unable to access the Advanced + Logging Settings screen of the GlobalProtect app using the ctrl + tab + key combination on the keyboard. The screen reader did not announce + the Keyboard options correctly. +
+
+
GPC-21090
+
+
+ Fixed an issue where GlobalProtect only displayed ADEM information for + approximately 120 users even though more than 600 ADEM users were + connected to GlobalProtect. +
+
+
GPC-21024
+
+
+ Fixed an issue where a HIP notification configured as "pop-up-message" + for pre-logon does not show up. The pop up window is blank. +
+
+
GPC-21005
+
+
+ Fixed an issue where after submitting the SAML credentials, a blank + screen was displayed and GlobalProtect got stuck in that stage. +
+
+
GPC-20992
+
+
+ Fixed an issue where the Teams application does not connect to the + server for macOS. +
+
+
GPC-20991
+
+
+ Fixed an issue where the Windows Registry value + (ext-key-usage-oid-for-client-cert) on + \HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto Networks\GlobalProtect\Settings + was deleted during the upgrade from GlobalProtect version 6.2.2 to + version 6.2.4. This makes the GlobalProtect client unable to select a + certificate by itself. +
+
+
GPC-20977
+
+
+ Fixed an issue where conditional connect was not set and GlobalProtect + connected to an external gateway on the internal network instead of + connecting to an internal gateway on the internal network. +
+
+
GPC-20813
+
+
+ Fixed an issue where GlobalProtect 6.3.0 on macOS was blocking + multicast traffic on the local network interface. +
+
+
GPC-20783
+
+
+ Fixed an issue where, when the embedded browser was used, the password + field did not work as expected when users typed their passwords in the + field. Users had to click inside the password field before entering + their password. +
+
+
GPC-20736
+
+
+ Fixed an issue where users are being logged out from GlobalProtect + when the device wakes up from modern standby and network discovery + happens. +
+
+
GPC-20632
+
+
+ Fixed an issue where GLobalProtect was stuck in connecting mode after + the customer manually selected a gateway that hit the maximum user + limit. This was a multi-gateway environment with SAML/CAS + authentication method. +
+
+
GPC-20550
+
+
+ Fixed an issue where Zoom and Outlook apps intermittently stop + connecting on macOS with an error "You are unable to connect to Zoom. + Please check your network connection and try again" when the apps are + excluded under both domains and applications +
+
+
GPC-20514
+
+
+ Fixed an issue where the remote users using GlobalProtect with Connect + Before Logon (CBL) were unable to reset their password when using the + app with an embedded browser. +
+
+
GPC-20461
+
+
+ Fixed an issue where the GlobalProtect agent version 6.1.4 would only + establish a connection via SSL to an IPv6 gateway. The IPSec tunnel + was not established or connected. +
+
+
GPC-20416
+
+
+ Fixed an issue where there is no network discovery once the laptop + came out of standby. +
+
+
GPC-20386
+
+
+ Fixed an issue where Windows users experienced a blue screen of death + issue due to a race condition between Microsoft IPSEC extension and + GlobalProtect. The issue happens only when IKE extensions are enabled + via IPSEC GPO on the endpoint along with GlobalProtect. +
+
+
GPC-20292
+
+
+ Fixed an issue where the Azure VDI RDP connection disconnects when + using enforcer. +
+
+
GPC-20168
+
+
+ Fixed an issue where it was possible to do a privilege escalation + and\or login bypass when using a 3rd party credential provider with + GlobalProtect +
+
+
GPC-18106
+
+
+ Fixed an issue where the GlobalProtect app intermittently did not send + the HIP report to the Prisma Access gateway due to a timeout issue. +
+