Add GP-6.3.3 backcatalog reference files

This commit is contained in:
2026-05-21 08:17:21 -05:00
parent 5606966180
commit 8489eab658
9 changed files with 2991 additions and 0 deletions
@@ -0,0 +1,123 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row">
<th class="entry">
<div class="p">Issue ID</div>
</th>
<th class="entry">
<div class="p">Description</div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23277</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect macOS client intermittently
experienced connection timeouts while browsing the internet in proxy
mode (when disconnected from the VPN tunnel). Ping operations were
successful, but website access through a browser was slow or failed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23237</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect macOS client restarted on
opening a zoom session in transparent proxy mode.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23215</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the traffic stopped passing through the
GlobalProtect app on macOS devices after upgrading to GP 6.2.8 and
when the computer screen was locked.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23161</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app stopped working after a
session change.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23139</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after a disconnection event, the GlobalProtect
agent could not connect to either the transparent proxy or the IPsec
tunnel until the client device was rebooted.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23117</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where after installing GlobalProtect on macOS devices,
the host ID displayed the device's MAC address instead of the UID, and
the GlobalProtect agent icon flickered.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23077</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where HIP reports were not sent to the GlobalProtect
gateway when transparent proxy is enabled, resulting in rules not
being matched.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-22777</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect entered proxy mode after the
computer woke from sleep but failed to apply the configured proxy
settings, resulting in a lost proxy connection.
</div>
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,396 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row">
<th class="entry">
<div class="p">Issue ID</div>
</th>
<th class="entry">
<div class="p">Description</div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23654</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect client displays the error
message "The virtual adapter was not set up correctly due to a delay"
on Windows endpoints, preventing VPN connectivity until the system is
restarted.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23604</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect users were not automatically
prompted for authentication on public Wi-Fi networks with a captive
portal
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23558</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect clients using SAML with Ping
Federate did not save the SAML token upon reboot or restart of the
pangps service, requiring users to re-authenticate even when the token
was not expired. This issue affected GlobalProtect client version
6.3.3 when SAML authentication was configured in Prisma Access and not
in Cloud Identity Engine.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23551</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the virtual network adapter retained the static
IP address assigned by GlobalProtect even after the GlobalProtect
client disconnected. This caused DNS registration conflicts, making
workstations unreachable by hostname even after a reboot.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23520</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where new GlobalProtect users were unable to connect to
the GlobalProtect app. The app got stuck in 'Connecting" stage and
stopped working when redirected to the embedded browser.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23519</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect HIP reports on MacBooks
intermittently failed with an "Invalid client IP" error, preventing
users from accessing resources over the GP tunnel. This issue occurred
after a system network change when GP attempted to send the HIP report
to an external gateway while the tunnel was disconnected. This issue
affected MacBooks running GP version 6.2.5.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23496</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app's Connect button did not
work as expected preventing users from connecting or changing
gateways.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23440</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Okta FastPass authentication did not work with
GlobalProtect 6.3.3 on macOS 15.5 Sequoia, where the Okta Verify app
did not open for the additional authentication prompt.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23432</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app version 6.3.3
intermittently got stuck on the "finding best gateway" status
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23404</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Host Information Profile (HIP) check was
unable to accurately identify key details from third-party security
products.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23294</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect app intermittently disconnected on
macOS endpoints even with a stable network connection. This was due to
a timeout that was too short for the route system command.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23263</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where after upgrading to GlobalProtect app version
6.3.3, the app did not save the username in the embedded browser when
"save username" was enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23218</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when using the GlobalProtect app with an
embedded browser, interrupting or canceling the SAML authentication
prompt terminated the pre-logon tunnel, potentially allowing full
internet access even when enforcer was enabled for the user-logon
profile. With default browser, the pre-logon tunnel remained active
when the SAML authentication prompt was interrupted.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23115</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the hardware token authentication option was
intermittently unavailable while using the embedded GlobalProtect
browser on Windows machines.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23088</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where portal login failed due to embedded browser not
popping up and GlobalProtect remains in connecting state
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23044</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when a machine was in Modern standby, the
GlobalProtect app repeatedly attempted to connect to gateways, even
when authentication failed due to SAML timeout. This resulted in
GlobalProtect connecting to non-optimal gateway
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-22989</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app intermittently stopped
sending HIP reports while connected to the gateway.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-22979</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading to GlobalProtect app version
6.2.6, the PanGPA application got stuck in 'Connecting' state and then
got terminated unexpectedly.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-22887</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect users experienced frequent
disconnections across various locations.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-22870</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when using domain-based split tunneling on
GlobalProtect clients, expired DNS TTL entries were not removed from
the Windows Filtering Platform filter driver. This resulted in
incorrect packet routing where traffic for domains not in the exclude
list, but resolving to the same IP address as excluded domains, was
routed via the physical interface instead of the tunnel.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-22804</b></div>
</td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect app remained in a connected state
after a network disconnection. As a result, when the network connection
was restored, the GlobalProtect app did not recover, and traffic failed
to pass until a refresh connection was performed.
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-22764</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where wa_3rd_party_host_xx.exe attempted to connect to
Microsofts update servers for information and the patch information
was not sent in the HIP report. This occured even though HIP
Exceptions for patch management were configured to exclude Windows
updates agent.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-22541</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Windows 11 where the GlobalProtect app (PanGPA)
would stop working when the device was locked. The crash occurred when
an expired authentication triggered a persistent smartcard login
dialog during sleep, leading to excessive memory swapping and a
crypt32.dll failure.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-22365</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where users experienced intermittent issues browsing
webpages while connected to the GlobalProtect app.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-22033</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect client version 6.3.1 experienced
DNS resolution failures for IPv4 addresses, specifically when
applications using the io.netty library attempted DNS lookups.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-22029</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Apple software downloads took longer to complete
when using GlobalProtect with split tunneling enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-21982</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue in which IPv6 traffic bypassed the valid route in the
rerouting table and instead passed through the physical adapter when
the GlobalProtect app was installed on Windows devices.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-21961</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading to GlobalProtect version 6.2.5,
the app triggered authentication and opened multiple browser tabs when
the computer woke from sleep.
</div>
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,241 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row">
<th class="entry">
<div class="p">Issue ID</div>
</th>
<th class="entry">
<div class="p">Description</div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24113</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, on Mac OS endpoints, the agent proxy was
attempting to download PAC files directly, bypassing the configured
proxy settings. This resulted in download failures when the corporate
network was configured to block direct traffic.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23947</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect agent-msg logs were not generated
on Panorama when a user disconnected from the GlobalProtect gateway.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23839</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue that caused the GlobalProtect 6.3.3 HIP report to fail
with the error Method: WAAPI_MID_GET_AGENT_STATE
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23760</b></div>
</td>
<td class="entry relcol">
<div class="p">
GlobalProtect app version 6.3.3 using SAML with the embedded browser
loses cursor focus in the password field, requiring users to click in
the password field before entering their password.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23753</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the DNS registration script configured on
pre-vpn-connect did not run on the first GlobalProtect connection on
version 6.3.3.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23752</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app failed to authenticate to
the portal and gateway after a machine certificate was renewed by
Intune MDM. A reboot was required to restore the connection.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23746</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect HIP check incorrectly detected
status for Symantec Endpoint Protection, which caused the device to
fail the
</div>
<div class="p">HIP check.</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23616</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect app was installed on
devices running macOS, the following error
</div>
<div class="p">
"TransparentProxy: openWithLocalEndpoint failed" occurred in
PanNExt.log when using an IPv6 address.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23488</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the HIP report intermittently detected MacOS
XProtect "Real Time Protection" status as disabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23468</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect HIP check failed to detect the
correct version of Forticlient Antivirus, which caused the device to
fail the HIP check.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23417</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SAML authentication with Azure AD, using Cisco
Duo EAM, failed after upgrading to GlobalProtect version 6.2.8
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23403</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect HIP report failed to detect the
status of SentinelOne, causing the device to fail the HIP check
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23361</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect HIP report did not detect the
Status for Zoho corporation - ManageEngine Patch Manager Plus Agent,
which caused the device to fail the HIP check.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23283</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect was unable to set [exclude/include]
0.0.0.0/netmask routes on Mac endpoint
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23095</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed and issue where the GlobalProtect HIP report failed to detect
the Symantec DLP software, which caused the device to fail the HIP
check.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-22156</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect application displayed
unexpected characters on the user interface after installing the
GlobalProtect client on Windows 11 machines. This issue was observed
with GlobalProtect client versions 6.3.1-c383 and 6.2.6-838, where the
Lato font appeared to be the cause.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-21745</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect HIP check failed to detect
Workspace ONE status, which caused the device to fail the HIP check.
</div>
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,368 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row">
<th class="entry">
<div class="p">Issue ID</div>
</th>
<th class="entry">
<div class="p">Description</div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24332</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where users on trusted networks were incorrectly
receiving a captive portal detection message and being redirected to a
separate browser tab. This occurred because the GlobalProtect app was
not properly handling captive portal detection response.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24330</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect app got stuck in a connecting state
when using GlobalProtect version 6.2.8-h4. The issue was seen when
saml-logout and enforcer was enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24235</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading to GlobalProtect agent 6.2.8 on
macOS, users were unable to select a different portal. Clicking
"Change Portal" would initiate a reconnection attempt instead of
displaying the portal selection menu.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24166</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect agents in proxy-only mode would
intermittently get stuck in a connecting state after upgrading from
version 6.2.8 to 6.3.3-676. The agent would become stuck in the
"Discovering external network" phase, and restarting the GlobalProtect
process would temporarily resolve the issue.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24086</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when Endpoint Traffic Policy Enforcement was
enabled with "No Direct Access to Local Network" on GlobalProtect,
Xcode running on macOS was unable to recognize iPhones connected via
USB-C. This issue occurred because traffic enforcement blocked
communication between Xcode and the iPhone.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24050</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect clients prompted a window to select
a certificate with the error "The parameter is incorrect" because the
client certificate request originated from a portal or gateway Access
Control Server (ACS) and was not required.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24048</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect apps installed on on Dell Vostro 15
3515 laptops were unable to connect to the GlobalProtect service with
the following error: "Could not connect to the GlobalProtect service.
If the issue persists, contact your administrator."
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24036</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the HIP check did not correctly detect the status
of the ESET firewall on Windows hosts.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23990</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the captive portal opened in the embedded
browser, but when the user tried to connect to the internet, it
redirected to the default browser and was blocked.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23913</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app would become unresponsive
when system extensions and a PAC file were enabled simultaneously.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23906</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect app displayed a "No Network
Connectivity" error and failed to initiate a network connection,
preventing access to applications.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23730</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where IPv6 traffic on Windows 11 24H2 did not work as
expected with GlobalProtect app.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23689</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app running on macOS devices
would stuck in a connecting loop indefinitely if the user did not
complete authentication, requiring manual cancellation of the
connection.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23650</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect enforcer blocked network
traffic on Windows endpoints even after the tunnel was successfully
connected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23549</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect (GP) agent briefly disconnected
when a user logged on to Windows, even when the 'Pre-Logon Tunnel
Rename Timeout (sec) (Windows Only)' setting was set to -1, with the
error "server cert verification failed".
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23546</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the SAML authentication window in the
GlobalProtect client on macOS devices running version 6.2.6 or higher
would sometimes display an incomplete or blank screen after the device
woke up from sleep mode. This issue affects devices using the embedded
browser for SAML authentication and with GlobalProtect set to
always-on mode with enforcer enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23525</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where on macOS Ventura and Sequoia, manually changing
the portal address using the GlobalProtect app UI would fail and
revert back to the last connected portal. This issue occurred even
when "Allow User to Change Portal Address" was enabled in the agent
configuration.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23466</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect app was installed on
devices running Windows OS and macOS, the Captive Portal detection
message briefly appeared and disappeared when the Captive Portal
exception timeout was set to 0.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23336</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where agent disable logs were not being logged to
Gateway System Logs on the firewall. The GlobalProtect agent reset the
authentication code, which falsely indicated that the gateway was not
fully authenticated, and the agent did not send the message.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-22683</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where tool tips were not available for the Add, Edit,
and Delete buttons on the GlobalProtect application's settings page on
Windows devices.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-22572</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the hamburger menu button was disabled in the
Refresh connection screen, which made it inaccessible when using a
keyboard.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-22522</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading the GlobalProtect app, external
users on Windows 11 computers with multiple Azure Entra accounts were
unable to authenticate to the portal using SAML with Azure Entra as
the Identity Provider (IdP). The new WebView2 embedded browser
automatically used the user's default Windows credential for Single
Sign-On (SSO), preventing them from selecting the correct account for
authentication.
</div>
<div class="p">
To resolve this issue a new registry key 'entra-sso' has been
introduced. You can add the registry key using two methods and set it
to no to disable SSO.
</div>
<div class="p">
1. For pre-deployment, use 'msiexec.exe /i globalprotect64.msi
ENTRASSO="no"
</div>
<div class="p">or</div>
<div class="p">
2. Add key "entra-sso" and set it to "no" under
HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto Networks\GlobalProtect\Settings.
If the "entra-sso" key does not exist under this path, the
GlobalProtect agent's default behavior is to 'Allow' Entra SSO.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-22148</b></div>
</td>
<td class="entry relcol">
<div class="p">
(GP App 6.3.1 enabled with FIPS-CC only) Fixed an issue where the OCSP
request did not send the Host header, causing the X509v3 certificate
validation to fail when accessing the OCSP or CRL.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-22021</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when using conditional-connect on macOS Sequoia
with GlobalProtect client version 6.2.6, manually switching gateways
caused the client to display a "Not connected" status for
approximately 10 seconds while establishing a connection to the second
gateway.
</div>
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,170 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row">
<th class="entry">
<div class="p">Issue ID</div>
</th>
<th class="entry">
<div class="p">Description</div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24683</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Host Information Profile (HIP) matching failed
for Anti-Malware criteria on macOS endpoints due to GlobalProtect
failing to detect the virus definition version for Kaspersky
Anti-Virus.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24579</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect clients were unable to authenticate
to internal gateways when multiple internal gateways were configured.
This issue occured because the GlobalProtect client did not properly
reset the SAML login flag, causing subsequent SAML pre-login requests
to be ignored.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24548</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where macOS GlobalProtect (GP) clients connected to an
internal gateway with the enforcer enabled were unable to access the
internet via a proxy. This occurred because the tunnel_connected flag
remained set to 1 after the gateway disconnected, even though the
gateway configuration was cleared.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24261</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect app running on macOS Sequoia 15.6.1
running GP 6.2.8 -c263 that receive both IPv4 and IPv6 addresses were
not receiving packets back from the Network Load Balancer (NLB)
instances.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24221</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app experienced a continuous
connect-disconnect loop when used on flights. This issue occurred
because rapid network wake-ups left network interfaces in an
inconsistent state, causing GlobalProtect to attempt tunnel
establishment on an unstable network foundation.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24103</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app running on macOS allowed
users to modify or add a new portal address after each device reboot,
even when the "Allow users to change portal" setting was configured as
"No" in the GlobalProtect app.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24037</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect app prompted users to log in with
SAML through the embedded browser even when the GlobalProtect app was
already connected. This occurred when users logged off and then back
onto their Cloud PC (Windows Azure PC), and closing the prompt
disconnected and reconnected the VPN session.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23929</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when GlobalProtect app was configured with
Enforcer, users could bypass Enforcer restrictions by repeatedly
canceling authentication prompts after logging into Windows. This
occurred because the cached portal configuration, which contains
Enforcer settings, was not loaded when a pre-logon tunnel failed to
establish due to a quick user login. This fix ensures that the cached
portal configuration is loaded as soon as PanGPA starts and PanGPS
learns the username, preventing unrestricted access in scenarios where
Enforcer is intended to lockdown the endpoint.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23394</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect app version 6.2.8-183. running on
macOS 15.5 was unable to accurately report the disk encryption status
of FileVault, resulting in an "unknown" status in HIP checks.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-22797</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the MAC address generated for the DHCP feature
changed on every GlobalProtect client restart. The MAC address should
remain static after initial generation to allow static IP assignment
on the DHCP server side for a specific GlobalProtect client.
Additionally, the generated MAC address was not always marked as
unicast and locally administered.
</div>
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,368 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row">
<th class="entry">
<div class="p">Issue ID</div>
</th>
<th class="entry">
<div class="p">Description</div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-25370</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect clients (versions
6.3.3-h2-6.3.3-h4) intermittently failed to honor enforcer bypass
rules for FQDNs and IP addresses after the client machine woke up from
sleep. This resulted in connections to bypassed URLs being blocked,
including GlobalProtect's own SAML authentication requests, and
required a manual restart of the PanGPS service to restore
connectivity.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-25172</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, on macOS GlobalProtect clients, exclude routes
were not properly removed from the system routing table after a PanGPS
(GlobalProtect client) crash. This occurred because the routes
remained in the macOS kernel, and upon reconnection, the client's
`checkExistingExRts()` function only validated the destination and
netmask, not the gateway. As a result, these stale routes, pointing to
an old or unreachable gateway, were marked as existing and skipped
during the reconnection process, leading to a corrupted routing state
and preventing correct route injection, especially after a network
change.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-25063</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, in the GlobalProtect app on macOS, keyboard
focus did not automatically move to the required "Enter portal
Address" field when a user attempted to add a new portal without
entering an address. This accessibility issue impacted
keyboard-dependent users.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24961</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall, when configured to obtain IP
addresses from a DHCP server for GlobalProtect clients, sent a MAC
address of '00' to the DHCP server specifically for MacOS 26 (Tahoe)
clients running GlobalProtect App versions 6.2 or 6.3, which resulted
in IP address collisions on the DHCP server.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24897</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect Connect Before Logon tunnel
disconnected for new users on their first logon. This issue affected
GP client versions 6.2.8-hx and 6.3.3-hx.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24892</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect Portal welcome page, when
displayed in German, incorrectly presented a button labeled 'Genau'
instead of 'Zustimmen' (Accept).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24880</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect clients, after upgrading to
versions 6.2.8-263, 6.3.3-h2, or 6.3.3-h3, would get stuck in a
connecting loop and fail to connect to the portal or gateways. This
occurred because the GlobalProtect app crashed when attempting to
delete previous SAML user data, specifically when the user data folder
path contained non-ANSI characters that the app could not convert to a
UTF-16 path.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-24842</b></div>
</td>
<td class="entry relcol">
<div class="p">
(macOS only) GlobalProtect crashed when you clicked
<span class="ph uicontrol">Change Portal</span> on setups that
included two or more portal entries and had a preferred gateway
marked.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24835</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where split tunneling domain exclusions on
GlobalProtect App version 6.3.3-C711 for Windows clients failed to
function as expected after the application disconnected and
reconnected. This resulted in traffic for domains configured for
exclusion being incorrectly routed through the VPN tunnel instead of
directly, because the TTLMap for split tunneling domain rules was not
properly cleared when the GlobalProtect App re-established its
connection.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24804</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect clients running version 6.3.3-711
would randomly get stuck in a 'connecting' status, preventing them
from establishing a successful VPN connection.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24796</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect HIP reports on macOS devices
intermittently failed with an "Invalid client IP" error. This occurred
on GlobalProtect client version 6.2.8-h4 (c317) due to a race
condition where the HIP report thread sent the report during the VPN
disconnect transition, causing the client to use a stale tunnel IP
address instead of the physical IP address.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24755</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect client on Windows machines
truncated the Proxy Auto-Configuration file URL (autoConfigURL) at 104
characters when configured through the GlobalProtect Portal,
preventing the full URL (up to 256 characters) from being correctly
set in the Windows registry due to an insufficient internal buffer
size.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24515</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect clients on macOS devices,
specifically version 6.3.3-h2, were unable to resolve internal IPv6
domains when split tunneling was enabled and the operating system
lacked native IPv6 connectivity. This occurred because the client's
logic, which was designed to apply IPv6 configuration only when the OS
already had native IPv6 connectivity, prevented the GlobalProtect
tunnel from properly handling IPv6 traffic, resulting in "Err name not
resolved" errors for internal FQDNs.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24242</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect portal authentication failed for
some macOS users when attempting to use saved credentials. This issue,
observed on GlobalProtect client versions 6.2.8 and 6.3.3, resulted in
an immediate authentication failure on the client and firewall logs
indicating an invalid username or password, even though the
credentials were valid for other macOS clients.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24216</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Host Information Profile (HIP) banner was not
displayed on Windows 11 client machines running GlobalProtect client
versions 6.2.8-h7 and 6.3.3. This occurred due to a timing or race
condition where the GlobalProtect client (PanGPA) received an outdated
status, preventing the visual display of HIP match or not-match
notifications, even though the messages were recorded in the client
logs.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23963</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect Client version 6.2.8 running in
Windows 365 environments, would experience PanGPA getting stuck during
the tunnel rename process. This prevented successful gateway
authentication and registration after users closed and re-opened their
Windows 365 session, leading to a pop-up message prompting users to
re-authenticate.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23787</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect clients on macOS devices, after
upgrading to version 6.2.8-h2, were unable to connect to the
authentication server. This occurred because incorrect logic in the
GlobalProtect Agent code prevented the Webview Process ID from syncing
with the Network Extension process, causing the Network Extension to
block SAML authentication traffic, resulting in a "Could not connect
to the authentication server" error and a blank embedded browser
during SAML authentication.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23723</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect clients running version 6.2.8-h1
(6.2.8-c223) experienced intermittent connection failures and
disconnections, with the client agent getting stuck in a 'connecting'
state even when backend logs indicated a successful connection. This
occurred because, when conditional connect mode was enabled, the
client attempted to impersonate a user and write On-Demand settings to
the user's registry hive (HKEY_CURRENT_USER) during pre-logon. As no
user was logged in at that stage, user impersonation failed, leading
to incorrect registry access or failed registry operations, which
caused service instability or misconfiguration.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23090</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app experienced connectivity
issues after the host computer resumed from sleep mode due to a
missing self-pointed route. This issue resulted in a delay of 5 to 10
minutes for the GlobalProtect connection to get stabilized.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-21852</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect Agent incorrectly displayed
"N/A" in the "Last Scan Time" field for the Trend Micro Deep Security
Agent within the Host Information Profile (HIP) report.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-20621</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where users from overseas locations were disconnected
from GlobalProtect due to the HIP report not being sent with manual
gateway selection.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-18976</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect client 6.1.1-5 would select the
incorrect Windows tile by default after locking the screen when using
Single Sign-On for Smart Card PIN (Windows) with the Yubikey Smart
Card Minidriver. When multiple smart cards were present, GlobalProtect
incorrectly selected the last enumerated card instead of the currently
active one.
</div>
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,99 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row">
<th class="entry">
<div class="p">Issue ID</div>
</th>
<th class="entry">
<div class="p">Description</div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-25300</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect clients experienced frequent
disconnections from GlobalProtect gateways. After being disconnected,
users were often unable to reconnect for extended periods, and
connection attempts to designated gateways, including those manually
selected or identified as 'Best Available', would incorrectly redirect
to other gateways.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-25222</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect clients failed to detect captive
portals on public Wi-Fi networks, even when the captive portal
responded with an HTTP 302 Redirect. This occurred because the
GlobalProtect agent expected the HTTP response to be terminated by
`\r\n\r\n` as per RFC, but some captive portals did not adhere to
this, causing the agent to incorrectly report that no data was
received from the captive portal server and thus fail to detect the
portal.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-25173</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect clients on macOS devices, when
configured in tunnel-proxy mode, intermittently displayed an "A valid
PAC file is required" notification after waking up from modern
standby, particularly when the PAC file contained a placeholder
statement instead of the actual EP-FQDN.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24992</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect users experienced significant login
delays after a system reboot or shutdown, such as after a weekend.
This delay was caused by a shared memory issue that disrupted
communication between the GlobalProtect agent and GlobalProtect
service.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23301</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect app 6.2.7 and later, was
installed on Windows 10 devices, the app deleted the predefined proxy
PAC file configuration whenever the app got disconnected regardless of
whether the disconnection was initiated manually or occurred
automatically due to a timeout.
</div>
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,88 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row">
<th class="entry">
<div class="p">Issue ID</div>
</th>
<th class="entry">
<div class="p">Description</div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-25889</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect clients, particularly when
connected to Prisma Access, were unable to extend their VPN session.
When the 'Extend Session' or 'Refresh connection' option was selected,
the client would disconnect and immediately reconnect, but the session
countdown timer would not reset. This was due to a race condition that
caused the `GetCurrentGateway()` function to return a null value
during the session extension thread, preventing the session from being
properly prolonged.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-25828</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where on macOS devices running GlobalProtect Agent
version 6.3.3-h6, the GlobalProtect Agent was unable to communicate
with the GlobalProtect Service, resulting in the error "Could not
connect to the GlobalProtect service." This occurred because when
prelogon was disabled, the PanGPS LaunchDaemon would exit prematurely
after boot, and the subsequent LaunchAgent failed to properly restart
PanGPS as a user-session agent, leaving no service listening on port
4767 for PanGPA to connect to.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-25702</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect service (PanGPS) failed to
start on macOS 26.3.1 after a system upgrade, preventing GlobalProtect
client version 6.2.8-814 from connecting. This was due to a regression
where `SetCurrentGateway` was set to `NULL` during `disconnectVPN`
operations.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-24033</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect Client 6.3.3-676 on Windows
endpoints would hang or freeze. This occurred when the client
connected to a GlobalProtect portal or gateway that initiated a client
certificate request, even if the certificate was not strictly required
for authentication. The client's certificate selection dialog would
appear briefly and then disappear, causing the GlobalProtect client
application to become unresponsive.
</div>
</td>
</tr>
</tbody>
</table>
File diff suppressed because it is too large Load Diff