diff --git a/web/data/issues/GlobalProtect/known/6.0_2026-04-02.md b/web/data/issues/GlobalProtect/known/6.0_2026-04-02.md new file mode 100644 index 0000000..073a32c --- /dev/null +++ b/web/data/issues/GlobalProtect/known/6.0_2026-04-02.md @@ -0,0 +1,151 @@ +--- +type: Known +product: GlobalProtect +version: 6.0 +--- + +## GPC-21829 + +After upgrading or downgrading the GlobalProtect client to version 6.0.10, SAML authentication fails when using the embedded browser along with enforcer without any exceptions. + +**Workaround:** Configure an enforcer exception for the SAML authentication service. + +## GPC-21558 + +After disabling and re-enabling extensions on macOS Sequoia, the Enforcer fails to block traffic as expected when the GlobalProtect client is disconnected, allowing traffic to flow improperly. + +## GPC-21554 + +If enforcer is configured, the Connect Before Logon connection fails with a portal unreachable error. + +## GPC-20108 + +The GlobalProtect app upgrade from version 6.0.9 and earlier to version 6.0.10 and later may fail for some users when the agent app configuration parameter on the portal is set to **Allow with prompt**. + +**Workaround:** Use the transparent upgrade method. + +## GPC-18964 + +The GlobalProtect tunnel disconnects after 10 minutes on app versions 6.0.8 and 6.2.1, when SAML authentication is used and the GlobalProtect app is running on macOS devices. + +## GPC-18467 + +In 6.0.8, when SAML authenticates a user that is not in the allow list, authentication fails. However, the SAML assertion is still used for subsequent authentication. + +## GPC-17226 + +After upgrade to GlobalProtect app version 6.0.5, macOS Ventura users are unable to refresh the connection when connected to an external gateway because the refresh menu disappears when the user hovers over it. + +## GPC-17099 + +```resolved +Fixed in GlobalProtect app 6.0.5-c35 and GlobalProtect app 6.0.7 +``` + +When the GlobalProtect app for Windows is upgraded to GlobalProtect app version 6.0.5, devices with Driver Verifier enabled and configured to monitor the PAN virtual adapter driver (pangpd.sys) display the `DRIVER_VERIFIER_DETECTED_VIOLATION` Blue Screen error. + +## GPC-15088 + +When the GlobalProtect app is installed on Android devices, the GlobalProtect notification is persistent and continues to stay on the screen even when the app is closed. This issue is not applicable for Android devices with Android 13 and later version. + +Fixed the issue where the GlobalProtect notification displayed on the screen was unresponsive and this is listed under the [Addressed Issues](/content/techdocs/en_US/globalprotect/release-notes/6-0/globalprotect-addressed-issues.html#id17B8E400LWR_id9668a13d-cdba-41cc-adc8-3cc42a92efe0) section. + +## GPC-14820 + +If you change the setting for **Connect with SSL Only** in the portal [configuration](https://docs.paloaltonetworks.com/globalprotect/10-0/globalprotect-admin/globalprotect-portals/define-the-globalprotect-client-authentication-configurations/customize-the-globalprotect-app.html), when the user views the Preferences in the GlobalProtect app, the Connect with SSL setting retains the previous setting. + +## GPC-14819 + +The first time end users connect using the GlobalProtect 6.0 app they may see an authentication failed message if their [SSO credentials](https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-portals/define-the-globalprotect-client-authentication-configurations/customize-the-globalprotect-app.html) are different from the credentials they used to log in to their computer. + +## GPC-14705 + +```resolved +Fixed in GlobalProtect app 6.0.5 +``` + +On macOS endpoints, when connected to an internal gateway the endpoint may not send a HIP report or receive HIP notifications, and the HIP reports are not available on the [Host Information Profile](https://docs.paloaltonetworks.com/globalprotect/6-0/globalprotect-app-user-guide/globalprotect-app-for-mac/use-the-globalprotect-app-for-mac) tab in the app. + +## GPC-14640 + +```resolved +Fixed in GlobalProtect app 6.0.1 +``` + +In [pre-logon deployments](https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-quick-configs/remote-access-vpn-with-pre-logon.html), the GlobalProtect enforcer remains enabled even after disabling GlobalProtect. + +## GPC-14578 + +```resolved +Fixed in GlobalProtect app 6.0.3 +``` + +After connecting to GlobalProtect using [Connect Before Logon (CBL)](https://docs.paloaltonetworks.com/globalprotect/5-2/globalprotect-app-new-features/new-features-released-in-gp-app/connect-before-logon) with SAML authentication, the GlobalProtect app keeps opening and closing after the user logs in. + +## GPC-14453 + +```resolved +Fixed in GlobalProtect app 6.0.1 +``` + +In some cases, TCP Option lookup for IP fragmented TCP packets can cause the endpoint to lose access to internal resources. + +## GPC-14329 + +```resolved +Fixed in GlobalProtect app 6.0.1 +``` + +macOS devices are able to bypass the GlobalProtect tunnel using the physical adapter even when **No direct access to local network** is [enabled](https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-web-interface-help/globalprotect/network-globalprotect-gateways/globalprotect-gateways-agent-tab/client-settings-tab.html). + +## GPC-14063 + +In cases where the GlobalProtect gateway does not push a [DNS suffix](https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-web-interface-help/globalprotect/network-globalprotect-gateways/globalprotect-gateways-agent-tab/network-services-tab.html) to the endpoint, the endpoint incorrectly pushes the DNS suffix from the physical adapter to the virtual adapter. + +## GPC-13998 + +When connected to GlobalProtect with **Resolve All FQDNs Using DNS Servers Assigned by the Tunnel (Windows Only)** set to **Yes** in the App Configurations area of the GlobalProtect portal configuration, performance is slow in the Windows Active Directory Users and Computers console. + +**Workaround:** Set **Resolve All FQDNs Using DNS Servers Assigned by the Tunnel (Windows Only)** to **No**. + +## GPC-13970 + +```resolved +Fixed in GlobalProtect app 6.0.1 +``` + +DNS queries for excluded domains are sent out on both the GlobalProtect app virtual adapter and the device's physical adapter when the **Split-Tunnel Option** is set to **Both Network Traffic and DNS** in the [App Configurations](https://docs.paloaltonetworks.com/globalprotect/10-0/globalprotect-admin/globalprotect-portals/define-the-globalprotect-client-authentication-configurations/customize-the-globalprotect-app.html) area of the GlobalProtect portal configuration. + +## GPC-13774 + +```resolved +Fixed in GlobalProtect app 6.0.1 +``` + +In some cases the GlobalProtect tunnel cannot send traffic after the system wakes up from sleep mode. + +## GPC-13757 + +In a [configuration](https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-web-interface-help/globalprotect/network-globalprotect-portals/globalprotect-portals-agent-configuration-tab/globalprotect-portals-agent-app-tab.html) where the **Welcome Page** is set to **None** and **Have User Accept Terms Of Use before Creating Tunnel** is set to **Yes**, the endpoint gets stuck in the connecting state. + +**Workaround:** Enable the Welcome Page or set **Have User Accept Terms Of Use before Creating Tunnel** to **No**. + +## GPC-13575 + +When the user is prompted to [select a certificate](https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/authentication/about-globalprotect-user-authentication/how-does-the-app-know-which-certificate-to-supply.html) to use to connect to GlobalProtect, if the user instead clicks Cancel without selecting a client certificate the app shows the`no network connectivity` error message. + +## GPC-13106 + +If the end user sets a preferred gateway in the GlobalProtect app and the administrator later disables the [manual gateway option](https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-portals/define-the-globalprotect-client-authentication-configurations/define-the-globalprotect-app-configurations.html) in the portal configuration, the app will still display the option to set a gateway as preferred after the end user refreshes the connection even though manual gateway selection is no longer an available option. + +## GPC-16597 + +The GlobalProtect app stops working when the app is upgraded from version 5.2.8 to 6.0.3. + +## GPC-10557 + +Users cannot install the GlobalProtect app on Linux devices with Ubuntu 20.04 LTS. + +**Workaround**: Install the GlobalProtect app on Linux devices using the `dpkg` utility of the Debian package along with the `apt-get` utility. + +To install the GlobalPtotect app CLI, use `$ sudo dpkg -i `. For example: `$ sudo dpkg -i GlobalProtect_deb-5.3.3.0-3.deb`. diff --git a/web/data/issues/GlobalProtect/known/6.2.1_2026-04-02.md b/web/data/issues/GlobalProtect/known/6.2.1_2026-04-02.md new file mode 100644 index 0000000..92542d1 --- /dev/null +++ b/web/data/issues/GlobalProtect/known/6.2.1_2026-04-02.md @@ -0,0 +1,83 @@ +--- +type: Known +product: GlobalProtect +version: 6.2.1 +--- + +## GPC-23149 + +Connection via captive portal does not work in agent proxy mode when the captive portal is hosted on a non-local network. + +## GPC-21694 + +When the GlobalProtect app is installed on Windows, a Microsoft Defender SmartScreen warning is displayed:. + +**Workaround:**Click More Info and then click Run to proceed with the installation. + +## GPC-21558 + +When the GlobalProtect app is installed on devices running on macOS and the end user enable or disable the system extensions, the GlobalProtect Enforcer feature is not working as expected. + +## GPC-21442 + +Users running GlobalProtect client with Enforcer enabled may see an "Internet Blocked message" when performing SAML authentication for the nth time (n>1) via embedded web browser. This happens when Webview2 or Edge browser is updated between previous successful authentication and the current unsuccessful authentication attempt.. + +**Workaround:**Disable webview2 auto update via the group policy. If you still see the error message, restart the device. + +## GPC-20970 + +GlobalProtect can have intermittent connectivity issues on Prisma Access IP optimization enabled tenants. + +**Workaround:** If your Prisma Access tenant is IP Optimization enabled (available starting in Prisma Access 5.0.1), upgrade to GlobalProtect 6.1.4 and later, 6.2.3 and later, or 6.3 and later. + +## GPC-20840 + +Loading content or text on the SAML embedded browser can take longer than usual. This does not impact authentication. + +## GPC-19339 + +When the GlobalProtect app is upgraded from version 6.1.4-c1 to 6.2.0-c4 on Linux devices, the GlobalProtect web interface displays the upgraded version only after a system reboot. + +## GPC-19180 + +When the GlobalProtect app is installed on Linux devices and the app is upgraded or downgraded, the GlobalProtect web interface and the command-line interface display the new version only after a system reboot. + +## GPC-18964 + +The GlobalProtect tunnel disconnects after 10 minutes on app versions 6.0.8 and 6.2.1, when SAML authentication is used and the GlobalProtect app is running on macOS devices. + +## GPC-18025 + +In 6.2.1, after a refresh connection, the HIP patch exclusion isn't visible on the GlobalProtect UI. However, the HIP patch exclusion logs are visible on the Pangphip.log file. + +## GPC-17820 + +Firefox is not supported for proxied traffic in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode). + +## GPC-17727 + +When the GlobalProtect app is connected in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode), SSH traffic cannot be sent over the proxy. + +## GPC-17513 + +When GlobalProtect is configured in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode), if the admin-defined PAC file has an HTTP URL, the GlobalProtect app will not download the PAC content. + +## GPC-17447 + +When the GlobalProtect app is configured in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), SSL VPN establishment over the proxy doesn't work. + +## GPC-17663 + +In [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), the GlobalProtect agent tunnel does not work seamlessly when the GlobalProtect app and the third-party VPN are configured to use overlapping IP subnets. + +**Workaround:** Use GlobalProtect in [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode) for better compatibility with third-party VPNs. + +## GPC-17555 + +In [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), the GlobalProtect agent tunnel on macOS does not coexist well with Cisco Anyconnect VPN due to an IP forwarding table issue. + +**Workaround:** Use GlobalProtect in [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode) for better compatibility with third-party VPNs. + +## GPC-17854 + +The GlobalProtect app does not prompt the users to extend the login lifetime user session when the device woke up from sleep or hibernation mode. diff --git a/web/data/issues/GlobalProtect/known/6.2.2_2026-04-02.md b/web/data/issues/GlobalProtect/known/6.2.2_2026-04-02.md new file mode 100644 index 0000000..73694fe --- /dev/null +++ b/web/data/issues/GlobalProtect/known/6.2.2_2026-04-02.md @@ -0,0 +1,79 @@ +--- +type: Known +product: GlobalProtect +version: 6.2.2 +--- + +## GPC-23149 + +Connection via captive portal does not work in agent proxy mode when the captive portal is hosted on a non-local network. + +## GPC-21694 + +When the GlobalProtect app is installed on Windows, a Microsoft Defender SmartScreen warning is displayed:. + +**Workaround:**Click More Info and then click Run to proceed with the installation. + +## GPC-21558 + +When the GlobalProtect app is installed on devices running on macOS and the end user enable or disable the system extensions, the GlobalProtect Enforcer feature is not working as expected. + +## GPC-21442 + +Users running GlobalProtect client with Enforcer enabled may see an "Internet Blocked message" when performing SAML authentication for the nth time (n>1) via embedded web browser. This happens when Webview2 or Edge browser is updated between previous successful authentication and the current unsuccessful authentication attempt.. + +**Workaround:**Disable webview2 auto update via the group policy. If you still see the error message, restart the device. + +## GPC-20970 + +GlobalProtect can have intermittent connectivity issues on Prisma Access IP optimization enabled tenants. + +**Workaround:** If your Prisma Access tenant is IP Optimization enabled (available starting in Prisma Access 5.0.1), upgrade to GlobalProtect 6.1.4 and later, 6.2.3 and later, or 6.3 and later. + +## GPC-20840 + +Loading content or text on the SAML embedded browser can take longer than usual. This does not impact authentication. + +## GPC-19339 + +When the GlobalProtect app is upgraded from version 6.1.4-c1 to 6.2.0-c4 on Linux devices, the GlobalProtect web interface displays the upgraded version only after a system reboot. + +## GPC-19180 + +When the GlobalProtect app is installed on Linux devices and the app is upgraded or downgraded, the GlobalProtect web interface and the command-line interface display the new version only after a system reboot. + +## GPC-18025 + +In 6.2.1, after a refresh connection, the HIP patch exclusion isn't visible on the GlobalProtect UI. However, the HIP patch exclusion logs are visible on the Pangphip.log file. + +## GPC-17820 + +Firefox is not supported for proxied traffic in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode). + +## GPC-17727 + +When the GlobalProtect app is connected in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode), SSH traffic cannot be sent over the proxy. + +## GPC-17513 + +When GlobalProtect is configured in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode), if the admin-defined PAC file has an HTTP URL, the GlobalProtect app will not download the PAC content. + +## GPC-17447 + +When the GlobalProtect app is configured in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), SSL VPN establishment over the proxy doesn't work. + +## GPC-17663 + +In [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), the GlobalProtect agent tunnel does not work seamlessly when the GlobalProtect app and the third-party VPN are configured to use overlapping IP subnets. + +**Workaround:** Use GlobalProtect in [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode) for better compatibility with third-party VPNs. + +## GPC-17555 + +In [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), the GlobalProtect agent tunnel on macOS does not coexist well with Cisco Anyconnect VPN due to an IP forwarding table issue. + +**Workaround:** Use GlobalProtect in [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode) for better compatibility with third-party VPNs. + +## GPC-17854 + +The GlobalProtect app does not prompt the users to extend the login lifetime user session when the device woke up from sleep or hibernation mode. diff --git a/web/data/issues/GlobalProtect/known/6.2.3-c287_2026-04-02.md b/web/data/issues/GlobalProtect/known/6.2.3-c287_2026-04-02.md new file mode 100644 index 0000000..d054932 --- /dev/null +++ b/web/data/issues/GlobalProtect/known/6.2.3-c287_2026-04-02.md @@ -0,0 +1,69 @@ +--- +type: Known +product: GlobalProtect +version: 6.2.3-c287 +--- + +## GPC-23149 + +Connection via captive portal does not work in agent proxy mode when the captive portal is hosted on a non-local network. + +## GPC-21694 + +When the GlobalProtect app is installed on Windows, a Microsoft Defender SmartScreen warning is displayed:. + +**Workaround:**Click More Info and then click Run to proceed with the installation. + +## GPC-21558 + +When the GlobalProtect app is installed on devices running on macOS and the end user enable or disable the system extensions, the GlobalProtect Enforcer feature is not working as expected. + +## GPC-21442 + +Users running GlobalProtect client with Enforcer enabled may see an "Internet Blocked message" when performing SAML authentication for the nth time (n>1) via embedded web browser. This happens when Webview2 or Edge browser is updated between previous successful authentication and the current unsuccessful authentication attempt.. + +**Workaround:**Disable webview2 auto update via the group policy. If you still see the error message, restart the device. + +## GPC-20840 + +Loading content or text on the SAML embedded browser can take longer than usual. This does not impact authentication. + +## GPC-19339 + +When the GlobalProtect app is upgraded from version 6.1.4-c1 to 6.2.0-c4 on Linux devices, the GlobalProtect web interface displays the upgraded version only after a system reboot. + +## GPC-19180 + +When the GlobalProtect app is installed on Linux devices and the app is upgraded or downgraded, the GlobalProtect web interface and the command-line interface display the new version only after a system reboot. + +## GPC-17820 + +Firefox is not supported for proxied traffic in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode). + +## GPC-17727 + +When the GlobalProtect app is connected in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode), SSH traffic cannot be sent over the proxy. + +## GPC-17513 + +When GlobalProtect is configured in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode), if the admin-defined PAC file has an HTTP URL, the GlobalProtect app will not download the PAC content. + +## GPC-17447 + +When the GlobalProtect app is configured in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), SSL VPN establishment over the proxy doesn't work. + +## GPC-17663 + +In [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), the GlobalProtect agent tunnel does not work seamlessly when the GlobalProtect app and the third-party VPN are configured to use overlapping IP subnets. + +**Workaround:** Use GlobalProtect in [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode) for better compatibility with third-party VPNs. + +## GPC-17555 + +In [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), the GlobalProtect agent tunnel on macOS does not coexist well with Cisco Anyconnect VPN due to an IP forwarding table issue. + +**Workaround:** Use GlobalProtect in [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode) for better compatibility with third-party VPNs. + +## GPC-17854 + +The GlobalProtect app does not prompt the users to extend the login lifetime user session when the device woke up from sleep or hibernation mode. diff --git a/web/data/issues/GlobalProtect/known/6.2.3_2026-04-02.md b/web/data/issues/GlobalProtect/known/6.2.3_2026-04-02.md new file mode 100644 index 0000000..7d840bf --- /dev/null +++ b/web/data/issues/GlobalProtect/known/6.2.3_2026-04-02.md @@ -0,0 +1,69 @@ +--- +type: Known +product: GlobalProtect +version: 6.2.3 +--- + +## GPC-23149 + +Connection via captive portal does not work in agent proxy mode when the captive portal is hosted on a non-local network. + +## GPC-21694 + +When the GlobalProtect app is installed on Windows, a Microsoft Defender SmartScreen warning is displayed:. + +**Workaround:**Click More Info and then click Run to proceed with the installation. + +## GPC-21558 + +When the GlobalProtect app is installed on devices running on macOS and the end user enable or disable the system extensions, the GlobalProtect Enforcer feature is not working as expected. + +## GPC-21442 + +Users running GlobalProtect client with Enforcer enabled may see an "Internet Blocked message" when performing SAML authentication for the nth time (n>1) via embedded web browser. This happens when Webview2 or Edge browser is updated between previous successful authentication and the current unsuccessful authentication attempt.. + +**Workaround:**Disable webview2 auto update via the group policy. If you still see the error message, restart the device. + +## GPC-20840 + +Loading content or text on the SAML embedded browser can take longer than usual. This does not impact authentication. + +## GPC-19339 + +When the GlobalProtect app is upgraded from version 6.1.4-c1 to 6.2.0-c4 on Linux devices, the GlobalProtect web interface displays the upgraded version only after a system reboot. + +## GPC-19180 + +When the GlobalProtect app is installed on Linux devices and the app is upgraded or downgraded, the GlobalProtect web interface and the command-line interface display the new version only after a system reboot. + +## GPC-17820 + +Firefox is not supported for proxied traffic in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode). + +## GPC-17727 + +When the GlobalProtect app is connected in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode), SSH traffic cannot be sent over the proxy. + +## GPC-17513 + +When GlobalProtect is configured in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode), if the admin-defined PAC file has an HTTP URL, the GlobalProtect app will not download the PAC content. + +## GPC-17447 + +When the GlobalProtect app is configured in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), SSL VPN establishment over the proxy doesn't work. + +## GPC-17663 + +In [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), the GlobalProtect agent tunnel does not work seamlessly when the GlobalProtect app and the third-party VPN are configured to use overlapping IP subnets. + +**Workaround:** Use GlobalProtect in [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode) for better compatibility with third-party VPNs. + +## GPC-17555 + +In [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), the GlobalProtect agent tunnel on macOS does not coexist well with Cisco Anyconnect VPN due to an IP forwarding table issue. + +**Workaround:** Use GlobalProtect in [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode) for better compatibility with third-party VPNs. + +## GPC-17854 + +The GlobalProtect app does not prompt the users to extend the login lifetime user session when the device woke up from sleep or hibernation mode. diff --git a/web/data/issues/GlobalProtect/known/6.2.4_2026-04-02.md b/web/data/issues/GlobalProtect/known/6.2.4_2026-04-02.md new file mode 100644 index 0000000..6ce9ec3 --- /dev/null +++ b/web/data/issues/GlobalProtect/known/6.2.4_2026-04-02.md @@ -0,0 +1,69 @@ +--- +type: Known +product: GlobalProtect +version: 6.2.4 +--- + +## GPC-23149 + +Connection via captive portal does not work in agent proxy mode when the captive portal is hosted on a non-local network. + +## GPC-21694 + +When the GlobalProtect app is installed on Windows, a Microsoft Defender SmartScreen warning is displayed:. + +**Workaround:**Click More Info and then click Run to proceed with the installation. + +## GPC-21558 + +When the GlobalProtect app is installed on devices running on macOS and the end user enable or disable the system extensions, the GlobalProtect Enforcer feature is not working as expected. + +## GPC-21442 + +Users running GlobalProtect client with Enforcer enabled may see an "Internet Blocked message" when performing SAML authentication for the nth time (n>1) via embedded web browser. This happens when Webview2 or Edge browser is updated between previous successful authentication and the current unsuccessful authentication attempt.. + +**Workaround:**Disable webview2 auto update via the group policy. If you still see the error message, restart the device. + +## GPC-20840 + +Loading content or text on the SAML embedded browser can take longer than usual. This does not impact authentication. + +## GPC-19339 + +When the GlobalProtect app is upgraded from version 6.1.4-c1 to 6.2.0-c4 on Linux devices, the GlobalProtect web interface displays the upgraded version only after a system reboot. + +## GPC-19180 + +When the GlobalProtect app is installed on Linux devices and the app is upgraded or downgraded, the GlobalProtect web interface and the command-line interface display the new version only after a system reboot. + +## GPC-17820 + +Firefox is not supported for proxied traffic in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode). + +## GPC-17727 + +When the GlobalProtect app is connected in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode), SSH traffic cannot be sent over the proxy. + +## GPC-17513 + +When GlobalProtect is configured in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode), if the admin-defined PAC file has an HTTP URL, the GlobalProtect app will not download the PAC content. + +## GPC-17447 + +When the GlobalProtect app is configured in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), SSL VPN establishment over the proxy doesn't work. + +## GPC-17663 + +In [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), the GlobalProtect agent tunnel does not work seamlessly when the GlobalProtect app and the third-party VPN are configured to use overlapping IP subnets. + +**Workaround:** Use GlobalProtect in [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode) for better compatibility with third-party VPNs. + +## GPC-17555 + +In [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), the GlobalProtect agent tunnel on macOS does not coexist well with Cisco Anyconnect VPN due to an IP forwarding table issue. + +**Workaround:** Use GlobalProtect in [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode) for better compatibility with third-party VPNs. + +## GPC-17854 + +The GlobalProtect app does not prompt the users to extend the login lifetime user session when the device woke up from sleep or hibernation mode. diff --git a/web/data/issues/GlobalProtect/known/6.2.5_2026-04-02.md b/web/data/issues/GlobalProtect/known/6.2.5_2026-04-02.md new file mode 100644 index 0000000..c96c66e --- /dev/null +++ b/web/data/issues/GlobalProtect/known/6.2.5_2026-04-02.md @@ -0,0 +1,63 @@ +--- +type: Known +product: GlobalProtect +version: 6.2.5 +--- + +## GPC-23149 + +Connection via captive portal does not work in agent proxy mode when the captive portal is hosted on a non-local network. + +## GPC-21694 + +When the GlobalProtect app is installed on Windows, a Microsoft Defender SmartScreen warning is displayed:. + +**Workaround:**Click More Info and then click Run to proceed with the installation. + +## GPC-21558 + +When the GlobalProtect app is installed on devices running on macOS and the end user enable or disable the system extensions, the GlobalProtect Enforcer feature is not working as expected. + +## GPC-20840 + +Loading content or text on the SAML embedded browser can take longer than usual. This does not impact authentication. + +## GPC-19339 + +When the GlobalProtect app is upgraded from version 6.1.4-c1 to 6.2.0-c4 on Linux devices, the GlobalProtect web interface displays the upgraded version only after a system reboot. + +## GPC-19180 + +When the GlobalProtect app is installed on Linux devices and the app is upgraded or downgraded, the GlobalProtect web interface and the command-line interface display the new version only after a system reboot. + +## GPC-17820 + +Firefox is not supported for proxied traffic in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode). + +## GPC-17727 + +When the GlobalProtect app is connected in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode), SSH traffic cannot be sent over the proxy. + +## GPC-17513 + +When GlobalProtect is configured in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode), if the admin-defined PAC file has an HTTP URL, the GlobalProtect app will not download the PAC content. + +## GPC-17447 + +When the GlobalProtect app is configured in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), SSL VPN establishment over the proxy doesn't work. + +## GPC-17663 + +In [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), the GlobalProtect agent tunnel does not work seamlessly when the GlobalProtect app and the third-party VPN are configured to use overlapping IP subnets. + +**Workaround:** Use GlobalProtect in [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode) for better compatibility with third-party VPNs. + +## GPC-17555 + +In [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), the GlobalProtect agent tunnel on macOS does not coexist well with Cisco Anyconnect VPN due to an IP forwarding table issue. + +**Workaround:** Use GlobalProtect in [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode) for better compatibility with third-party VPNs. + +## GPC-17854 + +The GlobalProtect app does not prompt the users to extend the login lifetime user session when the device woke up from sleep or hibernation mode. diff --git a/web/data/issues/GlobalProtect/known/6.2.6-c857_2026-04-02.md b/web/data/issues/GlobalProtect/known/6.2.6-c857_2026-04-02.md new file mode 100644 index 0000000..c766642 --- /dev/null +++ b/web/data/issues/GlobalProtect/known/6.2.6-c857_2026-04-02.md @@ -0,0 +1,63 @@ +--- +type: Known +product: GlobalProtect +version: 6.2.6-c857 +--- + +## GPC-23149 + +Connection via captive portal does not work in agent proxy mode when the captive portal is hosted on a non-local network. + +## GPC-21694 + +When the GlobalProtect app is installed on Windows, a Microsoft Defender SmartScreen warning is displayed:. + +**Workaround:**Click More Info and then click Run to proceed with the installation. + +## GPC-21558 + +When the GlobalProtect app is installed on devices running on macOS and the end user enable or disable the system extensions, the GlobalProtect Enforcer feature is not working as expected. + +## GPC-20840 + +Loading content or text on the SAML embedded browser can take longer than usual. This does not impact authentication. + +## GPC-19339 + +When the GlobalProtect app is upgraded from version 6.1.4-c1 to 6.2.0-c4 on Linux devices, the GlobalProtect web interface displays the upgraded version only after a system reboot. + +## GPC-19180 + +When the GlobalProtect app is installed on Linux devices and the app is upgraded or downgraded, the GlobalProtect web interface and the command-line interface display the new version only after a system reboot. + +## GPC-17820 + +Firefox is not supported for proxied traffic in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode). + +## GPC-17727 + +When the GlobalProtect app is connected in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode), SSH traffic cannot be sent over the proxy. + +## GPC-17513 + +When GlobalProtect is configured in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode), if the admin-defined PAC file has an HTTP URL, the GlobalProtect app will not download the PAC content. + +## GPC-17447 + +When the GlobalProtect app is configured in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), SSL VPN establishment over the proxy doesn't work. + +## GPC-17663 + +In [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), the GlobalProtect agent tunnel does not work seamlessly when the GlobalProtect app and the third-party VPN are configured to use overlapping IP subnets. + +**Workaround:** Use GlobalProtect in [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode) for better compatibility with third-party VPNs. + +## GPC-17555 + +In [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), the GlobalProtect agent tunnel on macOS does not coexist well with Cisco Anyconnect VPN due to an IP forwarding table issue. + +**Workaround:** Use GlobalProtect in [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode) for better compatibility with third-party VPNs. + +## GPC-17854 + +The GlobalProtect app does not prompt the users to extend the login lifetime user session when the device woke up from sleep or hibernation mode. diff --git a/web/data/issues/GlobalProtect/known/6.2.6_2026-04-02.md b/web/data/issues/GlobalProtect/known/6.2.6_2026-04-02.md new file mode 100644 index 0000000..96ccc25 --- /dev/null +++ b/web/data/issues/GlobalProtect/known/6.2.6_2026-04-02.md @@ -0,0 +1,63 @@ +--- +type: Known +product: GlobalProtect +version: 6.2.6 +--- + +## GPC-23149 + +Connection via captive portal does not work in agent proxy mode when the captive portal is hosted on a non-local network. + +## GPC-21694 + +When the GlobalProtect app is installed on Windows, a Microsoft Defender SmartScreen warning is displayed:. + +**Workaround:**Click More Info and then click Run to proceed with the installation. + +## GPC-21558 + +When the GlobalProtect app is installed on devices running on macOS and the end user enable or disable the system extensions, the GlobalProtect Enforcer feature is not working as expected. + +## GPC-20840 + +Loading content or text on the SAML embedded browser can take longer than usual. This does not impact authentication. + +## GPC-19339 + +When the GlobalProtect app is upgraded from version 6.1.4-c1 to 6.2.0-c4 on Linux devices, the GlobalProtect web interface displays the upgraded version only after a system reboot. + +## GPC-19180 + +When the GlobalProtect app is installed on Linux devices and the app is upgraded or downgraded, the GlobalProtect web interface and the command-line interface display the new version only after a system reboot. + +## GPC-17820 + +Firefox is not supported for proxied traffic in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode). + +## GPC-17727 + +When the GlobalProtect app is connected in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode), SSH traffic cannot be sent over the proxy. + +## GPC-17513 + +When GlobalProtect is configured in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode), if the admin-defined PAC file has an HTTP URL, the GlobalProtect app will not download the PAC content. + +## GPC-17447 + +When the GlobalProtect app is configured in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), SSL VPN establishment over the proxy doesn't work. + +## GPC-17663 + +In [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), the GlobalProtect agent tunnel does not work seamlessly when the GlobalProtect app and the third-party VPN are configured to use overlapping IP subnets. + +**Workaround:** Use GlobalProtect in [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode) for better compatibility with third-party VPNs. + +## GPC-17555 + +In [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), the GlobalProtect agent tunnel on macOS does not coexist well with Cisco Anyconnect VPN due to an IP forwarding table issue. + +**Workaround:** Use GlobalProtect in [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode) for better compatibility with third-party VPNs. + +## GPC-17854 + +The GlobalProtect app does not prompt the users to extend the login lifetime user session when the device woke up from sleep or hibernation mode. diff --git a/web/data/issues/GlobalProtect/known/6.2.7_2026-04-02.md b/web/data/issues/GlobalProtect/known/6.2.7_2026-04-02.md new file mode 100644 index 0000000..22931ef --- /dev/null +++ b/web/data/issues/GlobalProtect/known/6.2.7_2026-04-02.md @@ -0,0 +1,63 @@ +--- +type: Known +product: GlobalProtect +version: 6.2.7 +--- + +## GPC-23149 + +Connection via captive portal does not work in agent proxy mode when the captive portal is hosted on a non-local network. + +## GPC-21694 + +When the GlobalProtect app is installed on Windows, a Microsoft Defender SmartScreen warning is displayed:. + +**Workaround:**Click More Info and then click Run to proceed with the installation. + +## GPC-21558 + +When the GlobalProtect app is installed on devices running on macOS and the end user enable or disable the system extensions, the GlobalProtect Enforcer feature is not working as expected. + +## GPC-20840 + +Loading content or text on the SAML embedded browser can take longer than usual. This does not impact authentication. + +## GPC-19339 + +When the GlobalProtect app is upgraded from version 6.1.4-c1 to 6.2.0-c4 on Linux devices, the GlobalProtect web interface displays the upgraded version only after a system reboot. + +## GPC-19180 + +When the GlobalProtect app is installed on Linux devices and the app is upgraded or downgraded, the GlobalProtect web interface and the command-line interface display the new version only after a system reboot. + +## GPC-17820 + +Firefox is not supported for proxied traffic in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode). + +## GPC-17727 + +When the GlobalProtect app is connected in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode), SSH traffic cannot be sent over the proxy. + +## GPC-17513 + +When GlobalProtect is configured in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode), if the admin-defined PAC file has an HTTP URL, the GlobalProtect app will not download the PAC content. + +## GPC-17447 + +When the GlobalProtect app is configured in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), SSL VPN establishment over the proxy doesn't work. + +## GPC-17663 + +In [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), the GlobalProtect agent tunnel does not work seamlessly when the GlobalProtect app and the third-party VPN are configured to use overlapping IP subnets. + +**Workaround:** Use GlobalProtect in [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode) for better compatibility with third-party VPNs. + +## GPC-17555 + +In [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), the GlobalProtect agent tunnel on macOS does not coexist well with Cisco Anyconnect VPN due to an IP forwarding table issue. + +**Workaround:** Use GlobalProtect in [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode) for better compatibility with third-party VPNs. + +## GPC-17854 + +The GlobalProtect app does not prompt the users to extend the login lifetime user session when the device woke up from sleep or hibernation mode. diff --git a/web/data/issues/GlobalProtect/known/6.2.8-h1_2026-04-02.md b/web/data/issues/GlobalProtect/known/6.2.8-h1_2026-04-02.md new file mode 100644 index 0000000..05b1bde --- /dev/null +++ b/web/data/issues/GlobalProtect/known/6.2.8-h1_2026-04-02.md @@ -0,0 +1,63 @@ +--- +type: Known +product: GlobalProtect +version: 6.2.8-h1 +--- + +## GPC-23149 + +Connection via captive portal does not work in agent proxy mode when the captive portal is hosted on a non-local network. + +## GPC-21694 + +When the GlobalProtect app is installed on Windows, a Microsoft Defender SmartScreen warning is displayed:. + +**Workaround:**Click More Info and then click Run to proceed with the installation. + +## GPC-21558 + +When the GlobalProtect app is installed on devices running on macOS and the end user enable or disable the system extensions, the GlobalProtect Enforcer feature is not working as expected. + +## GPC-20840 + +Loading content or text on the SAML embedded browser can take longer than usual. This does not impact authentication. + +## GPC-19339 + +When the GlobalProtect app is upgraded from version 6.1.4-c1 to 6.2.0-c4 on Linux devices, the GlobalProtect web interface displays the upgraded version only after a system reboot. + +## GPC-19180 + +When the GlobalProtect app is installed on Linux devices and the app is upgraded or downgraded, the GlobalProtect web interface and the command-line interface display the new version only after a system reboot. + +## GPC-17820 + +Firefox is not supported for proxied traffic in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode). + +## GPC-17727 + +When the GlobalProtect app is connected in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode), SSH traffic cannot be sent over the proxy. + +## GPC-17513 + +When GlobalProtect is configured in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode), if the admin-defined PAC file has an HTTP URL, the GlobalProtect app will not download the PAC content. + +## GPC-17447 + +When the GlobalProtect app is configured in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), SSL VPN establishment over the proxy doesn't work. + +## GPC-17663 + +In [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), the GlobalProtect agent tunnel does not work seamlessly when the GlobalProtect app and the third-party VPN are configured to use overlapping IP subnets. + +**Workaround:** Use GlobalProtect in [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode) for better compatibility with third-party VPNs. + +## GPC-17555 + +In [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), the GlobalProtect agent tunnel on macOS does not coexist well with Cisco Anyconnect VPN due to an IP forwarding table issue. + +**Workaround:** Use GlobalProtect in [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode) for better compatibility with third-party VPNs. + +## GPC-17854 + +The GlobalProtect app does not prompt the users to extend the login lifetime user session when the device woke up from sleep or hibernation mode. diff --git a/web/data/issues/GlobalProtect/known/6.2.8-h2_2026-04-02.md b/web/data/issues/GlobalProtect/known/6.2.8-h2_2026-04-02.md new file mode 100644 index 0000000..d79f29a --- /dev/null +++ b/web/data/issues/GlobalProtect/known/6.2.8-h2_2026-04-02.md @@ -0,0 +1,63 @@ +--- +type: Known +product: GlobalProtect +version: 6.2.8-h2 +--- + +## GPC-23149 + +Connection via captive portal does not work in agent proxy mode when the captive portal is hosted on a non-local network. + +## GPC-21694 + +When the GlobalProtect app is installed on Windows, a Microsoft Defender SmartScreen warning is displayed:. + +**Workaround:**Click More Info and then click Run to proceed with the installation. + +## GPC-21558 + +When the GlobalProtect app is installed on devices running on macOS and the end user enable or disable the system extensions, the GlobalProtect Enforcer feature is not working as expected. + +## GPC-20840 + +Loading content or text on the SAML embedded browser can take longer than usual. This does not impact authentication. + +## GPC-19339 + +When the GlobalProtect app is upgraded from version 6.1.4-c1 to 6.2.0-c4 on Linux devices, the GlobalProtect web interface displays the upgraded version only after a system reboot. + +## GPC-19180 + +When the GlobalProtect app is installed on Linux devices and the app is upgraded or downgraded, the GlobalProtect web interface and the command-line interface display the new version only after a system reboot. + +## GPC-17820 + +Firefox is not supported for proxied traffic in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode). + +## GPC-17727 + +When the GlobalProtect app is connected in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode), SSH traffic cannot be sent over the proxy. + +## GPC-17513 + +When GlobalProtect is configured in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode), if the admin-defined PAC file has an HTTP URL, the GlobalProtect app will not download the PAC content. + +## GPC-17447 + +When the GlobalProtect app is configured in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), SSL VPN establishment over the proxy doesn't work. + +## GPC-17663 + +In [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), the GlobalProtect agent tunnel does not work seamlessly when the GlobalProtect app and the third-party VPN are configured to use overlapping IP subnets. + +**Workaround:** Use GlobalProtect in [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode) for better compatibility with third-party VPNs. + +## GPC-17555 + +In [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), the GlobalProtect agent tunnel on macOS does not coexist well with Cisco Anyconnect VPN due to an IP forwarding table issue. + +**Workaround:** Use GlobalProtect in [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode) for better compatibility with third-party VPNs. + +## GPC-17854 + +The GlobalProtect app does not prompt the users to extend the login lifetime user session when the device woke up from sleep or hibernation mode. diff --git a/web/data/issues/GlobalProtect/known/6.2.8-h3_2026-04-02.md b/web/data/issues/GlobalProtect/known/6.2.8-h3_2026-04-02.md new file mode 100644 index 0000000..4ed8083 --- /dev/null +++ b/web/data/issues/GlobalProtect/known/6.2.8-h3_2026-04-02.md @@ -0,0 +1,55 @@ +--- +type: Known +product: GlobalProtect +version: 6.2.8-h3 +--- + +## GPC-23149 + +Connection via captive portal does not work in agent proxy mode when the captive portal is hosted on a non-local network. + +## GPC-21694 + +When the GlobalProtect app is installed on Windows, a Microsoft Defender SmartScreen warning is displayed:. + +**Workaround:**Click More Info and then click Run to proceed with the installation. + +## GPC-21558 + +When the GlobalProtect app is installed on devices running on macOS and the end user enable or disable the system extensions, the GlobalProtect Enforcer feature is not working as expected. + +## GPC-20840 + +Loading content or text on the SAML embedded browser can take longer than usual. This does not impact authentication. + +## GPC-17820 + +Firefox is not supported for proxied traffic in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode). + +## GPC-17727 + +When the GlobalProtect app is connected in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode), SSH traffic cannot be sent over the proxy. + +## GPC-17513 + +When GlobalProtect is configured in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode), if the admin-defined PAC file has an HTTP URL, the GlobalProtect app will not download the PAC content. + +## GPC-17447 + +When the GlobalProtect app is configured in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), SSL VPN establishment over the proxy doesn't work. + +## GPC-17663 + +In [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), the GlobalProtect agent tunnel does not work seamlessly when the GlobalProtect app and the third-party VPN are configured to use overlapping IP subnets. + +**Workaround:** Use GlobalProtect in [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode) for better compatibility with third-party VPNs. + +## GPC-17555 + +In [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), the GlobalProtect agent tunnel on macOS does not coexist well with Cisco Anyconnect VPN due to an IP forwarding table issue. + +**Workaround:** Use GlobalProtect in [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode) for better compatibility with third-party VPNs. + +## GPC-17854 + +The GlobalProtect app does not prompt the users to extend the login lifetime user session when the device woke up from sleep or hibernation mode. diff --git a/web/data/issues/GlobalProtect/known/6.2.8-h4_2026-04-02.md b/web/data/issues/GlobalProtect/known/6.2.8-h4_2026-04-02.md new file mode 100644 index 0000000..e9f210e --- /dev/null +++ b/web/data/issues/GlobalProtect/known/6.2.8-h4_2026-04-02.md @@ -0,0 +1,59 @@ +--- +type: Known +product: GlobalProtect +version: 6.2.8-h4 +--- + +## GPC-24330 + +Fixed an issue where GlobalProtect app got stuck in a connecting state when using GlobalProtect version 6.2.8-h4. The issue was seen when saml-logout and enforcer was enabled. + +## GPC-23149 + +Connection via captive portal does not work in agent proxy mode when the captive portal is hosted on a non-local network. + +## GPC-21694 + +When the GlobalProtect app is installed on Windows, a Microsoft Defender SmartScreen warning is displayed:. + +**Workaround:**Click More Info and then click Run to proceed with the installation. + +## GPC-21558 + +When the GlobalProtect app is installed on devices running on macOS and the end user enable or disable the system extensions, the GlobalProtect Enforcer feature is not working as expected. + +## GPC-20840 + +Loading content or text on the SAML embedded browser can take longer than usual. This does not impact authentication. + +## GPC-17820 + +Firefox is not supported for proxied traffic in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode). + +## GPC-17727 + +When the GlobalProtect app is connected in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode), SSH traffic cannot be sent over the proxy. + +## GPC-17513 + +When GlobalProtect is configured in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode), if the admin-defined PAC file has an HTTP URL, the GlobalProtect app will not download the PAC content. + +## GPC-17447 + +When the GlobalProtect app is configured in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), SSL VPN establishment over the proxy doesn't work. + +## GPC-17663 + +In [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), the GlobalProtect agent tunnel does not work seamlessly when the GlobalProtect app and the third-party VPN are configured to use overlapping IP subnets. + +**Workaround:** Use GlobalProtect in [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode) for better compatibility with third-party VPNs. + +## GPC-17555 + +In [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), the GlobalProtect agent tunnel on macOS does not coexist well with Cisco Anyconnect VPN due to an IP forwarding table issue. + +**Workaround:** Use GlobalProtect in [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode) for better compatibility with third-party VPNs. + +## GPC-17854 + +The GlobalProtect app does not prompt the users to extend the login lifetime user session when the device woke up from sleep or hibernation mode. diff --git a/web/data/issues/GlobalProtect/known/6.2.8-h5_2026-04-02.md b/web/data/issues/GlobalProtect/known/6.2.8-h5_2026-04-02.md new file mode 100644 index 0000000..ce8ef14 --- /dev/null +++ b/web/data/issues/GlobalProtect/known/6.2.8-h5_2026-04-02.md @@ -0,0 +1,69 @@ +--- +type: Known +product: GlobalProtect +version: 6.2.8-h5 +--- + +## GPC-24842 + +(macOS only) GlobalProtect crashes when you click **Change Portal** on setups that include two or more portal entries and have a preferred gateway marked. This issue can corrupt the NSUserDefaults plist file leading to subsequent crashes. + +**Workaround**: Do one of the following: + +- Reinstall GlobalProtect. +- Remove the corrupted plist file located at ~/Library/Preferences/com.paloaltonetworks.GlobalProtect.client.plist. +- Remove portal entries only from the plist file using the following steps: + 1. $ launchctl unload -S Aqua /Library/LaunchAgents/com.paloaltonetworks.gp.pangpa.plist + 2. $ defaults delete com.paloaltonetworks.GlobalProtect.client PanPortalList + 3. killall cfprefsd + 4. launchctl load -S Aqua /Library/LaunchAgents/com.paloaltonetworks.gp.pangpa.plist + +## GPC-23149 + +Connection via captive portal does not work in agent proxy mode when the captive portal is hosted on a non-local network. + +## GPC-21694 + +When the GlobalProtect app is installed on Windows, a Microsoft Defender SmartScreen warning is displayed:. + +**Workaround:**Click More Info and then click Run to proceed with the installation. + +## GPC-21558 + +When the GlobalProtect app is installed on devices running on macOS and the end user enable or disable the system extensions, the GlobalProtect Enforcer feature is not working as expected. + +## GPC-20840 + +Loading content or text on the SAML embedded browser can take longer than usual. This does not impact authentication. + +## GPC-17820 + +Firefox is not supported for proxied traffic in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode). + +## GPC-17727 + +When the GlobalProtect app is connected in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode), SSH traffic cannot be sent over the proxy. + +## GPC-17513 + +When GlobalProtect is configured in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode), if the admin-defined PAC file has an HTTP URL, the GlobalProtect app will not download the PAC content. + +## GPC-17447 + +When the GlobalProtect app is configured in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), SSL VPN establishment over the proxy doesn't work. + +## GPC-17663 + +In [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), the GlobalProtect agent tunnel does not work seamlessly when the GlobalProtect app and the third-party VPN are configured to use overlapping IP subnets. + +**Workaround:** Use GlobalProtect in [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode) for better compatibility with third-party VPNs. + +## GPC-17555 + +In [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), the GlobalProtect agent tunnel on macOS does not coexist well with Cisco Anyconnect VPN due to an IP forwarding table issue. + +**Workaround:** Use GlobalProtect in [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode) for better compatibility with third-party VPNs. + +## GPC-17854 + +The GlobalProtect app does not prompt the users to extend the login lifetime user session when the device woke up from sleep or hibernation mode. diff --git a/web/data/issues/GlobalProtect/known/6.2.8-h6_2026-04-02.md b/web/data/issues/GlobalProtect/known/6.2.8-h6_2026-04-02.md new file mode 100644 index 0000000..f432fbc --- /dev/null +++ b/web/data/issues/GlobalProtect/known/6.2.8-h6_2026-04-02.md @@ -0,0 +1,27 @@ +--- +type: Known +product: GlobalProtect +version: 6.2.8-h6 +--- + +## GPC-24931 + +When GlobalProtect app has Enforcer and endpoint traffic policy enforcement enabled, it may fail to connect after a Wi-Fi switch, manual gateway change, or machine reboot. The error message "Could not connect to the authentication server," is displayed even when the device has an active internet connection. Disconnecting the GlobalProtect connection allows browsing, but attempting to reconnect immediately redirects to embedded browser Security Assertion Markup Language (SAML) authentication, which then displays the "Can't reach auth server" error. + +## GPC-24922 + +After waking up from modern standby, the GlobalProtect app may get stuck at finding the best available gateway. Disconnecting and reconnecting does not resolve the issue, even though the portal FQDN is reachable. + +## GPC-24842 + +(macOS only) GlobalProtect crashes when you click **Change Portal** on setups that include two or more portal entries and have a preferred gateway marked. This issue can corrupt the NSUserDefaults plist file leading to subsequent crashes. + +**Workaround**: Do one of the following: + +- Reinstall GlobalProtect. +- Remove the corrupted plist file located at ~/Library/Preferences/com.paloaltonetworks.GlobalProtect.client.plist. +- Remove portal entries only from the plist file using the following steps: + 1. $ launchctl unload -S Aqua /Library/LaunchAgents/com.paloaltonetworks.gp.pangpa.plist + 2. $ defaults delete com.paloaltonetworks.GlobalProtect.client PanPortalList + 3. killall cfprefsd + 4. launchctl load -S Aqua /Library/LaunchAgents/com.paloaltonetworks.gp.pangpa.plist diff --git a/web/data/issues/GlobalProtect/known/6.2.8_2026-04-02.md b/web/data/issues/GlobalProtect/known/6.2.8_2026-04-02.md new file mode 100644 index 0000000..e31b11a --- /dev/null +++ b/web/data/issues/GlobalProtect/known/6.2.8_2026-04-02.md @@ -0,0 +1,29 @@ +--- +type: Known +product: GlobalProtect +version: 6.2.8 +--- + +## GPC-22028 + +Fixed an issue where the disconnect reason for macOS users was getting cached. + +## GPC-21775 + +Fixed an issue where GlobalProtect users on macOS were disconnected immediately after sending the HIP report. + +## GPC-21743 + +Fixed an issue where a user was randomly prompted with a \"Login Successful\" message when connecting to GlobalProtect (GP), even though GP was not connected. + +## GPC-21639 + +Fixed an issue where the GlobalProtect macOS client did not extend the session even though the user clicked the Extend Session button. + +## GPC-21467 + +Fixed an issue where the Transparent Upgrade with Proxy only mode did not work as expected and no tunnel was established with the gateway. + +## GPC-21453 + +Fixed an issue where the GlobalProtect app window displayed "static" instead of the connected gateway name. diff --git a/web/data/products.json b/web/data/products.json index 2b39219..3c3d520 100644 --- a/web/data/products.json +++ b/web/data/products.json @@ -623,7 +623,24 @@ "6.2.8-h7_2026-03-16.md", "6.2.8-h9_2026-03-25.md" ], - "known": [] + "known": [ + "6.2.1_2026-04-02.md", + "6.2.2_2026-04-02.md", + "6.2.3_2026-04-02.md", + "6.2.3-c287_2026-04-02.md", + "6.2.4_2026-04-02.md", + "6.2.5_2026-04-02.md", + "6.2.6_2026-04-02.md", + "6.2.6-c857_2026-04-02.md", + "6.2.7_2026-04-02.md", + "6.2.8_2026-04-02.md", + "6.2.8-h1_2026-04-02.md", + "6.2.8-h2_2026-04-02.md", + "6.2.8-h3_2026-04-02.md", + "6.2.8-h4_2026-04-02.md", + "6.2.8-h5_2026-04-02.md", + "6.2.8-h6_2026-04-02.md" + ] }, "6.1": { "addressed": [