Add GP 6.3 known issues

This commit is contained in:
2026-04-02 13:40:09 -05:00
parent 9461287076
commit 97d2e530ab
10 changed files with 284 additions and 9 deletions
@@ -0,0 +1,15 @@
---
type: Known
product: GlobalProtect
version: 6.3.1
---
## GPC-21982
IPv6 traffic on the Windows client does not follow the routing table and leaks through the physical adapter.
## GPC-20983
When a Windows computer resumes from sleep, the GlobalProtect app remains stuck in the connecting stage.
**Workaround:** Restart the PanGPS service.
@@ -0,0 +1,15 @@
---
type: Known
product: GlobalProtect
version: 6.3.2
---
## GPC-21982
IPv6 traffic on the Windows client does not follow the routing table and leaks through the physical adapter.
## GPC-20983
When a Windows computer resumes from sleep, the GlobalProtect app remains stuck in the connecting stage.
**Workaround:** Restart the PanGPS service.
@@ -0,0 +1,55 @@
---
type: Known
product: GlobalProtect
version: 6.3.3-h1
---
## GPC-23149
Connection via captive portal does not work in agent proxy mode when the captive portal is hosted on a non-local network.
## GPC-21982
IPv6 traffic on the Windows client does not follow the routing table and leaks through the physical adapter.
## GPC-21694
When the GlobalProtect app is installed on Windows, a Microsoft Defender SmartScreen warning is displayed:.
**Workaround:**Click More Info and then click Run to proceed with the installation.
## GPC-21558
When the GlobalProtect app is installed on devices running on macOS and the end user enable or disable the system extensions, the GlobalProtect Enforcer feature is not working as expected.
## GPC-20840
Loading content or text on the SAML embedded browser can take longer than usual. This does not impact authentication.
## GPC-17820
Firefox is not supported for proxied traffic in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode).
## GPC-17513
When GlobalProtect is configured in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode), if the admin-defined PAC file has an HTTP URL, the GlobalProtect app will not download the PAC content.
## GPC-17447
When the GlobalProtect app is configured in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), SSL VPN establishment over the proxy doesn't work.
## GPC-17663
In [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), the GlobalProtect agent tunnel does not work seamlessly when the GlobalProtect app and the third-party VPN are configured to use overlapping IP subnets.
**Workaround:** Use GlobalProtect in [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode) for better compatibility with third-party VPNs.
## GPC-17555
In [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), the GlobalProtect agent tunnel on macOS does not coexist well with Cisco Anyconnect VPN due to an IP forwarding table issue.
**Workaround:** Use GlobalProtect in [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode) for better compatibility with third-party VPNs.
## GPC-17854
The GlobalProtect app does not prompt the users to extend the login lifetime user session when the device woke up from sleep or hibernation mode.
@@ -0,0 +1,51 @@
---
type: Known
product: GlobalProtect
version: 6.3.3-h2
---
## GPC-23149
Connection via captive portal does not work in agent proxy mode when the captive portal is hosted on a non-local network.
## GPC-21982
IPv6 traffic on the Windows client does not follow the routing table and leaks through the physical adapter.
## GPC-21694
When the GlobalProtect app is installed on Windows, a Microsoft Defender SmartScreen warning is displayed:.
**Workaround:**Click More Info and then click Run to proceed with the installation.
## GPC-21558
When the GlobalProtect app is installed on devices running on macOS and the end user enable or disable the system extensions, the GlobalProtect Enforcer feature is not working as expected.
## GPC-20840
Loading content or text on the SAML embedded browser can take longer than usual. This does not impact authentication.
## GPC-17513
When GlobalProtect is configured in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode), if the admin-defined PAC file has an HTTP URL, the GlobalProtect app will not download the PAC content.
## GPC-17447
When the GlobalProtect app is configured in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), SSL VPN establishment over the proxy doesn't work.
## GPC-17663
In [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), the GlobalProtect agent tunnel does not work seamlessly when the GlobalProtect app and the third-party VPN are configured to use overlapping IP subnets.
**Workaround:** Use GlobalProtect in [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode) for better compatibility with third-party VPNs.
## GPC-17555
In [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), the GlobalProtect agent tunnel on macOS does not coexist well with Cisco Anyconnect VPN due to an IP forwarding table issue.
**Workaround:** Use GlobalProtect in [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode) for better compatibility with third-party VPNs.
## GPC-17854
The GlobalProtect app does not prompt the users to extend the login lifetime user session when the device woke up from sleep or hibernation mode.
@@ -0,0 +1,55 @@
---
type: Known
product: GlobalProtect
version: 6.3.3-h3
---
## GPC-23760
GlobalProtect app version 6.3.3 using SAML with the embedded browser loses cursor focus in the password field, requiring users to click in the password field before entering their password.
## GPC-23149
Connection via captive portal does not work in agent proxy mode when the captive portal is hosted on a non-local network.
## GPC-21982
IPv6 traffic on the Windows client does not follow the routing table and leaks through the physical adapter.
## GPC-21694
When the GlobalProtect app is installed on Windows, a Microsoft Defender SmartScreen warning is displayed:.
**Workaround:**Click More Info and then click Run to proceed with the installation.
## GPC-21558
When the GlobalProtect app is installed on devices running on macOS and the end user enable or disable the system extensions, the GlobalProtect Enforcer feature is not working as expected.
## GPC-20840
Loading content or text on the SAML embedded browser can take longer than usual. This does not impact authentication.
## GPC-17513
When GlobalProtect is configured in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode), if the admin-defined PAC file has an HTTP URL, the GlobalProtect app will not download the PAC content.
## GPC-17447
When the GlobalProtect app is configured in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), SSL VPN establishment over the proxy doesn't work.
## GPC-17663
In [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), the GlobalProtect agent tunnel does not work seamlessly when the GlobalProtect app and the third-party VPN are configured to use overlapping IP subnets.
**Workaround:** Use GlobalProtect in [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode) for better compatibility with third-party VPNs.
## GPC-17555
In [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode), the GlobalProtect agent tunnel on macOS does not coexist well with Cisco Anyconnect VPN due to an IP forwarding table issue.
**Workaround:** Use GlobalProtect in [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode) for better compatibility with third-party VPNs.
## GPC-17854
The GlobalProtect app does not prompt the users to extend the login lifetime user session when the device woke up from sleep or hibernation mode.
@@ -0,0 +1,23 @@
---
type: Known
product: GlobalProtect
version: 6.3.3-h4
---
## GPC-24842
(macOS only) GlobalProtect crashes when you click **Change Portal** on setups that include two or more portal entries and have a preferred gateway marked. This issue can corrupt the NSUserDefaults plist file leading to subsequent crashes.
**Workaround**: Do one of the following:
- Reinstall GlobalProtect.
- Remove the corrupted plist file located at ~/Library/Preferences/com.paloaltonetworks.GlobalProtect.client.plist.
- Remove portal entries only from the plist file using the following steps:
1. $ launchctl unload -S Aqua /Library/LaunchAgents/com.paloaltonetworks.gp.pangpa.plist
2. $ defaults delete com.paloaltonetworks.GlobalProtect.client PanPortalList
3. killall cfprefsd
4. launchctl load -S Aqua /Library/LaunchAgents/com.paloaltonetworks.gp.pangpa.plist
## GPC-23695
When GlobalProtect is connected in hybrid mode with both tunnel and proxy enabled, disconnecting the tunnel while leaving the proxy active does not allow captive portals to be detected when toggling the Wi-Fi connection. The proxy remains active, preventing captive portal detection.
@@ -0,0 +1,23 @@
---
type: Known
product: GlobalProtect
version: 6.3.3-h6
---
## GPC-25112
The GlobalProtect agents on Windows and macOS experience persistent connection loops because of a misconfiguration in the Unified User-ID setup. This occurs when the agent identifies an internal network but connects to an external gateway that lacks a valid routing path back to that internal network. For this feature to function correctly, it is recommended to have at least one internal gateway reachable from the external gateway to ensure stable connectivity and proper network transitions.
## GPC-24842
(macOS only) GlobalProtect crashes when you click **Change Portal** on setups that include two or more portal entries and have a preferred gateway marked. This issue can corrupt the NSUserDefaults plist file leading to subsequent crashes.
**Workaround**: Do one of the following:
- Reinstall GlobalProtect.
- Remove the corrupted plist file located at ~/Library/Preferences/com.paloaltonetworks.GlobalProtect.client.plist.
- Remove portal entries only from the plist file using the following steps:
1. $ launchctl unload -S Aqua /Library/LaunchAgents/com.paloaltonetworks.gp.pangpa.plist
2. $ defaults delete com.paloaltonetworks.GlobalProtect.client PanPortalList
3. killall cfprefsd
4. launchctl load -S Aqua /Library/LaunchAgents/com.paloaltonetworks.gp.pangpa.plist
@@ -0,0 +1,21 @@
---
type: Known
product: GlobalProtect
version: 6.3.3-h8
---
## GPC-25624
When configuring multiple ports in a comma-separated value (CSV) format for split-tunnel domain exclusions on the firewall (e.g., `domain.com:80,443`), only the first port in the list is honored for exclusion on Windows devices. Subsequent ports configured in the exclusion list are not excluded, leading to unintended routing or policy enforcement for traffic on those ports.
## GPC-25576
When GlobalProtect is configured in Proxy-only or Tunnel + Proxy mode, disconnecting the agent may fail to clear the System Proxy PAC (Proxy Auto-Configuration) settings if the System Preferences (or System Settings) window is open at the time of disconnection. This results in the system attempting to use an invalid or unreachable PAC file while GlobalProtect Proxy is disabled, leading to a loss of internet connectivity.
**Workaround:** Remove the stale configuration entries and restart the system by following the steps below:
1. Ensure the System Preferences and Settings applications are closed.
2. Delete the PAC file entries from the following system files (requires root privileges):
- /Library/Preferences/SystemConfiguration/preferences.plist
- /Library/Preferences/SystemConfiguration/preferences.plist.old
3. Restart your system.
@@ -0,0 +1,15 @@
---
type: Known
product: GlobalProtect
version: 6.3.3
---
## GPC-21982
IPv6 traffic on the Windows client does not follow the routing table and leaks through the physical adapter.
## GPC-20983
When a Windows computer resumes from sleep, the GlobalProtect app remains stuck in the connecting stage.
**Workaround:** Restart the PanGPS service.
+11 -9
View File
@@ -1,10 +1,6 @@
{ {
"PAN-OS": { "PAN-OS": {
"12": { "12": {
"12.2": {
"addressed": [],
"known": []
},
"12.1": { "12.1": {
"addressed": [ "addressed": [
"12.1.2_2026-03-16.md", "12.1.2_2026-03-16.md",
@@ -583,10 +579,6 @@
}, },
"GlobalProtect": { "GlobalProtect": {
"6": { "6": {
"6.4": {
"addressed": [],
"known": []
},
"6.3": { "6.3": {
"addressed": [ "addressed": [
"6.3.1_2026-03-13.md", "6.3.1_2026-03-13.md",
@@ -600,7 +592,17 @@
"6.3.3-h7_2026-03-16.md", "6.3.3-h7_2026-03-16.md",
"6.3.3-h8_2026-03-16.md" "6.3.3-h8_2026-03-16.md"
], ],
"known": [] "known": [
"6.3.1_2026-04-02.md",
"6.3.2_2026-04-02.md",
"6.3.3_2026-04-02.md",
"6.3.3-h1_2026-04-02.md",
"6.3.3-h2_2026-04-02.md",
"6.3.3-h3_2026-04-02.md",
"6.3.3-h4_2026-04-02.md",
"6.3.3-h6_2026-04-02.md",
"6.3.3-h8_2026-04-02.md"
]
}, },
"6.2": { "6.2": {
"addressed": [ "addressed": [