Add reference files

This commit is contained in:
2026-06-16 08:22:31 -05:00
parent 79550889aa
commit c6e3095f26
21 changed files with 7128 additions and 81 deletions
@@ -0,0 +1,706 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 50%" />
<col style="width: 50%" />
</colgroup>
<thead class="thead">
<tr class="row">
<th class="entry">Issue ID</th>
<th class="entry">Description</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-18789</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app took a long time to connect
to the gateway when the include domain list was used, while the
enhanced split-tunnel feature was not used.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-18788</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect HIP check did not detect McAfee
Total Protection as an anti-malware application, which caused the
device to fail the HIP check.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-18594</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app was unable to send HIP
reports when the app was connected using IPv6.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-18566</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app incorrectly displayed the
gateway as internal when it was connected to an external gateway.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-18528</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect HIP check incorrectly detected
the version for KES 12 (Kaspersky Endpoint Security), which caused the
device to fail the HIP check.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-18509</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect app was configured with
the Internal Host Detection and Conditional Connect method, the app
did not connect to the internal network when the network was changed
from external to internal as it should have with the Conditional
Connect method enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-18452</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect app was installed on
Windows devices the app did not start right away after a system
reboot.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-18426</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where when the GlobalProtect app was configured with
the <span class="ph uicontrol">Disable GlobalProtect</span> set to
<span class="ph uicontrol">Allow with Ticket</span>, the app did not
display the correct Disable Duration time.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-18336</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app got automatically connected
after a system reboot even though the connection method configured was
<span class="ph uicontrol">On-Demand</span>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-18318</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect app was connected to the
internal gateway, the app displayed the message as
<span class="ph uicontrol">Connected - Inter....</span> instead of
<span class="ph uicontrol">Connected - Internal</span>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-18281</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the MSI install logs showed mutiple messages for
Autonomous DEM installation.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-18251</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect HIP check did not detect McAfee
LiveSafe as an anti-malware application, which caused the device to
fail the HIP check.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-18230</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the user entered credentials during SAML
authentication after the set internal login timer, the app displayed
an authentication failed message without providing the reason. The
<span class="ph uicontrol">Retry</span> button on the app web
interface did not work properly when using an embedded browser for
authentication. The <span class="ph uicontrol">Retry</span> button was
not fully visible on the embedded browser.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-18175</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where users were prompted to enter their credentials
even when the GlobalProtect app was configured for authenticating with
either Authentication Profile /Cookie or Client Certificate.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-18173</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the vertical scroll bar on the GlobalProtect app
web interface did not work properly when users tried to select the
certificate from the drop-down.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-18171</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where users were unable to select the external gateway
manually when connected to the internal network. The GlobalProtect
stayed in <span class="ph systemoutput">Connecting</span> state and
users had to manually disconnect the connection and connect to the
internal network to exit the
<span class="ph systemoutput">Connecting</span> state.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-18167</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app displayed the Prisma Access
gateways that are not set for manual selection.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-18146</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect app was installed on
Windows devices, the GlobalProtect HIP check did not detect the
correct details for Cortex XDR, which caused the device to fail the
HIP check.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-18135</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect app was installed on
devices running macOS, the GlobalProtect HIP check detected the
WithSecure antivirus software as XProtect, which caused the device to
fail the HIP check.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-18107</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect HIP check did not detect McAfee
LiveSafe Internet Security, which caused the device to fail the HIP
check.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-18092</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect connected to an internal gateway
got automatically disconnected after a certain period of time.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-18073</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app selected an unexpected
gateway due to a latency discrepancy seen between PanGPS and packet
capture.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-18060</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect HIP check did not detect McAfee
Total Protection, which caused the device to fail the HIP check.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-18036</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the
<span class="ph uicontrol">No direct access to local network</span>
option was enabled on the GlobalProtect app with access routes
excluded from the GlobalProtect VPN tunnel, the feature did not work
as expected when Endpoint Traffic Policy Enforcement was enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-17936</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Conditional Connect method did not work as
expected and users had to manually connect the app when they changed
their network.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-17921</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the language was set to Japanese, the time
to connect was not displayed properly when
<span class="ph uicontrol">Disconnect Timeout</span> for the app was
configured.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-17896</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where users were unable to connect to GlobalProtect
gateway when only one external gateway was added due to the following
error:
<span class="ph uicontrol"
>Cannot Verify Server Certificate of Gateway</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-17816</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue ehere after entering CIE SAML authentication
credentials to refresh an expired explicit proxy token or cookie when
connected in
<a
class="xref"
href="https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>Tunnel and Proxy mode</a
>
or
<a
class="xref"
href="https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>proxy mode</a
>, the GlobalProtect app got stuck while retrieving the portal
configuration.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-17795</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect HIP check did not detect the
Xcitium Enterprise, the Endpoint Protection Platform by COMODO, which
caused the device to fail the HIP check.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-17776</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect app was installed on
devices running macOS and GlobalProtect enforcer was configured with
allowed FQDNs, users were still able to access the internet and other
public domains.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-17762</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue when the GlobalProtect app was configured with the
option
<span class="ph uicontrol"
>Allow User to Disable GlobalProtect App</span
>
with comment, the option did not work as expected.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-17748</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect HIP check did not detect the
Real-Time Protection status correctly for the CrowdStrike Falcon
application, which caused the device to fail the HIP check.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-17740</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect app was connected through
the Prisma Access gateway, the upload speed of the internet was
reduced to 2 Mbps.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-17728</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where users were unable to connect to GlobalProtect
gateway when only one external gateway was added due to the following
error:
<span class="ph uicontrol"
>Cannot Verify Server Certificate of Gateway</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-17460</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect app was installed on
Windows 10 or 11 devices, and when the user tried to authenticate
using SAML authentication, the app did not display the
<span class="ph uicontrol">Term of Use </span> pop-up on the
<span class="ph uicontrol">Welcome</span> page properly.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-17398</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app
<span class="ph menucascade"
><span class="ph uicontrol">Settings</span
><span class="ph uicontrol">Connection</span></span
>
tab did not display the
<span class="ph uicontrol">Assigned IP Address(es)</span> and
<span class="ph uicontrol">Gateway IP Address</span> properly.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-17206</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when Internal Host Detection (IHD) was enabled
but failed to detect the internal network properly, the app failed to
switch to the external gateway when users switched from an internal
network to an external network.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-17161</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect app was installed on
devices running macOS, the GlobalProtect app failed to reconnect and
continued to stay in the
<span class="ph uicontrol">Connecting</span> state after the device
woke up from Modern Standby mode.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-17099</b></div>
</td>
<td class="entry relcol">
<div class="p">
When the GlobalProtect app for Windows is upgraded to version 6.0.5,
devices with Driver Verifier enabled and configured to monitor the PAN
virtual adapter driver (pangpd.sys) display the
DRIVER_VERIFIER_DETECTED_VIOLATION Blue Screen error.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-17001</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect app was installed on
devices running on macOS, the app did not display the
<span class="ph uicontrol">Connect</span> button and
<span class="ph uicontrol">Refresh Connection</span> button properly.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-16978</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app took a long time to
establish a connection due to an erroneous packet capture process.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-16851</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect app was installed on
devices running macOS, the app did not try to auto-connect to the
gateway after exceeding the
<span class="ph uicontrol">Disable Timeout Value</span>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-16397</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app was installed on devices
running macOS, a blank GlobalProtect app user interface was displayed
instead of the correct page.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-16126</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app did not display the
certificate name in the Client Certificate selection field properly.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-16003</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect app was installed on
devices running macOS, the app was not connected when the proxy was
configured for Safari or Chrome.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-15968</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app was stuck in
<span class="ph uicontrol">Connecting</span> state when users failed
to authenticate with SAML and using an embedded browser. Users were
unable to disconnect the app and had to reboot the device.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-15262</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where when single sign-on (SSO) for Smart Cards was
used for authentication, users were prompted to enter a PIN instead of
a password on the Windows login screen.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-15234</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the app would get stuck at Connecting state while
trying to connect to a gateway.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-15080</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where when the split tunnel was configured based on the
destination domain, split tunneling did not work as expected when IPv6
traffic exclusion was configured.
</div>
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,122 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 50%" />
<col style="width: 50%" />
</colgroup>
<thead class="thead">
<tr class="row">
<th class="entry">Issue ID</th>
<th class="entry">Description</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-19116</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the user faced authentication issues while the
GlobalProtect app was attempting to refresh the explicit proxy token.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-19049</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect app was configured in
hybrid mode with internal host detection, the app failed to connect
and continued to stay in the
<span class="ph systemoutput">Connecting</span> state when users tried
to connect using SAML authentication.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-19007</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where users were unable to connect to the GlobalProtect
portal and gateway after upgrading the app version to 6.2.1.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-19002</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app did not display the
<span class="ph uicontrol">Connect</span> button when the user clicked
the <span class="ph uicontrol">Get Started</span> button after the app
installation through Jamf.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-18991</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the proxy auto-configuration (PAC) files were not
restored as expected after a system reboot or when the user
disconnected the GlobalProtect app.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-18964</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect tunnel got disconnected after
10 minutes on the app versions 6.0.8 and 6.2.1, when the GlobalProtect
app was running on macOS devices and SAML authentication was used to
authenticate.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-18861</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect MSI download was getting stuck
at 27%.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-18471</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when multiple
<span class="ph systemoutput">wa_3rd_party_host_64.exe</span>
processes persisted even after the HIP check, the GlobalProtect app
stopped working.
</div>
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,50 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 50%" />
<col style="width: 50%" />
</colgroup>
<thead class="thead">
<tr class="row">
<th class="entry">Issue ID</th>
<th class="entry">Description</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry"><b class="ph b">GPC-20243</b></td>
<td class="entry relcol">
Fixed an issue where, when the GlobalProtect app was used with an
embedded browser, the browser displayed can't reach page due to a
Windows filter driver issue.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20157</b></td>
<td class="entry relcol">
Fixed an issue where the gateway location was not correctly displayed in
the Connections panel.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20143</b></td>
<td class="entry relcol">
Fixed an issue where the user was redirected to the Authentication page
twice on the default browser for both portal and gateway authentication
when SAML was configured.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19991</b></td>
<td class="entry relcol">
Fixed an issue where client certificate authentication between embedded
browser and IdP (SAML) failed.
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,698 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 50%" />
<col style="width: 50%" />
</colgroup>
<thead class="thead">
<tr class="row">
<th class="entry">Issue ID</th>
<th class="entry">Description</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry"><b class="ph b">GPC-20970</b></td>
<td class="entry relcol">
<div dir="ltr" class="p">
Fixed an issue where GlobalProtect had intermittent connectivity
issues on Prisma Access IP optimization enabled tenants.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19968</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect agent failed to detect
Bitdefender Antivirus Plus on the Windows ARM64 platform during the HIP
check.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19924</b></td>
<td class="entry relcol">
Resolved intermittent connection issues for users accessing
GlobalProtect via an embedded browser.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19901</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect client for Mac users was
intermittently disconnecting and reconnecting.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19840</b></td>
<td class="entry relcol">
Fixed an issue where Mac computers did not display all gateways in the
Search Gateway tab.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19818</b></td>
<td class="entry relcol">
Fixed an issue where when the Enforcer was enabled, Jamf connect was not
working after the MacBook was rebooted. Users had to log in manually.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19784</b></td>
<td class="entry relcol">
Fixed an issue where the HIP check did not detect McAfee Premium
individual.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19753</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect icon could not be selected using
the keyboard.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19712</b></td>
<td class="entry relcol">
Fixed an issue where PanGPS crashed on 6.0.4 caused by invalid memory
reference. GlobalProtect did not run correctly after the system was
rebooted.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19686</b></td>
<td class="entry relcol">
Fixed an issue where translation errors were observed in the
GlobalProtect app for French localization.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19664</b></td>
<td class="entry relcol">
Fixed an issue where users were able to deploy GlobalProtect from JAMF
on Mac Sonoma, but the connection to the portal was stuck.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19659</b></td>
<td class="entry relcol">
Fixed an issue where macOS users were connected to the GlobalProtect app
before they agreed to their companys terms of service.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19656</b></td>
<td class="entry relcol">
Resolved an issue where connecting to a GlobalProtect gateway with IPv6
from macOS resulted in the tunnel connection dropping every 45 seconds
when Endpoint Traffic Policy Enforcement was set to All Traffic.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19630</b></td>
<td class="entry relcol">
Fixed an issue where the prelogon connect method failed on the gateway
prelogin stage.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19587</b></td>
<td class="entry relcol">
Fixed an issue where the user could not login with Okta on macOS when
Endpoint Traffic Policy Enforcement was set to
<span class="ph uicontrol">All traffic</span>.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19581</b></td>
<td class="entry relcol">
Fixed an issue where GlobalProtect indicated that Windows firewall was
not enabled in the HIP report even though it was enabled.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19545</b></td>
<td class="entry relcol">
Fixed an issue where, when the GlobalProtect app was installed on
devices running macOS, users were unable to connect to the GlobalProtect
app when they used T-Mobile iPhone hotspot.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19524</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect app connection failed when the
user used CAS authentication to authenticate to the app. The app
displayed the error message, "Username from CAS SSO response is
different from the input".
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19513</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect client was trying to use the old
portal's authorization cookie to login instead of the newly migrated
portal. This happened when the user changed from secondary portal to
primary portal or vice versa without signing out.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19475</b></td>
<td class="entry relcol">
Fixed an issue where users got connection errors in an embedded browser
after the computer woke up from sleep or when the user switched
gateways.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19449</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect client was trying to use the old
portal's authorization cookie to login instead of the newly migrated
portal. This happened when the user changed the portal from secondary to
primary or vice versa without signing out.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19433</b></td>
<td class="entry relcol">
Fixed an issue where a small white blank page randomly popped up on the
user's screen and the focus shifted to this blank page. This issue
occurs while the computer is connected to Global Protect.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19431</b></td>
<td class="entry relcol">
Fixed an issue where interactive components in the session tray on
Windows did not receive keyboard focus and were not keyboard operable.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19418</b></td>
<td class="entry relcol">
Fixed an issue where GlobalProtect users randomly experienced issues
connecting to the gateway after their computer woke up. This occurred
when Enforce GlobalProtect for Network Access was enabled and Tunnel and
Proxy was set to agent mode.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19416</b></td>
<td class="entry relcol">
Fixed a GlobalProtect redirection issue in embedded browser. When a user
tried to connect to GlobalProtect, an error was displayed while waiting
for the SAML response instead of being redirected to the embedded
browser.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19414</b></td>
<td class="entry relcol">
Fixed an issue where GlobalProtect Always-On connect method was not
triggered after a reboot when the connect-method setting was set to
on-demand in the Windows Registry.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19403</b></td>
<td class="entry relcol">
Fixed an issue where OPSWAT was unable to detect Kaspersky after an
upgrade from 21.3.10.391 to 21.15.8.493.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19400</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect HIP check did not detect the
Definition Date for Bitdefender Virus Scanner, which caused the device
to fail the HIP check.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19391</b></td>
<td class="entry relcol">
Fixed an issue where GlobalProtect stayed disconnected even after being
unlocked.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19387</b></td>
<td class="entry relcol">
Fixed an issue where, when the GlobalProtect app was installed on
devices running macOS, the app displayed text incorrectly when the
system language was German.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19374</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect debug logs displayed information,
which was not supposed to display in the logs.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19359</b></td>
<td class="entry relcol">
Fixed an issue where system extensions on MacBook were not updated after
the GlobalProtect client was upgraded.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19340</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect app failed to send HIP reports
hourly.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19337</b></td>
<td class="entry relcol">
Fixed an issue where the Captive Portal functionality of the
GlobalProtect app did not work as expected when the users used public
Wi-Fi hotspots.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19331</b></td>
<td class="entry relcol">
Fixed an issue where, when SAML authentication was used to authenticate
to the GlobalProtect app, the app used an unknown username SAMLUser
which was not configured instead of the actual username of the user,
which caused an authentication failure.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19314</b></td>
<td class="entry relcol">
Fixed an issue where, when the GlobalProtect app is installed on devices
running macOS, the app displayed the message, Downloading in progress
when the GlobalProtect app was upgraded to 6.0.x using the option Allow
Transparently. The app should not display the message when upgraded
using the transparent method.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19284</b></td>
<td class="entry relcol">
Fixed an issue where GlobalProtect was unable to extend user session.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19280 </b></td>
<td class="entry relcol">
Fixed an issue where, when the GlobalProtect app transitioned from
pre-logon to user-logon tunnel, the app did not display the list of
gateways for the users to change the gateway. The gateway list was
displayed only when the app was refreshed.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19262</b></td>
<td class="entry relcol">
Fixed an issue where GlobalProtect 6.2.1 tried to connect automatically
after the user restarted their computer even though the connect method
was set to On-Demand.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19193</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect app was unable to fetch Windows
firewall and antimalware information correctly.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19162</b></td>
<td class="entry relcol">
Fixed an issue where, when the user upgraded the GlobalProtect version
to 5.2.13 or later, the HIP report displayed the DLP Digital Guardian
Agent as disabled.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19107</b></td>
<td class="entry relcol">
Fixed an issue where some log files were missing from the GlobalProtect
bundle when downloaded from the Explore app.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19104</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect HIP report failed to detect the
Real Time Protection status for Cortex XDR, which caused the device to
fail the HIP check.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19083</b></td>
<td class="entry relcol">
Fixed an issue where, when the GlobalProtect app was installed on
devices running macOS, the Connection tab under app Settings did not
display the connection status and refresh connection did not work when
the Settings window was opened.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19074</b></td>
<td class="entry relcol">
Fixed an issue where Login Lifetime was incorrectly translated on the
French version of the GlobalProtect 6.2.1 app.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19060</b></td>
<td class="entry relcol">
Fixed an issue where the app Settings -&gt; Connection tab did not
display the connection status when the app was changed from a
non-tunneled gateway to a tunneled gateway.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19044</b></td>
<td class="entry relcol">
Fixed an issue where, when the GlobalProtect app was installed on
Windows devices and the user changed the network from wired to wireless
within the organization, the device displayed a blue screen.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19023</b></td>
<td class="entry relcol">
Fixed an issue where, when the GlobalProtect app version 5.2.13 was
installed on devices running macOS, the users were unable to connect to
the Zoom application.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19009</b></td>
<td class="entry relcol">
Fixed an issue where, when SAML authentication was used to authenticate
to the GlobalProtect app and the user changed the gateway to a manual
gateway, the app stayed in the Connecting stage.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-18992</b></td>
<td class="entry relcol">
Fixed an issue where internet via WiFi connection was unavailable for
GlobalProtect users after their computer woke up from sleep because the
client WiFi adapter was unable to obtain a DHCP IP address. This issue
occurred on computers where Enforce GlobalProtect for Network Access was
enabled.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-18983</b></td>
<td class="entry relcol">
Fixed an issue where the Central Authentication Service (CAS)
authentication did not work when the GlobalProtect app was connected to
an internal gateway and the app repeatedly opened the SAML
authentication page.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-18913</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect app displayed the connection
status as Not Connected even though the app was connected to the
internal gateway.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-18907</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect app running on macOS endpoints
did not query the secondary DNS (when primary DNS is not responding)
when the domain was part of the exclude domain list (both network and
DNS).
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-18854</b></td>
<td class="entry relcol">
Fixed an issue where users were prompted twice to authenticate using
SAML authentication when used with CAS authentication and authentication
override cookie, the GlobalProtect app got stuck in the 'Connecting'
stage while trying to connect.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-18845</b></td>
<td class="entry relcol">
Fixed an issue, where the GlobalProtect app was installed manually and
the user clicked the Get Started button, the app displayed the
incorrect message, "Oops! Slow or No Network Connection" instead of the
actual message "Not Connected" window where they can input their portal
address.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-18828</b></td>
<td class="entry relcol">
Fixed an issue where split tunnel CNAME records were created before the
GlobalProtect tunnel was established.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-18822</b></td>
<td class="entry relcol">
Fixed an issue where, when the GlobalProtect app was installed on
Windows devices and the device was reset using the Microsoft Recovery
tool, the GlobalProtect app was not properly displayed.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-18815</b></td>
<td class="entry relcol">
Fixed an issue where the Logon button on the GlobalProtect login screen
stopped working after receiving the Microsoft Edge WebView2 runtime,
117.0.2045.36 update on the devices.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-18750</b></td>
<td class="entry relcol">
Fixed an issue where, when the GlobalProtect app was installed on
devices running macOS, the GlobalProtect HIP check did not detect the
Total Defense antivirus application, which caused the device to fail the
HIP check.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-18733</b></td>
<td class="entry relcol">
Fixed an issue where the hyperlinks with the URLs containing the "="
character in the HIP notification message did not work as expected and
the page did not open when the user clicked the URL.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-18720</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect app became unresponsive when the
user clicked the ESCbutton during authentication using a hard token.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-18703</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect HIP check did not detect the
Trellix Endpoint Security application, which caused the device to fail
the HIP check.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-18598</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect SSO tile was selected instead of
the Windows Password tile in the Windows Login screen even though the
registry key MakeGPCPDefault was set to No.
</td>
</tr>
<tr class="row">
<td class="entry">
<b class="ph b"><b class="ph b">GPC-18384</b></b>
</td>
<td class="entry relcol">
Fixed an issue where GlobalProtect did not connect while Netskope was
connected and vice-versa.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-18379</b></td>
<td class="entry relcol">
Fixed an issue where, when the IP address type was set to IPv4 and IPv6,
the GlobalProtect app could connect only to the manual gateway instead
of connecting to the best available gateway.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-18223</b></td>
<td class="entry relcol">
Fixed an issue where GlobalProtect experienced a prolonged connection
time when IPv6 was disabled on Windows devices.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-18157</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect app displayed the Credential
Provider language in English when the system language was German.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-18039</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect HIP check did not detect the
Definition Date correctly for the CrowdStrike application, which caused
the device to fail the HIP check.
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-18025</b></div>
</td>
<td class="entry relcol">
<div class="p">
In 6.2.1, after a refresh connection, the HIP patch exclusion isn't
visible on the GlobalProtect UI. However, the HIP patch exclusion logs
are visible on the <span class="ph codeph">Pangphip.log</span> file.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-17640</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect HIP check did not detect the
Definition Date correctly for the CrowdStrike application, which caused
the device to fail the HIP check.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-17518</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect app displayed the status as
'Connected-Internal' even when the app was not connected.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-17436</b></td>
<td class="entry relcol">
Fixed an issue where, when the GlobalProtect app was installed on
devices running macOS, the upload speed of the internet was reduced
after a version upgrade.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-17204</b></td>
<td class="entry relcol">
Fixed an issue where, when the GlobalProtect app was installed on
devices running macOS, the certificate information was not accessible
even though the GlobalProtect app had full access to the certificate
store.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-16975</b></td>
<td class="entry relcol">
Fixed an issue where, when the GlobalProtect app was installed on
devices running macOS, the screen reader did not announce the name of
the GlobalProtect gateway when the gateway was marked with the star
symbol.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-16584</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect HIP check did not detect the
CrowdStrike antivirus software correctly, causing the device to fail the
HIP check.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-15123</b></td>
<td class="entry relcol">
Fixed an issue where users were unable to collapse the Change Portal and
Change Gateway menus using the Escape key.
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,668 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 50%" />
<col style="width: 50%" />
</colgroup>
<thead class="thead">
<tr class="row">
<th class="entry">Issue ID</th>
<th class="entry">Description</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry"><b class="ph b">GPC-20741</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect app intermittently disconnected
from the gateway when the user was using the embedded browser for SAML
authentication.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20640</b></td>
<td class="entry relcol">
Fixed an issue where the GP App graphical interface on macOS does not
close on pressing the ESC key.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20585</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect app could not connect to the
GlobalProtect portal when configured with certificate authentication and
SAML authentication using an embedded browser
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20571</b></td>
<td class="entry relcol">
Fixed an issue where the Report an Issue option was not visible in the
GlobalProtect app version 6.2.3.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20542</b></td>
<td class="entry relcol">
Fixed an issue where, when the GlobalProtect app was installed on
Windows devices, the GlobalProtect logs did not display the username
correctly.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20537</b></td>
<td class="entry relcol">
Fixed an issue where the Login page got redirected twice and opened two
separate tabs for GlobalProtect portal and gateway, when the user tried
to connect the GlobalProtect app using the SAML authentication method.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20531</b></td>
<td class="entry relcol">
Fixed an issue where, when the user was using Remote Desktop with
GlobalProtect, the RDP sessions got disconnected because the
GlobalProtect on RDP station got disconnected with a grace period end
message.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20527</b></td>
<td class="entry relcol">
Fixed an issue where the Conditional Connect method configured for the
GlobalProtect app did not work as expected when the user shifted from
external network (home) to an internal network (office). Users had to
reboot the system to resolve this issue.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20514</b></td>
<td class="entry relcol">
Fixed an issue where the remote users using GlobalProtect with Connect
Before Logon (CBL) were unable to reset their password when using the
app with an embedded browser.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20455</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect app intermittently got stuck on
the 'Connecting' status when the computer resumed from sleep and a new
authentication was needed or authentication cookies had expired.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20445</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect app got stuck in Connecting state
after upgrading from PAN-OS 10.1.11-h5 version to PAN-OS 10.1.13
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20444</b></td>
<td class="entry relcol">
Fixed an issue where, when the GlobalProtect app was used with the SAML
authentication method, the app displayed two pop-up messages; one with a
successful authentication message and the other with an authentication
failure message.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20426</b></td>
<td class="entry relcol">
Fixed an issue where a new HIP report was not generated when the user
disabled AV on an end-user device.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20381</b></td>
<td class="entry relcol">
Fixed an issue where the Windows defender Real Time Protection state and
agent version is incorrectly identified in GlobalProtect app version
6.0.8 and 6.2.3.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20378</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect app was used with the SAML
authentication method with the embedded browser, the app got stuck while
redirecting to the SAML authentication page.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20374</b></td>
<td class="entry relcol">
Fixed an issue where users were unable to connect to GlobalProtect if
they accidentally clicked decline on the Terms of Service page.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20370</b></td>
<td class="entry relcol">
Fixed an issue where the Real Time Protection state from SentinelOne was
displayed as true even when the app was disabled.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20366</b></td>
<td class="entry relcol">
Fixed an issue where, when the GlobalProtect app was installed on
Windows devices and the users tried to authenticate to the app, the
screen displayed both authentication success and failed message even
when the authentication was successful.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20320</b></td>
<td class="entry relcol">
GlobalProtect unable to authenticate with SAML IdP using embedded
browser (webview2) when "Enforce GlobalProtect for Network Access" is
enabled
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20279</b></td>
<td class="entry relcol">
Fixed an issue where users were presented with suggested user names
during SAML authentication after upgrading to GlobalProtect 6.2.3.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20263</b></td>
<td class="entry relcol">
Fixed an issue where the correct label was not associated with the
GlobalProtect icon so voice over was unable to read the icon name.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20262</b></td>
<td class="entry relcol">
Fixed an issue where users were unable to select the GlobalProtect icon
from the status bar on macOS.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20243</b></td>
<td class="entry relcol">
Fixed an issue where, when the GlobalProtect app was used with an
embedded browser, the browser displayed can't reach page due to a
Windows filter driver issue.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20242</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect app displayed gibberish text on
the app.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20241</b></td>
<td class="entry relcol">
Resolved an issue where the GlobalProtect app did not detect HIP
information for HP Wolf Security software.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20178</b></td>
<td class="entry relcol">
Resolved an issue where the Certificate Revocation List was sent to a
URI that was not an exact match with the URI in the certificate.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20163</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect app was unable to connect to the
gateway via IPv6.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20162</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect enforcer blocked some DHCPv6
packets on Windows computers.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20157</b></td>
<td class="entry relcol">
Fixed an issue where the gateway location was not correctly displayed in
the Connections panel.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20143</b></td>
<td class="entry relcol">
Fixed an issue where the user was redirected to the Authentication page
twice on the default browser for both portal and gateway authentication
when SAML was configured.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20091</b></td>
<td class="entry relcol">
Fixed an issue where pre-logon failed when the computer was rebooted,
when the machine store had an expired and active certificate.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20080</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect logs displayed different event
messages for Windows and macOS devices when the
<span class="ph uicontrol"
>Allow User to Disable GlobalProtect App</span
>
was set to <span class="ph uicontrol">Allow with Passcode</span> for the
GlobalProtect app.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20060</b></td>
<td class="entry relcol">
Fixed an issue where it was possible for the GlobalProtect enforcer to
be disabled when there was a network change during portal
authentication.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20040</b></td>
<td class="entry relcol">
Resolved an issue where GlobalProtect did not re-check for internal
gateways when using cached portal configuration and an external network
was previously detected.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20028</b></td>
<td class="entry relcol">
Fixed an issue where macOS users, despite having 'Allow User to Change
Portal Address' set to No, were able to choose a different portal from
the existing list.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20005</b></td>
<td class="entry relcol">
Fixed an issue where, when the GlobalProtect app was installed on
Windows devices, users were able to select the manual gateway and
connect to the app even when the regional or global fall back gateway
was not configured.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20004</b></td>
<td class="entry relcol">
Fixed an issue where both certificates with and without the specified
OID were incorrectly being selected as potential machine certificates.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20003</b></td>
<td class="entry relcol">
Fixed an issue where GlobalProtect users with certificates were unable
to connect a gateway on version 6.0.9.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19991</b></td>
<td class="entry relcol">
Fixed an issue where client certificate authentication between embedded
browser and IdP (SAML) failed.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19972</b></td>
<td class="entry relcol">
Fixed an issue where users were unable to connect to Prisma Access after
a break and had to reboot their computer.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19961</b></td>
<td class="entry relcol">
Fixed an issue where the hamburger menu on the GlobalProtect app was
disabled and end users were unable to click on the Report an Issue
option when the GlobalProtect app was disabled in Alway-On mode.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19930</b></td>
<td class="entry relcol">
Fixed an issue where the HIP check did not detect the BitLocker disk
encryption correctly during windows update, causing the device to fail
the HIP check.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19918</b></td>
<td class="entry relcol">
Fixed an issue where, when the GlobalProtect app was installed on
devices running macOS, the HIP check did not detect CrowdStrike
antivirus software correctly, causing the device to fail the HIP check.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19889</b></td>
<td class="entry relcol">
Fixed an issue where, when the GlobalProtect app was installed on
Windows machine and Connect Before Logon (CBL) was configured for the
app, the app did not start properly when the user logged on to the
device.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19878</b></td>
<td class="entry relcol">
Fixed an issue where a typo in the IP address exclusion list was not
marked as invalid by the GlobalProtect enforcer, resulting in all IP
addresses in the range being allowed.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19833</b></td>
<td class="entry relcol">
Fixed an issue where, when the GlobalProtect app was installed on
Windows devices, the Smart card (Yubikey) authentication did not work
when the device woke up from sleep mode.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19829</b></td>
<td class="entry relcol">
Fixed an issue where the manual gateway login failed when users tried to
login using their user name and password.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19751</b></td>
<td class="entry relcol">
Fixed an issue where the programmatic and visual label for the
GlobalProtect form field was not announced.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19740</b></td>
<td class="entry relcol">
Fixed an issue where, when the GlobalProtect app was installed on VDI
devices running Windows OS, the GlobalProtect app got disconnected
without displaying any message.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19696</b></td>
<td class="entry relcol">
Fixed an issue where, when the GlobalProtect app was installed on
endpoints running macOS and the split tunnel was configured based on the
application for Zoom, users were unable to access any sites when the
split tunnel was disabled for Zoom and moved to full tunnel.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19660</b></td>
<td class="entry relcol">
Fixed an issue where the "Check for Updates" button on GlobalProtect app
version 6.2.2 did not work when the activated GlobalProtect version on
the firewall was earlier than 6.2.2.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19652</b></td>
<td class="entry relcol">
Fixed an issue where, when the GlobalProtect app was installed on
devices running macOS, users were unable to access the applications and
websites when the app got disconnected and reconnected while switching
the medium from wired to wireless and vice versa.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19629</b></td>
<td class="entry relcol">
Fixed an issue where, when the GlobalProtect app was installed on
devices running macOS, the split tunnel feature did not work as expected
when Jamf was used to push the configuration policy rules.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19610</b></td>
<td class="entry relcol">
Fixed an issue where, when the GlobalProtect app was installed on
devices running macOS, end users were not prompted to enter a password
and the app got stuck in Restoring VPN connection state until the cookie
was deleted.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19603</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect app displayed a generic SAML
login page and not the actual login page for authentication and the
connection was not established when cached portal configuration was
used.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19436</b></td>
<td class="entry relcol">
Fixed an issue where the screen reader could not identify the image in
the GlobalProtect app tray on the devices running macOS causing
accessibility issues.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19532</b></td>
<td class="entry relcol">
Fixed an issue where, after upgrading GlobalProtect via the portal
prompt, all traffic except DNS was being dropped because the new
GlobalProtect extensions were not being loaded.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19373</b></td>
<td class="entry relcol">
Fixed an issue where the HIP remediation pop up is displayed even when
the user is disconnected.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19373</b></td>
<td class="entry relcol">
Fixed an issue where the HIP remediation pop up is displayed even when
the user is disconnected.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19336</b></td>
<td class="entry relcol">
Fixed an issue where the ADEM portal did not display user information
such as User-ID when the ADEM portal was changed from on-premises to
Prisma Access.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19279</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect client was not displayed during
the upgrade from version 6.0.5-35 to 6.0.8-601.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19237</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect app did not disconnect when the
user used the Disable option on the hamburger menu. The tunnel was still
up and connected even when the user disconnected the GlobalProtect app.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19138</b></td>
<td class="entry relcol">
Resolved an issue where the exclude for google application was not
working for users.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19098</b></td>
<td class="entry relcol">
Resolved an issue where pre-logon setup was not working when
GlobalProtect 6.2.1 was deployed via Microsoft Intune.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19043</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect app did not add all routes
configured in the access route to the route table.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19011</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect app on a Windows computer was
unable to connect to an IPv4 gateway behind a NAT64 device.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-18933</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect HIP check incorrectly detected
Real Time Protection for Cortex XDR, which caused the device to fail the
HIP check.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-18778</b></td>
<td class="entry relcol">
Resolved an issue where devices supporting Modern Standby (Microsoft
Learn) crashed when they entered sleep mode while the VPN plugin had an
active connection and was sending data over its tunnel.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-18728</b></td>
<td class="entry relcol">
Fixed an issue where the I Agree option on the GlobalProtect app
Welcome page did not work as expected when the user selected the option
using a keyboard.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-18702</b></td>
<td class="entry relcol">
Fixed an issue where, when the GlobalProtect app was installed on
Windows devices, the “Allow Manually upgrade failed when the user tried
to upgrade the GlobalProtect app version from 6.0.5 to 6.0.7
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-18625</b></td>
<td class="entry relcol">
Fixed an issue where the Zoom app intermittently stopped connecting on
macOS and displayed an error message.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-18385</b></td>
<td class="entry relcol">
Fixed an issue where, when the GlobalProtect app got reconnected after
the user changed the network access from Wi-Fi (IPv4 only) to Ethernet
connection (Dual Stack IPv4 + IPv6), the IPv6 ip-user mapping was
missing on the firewall and only IPv6 ip-user mapping was available. The
user had to refresh the connection to resolve this issue.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-15750</b></td>
<td class="entry relcol">
Fixed an issue where a hyperlink in a HIP notification opened in the
GPO-disabled Internet Explorer 11 browser instead of the default
browser.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-14714</b></td>
<td class="entry relcol">
Fixed an error where the screen reader does the announce the status when
the radio button is selected for Network configuration, Routing table,
Sockets, and "Logs".
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,468 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 50%" />
<col style="width: 50%" />
</colgroup>
<thead class="thead">
<tr class="row">
<th class="entry">Issue ID</th>
<th class="entry">Description</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry"><b class="ph b">GPC-21656</b></td>
<td class="entry relcol">
Fixed an issue where an unexpected extra string was added to the end of
the MFA prompt.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21533</b></td>
<td class="entry relcol">
Fixed an issue where GlobalProtect connected and disconnected in a loop
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21483</b></td>
<td class="entry relcol">
Fixed an issue where users are intermittently unable to connect to
GlobalProtect and get stuck at the connecting stage.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21465</b></td>
<td class="entry relcol">
Fixed an issue where GlobalProtect is stuck in "Connecting... Finding
the Best Available Gateway".
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21442</b></td>
<td class="entry relcol">
Fixed an issue where there was a delay in GlobalProtect restoring
connectivity after the Windows host woke up from modern standby.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21443</b></td>
<td class="entry relcol">
Fixed an issue where GlobalProtect crashed when the PanGPS service was
stopped.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21414</b></td>
<td class="entry relcol">
Fixed an issue where GlobalProtect using SAML authentication gets stuck
in a connecting loop upon the expiration of the authentication cookie.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21392</b></td>
<td class="entry relcol">
Fixed an issue where GlobalProtect is stuck in the connecting state for
2-3 minutes during Windows Pre-logon.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21387</b></td>
<td class="entry relcol">
Fixed an issue that prevented users from connecting to Wi-Fi networks
when GlobalProtect was disconnected.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21355</b></td>
<td class="entry relcol">
Fixed an issue where GlobalProtect was incorrectly showing as connected
during Windows pre-logon.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21301</b></td>
<td class="entry relcol">
Fixed an issue where after upgrading to GlobalProtect 6.2.4, users were
unable to connect to GlobalProtect intermittently when Enforcer is
enabled.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21247</b></td>
<td class="entry relcol">
Fixed an issue where HIP checks for Disk Encryption status were failing
after Windows and Mac hosts were rebooted, on low power mode or were
resuming from standby.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21206</b></td>
<td class="entry relcol">
Fixed an issue where GlobalProtect intermittently does not restore
connection after the user logs back in or wakes a Windows host.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21172</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect agent gets disconnected right
after successful connection when SAML embedded browser authentication is
used along with "Enforce GlobalProtect for Network Access".
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21161</b></td>
<td class="entry relcol">
Fixed an issue where the notifications prior to 'Login Lifetime
Expiration' and 'Inactivity Logout' were not displayed even when
enabled.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21101</b></td>
<td class="entry relcol">
Fixed an issue where the embedded browser pop-up with "Login Successful"
was displayed for each SAML authentication.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21057</b></td>
<td class="entry relcol">
Fixed an issue where HIP checks for Disk Encryption status were failing
on Windows during modern standby.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21035</b></td>
<td class="entry relcol">
Fixed an issue where GlobalProtect HIP did not identify the definition
version of the SentinelOne Agent.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21024</b></td>
<td class="entry relcol">
Fixed an issue where a HIP notification configured as "pop-up-message"
for pre-logon does not show up. The pop up window is blank.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21005</b></td>
<td class="entry relcol">
Fixed an issue where after submitting the SAML credentials, a blank
screen was displayed and GlobalProtect got stuck in that stage.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20991</b></td>
<td class="entry relcol">
Fixed an issue where the 'Extended Key Usage OID' value for certificate
selection was deleted during an upgrade of the GlobalProtect agent. This
forces users to have to manually select the correct certificate tp be
used for authentication.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20988</b></td>
<td class="entry relcol">
Fixed an issue where GlobalProtect failed to resolve DNS queries when
the 'Allow traffic to specified FQDN when Enforce GlobalProtect
Connection for Network Access is enabled and GlobalProtect Connection is
not established' configuration is set.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20983</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect app remains stuck in the
connecting stage when Windows computer resumes from sleep.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20943</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect enforcer blocked DHCP packets.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20895</b></td>
<td class="entry relcol">
Fixed an issue where GlobalProtect users on macOS were able to add and
modify the portal address even when portal agent configuration was
"Allow User to Change Portal Address = NO".
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20884</b></td>
<td class="entry relcol">
Fixed an issue where users get disconnected a few seconds after logging
in to VDI when GlobalProtect connects. They are unable to reconnect
after that.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20864</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect embedded browser login window did
not stay pinned to the front of all open windows on Windows and MAC
computers.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20839</b></td>
<td class="entry relcol">
Fixed an issue where system extensions on MacBooks were not updated upon
GlobalProtect app upgrade.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20838</b></td>
<td class="entry relcol">
Fixed an issue where the HIP report generation was taking longer than
the 'Max Wait Time' on Windows devices when anti-malware and disk
encryption checks are configured.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20771</b></td>
<td class="entry relcol">
Fixed an issue where GlobalProtect 6.2 users on Windows 11(ARM &amp;
Intel) devices cannot connect to GlobalProtect due to "The Parameter is
incorrect" error.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20770</b></td>
<td class="entry relcol">
Fixed an issue where certain GlobalProtect HIP checks on Windows devices
failed when there was no internet connectivity.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20741</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect app intermittently disconnects
from the gateway when using the embedded browser for SAML
authentication.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20736</b></td>
<td class="entry relcol">
Fixed an issue where users are being logged out from GlobalProtect when
the device wakes up from modern standby and network discovery happens.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20700</b></td>
<td class="entry relcol">
Fixed an issue where macOS users had to enter the SAML username and
password each time they refreshed or rebooted their computer especially
when using Safari or Embedded browser.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20692 </b></td>
<td class="entry relcol">
Fixed an issue where GlobalProtect 6.2.3 with SAML authentication (via
Okta) opens the embedded browser page in the background instead of the
foreground.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20645</b></td>
<td class="entry relcol">
Fixed an issue where GlobalProtect app in macOS is stuck in connecting
state when the device wakes up from sleep.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20626</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect client overwrites valid
authentication override cookie with empty authentication override cookie
from portal when using cached portal configuration.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20601</b></td>
<td class="entry relcol">
Fixed an issue where macOS users are unable to connect to GlobalProtect
after upgrading from version 6.2.2 to 6.2.3 via JAMF.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20595</b></td>
<td class="entry relcol">
Fixed an issue where GlobalProtect users were unable to connect after
upgrading to 6.2.3-270 and received a "Your internet access is blocked"
error during SAML authentication using the embedded browser.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20550</b></td>
<td class="entry relcol">
Fixed an issue where Zoom and Outlook apps intermittently stop
connecting on macOS with an error "You are unable to connect to Zoom.
Please check your network connection and try again" when the apps are
excluded under both domains and applications.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20466</b></td>
<td class="entry relcol">
Fixed an issue where when the tunnel is broken on Windows computers in
modern standby mode, the Enforcer does not work even when it is enabled.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20442</b></td>
<td class="entry relcol">
Fixed an issue on appliances running PanOS 10.1.11-h1 and GlobalProtect
6.0.10-811 where the tunnel status failed to update to connected
immediately after establishment. This problem was specific to IPv4-only
clients connecting to dual-stack (IPv4 + IPv6) GlobalProtect gateways or
portals.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20441</b></td>
<td class="entry relcol">
Fixed an issue where HIP reports are sometimes not available on the
firewall for newly connected users.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20416</b></td>
<td class="entry relcol">
Fixed an issue where there is no network discovery once the laptop came
out of standby.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20360</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect app is stuck in the connecting
status after authentication and does not connect until the app is
restarted or the computer is rebooted.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20292</b></td>
<td class="entry relcol">
Fixed an issue where RDP to Azure VDI clients disconnects when
GlobalProtect is enabled on the VDI client with SAML authentication and
with 'Enforce GlobalProtect for Network Access' enabled
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20191</b></td>
<td class="entry relcol">
Fixed an issue where PanGPA.exe crashes on Windows clients
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20114</b></td>
<td class="entry relcol">
Fixed an issue where GlobalProtect on MacOS was incorrectly selecting
client certificates without a private key for certificate
authentication.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20112</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect HIP check incorrectly detected
Real time protection status for Kaspersky Endpoint Security, which
caused the device to fail the HIP check.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20072</b></td>
<td class="entry relcol">
Fixed an issue where domain-based split tunneling was not working on MAC
with Edge Chromium or Google Chrome browser though it was working on
Safari.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19819</b></td>
<td class="entry relcol">
Fixed an issue where SAML default browser IDP traffic is blocked during
a refresh connection when GlobalProtect is connected to the internal
network with 'Enforce GlobalProtect for Network Access' enabled.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19269</b></td>
<td class="entry relcol">
Fixed an issue where GlobalProtect would show as "connecting" but never
actually connect until the user restarted GlobalProtect on their Windows
machine.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-18943</b></td>
<td class="entry relcol">
Fixed an issue where GlobalProtect would fail to connect on Windows
hosts that were woken up from modern standby by initiating an RDP to the
host.
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,285 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 50%" />
<col style="width: 50%" />
</colgroup>
<thead class="thead">
<tr class="row">
<th class="entry">Issue ID</th>
<th class="entry">Description</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry"><b class="ph b">GPC-21774</b></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect ARM64 installers for 6.2.5
version did not display
<span class="ph uicontrol">Digital Signatures</span> tab.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21721</b></td>
<td class="entry relcol">
<div class="p">
Fixed an issue, where the GlobalProtect app got stuck in Connecting
status when the device woke up from sleep mode.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21731</b></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app is stuck in the
<span class="ph systemoutput">Connecting</span> status when upgraded
to 6.2.5-788 version and the users had to reboot the system to resolve
the issue.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21665</b></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect app was installed on
devices running macOS and the app was used with Trellix Proxy Agent,
the web browser displayed the following error,
<span class="ph uicontrol">ERR_SOCKET_NOT_CONNECTED</span>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21636</b></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the users were unable to login Windows 11 using
the User Principal Name (UPN) when GPCP was selected with
GlobalProtect app version 6.2.4 and
<span class="ph uicontrol"
>Interactive logon: Don't display last signed-in</span
>
was enabled in their Entra ID - group policy.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21604</b></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect app was installed on
devices running macOS and were connected to the internal gateway, the
app did not display the
<span class="ph uicontrol">Disconnect</span> option under
<span class="ph uicontrol">Settings</span>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21413</b></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect Credential Provider did not
reset focus on the password field when the user entered the wrong
password.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21375</b></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Windows SSO did not work when the SAML
authentication method was used to authenticate to the app. The
username retrieved from SAML was not matching configuration selection
criteria causing authentication issues.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21332</b></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect HIP check incorrectly detected
Real Time Protection status for Avast and XProtect, which caused the
device to fail the HIP check.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21320</b></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect HIP check did not detect
Kaspersky Endpoint Security antimalware application which caused the
device to fail the HIP check.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21281</b></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app got stuck in the
<span class="ph systemoutput">Connecting</span> status when the user
refreshed the connection.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21267</b></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the user installed the GlobalProtectARM
installer from the Customer Support Portal (CSP) and the user opened
GlobalProtect using the Start menu, the icon file (PanGPA.ico) was
opened instead of the executable (PanGPA.exe) file.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21247</b></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect HIP set the Filevault encryption
status to unencrypted on macOS running devices, which denied access to
the end-point machines.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21240</b></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect app was installed on
devices running macOS Sonoma 14.5, the app used the old FQDN names and
got stuck in the
<span class="ph systemoutput">Connecting</span> status instead of
prompting the user to enter the portal FQDN name.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21222</b></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect HIP check incorrectly detected
the Real Time Protection Status and Last Full Scan for Avast
application, which caused the device to fail the HIP check.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21811</b></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the PanGPS stopped working soon after the
GlobalProtect was installed on the endpoint and the GlobalProtect app
got stuck in the
<span class="ph systemoutput">Connecting</span> stage.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21174</b></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect HIP check did not detect Real
time protection status for Acronis Cyber Protection Agent, which
caused the device to fail the HIP check.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21131</b></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the users were unable to access the Advanced
Logging Settings screen of the GlobalProtect app using the
<span class="ph uicontrol">ctrl + tab</span> key combination on the
keyboard. The screen reader did not announce the keyboard options
correctly.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21106</b></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect HIP check did not detect 'Real
Time Protection' status for Malwarebytes anti-malware application,
which caused the device to fail the HIP check.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20783</b></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the password field was not automatically selected
for typing when using the embedded browser, requiring users to click
inside the field before entering their password
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20779</b></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Windows regional settings are not respected by
Webview 2 on SAML embedded browser resulting in regional
language(French, German, Chinese, Spanish, and Japanese) not loading
properly in embedded browser.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20674</b></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where all GlobalProtect portals except for the
currently connected portal were deleted during the upgrade from 6.2.2
to 6.2.3 or from 6.2.3 to 6.3.0.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-18647</b></td>
<td class="entry relcol">
<div class="p">
Fixed an issue with GlobalProtect App Log Collection feature where the
user reported an issue using
<span class="ph uicontrol">Report an Issue</span> option on the
GlobalProtect app and the issue was not reported as expected.
</div>
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,106 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 50%" />
<col style="width: 50%" />
</colgroup>
<thead class="thead">
<tr class="row">
<th class="entry">Issue ID</th>
<th class="entry">Description</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry"><b class="ph b">GPC-22107</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect agent was unable to validate the
server certificate after the CVE-2024-5921 remediation was applied.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-22104</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect HIP report failed to detect the
Seqrite Endpoint Protection application, when the application was
upgraded to a higher version 18.00 (14.0.0.1)
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-22082</b></td>
<td class="entry relcol">
Fixed an issue where GlobaProtect did not validate certificates with 3rd
parties or PKI and displayed a FIPS error.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-22079</b></td>
<td class="entry relcol">
Fixed an issue where users were unable to connect to the GlobalProtect
app due to Captive Portal connectivity issues.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-22046</b></td>
<td class="entry relcol">
Fixed an issue where when the GlobalProtect app was installed on devices
running macOS and the app version was upgraded to 6.2.5, end users were
unable to connect the app. The app got stuck in the Connecting state and
displayed the following message, “You are redirected to an embedded
browser to authenticate and connect.”
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-22010</b></td>
<td class="entry relcol">
Fixed an issue where loopback connection did not work when Endpoint
Traffic Policy Enforcement was enabled.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21950</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect connection on MacOS Sequoia 15+
was unstable.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21778</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect IPSec tunnel got disconnected on
GlobalProtect app version 6.2.5 when the<span class="keyword cmdname">
gpupdate /force</span
>
command was used to update a policy.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-21284</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect gateway did not receive the HIP
reports from the user correctly due to which the end users were unable
to access the resources even when the sessions were active.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20592</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect app could not establish the
tunnel and the app got stuck in the tunnel creation stage. The app
displayed the following error, “ The virtual adapter was not set up
correctly due to a delay.”
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,259 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 50%" />
<col style="width: 50%" />
</colgroup>
<thead class="thead">
<tr class="row">
<th class="entry">
<div class="p">Issue ID</div>
</th>
<th class="entry">
<div class="p">Description</div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-23215</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, the traffic stopped passing through the
GlobalProtect app on macOS devices after upgrading to GP 6.2.8 and
when the computer screen was locked.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-23174</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect failed to detect DNS during the
Network Detection stage, causing the GlobalProtect app to stop
working.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-23161</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app stopped working after a
session change.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-23088</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the portal login user authentication failed after
cookie expiration.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21982</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue in which IPv6 traffic bypassed the valid route in the
rerouting table and instead passed through the physical adapter when
the GlobalProtect app was installed on Windows devices.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-23046</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where users experienced connectivity problems when
GlobalProtect was used in a WiFi network with captive portal.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-23034</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect embedded browser did not
display certificate selection pop-up when there were multiple client
certificates available.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-23032</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect agent restarts when the device
wakes up from Modern Standby.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-23011</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue wherein wherein the Enforcer intermittently failed to
promptly block network access as configured, thereby resulting in
delays of 1 to 5 minutes before eventually blocking the traffic flow.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-22800</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect app was configured with
enforcer and Captive Portal, users faced issues in connecting to
Captive Portal using GlobalProtect.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-22610</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after an upgrade, GlobalProtect restarted and
failed to connect to the portal
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-22595</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where users were unable to select the correct client
certificate when using the GlobalProtect app on Windows devices and
connected to the internal network using SAML embedded browse
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-22536</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where users faced connectivity issues when the
GlobalProtect app version 6.2.6 was installed on devices running macOS
15.3.1
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-22365</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where users experienced intermittent issues browsing
webpages while connected to the GlobalProtect app.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-22294</b></div>
</td>
<td class="entry relcol">
<div class="p">
. Fixed an issue where intermittent internet access problems occurred
when the macOS was upgraded to 15.2 and the GlobalProtect app version
to 6.2.6.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21766</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the split tunnel excluded routes go missing from
routing table on Windows machine at intermittent times.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21755</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect users with enforcer enabled were
able to access applications that were not in the enforcer exception
list.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21737</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the SAML redirection page opened up on end user
computers even though they did not have internet connectivity.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-19024</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app incorrectly used an
embedded WebView instead of the system default browser for Captive
Portal logins.
</div>
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,150 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 50%" />
<col style="width: 50%" />
</colgroup>
<thead class="thead">
<tr class="row">
<th class="entry">
<div class="p">Issue ID</div>
</th>
<th class="entry">
<div class="p">Description</div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry"><b class="ph b">GPC-23294</b></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect app intermittently disconnected on
macOS endpoints even with a stable network connection. This was due to
a timeout that was too short for the route system command.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-23270</b></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect app version 6.3.3 using SAML with
the embedded browser would lose cursor focus in the password field,
requiring users to click in the password field before entering their
password.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-23191</b></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect took almost 2 minutes to reconnect
to an already connected gateway after a host reboot.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-23115</b></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the hardware token authentication option was
intermittently unavailable while using the embedded GlobalProtect
browser on Windows machines.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-23044</b></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when a machine was in Modern standby, the
GlobalProtect app repeatedly attempted to connect to gateways, even
when authentication failed due to SAML timeout. This resulted in
GlobalProtect connecting to non-optimal gateway
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-22763</b></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect prompted for credentials instead of
using authoverride cookie when authenticating to the best available
gateway.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-22522</b></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading from GlobalProtect app version
6.1.2 to 6.2.6, external users on Windows 11 computers with multiple
Azure Entra accounts were unable to authenticate to the portal using
SAML with Azure Entra as the Identity Provider (IdP). The new WebView2
embedded browser automatically used the user's default Windows
credential for Single Sign-On (SSO), preventing them from selecting
the correct account for authentication.To resolve this issue a new
registry key 'entra-sso' has been introduced. You can add the registry
key using two methods and set it to no to disable SSO.
<ul
id="globalprotect-app-6-2-8-h2-6-2-8-c243-windows-and-macos-addressed-issues_ul-tzk_b2y_rfc"
class="ul"
>
<li class="li">
For pre-deployment, use
<b class="ph b"
>msiexec.exe /i globalprotect64.msi ENTRASSO="no"</b
>
</li>
<li class="li">
Add key <b class="ph b">entra-sso</b> and set it to
<b class="ph b">no</b>under
<b class="ph b"
>HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto
Networks\GlobalProtect\Settings</b
>.
</li>
</ul>
</div>
<div class="p">
If the <b class="ph b">entra-sso</b> key does not exist under the
above path, the GlobalProtect app's default behavior is to
<b class="ph b">Allow</b> Entra SSO.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-22066</b></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the HIP check detected an incorrect real-time
protection status for Windows Defender ATP and CrowdStrike Falcon
anti-malware software, which could incorrectly mark non-compliant
devices as compliant.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-22029</b></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Apple software downloads took longer to complete
when using GlobalProtect with split tunneling enabled.
</div>
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,215 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 45.04504504504505%" />
<col style="width: 54.95495495495496%" />
</colgroup>
<thead class="thead">
<tr class="row">
<th class="entry">
<div class="p">Issue ID</div>
</th>
<th class="entry">
<div class="p">Description</div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23604</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect users were not automatically
prompted for authentication on public Wi-Fi networks with a captive
portal.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23520</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where new GlobalProtect users were unable to connect to
the GlobalProtect app. The app got stuck in
<span class="ph uicontrol">Connecting</span> stage and stopped working
when redirected to the embedded browser.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23496</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app's
<span class="ph uicontrol">Connect</span> button did not work as
expected preventing users from connecting or changing gateways.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23440</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Okta FastPass authentication did not work with
GlobalProtect 6.3.3 on macOS 15.5 Sequoia, where the Okta Verify app
did not open for the additional authentication prompt.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23466</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect app was installed on
devices running Windows OS and macOS, the Captive Portal detection
message briefly appeared and disappeared when the Captive Portal
exception timeout was set to 0.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23432</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app version 6.3.3
intermittently got stuck on the
<span class="ph uicontrol">finding best gateway</span> status
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23365</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect app was installed on
Windows machines, the app intermittently disconnected and then
reconnected with the error message
<span class="ph uicontrol">Failed to create exclude route</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23301</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect app 6.2.7 and later, was
installed on Windows 10 devices, the app deleted the predefined proxy
PAC file configuration whenever the app got disconnected regardless of
whether the disconnection was initiated manually or occurred
automatically due to a timeout.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23263</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where after upgrading to GlobalProtect app version
6.3.3, the app did not save the username in the embedded browser when
"<span class="ph uicontrol">Save Username</span> was enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23218</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when using the GlobalProtect app with an
embedded browser, interrupting or canceling the SAML authentication
prompt terminated the pre-logon tunnel, potentially allowing full
internet access even when enforcer was enabled for the user-logon
profile. With default browser, the pre-logon tunnel remained active
when the SAML authentication prompt was interrupted.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23125</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect did not remove older versions of
the WebView2 component from the
<span class="ph systemoutput"
>%LOCALAPPDATA%\Palo Alto Networks\GlobalProtect\GPAEdge</span
>
directory, which led to unnecessary disk space consumption over time.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-22989</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app intermittently stopped
sending HIP reports while connected to the gateway.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-22979</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading to GlobalProtect app version
6.2.6, the PanGPA application got stuck in
<span class="ph uicontrol">Connecting</span> 'state and then got
terminated unexpectedly.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-22541</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Windows 11 where the GlobalProtect app (PanGPA)
would stop working when the device was locked. The crash occurred when
an expired authentication triggered a persistent smartcard login
dialog during sleep, leading to excessive memory swapping and a
crypt32.dll failure.
</div>
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,361 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 42.5531914893617%" />
<col style="width: 57.446808510638306%" />
</colgroup>
<thead class="thead">
<tr class="row">
<th class="entry">
<div class="p">Issue ID</div>
</th>
<th class="entry">
<div class="p">Description</div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23839</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue that caused the GlobalProtect 6.3.3 HIP report to fail
with the error Method:
<span class="ph uicontrol">WAAPI_MID_GET_AGENT_STATE</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23786</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">agent-msg</span> log (<span
class="ph menucascade"
><span class="ph uicontrol">Panorama</span
><span class="ph uicontrol">Monitor</span
><span class="ph uicontrol">GlobalProtect</span></span
>) was not generated when a user disabled the GlobalProtect app and
logged out of the gateway.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23760</b></div>
</td>
<td class="entry relcol">
<div class="p">
GlobalProtect app version 6.3.3 using SAML with the embedded browser
loses cursor focus in the password field, requiring users to click in
the password field before entering their password.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23752</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app failed to authenticate to
the portal and gateway after a machine certificate was renewed by
Intune MDM. A reboot was required to restore the connection.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23746</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect HIP check incorrectly detected
status for Symantec Endpoint Protection, which caused the device to
fail the HIP check.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-23646</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app ignores the new
gateway-generated authentication override cookie and continues to use
the old, expired portal cookie when using the cached portal
configuration. As a result, the authentication override cookie
generated by a successful SAML authentication to a gateway is replaced
by the old, expired portal cookie during successive authentications,
causing the gateway to prompt for SAML authentication repeatedly.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-23616</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect app was installed on
devices running macOS, the following error
<span class="ph uicontrol"
>TransparentProxy: openWithLocalEndpoint failed</span
>
occurred in <span class="ph systemoutput">PanNExt.log</span> when
using an IPv6 address.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23583</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the pre-login tunnel rename timeout notification
would overlay other system tray icons, preventing users from accessing
them
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23558</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect clients using SAML with Ping
Federate did not save the SAML token upon reboot or restart of the
pangps service, requiring users to re-authenticate even when the token
was not expired. This issue affected GlobalProtect app version 6.3.3
when SAML authentication was configured in Prisma Access and not in
Cloud Identity Engine.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23519</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect HIP reports on MacBooks
intermittently failed with an
<span class="ph uicontrol">Invalid client IP</span> error, preventing
users from accessing resources over the GlobalProtect tunnel. This
issue occurred after a system network change when GlobalProtect
attempted to send the HIP report to an external gateway while the
tunnel was disconnected. This issue affected MacBooks running
GlobalProtect version 6.2.5.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23514</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when using a screen reader on Windows or macOS,
the GlobalProtect app's
<span class="ph uicontrol">Settings</span> button did not announce the
available options for the end users.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23488</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the HIP report intermittently detected MacOS
XProtect Real Time Protection status as disabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23468</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect HIP check failed to detect the
correct version of Forticlient Antivirus, which caused the device to
fail the HIP check.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-23441</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect installation failed after a
transparent upgrade automatically uninstalled the previous version.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23428</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the username and password fields in the
GlobalProtect app had incorrect labels.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23417</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SAML authentication with Azure AD, using Cisco
Duo EAM, failed after upgrading to GlobalProtect version 6.2.8
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23404</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Host Information Profile (HIP) check was
unable to accurately identify key details from third-party security
products.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23403</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect HIP report failed to detect the
status of SentinelOne, causing the device to fail the HIP check
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23361</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect HIP report did not detect the
Status for Zoho corporation - ManageEngine Patch Manager Plus Agent,
which caused the device to fail the HIP check.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-23283</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect was unable to set [exclude/include]
0.0.0.0/netmask routes on Mac endpoint.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-23142</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where an Explicit Proxy token refresh would fail with
the message EP TOKEN configuration is NULL, causing the GlobalProtect
app to get stuck in a
<span class="ph systemoutput">Connecting</span> state.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23095</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed and issue where the GlobalProtect HIP report failed to detect
the Symantec DLP software, which caused the device to fail the HIP
check.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-22353</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a comment was not visible in the GlobalProtect
logs when GlobalProtect was disabled with-comment.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-21745</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect HIP check failed to detect
Workspace ONE status, which caused the device to fail the HIP check.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-20617</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a notification appeared on the GlobalProtect app
every 10 seconds asking the end-user to re-authenticate. This
notification appeared during the pre-logon tunnel rename timeout
period.
</div>
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,321 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 41.66666666666667%" />
<col style="width: 58.333333333333336%" />
</colgroup>
<thead class="thead">
<tr class="row">
<th class="entry">
<div class="p">Issue ID</div>
</th>
<th class="entry">
<div class="p">Description</div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24581</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect disable agent messages were not
reported to firewall when machine certificate authentication with full
chain certificate validation was enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-24332</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where users on trusted networks were incorrectly
receiving a captive portal detection message and being redirected to a
separate browser tab. This occurred because the GlobalProtect app was
not properly handling captive portal detection response.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24330</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect app got stuck in a connecting state
when using GlobalProtect version 6.2.8-h4. The issue was seen when
saml-logout and enforcer was enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-24261</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect app running on macOS Sequoia 15.6.1
running GP 6.2.8 -c263 that receive both IPv4 and IPv6 addresses were
not receiving packets back from the Network Load Balancer (NLB)
instances.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24221</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app experienced a continuous
connect-disconnect loop when used on flights. This issue occurred
because rapid network wake-ups left network interfaces in an
inconsistent state, causing GlobalProtect to attempt tunnel
establishment on an unstable network foundation.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24103</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app running on macOS allowed
users to modify or add a new portal address after each device reboot,
even when the
<span class="ph uicontrol">Allow users to change portal</span> setting
was configured as <span class="ph uicontrol">No</span> in the
GlobalProtect app.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24048</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect apps installed on on Dell Vostro 15
3515 laptops were unable to connect to the GlobalProtect service with
the following error:
<span class="ph uicontrol"
>Could not connect to the GlobalProtect service. If the issue
persists, contact your administrator</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24037</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect app prompted users to log in with
SAML through the embedded browser even when the GlobalProtect app was
already connected. This occurred when users logged off and then back
onto their Cloud PC (Windows Azure PC), and closing the prompt
disconnected and reconnected the VPN session.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24036</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the HIP check did not correctly detect the status
of the ESET firewall on Windows hosts.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23990</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the captive portal opened in the embedded
browser, but when the user tried to connect to the internet, it
redirected to the default browser and was blocked.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23929</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when GlobalProtect app was configured with
Enforcer, users could bypass Enforcer restrictions by repeatedly
canceling authentication prompts after logging into Windows. This
occurred because the cached portal configuration, which contains
Enforcer settings, was not loaded when a pre-logon tunnel failed to
establish due to a quick user login. This fix ensures that the cached
portal configuration is loaded as soon as PanGPA starts and PanGPS
learns the username, preventing unrestricted access in scenarios where
Enforcer is intended to lockdown the endpoint.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23730</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where IPv6 traffic on Windows 11 24H2 did not work as
expected with GlobalProtect app.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23689</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app running on macOS devices
would stuck in a connecting loop indefinitely if the user did not
complete authentication, requiring manual cancellation of the
connection.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23650</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect enforcer blocked network
traffic on Windows endpoints even after the tunnel was successfully
connected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23525</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where on macOS Ventura and Sequoia, GlobalProtect app
versions 6.2.6-838, 6.2.7-1047, 6.2.8, and 6.3.3, manually changing
the portal address using the GlobalProtect app UI would fail and
revert back to the last connected portal. This issue occurred even
when
<span class="ph uicontrol">Allow User to Change Portal Address</span>
was enabled in the agent configuration.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23394</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect app version 6.2.8-183. running on
macOS 15.5 was unable to accurately report the disk encryption status
of FileVault, resulting in an
<span class="ph systemoutput">Unknown</span> status in HIP checks.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23336</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where agent disable logs were not being logged to
Gateway System Logs on the firewall. The GlobalProtect agent reset the
authentication code, which falsely indicated that the gateway was not
fully authenticated, and the agent did not send the message.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-22683</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where tool tips were not available for the
<span class="ph uicontrol">Add</span>,
<span class="ph uicontrol">Edit</span>, and
<span class="ph uicontrol">Delete</span> buttons on the GlobalProtect
application's settings page on Windows devices.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-22572</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the hamburger menu button was disabled in the
Refresh connection screen, which made it inaccessible when using a
keyboard.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-22021</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when using conditional-connect on macOS Sequoia
with GlobalProtect app version 6.2.6, manually switching gateways
caused the app to display a
<span class="ph systemoutput">Not Connected</span> status for
approximately 10 seconds while establishing a connection to the second
gateway.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-22010</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where loopback connection did not work when Endpoint
Traffic Policy Enforcement was enabled.
</div>
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,77 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row">
<th class="entry">
<div class="p">Issue ID</div>
</th>
<th class="entry">
<div class="p">Description</div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24859</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect HIP check did not detect the
Kaspersky signature information which caused the device to fail the
HIP check.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24827</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, on GlobalProtect client version 6.2.8-h3, HIP
checks for CrowdStrike Falcon or Microsoft/Windows Defender
intermittently took longer than expected to complete, sometimes
exceeding the default 20-second limit. This resulted in partial HIP
reports being sent to the gateway, causing connectivity issues for
users accessing internal resources or the internet.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24683</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Host Information Profile (HIP) matching failed
for Anti-Malware criteria on macOS endpoints due to GlobalProtect
failing to detect the virus definition version for Kaspersky
Anti-Virus.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23090</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app experienced connectivity
issues after the host computer resumed from sleep mode due to a
missing self-pointed route. This issue resulted in a delay of 5 to 10
minutes for the GlobalProtect connection to get stabilized.
</div>
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,318 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row">
<th class="entry">
<div class="p">Issue ID</div>
</th>
<th class="entry">
<div class="p">Description</div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-25063</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, in the GlobalProtect app on macOS, keyboard
focus did not automatically move to the required "Enter portal
Address" field when a user attempted to add a new portal without
entering an address. This accessibility issue impacted
keyboard-dependent users.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24961</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall, when configured to obtain IP
addresses from a DHCP server for GlobalProtect clients, sent a MAC
address of '00' to the DHCP server specifically for MacOS 26 (Tahoe)
clients running GlobalProtect App versions 6.2 or 6.3, which resulted
in IP address collisions on the DHCP server.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24897</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect Connect Before Logon tunnel
disconnected for new users on their first logon. This issue affected
GP client versions 6.2.8-hx and 6.3.3-hx.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24892</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect Portal welcome page, when
displayed in German, incorrectly presented a button labeled 'Genau'
instead of 'Zustimmen' (Accept).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24880</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect clients, after upgrading to
versions 6.2.8-263, 6.3.3-h2, or 6.3.3-h3, would get stuck in a
connecting loop and fail to connect to the portal or gateways. This
occurred because the GlobalProtect app crashed when attempting to
delete previous SAML user data, specifically when the user data folder
path contained non-ANSI characters that the app could not convert to a
UTF-16 path.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-24842</b></div>
</td>
<td class="entry relcol">
<div class="p">
(macOS only) GlobalProtect crashed when you clicked
<span class="ph uicontrol">Change Portal</span> on setups that
included two or more portal entries and had a preferred gateway
marked.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24835</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where split tunneling domain exclusions on
GlobalProtect App version 6.3.3-C711 for Windows clients failed to
function as expected after the application disconnected and
reconnected. This resulted in traffic for domains configured for
exclusion being incorrectly routed through the VPN tunnel instead of
directly, because the TTLMap for split tunneling domain rules was not
properly cleared when the GlobalProtect App re-established its
connection.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24515</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect clients on macOS devices,
specifically version 6.3.3-h2, were unable to resolve internal IPv6
domains when split tunneling was enabled and the operating system
lacked native IPv6 connectivity. This occurred because the client's
logic, which was designed to apply IPv6 configuration only when the OS
already had native IPv6 connectivity, prevented the GlobalProtect
tunnel from properly handling IPv6 traffic, resulting in "Err name not
resolved" errors for internal FQDNs.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24242</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect portal authentication failed for
some macOS users when attempting to use saved credentials. This issue,
observed on GlobalProtect client versions 6.2.8 and 6.3.3, resulted in
an immediate authentication failure on the client and firewall logs
indicating an invalid username or password, even though the
credentials were valid for other macOS clients.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24216</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Host Information Profile (HIP) banner was not
displayed on Windows 11 client machines running GlobalProtect client
versions 6.2.8-h7 and 6.3.3. This occurred due to a timing or race
condition where the GlobalProtect client (PanGPA) received an outdated
status, preventing the visual display of HIP match or not-match
notifications, even though the messages were recorded in the client
logs.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24144</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after a client machine regained internet access,
Network Discovery was skipped due to the fed-mandate-accept setting,
preventing automatic reconnection to the Prisma Access gateway. This
occurred when the device switched from a non-internet-accessible
Ethernet connection to a 5G connection.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-24083</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect clients intermittently failed
RADIUS authentication due to treating the portal challenge response as
a gateway challenge response. This resulted in incorrect handling of
the OTP response back to the server.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23963</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect Client version 6.2.8 running in
Windows 365 environments, would experience PanGPA getting stuck during
the tunnel rename process. This prevented successful gateway
authentication and registration after users closed and re-opened their
Windows 365 session, leading to a pop-up message prompting users to
re-authenticate.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23960</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect agent on macOS devices entered
a connecting loop when attempting to connect to an IPv6 gateway due to
a missing gateway preservation in the original script. This resulted
in the tunnel interface capturing the route to the gateway and an
infinite retry loop.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23909</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where AAAA DNS records were not working when connected
to GlobalProtect client versions 6.2.8-c243 or 6.2.8-c263, preventing
successful IPv6 connections. This issue occurred when split tunnel is
not configured, causing the IPv6 DNS settings to be incorrectly set.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23787</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect clients on macOS devices, after
upgrading to version 6.2.8-h2, were unable to connect to the
authentication server. This occurred because incorrect logic in the
GlobalProtect Agent code prevented the Webview Process ID from syncing
with the Network Extension process, causing the Network Extension to
block SAML authentication traffic, resulting in a "Could not connect
to the authentication server" error and a blank embedded browser
during SAML authentication.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-23723</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect clients running version 6.2.8-h1
(6.2.8-c223) experienced intermittent connection failures and
disconnections, with the client agent getting stuck in a 'connecting'
state even when backend logs indicated a successful connection. This
occurred because, when conditional connect mode was enabled, the
client attempted to impersonate a user and write On-Demand settings to
the user's registry hive (HKEY_CURRENT_USER) during pre-logon. As no
user was logged in at that stage, user impersonation failed, leading
to incorrect registry access or failed registry operations, which
caused service instability or misconfiguration.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-22424</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, on Windows endpoints running GlobalProtect,
roaming user profile data was not written or sent to the server shared
folder over SMB (TCP/445) during user logoff or system reboot when the
GlobalProtect client was connected to the internal corporate network.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-18976</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect client 6.1.1-5 would select the
incorrect Windows tile by default after locking the screen when using
Single Sign-On for Smart Card PIN (Windows) with the Yubikey Smart
Card Minidriver. When multiple smart cards were present, GlobalProtect
incorrectly selected the last enumerated card instead of the currently
active one.
</div>
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,256 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row">
<th class="entry">
<div class="p">Issue ID</div>
</th>
<th class="entry">
<div class="p">Description</div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-25324</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect client briefly displayed a
"Sign-out" option after the application was ended from the task
manager and restarted, even when the portal configuration had "Allow
users to sign-out" set to "No". This was caused by a race condition
during the client's initialization, where the sign-out button was
temporarily visible before the portal's configuration to disable it
could be loaded.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-25300</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect clients experienced frequent
disconnections from GlobalProtect gateways. After being disconnected,
users were often unable to reconnect for extended periods, and
connection attempts to designated gateways, including those manually
selected or identified as 'Best Available', would incorrectly redirect
to other gateways.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-25222</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect clients failed to detect captive
portals on public Wi-Fi networks, even when the captive portal
responded with an HTTP 302 Redirect. This occurred because the
GlobalProtect agent expected the HTTP response to be terminated by
`\r\n\r\n` as per RFC, but some captive portals did not adhere to
this, causing the agent to incorrectly report that no data was
received from the captive portal server and thus fail to detect the
portal.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-25215</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on macOS devices running the GlobalProtect agent and
has multiple physical interfaces, when Disable Local Subnet Access
(DLSA) feature was active, manually disabling the GlobalProtect agent
caused the client to lose routing information. This prevented the
client from reaching the GlobalProtect portal or gateway, even though
FQDN resolution was successful, resulting in "Network is unreachable"
errors and requiring a device reboot to restore connectivity.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-25172</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, on macOS GlobalProtect clients, exclude routes
were not properly removed from the system routing table after a PanGPS
(GlobalProtect client) crash. This occurred because the routes
remained in the macOS kernel, and upon reconnection, the client's
`checkExistingExRts()` function only validated the destination and
netmask, not the gateway. As a result, these stale routes, pointing to
an old or unreachable gateway, were marked as existing and skipped
during the reconnection process, leading to a corrupted routing state
and preventing correct route injection, especially after a network
change.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-25148</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect intermittently displayed a large
blank rectangle (bottom right side of the screen) on connection
failure on macOS 26 (Tahoe).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-25121</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect DNS proxy Network Extension on
macOS endpoints failed to start due to retaining an incorrect Process
ID (PID) for the GlobalProtect app (PanGPA) after PanGPA restarted.
This prevented split-tunnel exclude applications from functioning
correctly.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24845</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect users on Prisma Access
intermittently experienced "No user mapping" issues across multiple
gateways.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24659</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where macOS GlobalProtect clients failed to complete
transparent upgrades from a GlobalProtect portal because the download
of the upgrade package timed out.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24600</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where macOS GlobalProtect clients (versions 6.2.8 and
6.3.3) were stuck in a connecting state after the macOS device woke up
from sleep mode (Modern Standby), particularly when using Certificate
or SAML authentication, requiring a manual connection refresh.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24538</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect client, specifically versions
6.2.8 and 6.2.6-857, would crash immediately after installation on
Microsoft Windows 11 Pro (64-bit) endpoints. The `PanGPA` process
would exit due to a null pointer dereference, preventing the client
from launching.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24300</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect clients running version 6.2.8-h2,
when initially loading a pre-logon configuration, failed to correctly
apply traffic exclusion rules for specified FQDNs (such as Avaya VoIP
traffic), causing the excluded traffic to be sent through the
GlobalProtect tunnel instead of the physical interface. This occurred
because an internal driver event reset a flag, preventing additional
IP rules from being set, and was resolved after the GlobalProtect
connection was refreshed and the default configuration was loaded.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-24006</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where MacOS GlobalProtect clients, when configured for
Okta authentication with Prisma Access, intermittently failed to log
in after a previous log-off. This failure manifested as an "Okta
device not on-line" error, caused by the GlobalProtect client's
log-off process not completing gracefully, which resulted in the
client service not starting correctly on subsequent login attempts.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-25637</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where on macOS devices, after upgrading macOS to
version 26.3 (from 26.2), the GlobalProtect client was unable to
connect and displayed the error "Could not connect to the
GlobalProtect service.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-25196</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect client UI on macOS devices
would remain open in the dock and sometimes on top of other
applications after the device resumed from hibernation or sleep mode.
This behavior, observed in GlobalProtect client versions 6.2.8 and
6.3.2, was caused by the `globalClickMonitor` not being reset after
the device woke up, preventing the UI from properly minimizing or
closing.
</div>
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,732 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 50%" />
<col style="width: 50%" />
</colgroup>
<thead class="thead">
<tr class="row">
<th class="entry">
<div class="p">Issue ID</div>
</th>
<th class="entry">
<div class="p">Description</div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-22894</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobapProtect did not detect the correct version
of Kaspersky Endpoint Security.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-22847</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect did not detect Qualys for patch
management.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-22764</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where wa_3rd_party_host_xx.exe attempted to connect to
Microsofts update servers for information and the patch information
was not sent in the HIP report. This occured even though HIP
Exceptions for patch management were configured to exclude Windows
updates agent.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-22740</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where macOS computers displayed both the new and old
versions of the GlobalProtect welcome page.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-22688</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue for proxy-only mode where customers were unable to
access websites when the computer woke up from sleep.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-22638</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Global Protect HIP did not detect the drive state
when using Trellix Drive Encryption 8.0.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-22620</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect was not working correctly and
blocked internet access.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-22589</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Report an Issue functionality did not send
the troubleshooting log to the administrators Strata Logging Service
instance.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-22544</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect client did not send the HIP
report causing user-IP mapping to be cleared and resulting in traffic
drop.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-22542</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the embedded browser shown as part of SAML
authentication was blank.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-22487</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Norton 360 was not compatible with GlobalProtect
causing the device to fail the HIP check.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-22443</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect agent showed as connected even
when the virtual adapter was down.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-22437</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect macOS client experienced a
keep-alive timeout, preventing the tunnel from connecting.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-22412</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an error where virtual adapter is not set correctly during
tunnel creation.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-22297</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Customer was getting "A valid client
certificate is required for authentication" even though they had a
valid client certificate installed. In order to access the fix, you
must do one of the following:
<ul
id="globalprotect-app-6-2-8-windows-and-macos-known-issues_ul-dg3_rxb_cfc"
class="ul"
>
<li class="li">
uninstall the previous release (to remove all registry entries).
</li>
<li class="li">
manually delete the registry value
"ext-key-usage-oid-for-client-cert" under
"HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto
Networks\GlobalProtect\Settings" as it may contain a corrupted
value.
</li>
</ul>
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-22264</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect HIP report did not detect the
last full scan time for Avast antivirus software.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-22245</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where transparent upgrade from GlobalProtect version
6.2.4 or 6.2.5 to version 6.2.6 failed on some Windows endpoints with
error 1618.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-22237</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect shut down unexpectedly on Windows
11 devices running multiple versions of GlobalProtect 6.3. The issue
was caused by the firewall sending invalid IPv6 packets to
GlobalProtect, which did not have a validation method before
processing.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-22235</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where users were unable to connect to the app after the
system woke up from sleep mode.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-22233</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the users were unable to connect the
GlobalProtect app after performing the resolution of CVE-2024-5921.
The app displayed the following error, “The certificate CN name
mismatch.”
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-22126</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect version 6.2.6-838 was stuck
intermittently during the connection process.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-22123</b></div>
</td>
<td class="entry relcol">
<div class="p"></div>
Fixed an issue where the GlobalProtect app got stuck and users faced
connection issues after the system woke up from sleep mode even though
the internet connection was stable.
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-22092</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app failed to validate the
server certificate when the portal or gateway sent only the leaf
certificate.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-22061</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect client displayed an error when
using an ECDSA certificate with explicit EC parameters in FIPS mode.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-22043</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Okta push notification shows incorrect Windows
OS, when Okta SAML authentication is enabled in GlobalProtect.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-22036</b></div>
</td>
<td class="entry relcol">
<div class="p">
Resolved an issue where GlobalProtect did not populate the internal
routes in the user's routing table.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-22028</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the disconnect reason for macOS users was getting
cached.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21988</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect Client displayed a download
prompt or was updated even with an "upgrade disallow" configuration.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21979</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the included domain traffic was routed through
the physical interface when split tunnel was configured.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21961</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading to GlobalProtect version 6.2.5,
the app triggered authentication and opened multiple browser tabs when
the computer woke from sleep.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21960</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the HIP check failed to detect the Norton
anti-malware version 24.11.9615.0.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21955</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the HIP notification pop-up on macOS looked
different from that on Windows.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21938</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect app version 6.3.x was
installed on devices running macOS, the HIP check failed to detect
ESET Endpoint Security version 8.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21918</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the patch management category was excluded
for HIP checks, HIP checks were still happening for missing patches
which consumed CPU resources on users' machine.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-21938</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect app version 6.3.x was
installed on devices running macOS, the HIP check failed to detect
ESET Endpoint Security version 8.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-21775</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect users on macOS were disconnected
immediately after sending the HIP report.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21771</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect HIP check incorrectly detected
Malware Definition Date for Trend Micro Deep Security Agent, which
caused the device to fail the HIP check.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-21743</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a user was randomly prompted with a \"Login
Successful\" message when connecting to GlobalProtect (GP), even
though GP was not connected.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21695</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect embedded browser could not
utilize a new PIV certificate for SAML authentication if multiple
certificates were available.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21677</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect configured for Always-on Pre-logon
may not display the captive portal page if there is a delay with
network access or Internet connectivity.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21653</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect virtual adapter was not set up
correctly.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-21639</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect macOS client did not extend the
session even though the user clicked the Extend Session button.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-21627</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Report an Issue feature failed to work for a
specific user whose username contained Japanese character.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-21615</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect agent
(wa_3rd_party_host_64.exe) modified the __PSLockDownPolicy registry
key from 4 (secure language mode) to 0 (full language mode) after a
reboot.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-21571</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the hyperlink in HIP notification opened up in
Webview2 instead of the default browser.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-21565</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the SAML embedded browser did not remember the
username after sign-out, even when the user had selected the check box
“Remember Me" on the SAML embedded browser,
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-21527</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not exclude the APIPA
(169.254.0.0/16) range from GlobalProtect when the Endpoint Traffic
Policy Enforcement feature was enabled with the exclude option. As a
result, traffic to the APIPA range was sent over GlobalProtect instead
of the local interface.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-21467</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Transparent Upgrade with Proxy only mode did
not work as expected and no tunnel was established with the gateway.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-21453</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app window displayed "static"
instead of the connected gateway name.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-21222</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect HIP check incorrectly detected
the Real Time Protection Status and Last Full Scan for Avast
application, which caused the device to fail the HIP check.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-21090</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect only displayed ADEM information for
approximately 120 users even though more than 600 ADEM users were
connected to GlobalProtect.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-20967</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect app was installed with
the Conditional Connect method, users had to click the Connect button
twice to connect to an external gateway after a system reboot.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-20632</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GLobalProtect was stuck in connecting mode after
the customer manually selected a gateway that hit the maximum user
limit. This was a multi-gateway environment with SAML/CAS
authentication method.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-20621</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where users from overseas locations were disconnected
from GlobalProtect due to the HIP report not being sent with manual
gateway selection.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">GPC-18587</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect was installed on Windows
devices and Connect Before Logon was deployed, users were unable to
log in to the device using the User Principal Name (UPN). This issue
occurred when the GlobalProtect credential provider was selected and
the device was offline.
</div>
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,412 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 50%" />
<col style="width: 50%" />
</colgroup>
<thead class="thead">
<tr class="row">
<th class="entry">Issue ID</th>
<th class="entry">Description</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry"><b class="ph b">GPC-21022</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect re-authentication prompt appeared
in the background instead of the foreground after deploying Okta
FastPass.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20895</b></td>
<td class="entry relcol">
Fixed an issue where a macOS GlobalProtect app user was able to modify
or add a new portal even though the portal agent configuration specified
<span class="ph uicontrol"
>Allow User to Change Portal Address = NO</span
>
and
<span class="ph uicontrol"
>Allow user to Sign Out from GlobalProtect App = No</span
>.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20864</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect embedded browser login window did
not stay pinned to the front of all open windows on Windows and MAC
computers.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20839</b></td>
<td class="entry relcol">
Fixed an issue where a macOS user was unable to connect to the
GlobalProtect app.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20722</b></td>
<td class="entry relcol">
Fixed an issue in the GlobalProtect macOS client where the UI
incorrectly displayed a "Not Connected" status and a "Connect" button
while the user was in the process of connecting to a new gateway.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20645</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect macOS app was stuck in connecting
stage when the macOS computer woke from sleep and the user had to
restart the computer.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20601</b></td>
<td class="entry relcol">
Fixed an issue where users unable to connect to GlobalProtect after
upgrading from version 6.2.2 to 6.2.3 via JAMF.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20595</b></td>
<td class="entry relcol">
Fixed an issue where GlobalProtect users were unable to connect after
upgrading to 6.2.3-270 and received a Y<span class="ph uicontrol"
>our internet access is blocked</span
>
error during SAML authentication using the embedded browser.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20527</b></td>
<td class="entry relcol">
Fixed an issue where the Conditional Connect method configured for the
GlobalProtect app did not work as expected when the user shifted from
external network (home) to an internal network (office). Users had to
reboot the system to resolve this issue.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20463</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect status panel is not disabled at
startup when the
<span class="ph uicontrol"
>Display Status Panel at Startup parameter </span
>is set to no.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20442</b></td>
<td class="entry relcol">
Fixed an issue on appliances running PanOS 10.1.11-h1 and GlobalProtect
6.0.10-811 where the tunnel status failed to update to connected
immediately after establishment. This problem was specific to IPv4-only
clients connecting to dual-stack (IPv4 + IPv6) GlobalProtect gateways or
portals.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20427</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect client on Windows 11 devices
displayed an error message "The parameter is incorrect" when attempting
to connect to a firewall running PAN-OS 10.1.13 with SAML authentication
enabled.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20374</b></td>
<td class="entry relcol">
Fixed an issue where users were unable to connect to GlobalProtect if
they accidentally clicked decline on the Terms of Service page.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20157</b></td>
<td class="entry relcol">
Fixed an issue where the gateway location was not correctlydisplayed in
the Connections panel.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20143</b></td>
<td class="entry relcol">
Fixed an issue where the user was redirected to the Authentication page
twice on the default browser for both portal and gateway authentication
when SAML was configured.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20114</b></td>
<td class="entry relcol">
Fixed an issue where, when the GlobalProtect app was installed on
devices running macOS, the certificate information was incorrect during
the portal login phase causing authentication failure.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20112</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect HIP check incorrectly detected
Real time protection status for Kaspersky Endpoint Security, which
caused the device to fail the HIP check.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20091</b></td>
<td class="entry relcol">
Fixed an issue where pre-logon failed when the computer was rebooted,
when the machine store had an expired and active certificate.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20080</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect logs displayed different event
messages for Windows and macOS devices when the Allow User to Disable
GlobalProtect App was set to Allow with Passcode for the GlobalProtect
app.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20060</b></td>
<td class="entry relcol">
Fixed an issue where it was possible for the GlobalProtect enforcer to
be disabled when there was a network change during portal
authentication.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-20040</b></td>
<td class="entry relcol">
Fixed an issue where GlobalProtect did not re-check for internal
gateways when using cached portal configuration and an external network
was previously detected.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19991</b></td>
<td class="entry relcol">
Fixed an issue where client certificate authentication between embedded
browser and IdP (SAML) fails.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19966</b></td>
<td class="entry relcol">
Fixed an issue where the embedded browser was unable to load the
Microsoft IdP login page for the users to authenticate to the
GlobalProtect app.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19901</b></td>
<td class="entry relcol">
Fixed an issue where, when the GlobalProtect app was installed on
devices running macOS, the app got disconnected and reconnected
intermittently.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19889</b></td>
<td class="entry relcol">
Fixed an issue where, when the GlobalProtect app was installed on
Windows machine and Connect Before Logon (CBL) was configured for the
app, the app did not start properly when the user logged on to the
device.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19840</b></td>
<td class="entry relcol">
Fixed an issue where Mac computers did not display all gateways in the
Search Gateway tab.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19833</b></td>
<td class="entry relcol">
Fixed an issue where, when the GlobalProtect app was installed on
Windows devices, the Smart card (Yubikey) authentication did not work
when the device woke up from sleep mode.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19753</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect icon could not be selected using
the keyboard.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19751</b></td>
<td class="entry relcol">
Fixed an issue where the programmatic and visual label for the
GlobalProtect form field was not announced.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19686</b></td>
<td class="entry relcol">
Fixed an issue where translation errors were observed in the
GlobalProtect app for French localization.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19659</b></td>
<td class="entry relcol">
Fixed an issue where macOS users were connected to the GlobalProtect app
before they agreed to their companys terms of service.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19513</b></td>
<td class="entry relcol">
Fixed an issue where the GlobalProtect app was trying to use the old
portal's authorization cookie to login instead of the newly migrated
portal. This happened when the user changed from secondary portal to
primary portal or vice versa without signing out.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19475</b></td>
<td class="entry relcol">
Fixed an issue where users got connection errors in an embedded browser
after the computer woke up from sleep or when the user switched
gateways.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19433</b></td>
<td class="entry relcol">
Fixed an issue where a small white blank page randomly popped up on the
device screen distracting the users. This issue occurred while the
device was connected to GlobalProtect app.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-19373</b></td>
<td class="entry relcol">
Fixed an issue where the HIP remediation pop up is displayed even when
the user is disconnected.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-18991</b></td>
<td class="entry relcol">
Fixed an issue where the proxy auto-configuration (PAC) files were not
restored as expected after a system reboot or when the user disconnected
the GlobalProtect app.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-18728</b></td>
<td class="entry relcol">
Fixed an issue where the I Agree option on the GlobalProtect app
Welcome page did not work as expected when the user selected the option
using a keyboard.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-18702</b></td>
<td class="entry relcol">
Fixed an issue where, when the GlobalProtect app was installed on
Windows devices, the “Allow Manually upgrade failed when the user tried
to upgrade the GlobalProtect app version from 6.0.5 to 6.0.7.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-18647</b></td>
<td class="entry relcol">
Fixed an issue where the user reported an issue using the
<span class="ph uicontrol">Report an Issue</span> option on the
GlobalProtect app and the issue was not reported as expected.
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-17820</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Firefox was not supported for proxied traffic in
Tunnel and Proxy mode or proxy mode.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-17727</b></td>
<td class="entry relcol">
Fixed an issue where when the GlobalProtect app was connected in Tunnel
and Proxy mode or proxy mode, SSH traffic could not be sent over the
proxy.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-16975</b></td>
<td class="entry relcol">
Fixed an issue where, when the GlobalProtect app was installed on
devices running macOS, the screen reader did not announce the name of
the GlobalProtect gateway when the gateway was marked with the star
symbol.
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">GPC-15750</b></td>
<td class="entry relcol">
Fixed an issue where a hyperlink in a HIP notification opened in the
GPO-disabled Internet Explorer 11 browser instead of the default
browser.
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,619 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 50%" />
<col style="width: 50%" />
</colgroup>
<thead class="thead">
<tr class="row">
<th class="entry">Issue ID</th>
<th class="entry">Description</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-22087</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app was unable to validate the
certificate from OCSP.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-22080</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the OCSP requests were being rejected by the OCSP
responder with a
<span class="ph systemoutput">HTTP 400 Bad Request</span> error due to
the absence of the Host header in the OCSP request.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21938</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect app version 6.3.x was
installed on devices running macOS, the HIP check failed to detect
ESET Endpoint Security version 8.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21918</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the patch management category was excluded
for HIP checks, HIP checks were still happening for missing patches
which consumed CPU resources on users' machine.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21838</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue in which the GlobalProtect app, when installed on
Windows devices, caused a duplicate page to open in the system default
browser (Chrome) when the user clicked the hyperlink on the Welcome
page with fedmandate on the embedded browser.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21836</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue in GlobalProtect 6.3.1 for macOS where the Refresh
Connection option was missing during the
<span class="ph systemoutput">Connecting</span> state, specifically
for users who upgraded from version 6.3.0.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21778</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect IPSec tunnel got disconnected
on GlobalProtect app version 6.2.5 when
<span class="ph systemoutput">gpupdate /force</span> command was used
to update policy.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21774</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect ARM64 installers for 6.2.5
version did not display the
<span class="ph uicontrol">Digital Signatures </span> tab.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21771</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect HIP check incorrectly detected
Malware Definition Date for Trend Micro Deep Security Agent, which
caused the device to fail the HIP check.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21733</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where all the added portals got deleted from the portal
list except the connected portal when the GlobalProtect app was
upgraded from version 6.2.4 to 6.2.5-788. Users had to manually add
them again to resolve the issue.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21604</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect app was installed on
devices running macOS and were connected to the internal gateway, the
app did not display the
<span class="ph uicontrol">Disconnect</span> option under
<span class="ph uicontrol">Settings</span>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21571</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the hyperlink in HIP notification opened up in
Webview2 instead of the default browser.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21565</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the SAML embedded browser did not remember the
username after sign-out, even when the user had selected the check box
<span class="ph uicontrol">Remember Me</span> on the SAML embedded
browser.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21542</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect got stuck in connecting and failed
the connection after some time.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21443</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect crashed when the PanGPS service was
stopped.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21414</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the SAML authentication page would occasionally
fail to appear due to the usage of a previous SAML pre-login cookie.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21399</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect app was installed on
devices running macOS, the HIP check for the built-in firewall shows
N/A incorrectly.
</div>
<div class="p">
The value should be either <span class="ph systemoutput">Yes</span> or
<span class="ph systemoutput">No</span>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21370</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the HIP check could not detect Trellix Firewall
Status, which caused the device to fail the HIP check.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21332</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect HIP check incorrectly detected
Real Time Protection status for Avast and XProtect, which caused the
device to fail the HIP check.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21320</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect HIP check did not detect
Kaspersky Endpoint Security antimalware application which caused the
device to fail the HIP check.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21301</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the user upgraded the GlobalProtect app
version to 6.2.4 with SAML authentication, users were unable to
connect to GlobalProtect intermittently when Enforcer is enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21247</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect HIP set the Filevault encryption
status to unencrypted on macOS running devices, which denied access to
the end-point machines.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21222</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect HIP check incorrectly detected
the Real Time Protection Status and Last Full Scan for Avast
application, which caused the device to fail the HIP check.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21206</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect service exited when the user
logs off or put the computer in sleep mode.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21174</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect HIP check did not detect Real
time protection status for Acronis Cyber Protection Agent, which
caused the device to fail the HIP check.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21130</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect app was installed on
devices running macOS, the GlobalProtect app failed to reconnect and
continued to stay in the
<span class="ph systemoutput">Connecting</span> state after the device
woke up from <span class="ph uicontrol">Modern Standby</span> mode.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21106</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect HIP check did not detect Real
Time Protection status for Malwarebytes antimalware application, which
caused the device to fail the HIP check.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-21043</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app got stuck in connecting
stage after authentication when the app was upgraded to 6.2.4 version.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-20983</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect app was installed on devices
running macOS, the GlobalProtect got stuck in Connecting state when
the device woke up from sleep mode.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-20967</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect app was installed with
the <span class="ph uicontrol">Conditional Connect</span> method,
users had to click the
<span class="ph uicontrol">Connect</span> button twice to connect to
an external gateway after a system reboot.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-20943</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect enforcer blocked DHCP packets.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-20838</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the HIP report was not completed within the
allowed time.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-20807</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the HIP report for Symantec Encryption Desktop
shows the encryption state as unencrypted.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-20779</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Windows regional settings were not respected by
Webview 2 on SAML embedded browser resulting in regional
language(French, German, Chinese, Spanish, and Japanese) not loading
properly in embedded browser.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-20700</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where macOS users had to enter the SAML username and
password each time they refreshed or rebooted their computer. This
issue occurred more frequently when they used Safari as the default
browser or used the embedded browser.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-20674</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where all GlobalProtect portals except for the
currently connected portal were deleted during the upgrade from 6.2.2
to 6.2.3 or from 6.2.3 to 6.3.0.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-20492</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the PanGPS process crashed due to exception code
0xC0000374.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-20466</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the tunnel gets broken during modern standby when
using Enforce GlobalProtect for Network Access and the enforcer gets
re-enabled only after the user resumes working on the computer.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-20441</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where HIP reports are sometimes not available on the
firewall for newly connected users.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-20322</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where users were unable to install GlobalProtect 6.2 on
windows 11 ARM64 devices.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-20191</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the PanGPA executable version 6.1.2.83 did not
work as expected on Windows devices.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-20168</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where it was possible to do a privilege escalation
and\or login bypass when using a 3rd party credential provider with
GlobalProtect.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-18943</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where when Endpoint Traffic enforcement feature was
enabled, certain traffic was going through the physical adapter and
not getting blocked as per the rules set.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-18695</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect app version 6.0.7 was
installed on devices running macOS, the "<span class="ph uicontrol"
>Allow with Passcode</span
>
option did not work as expected when the user tried to disable the
GlobalProtect app with the configured passcode.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-18671</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect app was installed on
devices running macOS, the GlobalProtect macOS install package created
an unused /Library/Application folder.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">GPC-18452</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect app was installed on
Windows devices, the app did not start right away after a system
reboot.
</div>
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,305 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead" data-sticky-top="61.2" style="top: 61.2px">
<tr class="row">
<th class="entry">
<div class="p">Issue ID</div>
</th>
<th class="entry">
<div class="p">Description</div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry"><div class="p">GPC-26563</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where your GlobalProtect client deleted the pre-defined
Proxy Auto-Configuration file configuration from your client machine
when it refreshed its connection. This occurred on GlobalProtect
client versions 6.3.3-h9 and 6.3.3-h10. With this fix, your
GlobalProtect client no longer deletes the pre-defined PAC file
configuration upon connection refresh.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">GPC-26311</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect users were unable to submit Host
Information Profile (HIP) reports, which prevented security rules
requiring a HIP match from applying. This occurred when you connected
to an NGPA gateway using a dual-stack network, such as a mobile
hotspot. With this fix, GlobalProtect successfully submits HIP reports
regardless of your network configuration.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">GPC-26305</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect portal change option was not
visible when you were in internal host detection mode. With this fix,
you can now properly view and use the portal change option.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">GPC-26227</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where your GlobalProtect client connected to a
geographically distant GlobalProtect gateway even when a closer,
preferred gateway was available. This occurred when your network
connection became temporarily unavailable during the GlobalProtect
client's attempt to connect to the preferred gateway. With this fix,
your GlobalProtect client correctly prioritizes and connects to the
optimal gateway after network connectivity is restored.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">GPC-26119</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, on your macOS device, you were unable to
authenticate to captive portals on public Wi-Fi networks when
GlobalProtect's Network Enforcer was enabled. This occurred because
GlobalProtect exempted the primary Captive Network Assistant process
but did not dynamically exempt the associated WebKit eXtensible
Process Communication (XPC) subprocesses responsible for rendering the
captive portal page, which prevented the captive portal page from
loading. With this fix, GlobalProtect now correctly exempts these
subprocesses, ensuring captive portals load successfully.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">GPC-25967</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where your GlobalProtect client experienced a
significant delay in establishing a connection after your device woke
up from a sleep event, preventing timely network access. With this
fix, your GlobalProtect client now connects promptly after a sleep
event, ensuring a smoother user experience.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">GPC-25946</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where your GlobalProtect client did not send Host
Information Profile (HIP) check and report messages after you
established a connection to the gateway. This occurred even when a HIP
report was generated shortly before the connection, which could have
impacted security posture assessment. With this fix, your
GlobalProtect client now correctly sends HIP check and report messages
after establishing a connection.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">GPC-25776</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect clients displayed an incorrect
"Connecting" status after a GlobalProtect Portal or Gateway
authentication failure, specifically when "Portal auth failed but
SAML/CAS auth is successful". This misleading status persisted even
though the connection had actually failed, preventing users from
understanding the true connection state.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">GPC-25563</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect proxy agent intermittently
initiated proxy connections using a GET request instead of the
required CONNECT request, which resulted in failures to establish
connections to target websites.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">GPC-25541</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where MacOS GlobalProtect client version 6.2.8-416 was
unable to connect to the GlobalProtect gateway, getting stuck in a
connecting state.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">GPC-25490</div></td>
<td class="entry relcol">
<div class="p">
(MacBook devices) Fixed an issue where your GlobalProtect enabled
device lost internet access after returning from hibernation. This
occurred when your computer completely lost network connectivity,
requiring a restart to restore internet access. With this fix, your
device maintains network connectivity after resuming from hibernation.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">GPC-25446</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Host Information Profile (HIP) matching did not
function as expected after your device resumed from modern standby.
This occurred intermittently, requiring you to manually refresh to
restore proper HIP matching. With this fix, HIP matching now functions
correctly after your device resumes from modern standby.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">GPC-25394</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where your traffic continued to pass through the
GlobalProtect tunnel interface after you disconnected GobalProtect,
preventing it from reverting to your local interface. With this fix,
your traffic properly reverts to the local interface after
GlobalProtect disconnects.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">GPC-25383</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect clients on Windows machines
experienced intermittent disconnections, which self-resolved within
1-2 minutes.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">GPC-25359</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect client, when using the embedded
browser for SAML authentication with the Cloud Authentication Service,
failed to retrieve configuration from the GlobalProtect Portal. This
occurred because the GlobalProtect Agent incorrectly passed the
username with an additional backslash character, leading to improper
encoding and subsequent failure.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">GPC-25320</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect intermittently appeared in the
foreground of your user session. This occurred even when you
configured GlobalProtect for on-demand connections and were not
actively trying to connect, causing it to overshadow other
applications. With this fix, GlobalProtect remains in the background
until you actively initiate a connection.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">GPC-25280</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect clients on macOS devices would
intermittently get stuck in a "Connecting" state for several minutes
after waking from modern standby. This occurred due to a race
condition between DNS proxy reconfiguration and the VPN connection
process during wake from sleep, where the macOS DNS proxy would
temporarily stop and restart, causing the PanGPS service to time out
when attempting to send DNS configuration commands. This led to
repeated connection failures until the DNS proxy fully stabilized, a
condition that was exacerbated by the presence of multiple network
extensions on the macOS device.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">GPC-25019</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect App version 6.2.8-223, when
configured in a non-tunnel setup with internal gateways, would stop
sending Host Information Profile (HIP) reports, leading to policy
drops on the firewall. This occurred because of a time alignment
problem in the HIP report thread scheduler, which caused the app to
incorrectly skip sending reports when the
`tNextHipReportCheckSendTime` became stale, especially with longer HIP
check intervals.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">GPC-24845</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect users on Prisma Access
intermittently experienced "No user mapping" issues across multiple
gateways.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">GPC-24825</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect client version 6.2.8-263 failed to
transition from the pre-logon tunnel to the user tunnel after
successful Windows credential entry, causing the client to remain in a
'Connecting' state and requiring a force reboot or sign-out to clear.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">GPC-24006</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where MacOS GlobalProtect clients, when configured for
Okta authentication with Prisma Access, intermittently failed to log
in after a previous log-off. This failure manifested as an "Okta
device not on-line" error, caused by the GlobalProtect client's
log-off process not completing gracefully, which resulted in the
client service not starting correctly on subsequent login attempts.
</div>
</td>
</tr>
</tbody>
</table>
@@ -1,81 +0,0 @@
---
type: Addressed
product: GlobalProtect
version: 6.2.8-c223
---
## GPC-23215
Fixed an issue where, the traffic stopped passing through the GlobalProtect app on macOS devices after upgrading to GP 6.2.8 and when the computer screen was locked.
## GPC-23174
Fixed an issue where the GlobalProtect failed to detect DNS during the Network Detection stage, causing the GlobalProtect app to stop working.
## GPC-23161
Fixed an issue where the GlobalProtect app stopped working after a session change.
## GPC-23088
Fixed an issue where the portal login user authentication failed after cookie expiration.
## GPC-21982
Fixed an issue in which IPv6 traffic bypassed the valid route in the rerouting table and instead passed through the physical adapter when the GlobalProtect app was installed on Windows devices.
## GPC-23046
Fixed an issue where users experienced connectivity problems when GlobalProtect was used in a WiFi network with captive portal.
## GPC-23034
Fixed an issue where the GlobalProtect embedded browser did not display certificate selection pop-up when there were multiple client certificates available.
## GPC-23032
Fixed an issue where the GlobalProtect agent restarts when the device wakes up from Modern Standby.
## GPC-23011
Fixed an issue wherein wherein the Enforcer intermittently failed to promptly block network access as configured, thereby resulting in delays of 1 to 5 minutes before eventually blocking the traffic flow.
## GPC-22800
Fixed an issue where, when the GlobalProtect app was configured with enforcer and Captive Portal, users faced issues in connecting to Captive Portal using GlobalProtect.
## GPC-22610
Fixed an issue where, after an upgrade, GlobalProtect restarted and failed to connect to the portal
## GPC-22595
Fixed an issue where users were unable to select the correct client certificate when using the GlobalProtect app on Windows devices and connected to the internal network using SAML embedded browse
## GPC-22536
Fixed an issue where users faced connectivity issues when the GlobalProtect app version 6.2.6 was installed on devices running macOS 15.3.1
## GPC-22365
Fixed an issue where users experienced intermittent issues browsing webpages while connected to the GlobalProtect app.
## GPC-22294
. Fixed an issue where intermittent internet access problems occurred when the macOS was upgraded to 15.2 and the GlobalProtect app version to 6.2.6.
## GPC-21766
Fixed an issue where the split tunnel excluded routes go missing from routing table on Windows machine at intermittent times.
## GPC-21755
Fixed an issue where GlobalProtect users with enforcer enabled were able to access applications that were not in the enforcer exception list.
## GPC-21737
Fixed an issue where the SAML redirection page opened up on end user computers even though they did not have internet connectivity.
## GPC-19024
Fixed an issue where the GlobalProtect app incorrectly used an embedded WebView instead of the system default browser for Captive Portal logins.