--- type: Addressed product: GlobalProtect version: 6.2.5 --- ## GPC-21656 Fixed an issue where an unexpected extra string was added to the end of the MFA prompt. ## GPC-21533 Fixed an issue where GlobalProtect connected and disconnected in a loop ## GPC-21483 Fixed an issue where users are intermittently unable to connect to GlobalProtect and get stuck at the connecting stage. ## GPC-21465 Fixed an issue where GlobalProtect is stuck in "Connecting... Finding the Best Available Gateway". ## GPC-21442 Fixed an issue where there was a delay in GlobalProtect restoring connectivity after the Windows host woke up from modern standby. ## GPC-21443 Fixed an issue where GlobalProtect crashed when the PanGPS service was stopped. ## GPC-21414 Fixed an issue where GlobalProtect using SAML authentication gets stuck in a connecting loop upon the expiration of the authentication cookie. ## GPC-21392 Fixed an issue where GlobalProtect is stuck in the connecting state for 2-3 minutes during Windows Pre-logon. ## GPC-21387 Fixed an issue that prevented users from connecting to Wi-Fi networks when GlobalProtect was disconnected. ## GPC-21355 Fixed an issue where GlobalProtect was incorrectly showing as connected during Windows pre-logon. ## GPC-21301 Fixed an issue where after upgrading to GlobalProtect 6.2.4, users were unable to connect to GlobalProtect intermittently when Enforcer is enabled. ## GPC-21247 Fixed an issue where HIP checks for Disk Encryption status were failing after Windows and Mac hosts were rebooted, on low power mode or were resuming from standby. ## GPC-21206 Fixed an issue where GlobalProtect intermittently does not restore connection after the user logs back in or wakes a Windows host. ## GPC-21172 Fixed an issue where the GlobalProtect agent gets disconnected right after successful connection when SAML embedded browser authentication is used along with "Enforce GlobalProtect for Network Access". ## GPC-21161 Fixed an issue where the notifications prior to 'Login Lifetime Expiration' and 'Inactivity Logout' were not displayed even when enabled. ## GPC-21101 Fixed an issue where the embedded browser pop-up with "Login Successful" was displayed for each SAML authentication. ## GPC-21057 Fixed an issue where HIP checks for Disk Encryption status were failing on Windows during modern standby. ## GPC-21035 Fixed an issue where GlobalProtect HIP did not identify the definition version of the SentinelOne Agent. ## GPC-21024 Fixed an issue where a HIP notification configured as "pop-up-message" for pre-logon does not show up. The pop up window is blank. ## GPC-21005 Fixed an issue where after submitting the SAML credentials, a blank screen was displayed and GlobalProtect got stuck in that stage. ## GPC-20991 Fixed an issue where the 'Extended Key Usage OID' value for certificate selection was deleted during an upgrade of the GlobalProtect agent. This forces users to have to manually select the correct certificate tp be used for authentication. ## GPC-20988 Fixed an issue where GlobalProtect failed to resolve DNS queries when the 'Allow traffic to specified FQDN when Enforce GlobalProtect Connection for Network Access is enabled and GlobalProtect Connection is not established' configuration is set. ## GPC-20983 Fixed an issue where the GlobalProtect app remains stuck in the connecting stage when Windows computer resumes from sleep. ## GPC-20943 Fixed an issue where the GlobalProtect enforcer blocked DHCP packets. ## GPC-20895 Fixed an issue where GlobalProtect users on macOS were able to add and modify the portal address even when portal agent configuration was "Allow User to Change Portal Address = NO". ## GPC-20884 Fixed an issue where users get disconnected a few seconds after logging in to VDI when GlobalProtect connects. They are unable to reconnect after that. ## GPC-20864 Fixed an issue where the GlobalProtect embedded browser login window did not stay pinned to the front of all open windows on Windows and MAC computers. ## GPC-20839 Fixed an issue where system extensions on MacBooks were not updated upon GlobalProtect app upgrade. ## GPC-20838 Fixed an issue where the HIP report generation was taking longer than the 'Max Wait Time' on Windows devices when anti-malware and disk encryption checks are configured. ## GPC-20771 Fixed an issue where GlobalProtect 6.2 users on Windows 11(ARM & Intel) devices cannot connect to GlobalProtect due to "The Parameter is incorrect" error. ## GPC-20770 Fixed an issue where certain GlobalProtect HIP checks on Windows devices failed when there was no internet connectivity. ## GPC-20741 Fixed an issue where the GlobalProtect app intermittently disconnects from the gateway when using the embedded browser for SAML authentication. ## GPC-20736 Fixed an issue where users are being logged out from GlobalProtect when the device wakes up from modern standby and network discovery happens. ## GPC-20700 Fixed an issue where macOS users had to enter the SAML username and password each time they refreshed or rebooted their computer especially when using Safari or Embedded browser. ## GPC-20692 Fixed an issue where GlobalProtect 6.2.3 with SAML authentication (via Okta) opens the embedded browser page in the background instead of the foreground. ## GPC-20645 Fixed an issue where GlobalProtect app in macOS is stuck in connecting state when the device wakes up from sleep. ## GPC-20626 Fixed an issue where the GlobalProtect client overwrites valid authentication override cookie with empty authentication override cookie from portal when using cached portal configuration. ## GPC-20601 Fixed an issue where macOS users are unable to connect to GlobalProtect after upgrading from version 6.2.2 to 6.2.3 via JAMF. ## GPC-20595 Fixed an issue where GlobalProtect users were unable to connect after upgrading to 6.2.3-270 and received a "Your internet access is blocked" error during SAML authentication using the embedded browser. ## GPC-20550 Fixed an issue where Zoom and Outlook apps intermittently stop connecting on macOS with an error "You are unable to connect to Zoom. Please check your network connection and try again" when the apps are excluded under both domains and applications. ## GPC-20466 Fixed an issue where when the tunnel is broken on Windows computers in modern standby mode, the Enforcer does not work even when it is enabled. ## GPC-20442 Fixed an issue on appliances running PanOS 10.1.11-h1 and GlobalProtect 6.0.10-811 where the tunnel status failed to update to connected immediately after establishment. This problem was specific to IPv4-only clients connecting to dual-stack (IPv4 + IPv6) GlobalProtect gateways or portals. ## GPC-20441 Fixed an issue where HIP reports are sometimes not available on the firewall for newly connected users. ## GPC-20416 Fixed an issue where there is no network discovery once the laptop came out of standby. ## GPC-20360 Fixed an issue where the GlobalProtect app is stuck in the connecting status after authentication and does not connect until the app is restarted or the computer is rebooted. ## GPC-20292 Fixed an issue where RDP to Azure VDI clients disconnects when GlobalProtect is enabled on the VDI client with SAML authentication and with 'Enforce GlobalProtect for Network Access' enabled ## GPC-20191 Fixed an issue where PanGPA.exe crashes on Windows clients ## GPC-20114 Fixed an issue where GlobalProtect on MacOS was incorrectly selecting client certificates without a private key for certificate authentication. ## GPC-20112 Fixed an issue where the GlobalProtect HIP check incorrectly detected Real time protection status for Kaspersky Endpoint Security, which caused the device to fail the HIP check. ## GPC-20072 Fixed an issue where domain-based split tunneling was not working on MAC with Edge Chromium or Google Chrome browser though it was working on Safari. ## GPC-19819 Fixed an issue where SAML default browser IDP traffic is blocked during a refresh connection when GlobalProtect is connected to the internal network with 'Enforce GlobalProtect for Network Access' enabled. ## GPC-19269 Fixed an issue where GlobalProtect would show as "connecting" but never actually connect until the user restarted GlobalProtect on their Windows machine. ## GPC-18943 Fixed an issue where GlobalProtect would fail to connect on Windows hosts that were woken up from modern standby by initiating an RDP to the host.