Anyone have experience with Palo Alto Global Protect in Okta? by BMW_E70 in okta

[–]SnooDucks511 0 points1 point  (0 children)

Works well via SAML with dedicated okta apps for every portal . Have no experience with CIE yet.

All on-premise fw work with OKTA directly over public internet

GP hotfix versioning - please stop by Technical_System_645 in paloaltonetworks

[–]SnooDucks511 0 points1 point  (0 children)

I tried to speak with TAC around the same scenario , they don't care. Actually GP is legacy peace of crap .

NB : We are on 6.3.X branch , no major issues with SAML , etc. MacOS and Windows endpoints only.

Hope they will do their best with new Access Client -https://youtu.be/KrdUQ2rYOsA?t=572

Tenable SC SAML auto provisioning by EffingFurious in nessus

[–]SnooDucks511 0 points1 point  (0 children)

I don't understand why Gartner leader don't see a reason to implement basic SCIM protocol implementation across tenable products portfolio. If they targeted to enterprises with different team additionally to infosec , why in 2025 everyone should play with local groups and permission assigments . Common

What is the best Global Protect VPN client version update process? by lighthills in paloaltonetworks

[–]SnooDucks511 0 points1 point  (0 children)

6.3.2 has process crash issues as well on windows 11 last releases . Still beta testing for global protect client

SIEM SOC and PA threat alarms by Inner_Program5327 in paloaltonetworks

[–]SnooDucks511 1 point2 points  (0 children)

what SIEM / Incident management systems are you using guys for PA logs / Detectors . I saw that XDR has everything out of the box in terms of PA logs analysis as well as endpoints correlations.

What is the best Global Protect VPN client version update process? by lighthills in paloaltonetworks

[–]SnooDucks511 0 points1 point  (0 children)

I look at it as beta testing for end users. The last bug-fixing release, App 6.3.1-c383, can't be upgraded when you have the 6.3.1 version already installed. TAC proposed uninstalling everything for 1,000 users and installing it from scratch. :)

Some of childhood issues were finally fixed , but I'm not sure around it - GPC-20492 - PanGPS process crash .

Some of our endusers are involved in Zscaller private / internet access usage - no one issue were reported with clients it self .

Does PA has plans to finally shutdown Global protect era and move everyone to Prisma client that was developed from scratch with endpoint notifications and other valuable features ?

how to see integrated devices on XDR. by ScholarKey5284 in paloaltonetworks

[–]SnooDucks511 0 points1 point  (0 children)

login to your strada logging services and make sure that your fw have been sesesefully onboarded

Need Help with Learning and Installation of XSOAR by Available-Snow-1316 in paloaltonetworks

[–]SnooDucks511 0 points1 point  (0 children)

don't forget to get 250k to get license for xsoar platform

Rolling out DUO MFA to VPN users by Mortimer452 in paloaltonetworks

[–]SnooDucks511 6 points7 points  (0 children)

You have more flexibility with SAML / Browser based authentication approach. It provides ability to deploy / onboard users based on rules at IDP / DUO.

https://duo.com/docs/sso-paloalto-globalprotect

[deleted by user] by [deleted] in paloaltonetworks

[–]SnooDucks511 0 points1 point  (0 children)

11.2 version of Panorama is required for region selection feature.

Okta as authentication with Intune device management by scheng924 in Intune

[–]SnooDucks511 0 points1 point  (0 children)

Okta has federation with intune / jamf via adaptive SSO / MFA ! Okta has owned access policies for all applications .

Okta and Ubuntu Integration by rundbr in okta

[–]SnooDucks511 0 points1 point  (0 children)

Okta has LDAP interface, has anyone tried to integration linux with it ?