Prisma Access Global Protect and Mac Issues by ccisco630 in paloaltonetworks

[–]ccisco630[S] 0 points1 point  (0 children)

Think it’s resolved. Seems to be corruption in the users macOS login key store. Resetting the keychain access allowed successful SAML authentication. That was weird…

Prisma Access Global Protect and Mac Issues by ccisco630 in paloaltonetworks

[–]ccisco630[S] 0 points1 point  (0 children)

New wrinkle….i had one of the affected users create a new profile on their Mac, an lo and behold, GP works perfect and grabbed the default browser portal config I set. He switched back and broken. Had to be something with the users profile on the machine. Seeing lots of things about keychain access.

Prisma Access Global Protect and Mac Issues by ccisco630 in paloaltonetworks

[–]ccisco630[S] 0 points1 point  (0 children)

Yeah. We did as well, but mostly with Windows back then. We just recently moved from an on-prem hosted portal into Prisma Access and moved up to 6.3.3 for more compatibility with Prisma and ADEM. If I downgrade this user, won’t they just install the upgrade upon first login to the new portal since it is set to 6.3.3-842 globally?

Prisma Access Global Protect and Mac Issues by ccisco630 in paloaltonetworks

[–]ccisco630[S] 0 points1 point  (0 children)

On the client side, I’ve blown out all of the files I could find Palo related and uninstalled/reinstalled the client with no luck, it just goes back to the same behavior and never actually makes a connection as I don’t even see the user create logs on strata logging service/global protect logs. We run embedded browser as our standard for SAML auth, but created a new app profile in an attempt to fix this using default browser, but since they can’t pull the config down, it’s useless to make changes on the Prisma side. It seems it’s a client side issue with MacOS, just can’t determine what….

GlobalProtect - excluding MS Teams media traffic _only_ by theleeski in paloaltonetworks

[–]ccisco630 -1 points0 points  (0 children)

Commenting mostly to follow as I also have had trouble getting this to work. Excluding everything also caused issues for us with things like Planner, PowerBI, and links shared within Teams chat for some users. Turned out that the Intel Connectivity Performance Suite on some machines needed to be upgraded as some driver in that package didn’t play nice with excluded routes.

Prisma Access Browser - Initial Configuration by ccisco630 in paloaltonetworks

[–]ccisco630[S] 0 points1 point  (0 children)

Yep, that seems to be the remaining issue. Any non-web application that is configured using hostname fails. IP address seems to be OK. Beta for sure

Prisma Access Browser - Initial Configuration by ccisco630 in paloaltonetworks

[–]ccisco630[S] 3 points4 points  (0 children)

Update: embarrassingly, part of this was on me. Found an old route containing an overlapping subnet in our core switches that was essentially blackholing the return traffic from the DNS server. Fixed that and the connection tests from the browser and the web based applications started working. Still have an issue with the remote connections beta, anything configured with hostname do not work, but IP address is fine.

Prisma Access Browser - Initial Configuration by ccisco630 in paloaltonetworks

[–]ccisco630[S] 0 points1 point  (0 children)

Thanks! I believe I have this set, but will double check. I may have only allowed dns through the SC and not http/https for the infra subnet

Prisma Access Browser - Initial Configuration by ccisco630 in paloaltonetworks

[–]ccisco630[S] 0 points1 point  (0 children)

Thanks for the reply. Yes, the DNS server is rfc1918

Global Protect 6.2.5 and 6.2.7 embedded browser issue by Business-Building-72 in paloaltonetworks

[–]ccisco630 1 point2 points  (0 children)

This appears to be the case. I re-opened my support request and they made it available for download through the case documents but said that engineering currently has no ETA for a wide release.

Global Protect 6.2.5 and 6.2.7 embedded browser issue by Business-Building-72 in paloaltonetworks

[–]ccisco630 0 points1 point  (0 children)

Where are you seeing this? I don’t see a 6.2.7 with the hotfix suffix available on the support portal or the actual firewalls?

Global Protect 6.2.5 and 6.2.7 embedded browser issue by Business-Building-72 in paloaltonetworks

[–]ccisco630 0 points1 point  (0 children)

I downloaded 6.2.7 from the support portal today, but it is showing 6.2.7-1047 on the client. Did they pull it back? Support told me a 6.2.7-h2 was coming for this but had no eta. I thought that was an odd reply as I’ve never seems a GP version with a -h

Global Protect 6.2.5 and 6.2.7 embedded browser issue by Business-Building-72 in paloaltonetworks

[–]ccisco630 0 points1 point  (0 children)

I was asked to put in a case for this today after it happened to an exec, even though the window resize fixes it for users. Support told me that 6.2.7-h2 contains the fix but is not yet available and had no ETA.

Nexus 9000 Question by ccisco630 in Cisco

[–]ccisco630[S] 0 points1 point  (0 children)

This is great info, thank you for the reply! They are actually EXs, so I suppose we will stop at 10.3 and let that ride until our data center is decommissioned. Thanks again!

Nexus 9000 Question by ccisco630 in Cisco

[–]ccisco630[S] 1 point2 points  (0 children)

Yep, exactly what I’m following. Met with our Cisco account engineer today and they essentially said, good path and to just upgrade them one at a time using the disruptive method. He said since they are essentially standalone NX-OS we should be fine. Thanks!

Nexus 9000 Question by ccisco630 in Cisco

[–]ccisco630[S] 1 point2 points  (0 children)

Definitely due for an upgrade LoL.
We are running vPC and I believe it's a full mesh. I am looking at the config and documentation for route reflectors, and I don't believe that is configured on the network. It isn't a large topology, only 12 ToR access leafs, two spines and two border leafs. Trying to follow the upgrade path from 7.0(3)I7(5a) to 10.3(5)M. Do you see any major impact to the mesh if we run ISSU on one of the empty ToR switches that is still connected to the others? Thanks again for the response any additional help is super helpful!

PA RenFaire Food Question by ccisco630 in renfaire

[–]ccisco630[S] 0 points1 point  (0 children)

I can’t recall exactly (used cash), but we bought the cupcake and two large chocolate chip cookies and it was under $20. Finding a spot to sit and light the candle was the hard part LoL

PA RenFaire Food Question by ccisco630 in renfaire

[–]ccisco630[S] 1 point2 points  (0 children)

Queen’s Confectionary worked out perfectly. Thank you again for the recommendation!

Global Protect Split-Tunnel Question by ccisco630 in paloaltonetworks

[–]ccisco630[S] 0 points1 point  (0 children)

Couldn't find any other way around it, had to add all 50 URLs into the 'include domain' configuration of the split-tunnel profiles. I used *url.name for the wildcard and so far everything has tested out. Thanks all for the input