Globalprotect App User Guide
Globalprotect App User Guide
4.1
paloaltonetworks.com/documentation
Contact Information
Corporate Headquarters:
Palo Alto Networks
3000 Tannery Way
Santa Clara, CA 95054
www.paloaltonetworks.com/company/contact-support
Copyright
Palo Alto Networks, Inc.
www.paloaltonetworks.com
© 2018-2018 Palo Alto Networks, Inc. Palo Alto Networks is a registered trademark of Palo
Alto Networks. A list of our trademarks can be found at www.paloaltonetworks.com/company/
trademarks.html. All other marks mentioned herein may be trademarks of their respective companies.
Last Revised
March 1, 2018
5
6 GLOBALPROTECT APP USER GUIDE | GlobalProtect App for Windows
© 2018 Palo Alto Networks, Inc.
Download and Install the GlobalProtect App
for Windows
Before connecting to the GlobalProtect network, you must download and install the GlobalProtect app on
your Windows endpoint.
To download and install the app, you must obtain the IP address or fully qualified domain name (FQDN)
of the GlobalProtect portal from the administrator. The administrator should also verify the username and
password that you can use to connect to the portal. In most instances, you can use the same username and
password that you use to connect to your corporate network. After you gather the required information,
use the following steps to download and install the app:
1. Launch the GlobalProtect app by clicking the system tray icon. The status panel opens.
This option is only available if your administrator enables manual gateway selection.
4. (Optional) Depending on the connection mode, click Connect to initiate the connection.
5. (Optional) If prompted, enter your Username and Password, and then click Sign In. If authentication
is successful, you are connected to your corporate network, and the status panel displays the
Connected or Connected - Internal status. If your administrator sets up a GlobalProtect welcome
page, it displays after you log in successfully.
You can determine whether you are connected by checking the GlobalProtect system tray
icon. If you are not connected, the icon is gray ( ), and Disconnected appears when the
you hover over the icon.
1. Launch the GlobalProtect app by clicking the system tray icon. The status panel opens.
2. (Optional) If you are logging in to the GlobalProtect app for the first time, enter the FQDN or IP
address of the GlobalProtect portal, and then click Connect.
3. (Optional) If multiple portals are saved on your app, select a portal from the Portal drop-down. By
default, the most recently connected portal is pre-selected from the Portal drop-down.
4. (Optional) By default, you are automatically connected to the Best Available gateway, based on
the configuration that the administrator defines and the response times of the available gateways.
To connect to a different gateway, select the gateway from the Gateway drop-down (for external
gateways only).
This option is only available if your administrator enables manual gateway selection.
5. (Optional) Depending on the connection mode, click Connect to initiate the connection.
6. (Optional) If prompted, enter your Username and Password, and then Sign In.
When the app connects in external mode, the GlobalProtect system tray icon displays a shield ( ),
and Connected appears when you hover over the icon. When the app connects in internal mode, the
GlobalProtect system tray icon displays a house ( ), and Internal Network appears when you hover
over the icon.
After you launch the app, click the settings icon ( ) on the status panel to open the settings menu.
Select Settings to open the GlobalProtect Settings panel, and then select one of the following tabs to
view information about your network connection:
• General—Displays the username and portal(s) associated with the GlobalProtect account. You can
also add, delete, or modify portals from this tab.
For internal mode, the Connection tab displays the entire list of available gateways.
For external mode, the Connection tab displays only the gateway to which you are
connected and additional details about the gateway (such as the gateway IP address
and uptime).
• Troubleshooting—Enables you to Collect Logs, set the Logging Level, and view information about the
network configuration, route settings, active connections, and logs.
If your GlobalProtect administrator configures the GlobalProtect portal agent to Save User
Credentials, your credentials are automatically saved to the GlobalProtect app. If your
password for accessing the corporate network changes, you must log in to GlobalProtect
using your new password.
1. Launch the GlobalProtect app by clicking the system tray icon. The status panel opens.
2.
Click the settings icon ( ) to open the settings menu.
3. Select Settings to open the GlobalProtect Settings panel.
4. On the General tab of the GlobalProtect Settings panel, Sign Out to clear your saved user credentials
from the GlobalProtect app.
5. After you clear your user credentials, you can reconnect to GlobalProtect with your new username
and password.
The Disable option is visible only if your GlobalProtect agent configuration allows you
to disable the app. If the configuration allows you disable the GlobalProtect app without
requiring you to respond to a challenge, the GlobalProtect app closes without requiring
further action.
STEP 1 | Select Start > Control Panel > Programs > Programs and Features.
STEP 2 | Select GlobalProtect from the list, and then click Uninstall.
STEP 2 | Stop all third-party installers that are running in the background.
1. Press Ctrl+Alt+Delete, and then click Task Manager.
2. In the Task Manager, locate all third-party msiexec programs that are currently running (for
example, msiexec command line - Google Search).
3. Select the third party installer, and then click End Task to stop the installer.
STEP 3 | Restore the existing version of GlobalProtect, and then upgrade to the newer version of the
app.
1. (Optional) If necessary, re-install the existing (older) version of GlobalProtect to repair it. This step is
required if the upgrade continues to fail.
2. Allow the upgrade to proceed as expected.
19
20 GLOBALPROTECT APP USER GUIDE | GlobalProtect App for Mac
© 2018 Palo Alto Networks, Inc.
Download and Install the GlobalProtect App
for Mac
To download and install the app, you must obtain the IP address or fully qualified domain name (FQDN)
of the GlobalProtect portal from the administrator. The administrator should also verify the username and
password that you can use to connect to the portal. In most instances, you can use the same username and
password that you use to connect to your corporate network. After you gather the required information,
use the following steps to download and install the app:
STEP 4 | Complete the GlobalProtect app setup using the GlobalProtect Installer.
2. Enter the FQDN or IP address of the portal that your GlobalProtect administrator provided, and then
click Connect.
3. (Optional) By default, you are automatically connected to the Best Available gateway, based on
the configuration that the administrator defines and the response times of the available gateways.
To connect to a different gateway, select the gateway from the Gateway drop-down (for external
gateways only).
This option is only available if your administrator enables manual gateway selection.
4. (Optional) Depending on the connection mode, click Connect to initiate the connection.
5. (Optional) If prompted, enter your Username and Password, and then click Sign In. If authentication
is successful, you are connected to your corporate network, and the status panel displays the
Connected or Connected - Internal status. If your administrator sets up a GlobalProtect welcome
page, it displays after you log in successfully.
You can determine if you are connected by checking the GlobalProtect system tray icon.
If you are not connected, the icon is gray ( ), and Disconnected appears when you
hover over the icon.
1. Launch the GlobalProtect app by clicking the system tray icon. The status panel opens.
2. (Optional) If you are logging in to the GlobalProtect app for the first time, enter the FQDN or IP
address of the GlobalProtect portal, and then click Connect.
3. (Optional) If multiple portals are saved on your app, select a portal from the Portal drop-down. By
default, the most recently connected portal is pre-selected from the Portal drop-down.
4. (Optional) By default, you are automatically connected to the Best Available gateway, based on
the configuration that the administrator defines and the response times of the available gateways.
To connect to a different gateway, select the gateway from the Gateway drop-down (for external
gateways only).
This option is only available if your administrator enables manual gateway selection.
5. (Optional) Depending on the connection mode, click Connect to initiate the connection.
6. (Optional) If prompted, enter your Username and Password, and then Sign In.
When the app connects in external mode, the GlobalProtect system tray icon displays a shield ( ),
and Connected appears when you hover over the icon. When the app connects in internal mode, the
GlobalProtect system tray icon displays a house ( ), and Internal Network appears when you hover
over the icon.
After you launch the app, click the settings icon ( ) on the status panel to open the settings menu.
Select Settings to open the GlobalProtect Settings panel, and then select one of the following tabs to
view information about your network connection:
• General—Displays the username and portal(s) associated with the GlobalProtect account. You can
also add, delete, or modify portals from this tab.
For internal mode, the Connection tab displays the entire list of available gateways.
For external mode, the Connection tab displays only the gateway to which you are
connected and additional details about the gateway (such as the gateway IP address
and uptime).
If your GlobalProtect administrator configures the GlobalProtect portal agent to Save User
Credentials, your credentials are automatically saved to the GlobalProtect app. If your
password for accessing the corporate network changes, you must log in to GlobalProtect
using your new password.
1. Launch the GlobalProtect app by clicking the system tray icon. The status panel opens.
2.
Click the settings icon ( ) to open the settings menu.
3. Select Settings to open the GlobalProtect Settings panel.
4. On the General tab of the GlobalProtect Settings panel, Sign Out to clear your saved user credentials
from the GlobalProtect app.
5. After you clear your user credentials, you can reconnect to GlobalProtect with your new username
and password.
The Disable option is visible only if your GlobalProtect agent configuration allows you to
disable the app. If the configuration allows you to disable the GlobalProtect app without
requiring you to respond to a challenge, the GlobalProtect app closes without requiring
further action.
• Passcode—A passcode that is typically provided by your administrator in advance, based on a known
issue or event that requires you to disable the app.
If you no longer have the GlobalProtect Installer on your Mac endpoint, you can uninstall
GlobalProtect by running the following command from the command line:
sudo /Applications/GlobalProtect.app/Contents/Resources/
uninstall_gp.sh
If your system administrator has enabled GlobalProtect Clientless VPN access, the
application page opens after you log in to the portal (instead of the app download page).
Select GlobalProtect Agent to open the download page.
STEP 2 | Determine if the GlobalProtect enforcer kernel extension exists on the endpoint.
On the Mac endpoint, open the Terminal application under the Applications > Utilities folder, and then
enter the following command:
kextstat | grep gplock
> Download and Install the GlobalProtect App for Chrome OS on page 39
> Use the GlobalProtect App for Chrome OS on page 41
> Disconnect from GlobalProtect on a Chromebook on page 43
> Uninstall the GlobalProtect App for Chrome OS on page 44
37
38 GLOBALPROTECT APP USER GUIDE | GlobalProtect App for Chrome OS
© 2018 Palo Alto Networks, Inc.
Download and Install the GlobalProtect App
for Chrome OS
Before you can connect your Chromebook to the GlobalProtect network, you must download and install the
app. If your Chromebook is managed by the Chromebook Management Console, your administrator may
have automatically pushed the GlobalProtect app to your device and configured the VPN settings. If you do
not already have the GlobalProtect app on your Chromebook, you can download it from the Chrome Web
Store.
After downloading the app, you will need the IP address or FQDN of the GlobalProtect portal, which
you can get from your administrator. In addition, your administrator should verify which username and
password you should use to connect to the portal and gateways. Usually this is the same username and
password you use to connect to your corporate network. After you gather the required information, you
can download and install the app as follows:
STEP 1 | Download the app from the Chrome Web Store. If you already have the app, skip to 2.
1. If you haven't already, add a Google account on your Chromebook.
2. Search for the app in the Chrome Web Store or go directly to the GlobalProtect app page.
3. Click Add to Chrome and then follow the prompts to download and install the app.
4. When successfully installed, the Chrome App Launcher displays the GlobalProtect icon in the list of
apps.
When connected to the VPN, the status area displays the VPN icon along the bottom of
the Wi-Fi icon ( ). To view the portal to which you are connected, select the status area.
From the Chrome App Launcher, click the GlobalProtect icon to launch the app.
STEP 3 | Continue to use the app to perform any of the following tasks:
• View information about your network connection.
• Disconnect from the VPN through the GlobalProtect app for Chrome OS.
If the GlobalProtect administrator has selected the option to save user credentials in the
GlobalProtect portal configuration, the credentials are automatically saved when you
disconnect from the VPN. To clear the credentials and force you to enter them when you
reconnect, use the Sign-Out option.
From the Chrome App Launcher, click the GlobalProtect icon to launch the app, and then do either of
the following:
• Disconnect the VPN connection but retain your user credentials. When you next log in, you will not
be prompted to enter your credentials if your administrator has permitted GlobalProtect to save
them.
• Click your username in the top-right corner and select Sign-Out to disconnect the VPN connection
and clear your user credentials. When you next log in, you must enter your credentials for the portal
and gateway.
STEP 2 | Click the Chrome App Launcher and select All Apps.
STEP 3 | Two-finger tap (or Alt-click) on the app and select Uninstall.
STEP 4 | When prompted to confirm the removal, click Remove. The Chromebook uninstalls the app
and removes it from the launcher.
45
46 GLOBALPROTECT APP USER GUIDE | GlobalProtect App for Linux
© 2018 Palo Alto Networks, Inc.
Download and Install the GlobalProtect App
for Linux
The GlobalProtect app for Linux supports the DEB, RPM, and TAR installation packages.
where <DestinationFolder> is a location such as ~/pkgs/ where you want to store the TGZ
file.
2. From the Linux endpoint, unzip the package.
After you unzip the package, you will see installation packages—DEB for Ubuntu and RPM for
CentOS and Red Hat—and the scripts to install and uninstall the packages.
STEP 2 | Install the app package using either the sudo dpkg -i <gp-app-pkg> or apt-get install
<gp-app-pkg> command where <gp-app-pkg> is the name of your distribution package for
your Linux version.
user@linuxhost:~$ globalprotect
>>
2. To exit prompt mode, enter quit.
>> quit
user@linuxhost:~$
>> help
Usage: only the following commands are supported:
collect-log -- collect log information
connect -- connect to server
disconnect -- disconnect
disable -- disable connection
import-certificate -- import client certificate file
quit -- quit from prompt mode
rediscover-network -- network rediscovery
remove-user -- clear credential
resubmit-hip -- resubmit hip information
set-log -- set debug level
show -- show information
Command-line mode:
When you use certificate-based authentication, the first time you connect without a root CA certificate,
the GlobalProtect app and GlobalProtect portal exchange certificates. The GlobalProtect app displays
a certificate error, which you must acknowledge before you authenticate. When you next connect, you
will not be prompted with the certificate error message.
You can also specify a username in the command using the --username <username>
option. The GlobalProtect app prompts you to authenticate and, if you specified the
username option, confirm your username.
• Import a certificate.
• Connect to a gateway:
1. (Optional) Display the manual gateways to which you can connect using the globalprotect show
--manual-gateways command.
2. Connect to a gateway using the globalprotect connect --gateway <gp-gateway>
command where <gp-gateway> is the IP address or FQDN of the GlobalProtect gateway.
3. View details about your connection using the globalprotect show --details command.
network-interface
enp0s31f6
description: enp0s31f6
mac-address: D4:81:D7:D4:5A:A5
wlp2s0
description: wlp2s0
mac-address: 14:AB:C5:DE:D1:0E
user@linuxhost:~$ globalprotect resubmit-hip
Resubmit is successful.
• View errors.
Use the globalprotect show --error command to view errors reported by the app.
• Collect logs.
The app stores the PanGPA and PanGPI log files in the /home/<user>/.Globalprotect directory.
Use the globalprotect collect-logs command to enable the GlobalProtect app for Linux to
package these logs and other useful information. You can then use the logs to troubleshoot issues or
forward them to a Support engineer for expert analysis.