Looking for: GlobalProtect App 4.1.6 (windows and macOS clients)

Is there any nice Palo Alto / globalprotect admins out there, who can share the latest clients please

Looking for: GlobalProtect App 4.1.6 (windows and macOS clients)

I find it frustrating that paloalto

a) Don’t have their clients freely available on their site

b) That each company who employ the service have to manually update their own downloads

Agreed. I usually find them publicly if I google the file name with the .edu domain…

Just get it from the support site?

/u/coffeesurfers
Here is v4.1.8
https://www.ssc.wisc.edu/sscc/pubs/vpn.htm

Hmm will give that a go mate thanks :+1:

I’ve tried googling getsoftwarepage.esp but usually end up getting ancient clients!

I don’t have an admin login for the support site :pensive_face:

or login to the vpn portal, if the firewall is current, the download from there will be current.

I work for a large company who are slow as hell to update… We are several versions behind the latest client

As an admin that has had no end of issues with GP, they may have a very good reason for that.

There’s a reason for that. The 4.1 client isn’t known for its stability.

I have had a number of oddball issues, but the quality of the GP client has generally been getting better. Unlike new firmware I’m not as reluctant to test a new version.

Agreed however for staff like myself I get involved with a lot of troubleshooting and not having quick access to the latest client is really frustrating… Back peddling a tad, do you have access to the latest clients? If so can you share them? :grin:

The latest clients we tested (4.1.4) had issues with just sitting and spinning during login, which while I’m willing to smack it around to wake it up, I can’t expect general (international) users to do so (let alone management). After I upgrade to 8.0.14 (when it comes out on or about Nov 15th to fix the Chrome issue), I’ll revisit 4.1.6 or whatever is out at that time.

My biggest issue with 4.1.x of GP has been its messing around with HIP collection.

It changed the way it reported drive encryption from [driveletter]: to [driveletter]:\

A trivial thing to correct on the firewall, but a pain when suddenly clients aren’t able to access resources due to not matching your profile.

I have a ticket open with TAC for the next HIP issue, which is that it doesn’t identify Sophos Client Firewall correctly.
Initially, the GP client will pick it up as “Sophos Endpoint Security and Control” with a vendor of “Sophos Limited”, both of which aren’t listed on the firewall as a vendor nor a product.

If you hit resubmit host profile, this changes to “Sophos Anti-Virus” and the vendor “Sophos Plc”. 50% of the way there, the vendor is one listed on the firewall, but that isn’t a product option. Simply choosing “Other Sophos Plc. Firewall” doesn’t generate a match, either.

Just waiting for PA to inform me of their progress on fixing this, as it is behaviour that has existed in 4.1.0. They fixed the problem I had with it not picking up Crowdstrike, just need this before I make any 4.1.x client live.

It’s a shame, cause 4.1.x looks like a more modern application rather than the visual basic project looking prior versions.