GlobalProtect users are identified with domain '(null)' when using authenticated cookie
6063
Created On 06/21/22 01:25 AM - Last Modified 05/08/25 08:27 AM
Symptom
- The globalprotect users are identified as '(null)\username' instead of expected domain prefix or '(empty-domain)', which causes the user traffic to hit the deny rule
- The issue happens only when the Portal cookie is enabled and gateway cookie is not enabled.
> show user ip-user-mapping all
IP Vsys From User Connected GW IP IdleTimeout(s) MaxTimeout(s)
--------------------------------------------- ------------------- ------- -------------------------------- ------------------------- -------------- -------------
x.x.x.x vsys1 GP (null)\user1 y.y.y.y 10359 10359
Environment
- GlobalProtect with authentication cookie enabled on Portal
- Prisma Access
- PAN-OS 10.0.8
Cause
Software Defect PAN-184291.
Resolution
- As a workaround, Disable cookie generation on GP Portal or Generate cookie on the GP Gateway.
- For fix, Upgrade to PAN-OS 10.0.11 or 10.1.6 or higher which resolves PAN-184291.
Additional Information
- To disable cookie on Portal:
- GUI: Network > GlobalProtect > Portals > GlobalProtecct_Portal > Agent > Configs > Authentication > and Uncheck 'Generate cookie for authentication override'
- How to generate cookies on GlobalProtect Portal and use cookies for Gateway Authentication