GlobalProtect users are identified with domain '(null)' when using authenticated cookie

GlobalProtect users are identified with domain '(null)' when using authenticated cookie

6063
Created On 06/21/22 01:25 AM - Last Modified 05/08/25 08:27 AM


Symptom


  • The globalprotect users are identified as '(null)\username' instead of expected domain prefix or '(empty-domain)', which causes the user traffic to hit the deny rule
  • The issue happens only when the Portal cookie is enabled and gateway cookie is not enabled.
> show user ip-user-mapping all
IP                                            Vsys                From    User                             Connected GW IP           IdleTimeout(s) MaxTimeout(s)
--------------------------------------------- ------------------- ------- -------------------------------- ------------------------- -------------- -------------
x.x.x.x                                   vsys1               GP      (null)\user1                  y.y.y.y           10359          10359


Environment


  • GlobalProtect with authentication cookie enabled on Portal
  • Prisma Access
  • PAN-OS 10.0.8


Cause


Software Defect PAN-184291.



Resolution


  1. As a workaround, Disable cookie generation on GP Portal or Generate cookie on the GP Gateway.
  2. For fix, Upgrade to PAN-OS 10.0.11 or 10.1.6 or higher which resolves PAN-184291.


Additional Information




Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000Cq6zCAC&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language