How to logout a single GlobalProtect user from the gateway using CLI?
18897
Created On 04/21/21 18:09 PM - Last Modified 09/27/21 21:34 PM
Question
This article describes how to logout a single GlobalProtect user from the gateway using CLI
Environment
- PAN-OS 9.0 and above.
- Palo Alto Firewall.
- GlobalProtect Configured.
Answer
Starting from PAN-OS 9.0, you can logout a single GlobalProtect user by using the below CLI command:
> request global-protect-gateway client-logout domain <domain-name> reason force-logout user <username> gateway "<gateway-name>-N" computer <computer-name>
Use the parameters from the command show global-protect-gateway current-user for that user. Username information should be taken from the Domain-User Name field.
Additional Information
How to Remote Disconnect SSL-VPN or GlobalProtect Users