GlobalProtect client on iPhone or iPad unable to connect when using SAML authentication

GlobalProtect client on iPhone or iPad unable to connect when using SAML authentication

16135
Created On 08/23/19 22:55 PM - Last Modified 09/07/22 19:07 PM


Symptom
Global Protect agent on iOS iPad or iPhone configured with Pre-logon or User-logon using SAML authentication will briefly connect and then get disconnected with the error message: Connection Failed. The internet connection appears to be offline.

 


Environment
  • PAN-OS 8.0 and above.
  • GlobalProtect Agent 5.0 and above on iOS iPad or iPhone.
  • GlobalProtect configured with Always-On connect method.
  • SAML configured for client authentication.

 


Cause
GlobalProtect iOS application only supports SAML authentication for on-demand connect method (Manual user-initiated connection) due to Apple VPN framework limitation. When Always-on mode is deployed to iOS devices, the Apple device blocks the internet connection and since SAML authentication requires internet, it will not work. Refer to Link for more details.

Resolution

To allow iOS iPhone or iPad to work with Global Protect, we need to have On-demand as the connect method. The best way to accomplish the same is to configure a new agent and move it to the top of the list as shown below:

 

  1. GUI:  Network >GlobalProtect > Portal > (select the portal) > Agent > Add > User/User Group > Add > select iOS in the OS tab instead of Any.
 Portal agent configuration
 
  1. GUI: Network >GlobalProtect > Portal > (select the portal) > Agent > (select the new agent) > App > App Configuration > Select On-demand as Connect Method.
 
on-demand
  1. Fill in other information as appropriate.
  2. GUI: Network >GlobalProtect > Portal > (select the portal) > Agent > (select the new agent) >  Use Move Up for the new agent to be the first one in the list.
  3. Commit the changes.


Additional Information
With the above configuration, the new Agent will take care of iOS Pad and iPhone clients. All other clients will use the second Agent in the list and are not affected.

Attachments
Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/kCSArticleDetail?id=kA10g000000PMfY&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FkCSArticleDetail

Attachments