Just got hit with the classic "patch Tuesday" surprise from Palo Alto. The new critical CVE (CVE-2024-XXXX, the one for GlobalProtect) meant we had to patch our PA-5200 series ASAP last night.
Patch applied fine, but now a subset of our remote users on macOS Sonoma can't establish VPN connections. The client authenticates, but the tunnel never establishes. No useful logs on the client side, and the firewall logs just show a generic "phase 1 failure." Rolling back the patch isn't an option per security. We're digging into IKEv2 configs, but nothing changed there.
Quick side-by-side of our configs pre/post-patch shows zero differences in the VPN settings. We're testing a theory about a specific cipher suite being deprecated in the patch.
Anyone else in the same boat? Specifically:
* Seeing issues **only with macOS clients** after this PAN-OS patch?
* Found a workaround **without** downgrading or disabling the fix for the CVE?
* Noticed any changes to **IKE or IPSec config defaults** in the new version?
Our infosec team is breathing down our necks to stay patched, but the helpdesk is flooded with VPN tickets. Any insights would save my sanity 🙏.
ā alex
Data > opinions