GlobalProtect updates?

jhuls
Contributor III

I'm curious how those using GlobalProtect are handling updates. At the moment we're looking at using Self Service for the user to do it themself but I don't think that's a wise choice from a security perspective since users are notorious for not doing updates.

With that said I would like to configure it to be updated in the background but I'm concerned that if the vpn is being used that either the update will fail and/or the connection might be disrupted.

Can anyone share their experience?

2 REPLIES 2

sdamiano
Contributor

Our ideal version is locked in and defined on the PAN. Only when our network team vets a new version of Global Protect does it then get pushed to the PAN, and that handles the update on endpoints.

jhuls
Contributor III

Hmmm...maybe I should inquire about that. Does that update occur in the background? Just curious what the end user experience is like.