Install and Connect to GlobalProtect VPN (Linux)

Context

This article will help you download and install GlobalProtect VPN version 6.2.8 on your Linux workstation, upgrade from an older version, and connect to the UT Dallas VPN. All instructions are based on Ubuntu (Debian) and Rocky Linux (based on Red Hat Enterprise Linux). You may need to adjust these instructions if you use another Linux distribution.

Note: Only specific versions of Linux are supported. To check whether your version of Linux is compatible with GlobalProtect, see the Palo Alto Networks Compatibility Matrix.
Already using GlobalProtect 6.1.x or older? Older versions may not work on newer Linux releases such as Ubuntu 24.04. Follow Upgrading from an older version below.

Download

Download GlobalProtect-Linux-6.2.8.tgz (UT Dallas Box, sign in with your NetID). Box can't preview this file type, so click Download.

After you extract it (step 2 below), use the file that matches your computer:

Your computer File to use
Ubuntu / Debian (64-bit Intel/AMD) GlobalProtect_UI_deb-6.2.8.1-1057.deb
RHEL / Rocky Linux (64-bit Intel/AMD) GlobalProtect_UI_rpm-6.2.8.1-1057.rpm
Command line only (no desktop) GlobalProtect_deb-6.2.8.1-1057.deb or GlobalProtect_rpm-6.2.8.1-1057.rpm
ARM computers (command line only) GlobalProtect_deb_aarch64-… / GlobalProtect_rpm_aarch64-… (64-bit ARM), or …_arm-… (32-bit ARM)

Installing

  1. Open the terminal and use cd to go to the folder you downloaded to, for example:
    cd ~/Downloads
  2. Extract the file:
    tar -xvf GlobalProtect-Linux-6.2.8.tgz
  3. Install the package for your system:
    • Ubuntu / Debian:
      sudo apt install ./GlobalProtect_UI_deb-6.2.8.1-1057.deb
    • RHEL / Rocky Linux:
      sudo yum localinstall GlobalProtect_UI_rpm-6.2.8.1-1057.rpm
    • If the system asks to install additional packages (dependencies), type y and press Enter.
  4. Enable the default browser for sign-in (SAML). This is required for Duo.
    • Type sudo nano /opt/paloaltonetworks/globalprotect/pangps.xml and press Enter.
    • Add <default-browser>yes</default-browser> on a new line under <Settings>.
    • Save by pressing Ctrl+O, then Enter. Exit by pressing Ctrl+X.
    • Restart your computer.
  5. To open the GlobalProtect UI, choose GlobalProtect from your Applications menu, or run globalprotect launch-ui.

Note: The GlobalProtect icon will generally not appear in the top taskbar in Linux. This is a known issue. You can always re-launch GlobalProtect (to connect or disconnect) using the methods listed above.

Upgrading from an older version

  1. Check your current version: open GlobalProtect and go to Settings > About, or run globalprotect show --version.
  2. If it shows 6.1.x or lower, disconnect, then follow Installing above. Installing over the old version upgrades it.
  3. Check that the <default-browser>yes</default-browser> line is still in pangps.xml (Installing, step 4). Add it again if it is missing.
  4. Check the version again. It should show 6.2.8.

Connecting

  1. To open the GlobalProtect UI, choose GlobalProtect from your Applications menu, or run globalprotect launch-ui.
  2. Enter the portal address: utdvpn.utdallas.edu
  3. Click Connect.
  4. Your default browser will open to complete authentication. Log in with your NetID and Password, then complete Duo authentication.
Note: OIT is aware of issues with GlobalProtect for Linux when Firefox is set as your default browser. If you can't log in, keep Firefox installed but set Chrome as your default browser, then try again.
  1. When prompted, choose to open the application. The prompt may vary based on your version of Linux (Ubuntu and Rocky Linux are shown below). If you do not see the popup, choose the "click here to launch GlobalProtect" option.


  2. Your client will now show as connected.
Note: If you're having trouble running the VPN on Linux, visit KA 900 for a list of possible fixes. When contacting the OIT Service Desk, include your Linux version (cat /etc/os-release), your GlobalProtect version, and a screenshot of the error.
50% helpful - 2 reviews
Print Article

Related Articles (2)

The Evolution Mail client supports Microsoft 365 through the evolution-ews plugin, starting in evolution-ews v3.27.91 and above.
Issue with the Global Protect VPN where users on Ubuntu 22.04 and other similar Linux versions cannot connect to VPN due to an SSL handshake issue. The issue is caused by the software update due to some package incompatibility. Follow the instructions in this article for possible solutions.

Related Services / Offerings (1)

The GlobalProtect Virtual Private Network (VPN) provides secure access to restricted University data and resources using an off-campus computer through a secured Internet connection. In order to utilize VPN services, you must first be enrolled in Duo.