Palo Alto VPN

TAU uses Palo Alto GlobalProtect VPN with two-factor authentication (Google Authenticator).

Required if connecting to the cluster from outside the TAU network.

Ubuntu 26.04: No official GlobalProtect build yet.
You can use the open-source alternative: github.com/levcovenant/GlobalProtect-openconnect

Enrollment

  1. Go to https://mytau.tau.ac.il/GetResource.php and register your mobile phone
  2. Install Google Authenticator on your mobile device
  3. Scan the QR code provided during enrollment

Download

Download the appropriate version for your system:


Install

RHEL/Rocky/CentOS:

tar -xzf PanGPLinux-6.x.x-cx.tgz
yum localinstall GlobalProtect_UI_rpm-*.rpm

Debian/Ubuntu:

tar -xzf PanGPLinux-6.x.x-cx.tgz
dpkg -i GlobalProtect_UI_deb-*.deb

 

Ubuntu 26.04 – Alternative (no official client yet)

For Ubuntu 26.04 there is no official GlobalProtect build yet. You can use the open-source alternative based on OpenConnect.

Fork of the Qt6 GUI client with SAML support. Portal is still vpn.tau.ac.il

Repo: github.com/levcovenant/GlobalProtect-openconnect

Install on Ubuntu / Mint:

git clone https://github.com/levcovenant/GlobalProtect-openconnect.git
cd GlobalProtect-openconnect
./scripts/install-ubuntu.sh

Run:

gpclient

Then enter gateway vpn.tau.ac.il and login with your TAU credentials + Authenticator code as usual.

Configure

  1. Open the GlobalProtect client
  2. Enter gateway address: vpn.tau.ac.il
  3. Log in with your TAU credentials
  4. Enter the code from Google Authenticator when prompted

Troubleshooting: SSL Error on Ubuntu 22.04+

If you see an SSL error after connecting, apply this fix:

Open /usr/lib/ssl/openssl.cnf and add:

[openssl_init]
ssl_conf = ssl_sect

[ssl_sect] system_default = system_default_sect


[system_default_sect] Options = UnsafeLegacyRenegotiation


 

Restart the GlobalProtect app.


Created 2026-06-11 14:44:32 UTC by levk
Updated 2026-10-06 12:26:04 UTC by levk