# Palo Alto VPN

TAU uses Palo Alto GlobalProtect VPN with two-factor authentication (Google Authenticator).

Required if connecting to the cluster from outside the TAU network.

**Ubuntu 26.04:** No official GlobalProtect build yet.   
You can use the open-source alternative: [github.com/levcovenant/GlobalProtect-openconnect](https://github.com/levcovenant/GlobalProtect-openconnect)

## Enrollment

1. Go to [https://mytau.tau.ac.il/GetResource.php](https://mytau.tau.ac.il/GetResource.php) and register your mobile phone
2. Install **Google Authenticator** on your mobile device
3. Scan the QR code provided during enrollment

## Download

Download the appropriate version for your system:

- [PanGPLinux-6.2.9-c4.tgz](https://hpcguide.tau.ac.il/attachments/2)
- [PanGPLinux-6.3.3-c22.tgz](https://hpcguide.tau.ac.il/attachments/1)



## Install

**RHEL/Rocky/CentOS:**

```bash
tar -xzf PanGPLinux-6.x.x-cx.tgz
yum localinstall GlobalProtect_UI_rpm-*.rpm
```

**Debian/Ubuntu:**

```bash
tar -xzf PanGPLinux-6.x.x-cx.tgz
dpkg -i GlobalProtect_UI_deb-*.deb
```

##  

## Ubuntu 26.04 – Alternative (no official client yet)

**For Ubuntu 26.04** there is no official GlobalProtect build yet. You can use the open-source alternative based on OpenConnect.

Fork of the Qt6 GUI client with SAML support. Portal is still `vpn.tau.ac.il`

**Repo:** [github.com/levcovenant/GlobalProtect-openconnect](https://github.com/levcovenant/GlobalProtect-openconnect)

**Install on Ubuntu / Mint:**

```bash
git clone https://github.com/levcovenant/GlobalProtect-openconnect.git
cd GlobalProtect-openconnect
./scripts/install-ubuntu.sh
```

**Run:**

```bash
gpclient
```

Then enter gateway `vpn.tau.ac.il` and login with your TAU credentials + Authenticator code as usual.

## Configure

1. Open the GlobalProtect client
2. Enter gateway address: **vpn.tau.ac.il**
3. Log in with your TAU credentials
4. Enter the code from Google Authenticator when prompted

## Troubleshooting: SSL Error on Ubuntu 22.04+

If you see an SSL error after connecting, apply this fix:

Open `/usr/lib/ssl/openssl.cnf` and add:

```
[openssl_init]
ssl_conf = ssl_sect

```

\[ssl\_sect\] system\_default = system\_default\_sect

```


```

`[system_default_sect]Options = UnsafeLegacyRenegotiation`

```
```

Restart the GlobalProtect app.