VPN Tracker 26.8 introduces beta support for Palo Alto Networks GlobalProtect VPN connections, new OpenVPN authentication and encryption capabilities, and easier connection organization. The update also brings important reliability improvements for GlobalProtect, SonicWall SSL, WireGuard, Split DNS, AppleScript automation, and fast reconnects.
If your organization uses GlobalProtect or advanced OpenVPN configurations, this is an especially useful update to test.
In this article
GlobalProtect VPN Support (Beta)
VPN Tracker 26.8 introduces Palo Alto Networks GlobalProtect VPN support — a major addition for Mac users who need secure access to company networks. GlobalProtect connections can now sit alongside your other business VPNs in VPN Tracker, giving you one place to organize, launch, and troubleshoot remote access on macOS.

GlobalProtect Support at a Glance
GlobalProtect environments often use several authentication stages across a portal and one or more gateways. VPN Tracker supports these workflows, including password prompts, browser-based sign-in, one-time codes, challenge responses, and authentication cookies.
The latest release also includes important reliability work for real-world GlobalProtect deployments. VPN Tracker can reuse authentication cookies to reduce repeated sign-in prompts, prefer current portal credentials when connecting to a gateway, retrieve a separately requested gateway password from the macOS keychain, and recover more reliably when a portal or gateway asks for a different authentication method.

New: Palo Alto GlobalProtect connections are supported in the latest version
Which Palo Alto Networks Devices Can I Connect To?
VPN Tracker supports GlobalProtect connections across a wide range of Palo Alto Networks firewalls and cloud deployments. Popular examples include:
- PA-400 Series – including the PA-410, PA-440, PA-450, and PA-460
- PA-1400 Series – including the PA-1410 and PA-1420
- PA-3400 Series – for larger enterprise networks
- VM-Series Virtual Firewalls – for virtualized and cloud environments
- Prisma Access – for GlobalProtect Mobile Users deployments
As GlobalProtect support is currently in beta, compatibility may vary depending on your PAN-OS version, portal and gateway configuration, licensing, and authentication setup. We recommend testing your specific environment before a wider rollout.
Who Can Test GlobalProtect Support?
Everyone can test it. GlobalProtect support is included in the latest full release of VPN Tracker 26.8, so there is no separate beta app or special download channel. The VPN Tracker release itself is production software; only the new GlobalProtect connection type remains a beta feature.
That beta label is a testing advisory: before relying on GlobalProtect for business-critical access, check your portal and gateway sign-in, browser authentication, MFA or one-time-code prompts, challenge responses, internal DNS and resources, and reconnect behavior in your own environment. Please send us your feedback — especially if your setup uses multi-step authentication or device-bound cookies.
How to Connect to GlobalProtect with VPN Tracker
Getting started takes just a few steps:
- Install or update to the latest VPN Tracker version
- Open the VPN Tracker Connection Creator for Palo Alto GlobalProtect
- Enter your connection details and save to your VPN Tracker account
Palo Alto Setup Guide: Our step-by-step guide contains detailed information about supported devices, how to set up VPN access for Palo Alto, and Team Rollout. Read the guide →
OpenVPN Improvements
VPN Tracker 26.8 expands OpenVPN compatibility with support for tls-crypt-v2 client keys, static challenge authentication, and additional authentication and encryption options. Together, these improvements make it easier to use VPN Tracker with advanced OpenVPN deployments and configurations that require multi-step authentication.
tls-crypt-v2 Client Keys
OpenVPN connections in VPN Tracker now support tls-crypt-v2 client keys. This OpenVPN option uses a client-specific key to protect the control channel before the TLS session is established.
For organizations already provisioning tls-crypt-v2 in their OpenVPN profiles, VPN Tracker can now use the supplied client key as part of the connection setup. This makes it easier to bring advanced OpenVPN deployments into the same Mac VPN client used for your other connections.
Static Challenge Authentication
VPN Tracker 26.8 also supports OpenVPN static challenge authentication. When an OpenVPN gateway requires both a regular password and a one-time code, VPN Tracker can present separate password and one-time-code prompts.
This is particularly useful for OpenVPN Access Server and other setups that use the static-challenge option for two-factor authentication. Users can respond to the challenge directly during connection startup without combining the password and one-time code manually.
New Authentication and Encryption Options
In addition to tls-crypt-v2 and static challenges, this release adds further OpenVPN authentication and encryption options. These options improve compatibility with OpenVPN gateways that use more specialized combinations of authentication and encryption settings.
If an existing OpenVPN profile did not previously expose the settings required by your gateway, update VPN Tracker and review the connection’s OpenVPN configuration options. Your VPN administrator can confirm which values are required for your environment.
New to OpenVPN in VPN Tracker? See our guide to connecting to OpenVPN with VPN Tracker.
Also New in VPN Tracker 26.8
This version includes a broad range of connection management, authentication, networking, automation, and diagnostic improvements:
- Alphabetical connection sorting: Sort connection lists alphabetically to find customer, office, and test VPNs more quickly, including connections organized in nested groups.
- SonicWall SSL: Fixed sign-in failures that could prevent connections from authenticating.
- GlobalProtect authentication: Improved authentication-cookie reuse, including servers that bind cookies to a specific device. VPN Tracker now prefers current portal credentials at the gateway and can use a password saved in the keychain when a gateway requests a separate password.
- GlobalProtect recovery: Connections recover more reliably when a gateway rejects portal credentials, a web sign-in, a password, or a challenge response.
- GlobalProtect diagnostics: More detailed logging for authentication, gateway failures, and tunnel setup makes troubleshooting easier.
- Split DNS: Domains pushed by VPN gateways are applied correctly, with more reliable DNS behavior during network changes.
- Reconnect reliability: VPN authentication and connection handling are more reliable, including rapid reconnect sequences.
- WireGuard: Full-tunnel connections now handle network changes more reliably.
- AppleScript: Nested connection groups are handled reliably, ping results are returned correctly, and scripts can optionally wait for a connection to finish starting or stopping.
- Update information: The update dialog now shows both the available update and the currently installed VPN Tracker version.
Compatible macOS Versions and Macs
VPN Tracker 26.8 supports:
- macOS 27 Golden Gate
- macOS 26 Tahoe
- macOS 15 Sequoia
- macOS 14 Sonoma
- macOS 13 Ventura
- macOS 12 Monterey
- macOS 11 Big Sur
The update runs on both Apple silicon Macs, including M1, M2, M3, and M4 models, and Intel-based Macs.
How to Download VPN Tracker 26.8
This is a free update for all existing VPN Tracker users.
To update on your Mac: Open VPN Tracker and choose VPN Tracker > Check for Updates. The update window now also shows which version is currently installed, making it easy to confirm whether the update has completed.
New to VPN Tracker? You can try Company Connect free for 7 days. A 24-hour World Connect trial is also available for secure browsing on the go.
Ready to Try VPN Tracker 26.8?
Download the latest VPN Tracker version for Mac and test the new GlobalProtect and OpenVPN features with your own VPN setup.


