<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect, 1 Portal - 2 gateways - AlwaysOn users don't disconnect in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-1-portal-2-gateways-alwayson-users-don-t/m-p/331499#M170</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/98540"&gt;@mwunder&lt;/a&gt;&amp;nbsp;, hi. No problem... &amp;nbsp;&lt;/P&gt;&lt;P&gt;i’m not sure i can give the exact reasons behind the settings but yes they are within the area of gateway agent connection settings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i use...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;login lifetime 12 hours&lt;/P&gt;&lt;P&gt;inactivity timeout 2 hours&lt;/P&gt;&lt;P&gt;disconnect on idle 180 minutes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we do have gateway license that covers HIP but even the login lifetime of 12 hours will make your stats more accurate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;not sure why it would be set to 5 days, &amp;nbsp;... &amp;nbsp; perhaps ok for a branch office but do your users never sleep...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the help file is not much use...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 03 Jun 2020 20:33:04 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2020-06-03T20:33:04Z</dc:date>
    <item>
      <title>Global Protect, 1 Portal - 2 gateways - AlwaysOn users don't disconnect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-1-portal-2-gateways-alwayson-users-don-t/m-p/330951#M159</link>
      <description>&lt;P&gt;We run a Solarwinds script to count&amp;nbsp;&lt;SPAN&gt;panGPGWUtilizationActiveTunnels from each of our active gateways (2 different firewalls).&amp;nbsp; Currently we have 900 Global Protect clients installed, but there are 1,355 active tunnels due to the fact that we use Always-On with a Login Lifetime of 5 days.&amp;nbsp; Essentially, if a user connects to gateway A, then disconnects for any reason, and then connects to gateway B, the first connection on gateway A remains for 5 days and is in essence, double counted in the Solarwinds report.&amp;nbsp; Is anyone else having this issue??&amp;nbsp; It seems that the portal would be smart enough to know that there was a session at gateway A and send the user back there....or better yet, Palo Alto and all it's sophistication, could give me a reliable count as to how many actual active users are connected to my firewalls.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any ideas would be appreciated.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2020 02:20:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-1-portal-2-gateways-alwayson-users-don-t/m-p/330951#M159</guid>
      <dc:creator>mwunder</dc:creator>
      <dc:date>2020-06-02T02:20:27Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect, 1 Portal - 2 gateways - AlwaysOn users don't disconnect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-1-portal-2-gateways-alwayson-users-don-t/m-p/331322#M166</link>
      <description>&lt;P&gt;We did have a similar issue with PRTG monitoring and with over 5k users this also gave ridiculous connection stats... &amp;nbsp;we just reduced the gateway idle timeout to 2 hours as we do not need to know the exact number of connections, just approx for monitoring.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are many calls logged regarding duplicate user connections and am pretty sure someone has it as a feature release somewhere...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mick.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2020 08:08:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-1-portal-2-gateways-alwayson-users-don-t/m-p/331322#M166</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-06-03T08:08:19Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect, 1 Portal - 2 gateways - AlwaysOn users don't disconnect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-1-portal-2-gateways-alwayson-users-don-t/m-p/331387#M167</link>
      <description>&lt;P&gt;Thanks for the response Mick.&amp;nbsp; Are you talking about the Gateway &amp;gt; Agent &amp;gt; Connection Settings &amp;gt; Inactivity Logout?&amp;nbsp; If so, are you using HIP checks with the GlobalProtect Gateway license?&amp;nbsp; I believe I messed with this setting but since I'm not using HIP checks, All clients were getting disconnected after 12 hours (I believe that's what I set it to at the time).&amp;nbsp; If you're not using the GP Gateway license and HIP checks, maybe this is a direction for me to start looking.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the lead!&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2020 14:41:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-1-portal-2-gateways-alwayson-users-don-t/m-p/331387#M167</guid>
      <dc:creator>mwunder</dc:creator>
      <dc:date>2020-06-03T14:41:38Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect, 1 Portal - 2 gateways - AlwaysOn users don't disconnect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-1-portal-2-gateways-alwayson-users-don-t/m-p/331499#M170</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/98540"&gt;@mwunder&lt;/a&gt;&amp;nbsp;, hi. No problem... &amp;nbsp;&lt;/P&gt;&lt;P&gt;i’m not sure i can give the exact reasons behind the settings but yes they are within the area of gateway agent connection settings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i use...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;login lifetime 12 hours&lt;/P&gt;&lt;P&gt;inactivity timeout 2 hours&lt;/P&gt;&lt;P&gt;disconnect on idle 180 minutes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we do have gateway license that covers HIP but even the login lifetime of 12 hours will make your stats more accurate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;not sure why it would be set to 5 days, &amp;nbsp;... &amp;nbsp; perhaps ok for a branch office but do your users never sleep...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the help file is not much use...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2020 20:33:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-1-portal-2-gateways-alwayson-users-don-t/m-p/331499#M170</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-06-03T20:33:04Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect, 1 Portal - 2 gateways - AlwaysOn users don't disconnect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-1-portal-2-gateways-alwayson-users-don-t/m-p/331678#M175</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;New to Always-On I guess.&amp;nbsp; The management decision was made to allow the user to remain connected for forever, thus the settings being so long.&amp;nbsp; I am going to bump down to 14 hours and 2 hours.&amp;nbsp; The inactivity timer means nothing when the connect method is Always-On, so I'm not going to touch that one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again for leading me down the path.&amp;nbsp; I forgot that I had turned off HIP check when I noticed that it was booting active sessions, but what I missed at the time was that I was blocking those sessions as seen here:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-err-http2-inadequate-transport-security/td-p/306467" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-topics/ssl-decryption-err-http2-inadequate-transport-security/td-p/306467&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2020 18:22:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-1-portal-2-gateways-alwayson-users-don-t/m-p/331678#M175</guid>
      <dc:creator>mwunder</dc:creator>
      <dc:date>2020-06-04T18:22:08Z</dc:date>
    </item>
  </channel>
</rss>

