<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect license usage and behavior on running out in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-license-usage-and-behavior-on-running-out/m-p/447773#M2147</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132469"&gt;@MichaelMedwid&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't think the firewall records the peak users, but you can check current or previous -&amp;gt; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClorCAC" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClorCAC&lt;/A&gt;.&amp;nbsp; Previous should show the "peak" from a unique username count.&amp;nbsp; I would hope that an NMS could graph GP users via SNMP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The maximum GP users is a hardware limit.&amp;nbsp; If it is exceeded the gateway will refuse the connection.&amp;nbsp; See the picture in this thread -&amp;gt; &lt;A href="https://live.paloaltonetworks.com/t5/general-topics/global-protect-firewall-behavior-after-reaching-max-users/td-p/310408" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/general-topics/global-protect-firewall-behavior-after-reaching-max-users/td-p/310408&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Mon, 15 Nov 2021 23:37:12 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2021-11-15T23:37:12Z</dc:date>
    <item>
      <title>Global Protect license usage and behavior on running out</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-license-usage-and-behavior-on-running-out/m-p/447729#M2146</link>
      <description>&lt;P&gt;How can you view the peak number of global protect licenses are being consumed&lt;/P&gt;&lt;P&gt;on a PAN? And when those licenses are consumed, what is the behavior of the GP&lt;/P&gt;&lt;P&gt;clients that connect beyond the limit? For example the 3220 allows for 1024 GP&lt;/P&gt;&lt;P&gt;connections simultaneously from what I understand. What happens to the 1025th&lt;/P&gt;&lt;P&gt;GP client that attempts to connect? TY&lt;/P&gt;</description>
      <pubDate>Mon, 15 Nov 2021 19:24:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-license-usage-and-behavior-on-running-out/m-p/447729#M2146</guid>
      <dc:creator>MichaelMedwid</dc:creator>
      <dc:date>2021-11-15T19:24:46Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect license usage and behavior on running out</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-license-usage-and-behavior-on-running-out/m-p/447773#M2147</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132469"&gt;@MichaelMedwid&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't think the firewall records the peak users, but you can check current or previous -&amp;gt; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClorCAC" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClorCAC&lt;/A&gt;.&amp;nbsp; Previous should show the "peak" from a unique username count.&amp;nbsp; I would hope that an NMS could graph GP users via SNMP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The maximum GP users is a hardware limit.&amp;nbsp; If it is exceeded the gateway will refuse the connection.&amp;nbsp; See the picture in this thread -&amp;gt; &lt;A href="https://live.paloaltonetworks.com/t5/general-topics/global-protect-firewall-behavior-after-reaching-max-users/td-p/310408" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/general-topics/global-protect-firewall-behavior-after-reaching-max-users/td-p/310408&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 15 Nov 2021 23:37:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-license-usage-and-behavior-on-running-out/m-p/447773#M2147</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2021-11-15T23:37:12Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect license usage and behavior on running out</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-license-usage-and-behavior-on-running-out/m-p/447785#M2148</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132469"&gt;@MichaelMedwid&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I presumed that the 1025th session would be dropped due to the hardware limitation.&lt;BR /&gt;Here are the SNMP OIDs that you can draw SNMP graphs for the GlobalProtect sessions, and you may set up a threshold alert when it reaches a specific value like 800 sessions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;TABLE border="1" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;GlobalProtect gateway % utilization&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;panGPGWUtilizationPct.0&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;1.3.6.1.4.1.25461.2.1.2.5.1.1&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;PAN-COMMON-MIB&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;GlobalProtect gateway max tunnels&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;panGPGWUtilizationMaxTunnels.0&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;1.3.6.1.4.1.25461.2.1.2.5.1.2&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;PAN-COMMON-MIB&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;GlobalProtect gateway active tunnels&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;panGPGWUtilizationActiveTunnels.0&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;1.3.6.1.4.1.25461.2.1.2.5.1.3&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;PAN-COMMON-MIB&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can simply test with a snmpwalk query for the active GP connections.&lt;BR /&gt;snmpwalk -v3 -l authPriv -u SNMPUser -a SHA -A "Auth_Password" -x AES -X "Priv_Password" 192.168.1.1 .1.3.6.1.4.1.25461.2.1.2.5.1.3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FYI, for the SNMP setup&lt;BR /&gt;Device -&amp;gt; Setup -&amp;gt; Operations -&amp;gt; Miscellaneous -&amp;gt; SNMP Setup&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 00:34:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-license-usage-and-behavior-on-running-out/m-p/447785#M2148</guid>
      <dc:creator>AnalysisMan</dc:creator>
      <dc:date>2021-11-16T00:34:29Z</dc:date>
    </item>
  </channel>
</rss>

