<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic GP Client and DUO 2F Very strange behavior in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-client-and-duo-2f-very-strange-behavior/m-p/524036#M3499</link>
    <description>&lt;P&gt;Thoughts and ideas are welcome.&amp;nbsp; Note, I have yet to tune the GP APP on the portal.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Okay... I would like to keep this brief, but I have conducted numerous tests and lots of log files.&amp;nbsp; This is a new implementation and I will tell you what is "broken" and what is NOT broken.&amp;nbsp; Customer is using GP client ver 6.1 and 5.2.6-87.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. GP client successfully auth to 1f ldap, sussceefully auth to 2f DUO proxy server, using DUO app on iphone, message arrive to accept or reject, I accept and all is perfect.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. Same scenario as above 1, but now DUO is set to actually ring / call the user phone... phone rings.. # to accept and then GP client immediately closes indicating cannot find gateway.&amp;nbsp; Remember, using DUO app and accept all works well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3. To eliminate the GP components, I did the following... I setup a firewall admin account to when the test admin account logs to the firewall, auth against the DUO Proxy and in this test on the firewall I am using the same radius server and auth profile as above... I test by https to the firewall mgt interface... I enter my creds... I am not doing 1stF, just auth against DUO Proxy via radius... after I enter my firewall admin creds...DUO call me, I accept the call and hit # and I can login to the firewall.&amp;nbsp; This is similar to 2 above, but I am not using GP and DUO works and I can login.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is a little crazy.&amp;nbsp; I have lots of interesting logs and from the firewall authd.log... everything is great.. no failures.&amp;nbsp; The GUI GP logs too look good, but I need to retest.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Something interesting from the GP Client logs.....&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PanGPA log...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(P1640-T6924)Info (3368): 12/13/22 14:25:08:190 PanWinhttpCallback(dwInternetStatus=WINHTTP_CALLBACK_STATUS_RECEIVING_RESPONSE, this=000001B26A0E86B0)&lt;BR /&gt;(P1640-T6924)Info (3368): 12/13/22 14:25:08:190 PanWinhttpCallback(dwInternetStatus=WINHTTP_CALLBACK_STATUS_RESPONSE_RECEIVED, this=000001B26A0E86B0)&lt;BR /&gt;(P1640-T6924)Info (3368): 12/13/22 14:25:08:190 PanWinhttpCallback(dwInternetStatus=WINHTTP_CALLBACK_STATUS_HEADERS_AVAILABLE, this=000001B26A0E86B0)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(P1640-T6924)Debug(2366): 12/13/22 14:25:08:190 got header ready event, exit wait loop now&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(P1640-T6924)Info (2432): 12/13/22 14:25:08:190 http request status code = 502&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(P1640-T6924)Error(2575): 12/13/22 14:25:08:190 Unexpected http status 502&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(P1640-T6924)Error(4585): 12/13/22 14:25:08:190 winhttpObj, error! ipaddress vpn.company.com&lt;BR /&gt;bRetryWithoutCert is 0, bClientCertNeeded=0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(P1640-T6924)Info (3368): 12/13/22 14:25:08:190&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PanWinhttpCallback(dwInternetStatus=WINHTTP_CALLBACK_STATUS_HANDLE_CLOSING, this=000001B26A0E86B0)&lt;BR /&gt;(P1640-T6924)Debug(3459): 12/13/22 14:25:08:190 handle 67f38be0 closed&lt;BR /&gt;(P1640-T6924)Debug(3463): 12/13/22 14:25:08:190 REUSE, request closed&lt;BR /&gt;(P1640-T6924)Info ( 860): 12/13/22 14:25:08:190 wait for closing callback success!&lt;/P&gt;</description>
    <pubDate>Wed, 14 Dec 2022 00:41:37 GMT</pubDate>
    <dc:creator>zenithnetworks</dc:creator>
    <dc:date>2022-12-14T00:41:37Z</dc:date>
    <item>
      <title>GP Client and DUO 2F Very strange behavior</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-client-and-duo-2f-very-strange-behavior/m-p/524036#M3499</link>
      <description>&lt;P&gt;Thoughts and ideas are welcome.&amp;nbsp; Note, I have yet to tune the GP APP on the portal.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Okay... I would like to keep this brief, but I have conducted numerous tests and lots of log files.&amp;nbsp; This is a new implementation and I will tell you what is "broken" and what is NOT broken.&amp;nbsp; Customer is using GP client ver 6.1 and 5.2.6-87.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. GP client successfully auth to 1f ldap, sussceefully auth to 2f DUO proxy server, using DUO app on iphone, message arrive to accept or reject, I accept and all is perfect.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. Same scenario as above 1, but now DUO is set to actually ring / call the user phone... phone rings.. # to accept and then GP client immediately closes indicating cannot find gateway.&amp;nbsp; Remember, using DUO app and accept all works well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3. To eliminate the GP components, I did the following... I setup a firewall admin account to when the test admin account logs to the firewall, auth against the DUO Proxy and in this test on the firewall I am using the same radius server and auth profile as above... I test by https to the firewall mgt interface... I enter my creds... I am not doing 1stF, just auth against DUO Proxy via radius... after I enter my firewall admin creds...DUO call me, I accept the call and hit # and I can login to the firewall.&amp;nbsp; This is similar to 2 above, but I am not using GP and DUO works and I can login.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is a little crazy.&amp;nbsp; I have lots of interesting logs and from the firewall authd.log... everything is great.. no failures.&amp;nbsp; The GUI GP logs too look good, but I need to retest.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Something interesting from the GP Client logs.....&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PanGPA log...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(P1640-T6924)Info (3368): 12/13/22 14:25:08:190 PanWinhttpCallback(dwInternetStatus=WINHTTP_CALLBACK_STATUS_RECEIVING_RESPONSE, this=000001B26A0E86B0)&lt;BR /&gt;(P1640-T6924)Info (3368): 12/13/22 14:25:08:190 PanWinhttpCallback(dwInternetStatus=WINHTTP_CALLBACK_STATUS_RESPONSE_RECEIVED, this=000001B26A0E86B0)&lt;BR /&gt;(P1640-T6924)Info (3368): 12/13/22 14:25:08:190 PanWinhttpCallback(dwInternetStatus=WINHTTP_CALLBACK_STATUS_HEADERS_AVAILABLE, this=000001B26A0E86B0)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(P1640-T6924)Debug(2366): 12/13/22 14:25:08:190 got header ready event, exit wait loop now&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(P1640-T6924)Info (2432): 12/13/22 14:25:08:190 http request status code = 502&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(P1640-T6924)Error(2575): 12/13/22 14:25:08:190 Unexpected http status 502&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(P1640-T6924)Error(4585): 12/13/22 14:25:08:190 winhttpObj, error! ipaddress vpn.company.com&lt;BR /&gt;bRetryWithoutCert is 0, bClientCertNeeded=0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(P1640-T6924)Info (3368): 12/13/22 14:25:08:190&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PanWinhttpCallback(dwInternetStatus=WINHTTP_CALLBACK_STATUS_HANDLE_CLOSING, this=000001B26A0E86B0)&lt;BR /&gt;(P1640-T6924)Debug(3459): 12/13/22 14:25:08:190 handle 67f38be0 closed&lt;BR /&gt;(P1640-T6924)Debug(3463): 12/13/22 14:25:08:190 REUSE, request closed&lt;BR /&gt;(P1640-T6924)Info ( 860): 12/13/22 14:25:08:190 wait for closing callback success!&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 00:41:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-client-and-duo-2f-very-strange-behavior/m-p/524036#M3499</guid>
      <dc:creator>zenithnetworks</dc:creator>
      <dc:date>2022-12-14T00:41:37Z</dc:date>
    </item>
    <item>
      <title>Re: GP Client and DUO 2F Very strange behavior</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-client-and-duo-2f-very-strange-behavior/m-p/524366#M3512</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7197"&gt;@zenithnetworks&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have not observed this kind of issue, however, have you tried increasing the timeout as suggested in the &lt;A href="https://duo.com/docs/paloalto" target="_self"&gt;Duo document&lt;/A&gt;?&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;Increase the "Timeout" to at least&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;30&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(&lt;STRONG&gt;60&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;recommended if using push or phone authentication).&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Suspecting this to a timeout issue. Do you think it take more than 30secs for the call to be received?&lt;/P&gt;
&lt;P&gt;This need to be done in the RADIUS server settings &amp;gt; GUI &amp;gt; Device &amp;gt; RADIUS&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2022 10:53:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-client-and-duo-2f-very-strange-behavior/m-p/524366#M3512</guid>
      <dc:creator>Arnesh</dc:creator>
      <dc:date>2022-12-16T10:53:50Z</dc:date>
    </item>
  </channel>
</rss>

