<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Connection Issue With F5 - Makes No Sense in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/connection-issue-with-f5-makes-no-sense/m-p/537607#M3878</link>
    <description>&lt;P&gt;I have been in a rabbit hole for a bit now, and have tried everything that i could find here, for the fix, with no success. This is only happening on one box, and the only thing different between that box and others, is the user needs to use F5 for one task, and does not look/feel like that is the root cause.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The box is running Win 10 22H2, so it is not the issue i have seen with the 21H2 issue. Oddly, when i install and run GP over the wired connection, it will not download the certs (2 "CC", and maybe "TPN"?) if i connect via wireless, it will then download them. Once i have the certs, it still has an issue of not finding the PA IP, the logs also show that, but the IP is good, and is the only box. To eliminate a switch port, and such, i am able to connect with my laptop, using that drop.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At some point, one of the people who worked here, told the user, the issue is with F5 and GP being on the same box, but makes zero sense, since F5 is more browser based, than software/install, and it is not running, when connecting with GP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can someone confirm that F5 and GP will not get along?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;</description>
    <pubDate>Tue, 04 Apr 2023 16:08:32 GMT</pubDate>
    <dc:creator>Frootloops</dc:creator>
    <dc:date>2023-04-04T16:08:32Z</dc:date>
    <item>
      <title>Connection Issue With F5 - Makes No Sense</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/connection-issue-with-f5-makes-no-sense/m-p/537607#M3878</link>
      <description>&lt;P&gt;I have been in a rabbit hole for a bit now, and have tried everything that i could find here, for the fix, with no success. This is only happening on one box, and the only thing different between that box and others, is the user needs to use F5 for one task, and does not look/feel like that is the root cause.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The box is running Win 10 22H2, so it is not the issue i have seen with the 21H2 issue. Oddly, when i install and run GP over the wired connection, it will not download the certs (2 "CC", and maybe "TPN"?) if i connect via wireless, it will then download them. Once i have the certs, it still has an issue of not finding the PA IP, the logs also show that, but the IP is good, and is the only box. To eliminate a switch port, and such, i am able to connect with my laptop, using that drop.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At some point, one of the people who worked here, told the user, the issue is with F5 and GP being on the same box, but makes zero sense, since F5 is more browser based, than software/install, and it is not running, when connecting with GP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can someone confirm that F5 and GP will not get along?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Tue, 04 Apr 2023 16:08:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/connection-issue-with-f5-makes-no-sense/m-p/537607#M3878</guid>
      <dc:creator>Frootloops</dc:creator>
      <dc:date>2023-04-04T16:08:32Z</dc:date>
    </item>
    <item>
      <title>Re: Connection Issue With F5 - Makes No Sense</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/connection-issue-with-f5-makes-no-sense/m-p/537979#M3905</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/283759"&gt;@Frootloops&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;Without proper understanding what F5 agent is doing and if it is running on the endpoint we cannot tell for sure. BUT!&lt;/P&gt;
&lt;P&gt;Have in mind that when GlobalProtect establish connection it is actually generating HTTPS traffic, over TCP/443 port. GP client will try to authenticate and get config from firewall over this HTTPS connection. It then will generate another HTTPS connection to GP gateway again first to authenticate and get instructions how to connect. Only after that it will try to establish IPsec (ESP) connection to GP gateway.&lt;/P&gt;
&lt;P&gt;When you say "F5 is more browser base" it could probably means that F5 agent could be acting as SSL proxy for any HTTP/HTTPS traffic, which will also try to proxy the traffic from GP agent.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With limited knowledge of F5 agent I would say it is very plausible that F5 agent is breaking GP connection and you may need to apply some exceptions/exclusions on F5 agent for the GP traffic&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/153031"&gt;@nikoolayy1&lt;/a&gt; is amazing F5 expert and I hope he can provide better assistance than me on this topic.&lt;A id="link_60eaf9c843d9ea" class="lia-link-navigation lia-page-link lia-user-name-link" style="color: #eb5757;" href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/153031" target="_self" aria-label="View Profile of nikoolayy1"&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2023 09:07:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/connection-issue-with-f5-makes-no-sense/m-p/537979#M3905</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-04-07T09:07:34Z</dc:date>
    </item>
  </channel>
</rss>

