<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect Issue on PA-3020 9.1.17 in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-issue-on-pa-3020-9-1-17/m-p/572841#M4824</link>
    <description>&lt;P&gt;Hi Lide,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have already reverted back to 6.1.0, but some users are still encountering the same issue There was another thread that suggested to revert/downgrade the OS version of the firewall.&amp;nbsp;Kindly refer here:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/globalprotect-discussions/pan-os-9-1-17-global-protect-issues/td-p/571458" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/globalprotect-discussions/pan-os-9-1-17-global-protect-issues/td-p/571458&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The thing about reverting of the firewall means we will be under the target version of the firewall to mitigate the issue about &lt;A href="https://live.paloaltonetworks.com/t5/customer-advisories/emergency-update-required-pan-os-root-and-default-certificate/ta-p/564672" target="_self"&gt;PAN-OS Root and Default Certificate&lt;/A&gt;&amp;nbsp;and it might cause another problem.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you and Regards,&lt;/P&gt;
&lt;P&gt;Marlo&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 12 Jan 2024 07:55:44 GMT</pubDate>
    <dc:creator>Marlo_Perez</dc:creator>
    <dc:date>2024-01-12T07:55:44Z</dc:date>
    <item>
      <title>GlobalProtect Issue on PA-3020 9.1.17</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-issue-on-pa-3020-9-1-17/m-p/572652#M4810</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd want to seek your guidance on a matter that we're now dealing with. So, last year, around the third week of December, we upgraded the firmware of PA-3020 from 9.1.15 to 9.1.17 as per the&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/customer-advisories/emergency-update-required-pan-os-root-and-default-certificate/ta-p/564672" target="_self"&gt;advisory&lt;/A&gt; of Palo Alto. So far, no issues have been reported following the upgrade, but after a while we have discovered an issue regarding on GlobalProtect (currently on 6.1.0) where some of our users are having difficulties connecting.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The error displayed is 'Your GlobalProtect session has been disconnected due to network connectivity issues or session timeouts.' This problem occurs after the user has successfully connected; however, after a few seconds, the error appears. To establish a connection, we need to disconnect and reconnect multiple times—approximately 5-10 times—before successfully connecting and gaining access to our system. Please refer to the image below for a sample of the error.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Marlo_Perez_0-1704948532651.png" style="width: 447px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56431i9A1A6C8CCC76F8B0/image-dimensions/447x259/is-moderation-mode/true?v=v2" width="447" height="259" role="button" title="Marlo_Perez_0-1704948532651.png" alt="Marlo_Perez_0-1704948532651.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After that, we looked for knowledge base articles about this issue and came across this &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000g1umCAA" target="_self"&gt;one&lt;/A&gt;. It advises us to upgrade to a different GlobalProtect version other than 6.1.x, so we attempted updating to 6.2.0 and 6.2.2, but encountered more issues. As a result, we reverted back to 6.1.0.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We tried various methods, such as uploading the techsupport file to Palo Alto's AutoAssistant Tool, and discovered some information about firewall configuration that attracted my eye. It is about High Resource Utilization. Please see the image below.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Marlo_Perez_2-1704949007599.png" style="width: 893px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56432iE3E9FD7840237FC3/image-dimensions/893x112/is-moderation-mode/true?v=v2" width="893" height="112" role="button" title="Marlo_Perez_2-1704949007599.png" alt="Marlo_Perez_2-1704949007599.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As stated on the image, this may cause for the new connection requests to fail and the existing once to encounter slowness when accessing the web. So, in order to resolve this issue, we will be trying to use this &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClaJCAS" target="_self"&gt;KB&lt;/A&gt;&amp;nbsp;to lower the usage from 94 to 90. We will be performing this later. So for the meantime, I have come across this LIVEcommunity &lt;A href="https://live.paloaltonetworks.com/t5/globalprotect-discussions/pan-os-9-1-17-global-protect-issues/td-p/571458" target="_self"&gt;post&lt;/A&gt; that is experiencing the same issue, the solution they have done is to rollback from their old version of PAN-OS. Our concern being, we cannot revert back to the old PAN-OS version because of PAN-OS Root Certificate Advisory provided above.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;May I know if this is a known issue/bug for PAN-OS 9.1.17 on PA-3000 Series?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks and Best Regards,&lt;/P&gt;
&lt;P&gt;Marlo&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2024 05:15:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-issue-on-pa-3020-9-1-17/m-p/572652#M4810</guid>
      <dc:creator>Marlo_Perez</dc:creator>
      <dc:date>2024-01-11T05:15:55Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Issue on PA-3020 9.1.17</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-issue-on-pa-3020-9-1-17/m-p/572840#M4823</link>
      <description>&lt;P&gt;Hi Marlo,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; I got same issue on PA-3000 Series. So can solved this issue&amp;nbsp;&lt;SPAN&gt;revert back to 6.1.0? Thank you.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Lide&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 07:35:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-issue-on-pa-3020-9-1-17/m-p/572840#M4823</guid>
      <dc:creator>lidewu</dc:creator>
      <dc:date>2024-01-12T07:35:54Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Issue on PA-3020 9.1.17</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-issue-on-pa-3020-9-1-17/m-p/572841#M4824</link>
      <description>&lt;P&gt;Hi Lide,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have already reverted back to 6.1.0, but some users are still encountering the same issue There was another thread that suggested to revert/downgrade the OS version of the firewall.&amp;nbsp;Kindly refer here:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/globalprotect-discussions/pan-os-9-1-17-global-protect-issues/td-p/571458" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/globalprotect-discussions/pan-os-9-1-17-global-protect-issues/td-p/571458&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The thing about reverting of the firewall means we will be under the target version of the firewall to mitigate the issue about &lt;A href="https://live.paloaltonetworks.com/t5/customer-advisories/emergency-update-required-pan-os-root-and-default-certificate/ta-p/564672" target="_self"&gt;PAN-OS Root and Default Certificate&lt;/A&gt;&amp;nbsp;and it might cause another problem.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you and Regards,&lt;/P&gt;
&lt;P&gt;Marlo&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 07:55:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-issue-on-pa-3020-9-1-17/m-p/572841#M4824</guid>
      <dc:creator>Marlo_Perez</dc:creator>
      <dc:date>2024-01-12T07:55:44Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Issue on PA-3020 9.1.17</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-issue-on-pa-3020-9-1-17/m-p/573043#M4829</link>
      <description>&lt;P&gt;Hi Marlo,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Last week, I did "enable ipsec"(It was must allow UDP: 4501 if you have other firewall in front of PA). The issue was reduced even not happen again.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="截圖 2024-01-15 下午3.54.19.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56525i4C32C0B8F76EBA9B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="截圖 2024-01-15 下午3.54.19.png" alt="截圖 2024-01-15 下午3.54.19.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Lide&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jan 2024 08:03:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-issue-on-pa-3020-9-1-17/m-p/573043#M4829</guid>
      <dc:creator>lidewu</dc:creator>
      <dc:date>2024-01-15T08:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Issue on PA-3020 9.1.17</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-issue-on-pa-3020-9-1-17/m-p/573068#M4830</link>
      <description>&lt;P&gt;GlobalProtect instability is in all latest versions.&lt;/P&gt;
&lt;P&gt;Downgrade to 9.1.16-hx&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Enable IPSec reduces the issue and it is always best to have it enabled because then GlobalProtect encapsulates traffic into UDP instead of TCP.&lt;/P&gt;
&lt;P&gt;IPSec offers better performance and don't have TCP meltdown problems.&lt;/P&gt;
&lt;P&gt;IPSec requires UDP/4501 to be permitted.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Global Protect Client disconnect Issues after upgrading to Pan-OS 11.1.0&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-client-disconnect-issues-after-upgrading-to-pan/td-p/568088" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-client-disconnect-issues-after-upgrading-to-pan/td-p/568088&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;GlobalProtect Connection Issues in PAN-OS 10.2.7-h3&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-connection-issues-in-pan-os-10-2-7-h3/td-p/571507" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-connection-issues-in-pan-os-10-2-7-h3/td-p/571507&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;PAN OS 9.1.17 Global Protect Issues&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/globalprotect-discussions/pan-os-9-1-17-global-protect-issues/td-p/571458" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/globalprotect-discussions/pan-os-9-1-17-global-protect-issues/td-p/571458&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jan 2024 13:22:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-issue-on-pa-3020-9-1-17/m-p/573068#M4830</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2024-01-15T13:22:20Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Issue on PA-3020 9.1.17</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-issue-on-pa-3020-9-1-17/m-p/573573#M4847</link>
      <description>&lt;P&gt;Apologies for the delays; we need to go through approval for downgrading the firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi&amp;nbsp;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is confirmed that by downgrading from 9.1.17 to 9.1.16-h3 resolves the GlobalProtect issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cheers,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Marlo&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 01:19:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-issue-on-pa-3020-9-1-17/m-p/573573#M4847</guid>
      <dc:creator>Marlo_Perez</dc:creator>
      <dc:date>2024-01-19T01:19:06Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Issue on PA-3020 9.1.17</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-issue-on-pa-3020-9-1-17/m-p/576236#M4947</link>
      <description>&lt;P&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Is there an Pan-Issue-ID for this?&amp;nbsp;&lt;BR /&gt;I could not find it searching through known and adresses issues for 9.1.17 or 10.1.11/12.&lt;BR /&gt;These stability issues hit us rather hard on some appliances (some not even affected), and while in some areas we have our reasons to keep IPSec shut off, we would like to keep Firmware up-to-date to mitigate other issues (SNMP / PAN-217208).&lt;BR /&gt;&lt;BR /&gt;Regards, Alex&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 10:12:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-issue-on-pa-3020-9-1-17/m-p/576236#M4947</guid>
      <dc:creator>AlexanderWied</dc:creator>
      <dc:date>2024-02-06T10:12:54Z</dc:date>
    </item>
  </channel>
</rss>

