<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic GlobalProtect failing after upgrading PanOS to 11.1.4 in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-failing-after-upgrading-panos-to-11-1-4/m-p/592349#M5578</link>
    <description>&lt;P&gt;Dear all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a very strange issue after I upgraded to 11.1.4&lt;/P&gt;
&lt;P&gt;The mobile GlobalProtect client stopped working.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The network connection is unreachable or the portal is unresponsive.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I ran some packet captures and noticed that the firewall sees the SYN packets, but it never replies.&lt;/P&gt;
&lt;P&gt;Nothing in the transmit stage pcap&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Although I can see the connection attempts in the traffic logs.&lt;/P&gt;
&lt;P&gt;They are aged out&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;out of curiosity I changed the settings for the sessions by entering:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;set session tcp-reject-non-syn no&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;With this settings I can see also the SYN/ACK packets from the firewall back to the mobile device.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;But it looks like these two streams are not recognized as being part of the same session?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Any idea how to further debug this issue?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;Andreas&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 17 Jul 2024 22:27:05 GMT</pubDate>
    <dc:creator>idelconsulting</dc:creator>
    <dc:date>2024-07-17T22:27:05Z</dc:date>
    <item>
      <title>GlobalProtect failing after upgrading PanOS to 11.1.4</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-failing-after-upgrading-panos-to-11-1-4/m-p/592349#M5578</link>
      <description>&lt;P&gt;Dear all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a very strange issue after I upgraded to 11.1.4&lt;/P&gt;
&lt;P&gt;The mobile GlobalProtect client stopped working.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The network connection is unreachable or the portal is unresponsive.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I ran some packet captures and noticed that the firewall sees the SYN packets, but it never replies.&lt;/P&gt;
&lt;P&gt;Nothing in the transmit stage pcap&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Although I can see the connection attempts in the traffic logs.&lt;/P&gt;
&lt;P&gt;They are aged out&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;out of curiosity I changed the settings for the sessions by entering:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;set session tcp-reject-non-syn no&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;With this settings I can see also the SYN/ACK packets from the firewall back to the mobile device.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;But it looks like these two streams are not recognized as being part of the same session?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Any idea how to further debug this issue?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;Andreas&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2024 22:27:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-failing-after-upgrading-panos-to-11-1-4/m-p/592349#M5578</guid>
      <dc:creator>idelconsulting</dc:creator>
      <dc:date>2024-07-17T22:27:05Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect failing after upgrading PanOS to 11.1.4</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-failing-after-upgrading-panos-to-11-1-4/m-p/592526#M5580</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18002"&gt;@idelconsulting&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd start by grabbing and checking the GP debug logs.&lt;/P&gt;
&lt;P&gt;These generally give a pretty good indication why the portal isn't responding.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you able to just browse to the portal ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2024 06:19:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-failing-after-upgrading-panos-to-11-1-4/m-p/592526#M5580</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2024-07-19T06:19:11Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect failing after upgrading PanOS to 11.1.4</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-failing-after-upgrading-panos-to-11-1-4/m-p/592592#M5584</link>
      <description>&lt;P&gt;Long story short:&lt;/P&gt;
&lt;P&gt;It works again&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;TL;DR&lt;/P&gt;
&lt;P&gt;the fact that I saw SYN packets received by the server without a reply and SYN/ACK sent by the server without being seen by the client made me thing about some strange case of asymmetric routing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have two ISPs, one primary and a secondary.&lt;/P&gt;
&lt;P&gt;Primary ISP has a metric of 10, secondary 200 for the default route out via the respective interfaces.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I checked services like whatsmyip I saw the IP of the primary ISP, which is also the one GlobalProtect is listening on.&lt;/P&gt;
&lt;P&gt;But, when checking the virtual router runtime stats and looking at the forwarding table, it showed the route via the secondary ISP as being active.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No idea how in such a case I saw the IP from the primary ISP on whatsmyip&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyway, after deleting and re-adding the secondary ISP interface everything started working again.&lt;/P&gt;
&lt;P&gt;I now see in the runtime forwarding table that the primary ISP is used.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How did this happen after the upgrade and why the internal routing was screwed up?&lt;/P&gt;
&lt;P&gt;I have no idea.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;Andreas&lt;/P&gt;</description>
      <pubDate>Sat, 20 Jul 2024 15:40:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-failing-after-upgrading-panos-to-11-1-4/m-p/592592#M5584</guid>
      <dc:creator>idelconsulting</dc:creator>
      <dc:date>2024-07-20T15:40:36Z</dc:date>
    </item>
  </channel>
</rss>

