<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Assign private IP address failed in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/assign-private-ip-address-failed/m-p/1249548#M7307</link>
    <description>&lt;P&gt;Thanks, I will do that. Interestingly we actually pay for slightly more capacity than /22 provides, and I have wondered if there are two pools defined in one part of the config, and just the one in another, and that IPs are occasionally being allocated from the second pool, which the rest of the config then can't handle. If that makes sense.&lt;/P&gt;</description>
    <pubDate>Thu, 05 Mar 2026 15:34:11 GMT</pubDate>
    <dc:creator>stephen.mellor</dc:creator>
    <dc:date>2026-03-05T15:34:11Z</dc:date>
    <item>
      <title>Assign private IP address failed</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/assign-private-ip-address-failed/m-p/1249413#M7302</link>
      <description>&lt;P&gt;We buy GlobalProtect VPN as a service from a third party, for 1000+ users, and though the service worked well for some months our users have been plagued by login issues since the Christmas/New Year break - &lt;STRONG&gt;something changed, but we don't know what&lt;/STRONG&gt;. The issue is that login fails with &lt;EM&gt;"Assign Private IP address failed"&lt;/EM&gt;. It's difficult to estimate the impact but this seems to happen for up to 10% of users at random - if they continue to try logging in they usually meet with success fairly quickly, but some users have been unable to log in for up to 2 hours.&lt;BR /&gt;&lt;BR /&gt;Many of our users work from home, therefore this is quite a problem. Of course I have opened a support case with our provider, but they seem to be struggling. We have provided many troubleshooting logs from the client side, for successful and failed logins, but this seems to not be helping as the failure message is somewhat generic and there's no detail as to what has actually gone wrong.&lt;BR /&gt;&lt;BR /&gt;We have a couple of client versions, all recent, eg 6.3.3-676. We can find no common factors with users that are seeing this error - we suspect that's it's actually all users, at random.&lt;BR /&gt;&lt;BR /&gt;A quick google suggests that overlapping subnets can be a cause - that's definitely not the case here as our subnet is in the 10.0.0.0/8 space, and our users are typically connecting from home, with home routers usually providing IPs in the 192.168.0.0/16 space. Also, the failure is not permanent and repeated attempts can result in success, which rules this out.&lt;BR /&gt;&lt;BR /&gt;We have a /22 allocation, so theoretically a maximum of 1021 simultaneous users. We typically see 700 users a day online, never more than 850. As is common with a VPN connection the clients report no DHCP lease time, as such, but presumably there is a DHCP server handing out IPs and presumably it has some sort of caching of IPs. Could this be a potential cause? What would the recommended settings be?&lt;BR /&gt;&lt;BR /&gt;Clock errors have been cited as a possible cause - we've verified that our clients and authentication systems are all within spec - typically within tens of milliseconds, so that's not a problem.&lt;BR /&gt;&lt;BR /&gt;What I'm looking for is clues as to what else may be the cause of such failures, and how we might be able to help our service provider to diagnose the issue. Unfortunately because we buy this as a service from a third party we don't have access to the back-end configuration or logs, but if we can point them in the right direction that would be great.&lt;BR /&gt;&lt;BR /&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2026 11:06:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/assign-private-ip-address-failed/m-p/1249413#M7302</guid>
      <dc:creator>stephen.mellor</dc:creator>
      <dc:date>2026-03-04T11:06:05Z</dc:date>
    </item>
    <item>
      <title>Re: Assign private IP address failed</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/assign-private-ip-address-failed/m-p/1249432#M7303</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/778300663"&gt;@stephen.mellor&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is the exact /22 that is configured as an IP pool within the GlobalProtect Gateway config? I would ask your SP to provide the list of client pools they have configured.&amp;nbsp;&lt;/P&gt;
&lt;P data-end="570" data-start="392"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2026 14:35:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/assign-private-ip-address-failed/m-p/1249432#M7303</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2026-03-04T14:35:56Z</dc:date>
    </item>
    <item>
      <title>Re: Assign private IP address failed</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/assign-private-ip-address-failed/m-p/1249461#M7305</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/778300663"&gt;@stephen.mellor&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I don't think you're going to get a ton of help on this one because you don't know how the backend is actually configured. Whether they have GlobalProtect using a DHCP server to handle address assignment or if it's using IP Pools under GlobalProtect directly isn't really known here.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regardless of how they're handling address assignment, if they were hitting any address exhaustion that should be readily clear on the DHCP server side of things and from GlobalProtect on their end as well. I'd also just point out that you&amp;nbsp;&lt;EM&gt;should&amp;nbsp;&lt;/EM&gt;have multiple pools available in the event that there is overlap.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2026 22:44:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/assign-private-ip-address-failed/m-p/1249461#M7305</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2026-03-04T22:44:22Z</dc:date>
    </item>
    <item>
      <title>Re: Assign private IP address failed</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/assign-private-ip-address-failed/m-p/1249547#M7306</link>
      <description>&lt;P&gt;I think you're right, but at this point I'm trying anything. I think it won't be long before we abandon the service and roll our own solution - I'd really rather not though!&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2026 15:30:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/assign-private-ip-address-failed/m-p/1249547#M7306</guid>
      <dc:creator>stephen.mellor</dc:creator>
      <dc:date>2026-03-05T15:30:48Z</dc:date>
    </item>
    <item>
      <title>Re: Assign private IP address failed</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/assign-private-ip-address-failed/m-p/1249548#M7307</link>
      <description>&lt;P&gt;Thanks, I will do that. Interestingly we actually pay for slightly more capacity than /22 provides, and I have wondered if there are two pools defined in one part of the config, and just the one in another, and that IPs are occasionally being allocated from the second pool, which the rest of the config then can't handle. If that makes sense.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2026 15:34:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/assign-private-ip-address-failed/m-p/1249548#M7307</guid>
      <dc:creator>stephen.mellor</dc:creator>
      <dc:date>2026-03-05T15:34:11Z</dc:date>
    </item>
    <item>
      <title>Re: Assign private IP address failed</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/assign-private-ip-address-failed/m-p/1249641#M7310</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Out of curiosity, what do you pay per user per month for the service? If you dont want to share publicly, you can DM me.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2026 21:24:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/assign-private-ip-address-failed/m-p/1249641#M7310</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2026-03-06T21:24:29Z</dc:date>
    </item>
    <item>
      <title>Re: Assign private IP address failed</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/assign-private-ip-address-failed/m-p/1249648#M7311</link>
      <description>&lt;P&gt;Could you please confirm the &lt;STRONG&gt;PAN-OS version&lt;/STRONG&gt; running on the gateway? Some versions earlier than &lt;STRONG&gt;11.2&lt;/STRONG&gt; have known issues that may affect IP address assignment in &lt;STRONG&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;GlobalProtect&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;, particularly when DHCP is used as the IP assignment method.&lt;/P&gt;&lt;P&gt;You may also want to review the &lt;STRONG&gt;GlobalProtect logs on the affected client machines&lt;/STRONG&gt;, as these logs usually provide more detailed information about the failure stage during the connection process.&lt;/P&gt;&lt;P&gt;Additionally, capturing traffic on the client side using &lt;STRONG&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Wireshark&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt; could help identify whether DHCP communication is occurring correctly and at which stage the process fails.&lt;/P&gt;&lt;P&gt;As a recommendation, if DHCP is being used for IP allocation, consider creating an additional DHCP scope or segmenting the address pools to reduce potential allocation contention. In many deployments it is also preferable to use an &lt;STRONG&gt;external DHCP server&lt;/STRONG&gt; to handle address assignment, as this can provide better scalability and easier troubleshooting.&lt;/P&gt;</description>
      <pubDate>Sun, 08 Mar 2026 09:17:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/assign-private-ip-address-failed/m-p/1249648#M7311</guid>
      <dc:creator>abayoumi21</dc:creator>
      <dc:date>2026-03-08T09:17:22Z</dc:date>
    </item>
    <item>
      <title>Re: Assign private IP address failed</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/assign-private-ip-address-failed/m-p/1249721#M7313</link>
      <description>&lt;P&gt;Thanks, it looks like there's some things for me to look into there - the server-side info I'll pass on to our provider, and I'll look into the client-side stuff myself - I have had a good look at the client logs and haven't spotted anything relevant but I'll go through them again just to be sure. I personally have had this failure only a couple of times over two months, so wireshark is tricky, but maybe I can spend a morning repeatedly connecting / disconnecting, see if I can catch it. I'm intrigued that there are different methods for IP provision - I'll see if I can find some documentation on that, and I'll try to find out what our provider are using.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2026 09:59:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/assign-private-ip-address-failed/m-p/1249721#M7313</guid>
      <dc:creator>stephen.mellor</dc:creator>
      <dc:date>2026-03-09T09:59:03Z</dc:date>
    </item>
  </channel>
</rss>

