<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: [SOLVED] GPUDATE /FORCE DOESN'T WORK WITH GLOBAL PROTECT in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/solved-gpudate-force-doesn-t-work-with-global-protect/m-p/1260255#M7447</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hello LiveCommunity Team!&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;For additional information, we have implemented the following changes to improve GPO performance for mobile users:&lt;BR /&gt;&lt;BR /&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;Prisma Access GlobalProtect GPUPDATE Slowness Troubleshooting Steps:&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;1- Test GPO functionality with the preferred version of GlobalProtect, such as &lt;STRONG&gt;6.2.8-263&lt;/STRONG&gt;&amp;nbsp;to avoid buffer and performance issues (&lt;SPAN&gt;Didn't work&lt;/SPAN&gt;).&lt;BR /&gt;2- Reduce the virtual adapter MTU value from 1400 to 1300 bytes (&lt;SPAN&gt;Didn't work&lt;/SPAN&gt; completely).&lt;BR /&gt;3- Disable IPv6 on the physical adapter (&lt;SPAN&gt;Didn't work&lt;/SPAN&gt;).&lt;BR /&gt;4- Test using a mobile hotspot or a different Internet Service Provider (ISP) (&lt;SPAN&gt;Didn't work&lt;/SPAN&gt;).&lt;BR /&gt;5- Enable "&lt;STRONG&gt;Best Gateway Selection&lt;/STRONG&gt;" to use TCP instead of TLS when selecting the best available gateway (&lt;SPAN&gt;Didn't work&lt;/SPAN&gt;).&lt;BR /&gt;6- Enable manual selection of IPsec and SSL for the GlobalProtect connection (&lt;SPAN&gt;Didn't work&lt;/SPAN&gt;).&lt;BR /&gt;7- Enable &lt;STRONG&gt;DSRI&lt;/STRONG&gt; in the security rules (&lt;SPAN&gt;Didn't work&lt;/SPAN&gt;).&lt;BR /&gt;8- Change the GlobalProtect mode from "&lt;STRONG&gt;Tunnel and Proxy&lt;/STRONG&gt;" to "&lt;STRONG&gt;Tunnel Only&lt;/STRONG&gt;" (&lt;SPAN&gt;Didn't work&lt;/SPAN&gt;).&lt;BR /&gt;9- Create a custom application with TCP port 445 as the destination for SMB traffic, along with an application override rule created within the GlobalProtect scope (&lt;SPAN&gt;Didn't work&lt;/SPAN&gt;).&lt;BR /&gt;10- Verify QoS rules (Did not work).&lt;BR /&gt;&lt;SPAN&gt;11- Disable SMB Multichannel (SMBv3) on the clients/servers sides (Not scalable &amp;amp; recommended).&lt;BR /&gt;12-&amp;nbsp;Increase the GPO wait time on the server side (Not recommended).&lt;BR /&gt;13- The backend team increased the CPU version on the MU-SPN South America Ecuador Gateway node&amp;nbsp;(Didn't work).&lt;BR /&gt;14- Enable App Acceleration on Prisma Access to expedite only the IPv4 TCP traffic (Didn't work).&lt;BR /&gt;15- The backend team deploys and upgraded a new gateway node in the Central Colombia region., then&amp;nbsp;we setup the tunnel for the Colombia location and also tested with user connected to the GPGW Colombia location and saw significant improvement with GPO's finishing between 6-8 minutes sucessfully, as belows:&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;PRISMA ACCESS ARCHITECTURE&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DanielSRomero_4-1785263505888.png" style="width: 585px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/72126iB344BCE6553DC3E7/image-dimensions/585x392?v=v2" width="585" height="392" role="button" title="DanielSRomero_4-1785263505888.png" alt="DanielSRomero_4-1785263505888.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;PRISMA ACCESS GLOBALPROTECT LOCATIONS&lt;/STRONG&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DanielSRomero_3-1785263323838.png" style="width: 482px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/72125i70C42F986F4F8C70/image-dimensions/482x248?v=v2" width="482" height="248" role="button" title="DanielSRomero_3-1785263323838.png" alt="DanielSRomero_3-1785263323838.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;PRISMA ACCESS GW COLOMBIA CENTRAL PING TO GPO SERVER&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DanielSRomero_5-1785266171119.png" style="width: 482px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/72127i056784402DE15517/image-dimensions/482x567?v=v2" width="482" height="567" role="button" title="DanielSRomero_5-1785266171119.png" alt="DanielSRomero_5-1785266171119.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT size="5"&gt;Conclusions:&lt;/FONT&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;BR /&gt;-&amp;nbsp;&lt;SPAN&gt;Prisma Access offers worldwide locations for deployment, and a key best practice is to choose locations that are geographically closest to your users or NGFWs to connect with SC-CANs or RN-SPN nodes.&lt;BR /&gt;&lt;/SPAN&gt;&lt;BR /&gt;-&amp;nbsp;&lt;SPAN&gt;Deploying a gateway node in a region like Colombia Central directly addresses potential latency and performance issues by reducing the physical distance data needs to travel between the user and the Prisma Access service.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;-&amp;nbsp;&lt;SPAN&gt;This successful deployment demonstrates a well-executed troubleshooting step that directly aligns with Prisma Access best practices for optimizing mobile user connectivity and performance.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;-&amp;nbsp;SMB is a chattier protocol that performs poorly under elevated latency. The previous route via the &lt;STRONG data-index-in-node="121" data-path-to-node="7,0,0"&gt;MU-SPN South America Ecuador&lt;/STRONG&gt; gateway incurred round-trip times of &lt;STRONG data-index-in-node="187" data-path-to-node="7,0,0"&gt;~174 ms&lt;/STRONG&gt;, causing severe GPO processing delays and timeouts.&lt;BR /&gt;&lt;BR /&gt;-&amp;nbsp;Modifying client/firewall configurations (MTU adjustments, DSRI, IPv6 disabling, App-ID overrides, QoS, App Acceleration, and gateway CPU upgrades) did not mitigate the issue because the underlying constraint was physical propagation delay across regions.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT size="5"&gt;Why Colombia&amp;nbsp;Central Solved the Issue?&lt;BR /&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;- &lt;STRONG data-index-in-node="0" data-path-to-node="3,0,0"&gt;BGP Routing &amp;amp; Latency (~174 ms in Ecuador):&lt;/STRONG&gt; Traffic targeting Colombia-bound resources via the Ecuador gateway suffered from regional BGP routing paths. In South-America ISPs, cross-border traffic frequently hairpins through international NAPs (such as Miami) rather than taking direct terrestrial routes. This added massive physical propagation delay, raising RTT to &lt;STRONG data-index-in-node="379" data-path-to-node="3,0,0"&gt;~174 ms&lt;/STRONG&gt;.&lt;BR /&gt;&lt;BR /&gt;- &lt;STRONG data-index-in-node="0" data-path-to-node="3,1,0"&gt;SMB/GPO Protocol Sensitivity:&lt;/STRONG&gt; Group Policy Object updates rely heavily on &lt;STRONG data-index-in-node="83" data-path-to-node="3,1,0"&gt;SMB/CIFS (TCP 445)&lt;/STRONG&gt;. SMB is an inherently "chatty" protocol that requires hundreds of sequential round-trips to negotiate sessions and transfer data. At ~174 ms, this back-and-forth communication accumulated into severe application timeouts and failed GPO syncs.&lt;BR /&gt;&lt;BR /&gt;-&amp;nbsp;&lt;STRONG data-index-in-node="0" data-path-to-node="3,2,0"&gt;Direct Local Peering (~41 ms in Central Colombia):&lt;/STRONG&gt; Moving to the &lt;STRONG data-index-in-node="65" data-path-to-node="3,2,0"&gt;Central Colombia&lt;/STRONG&gt; gateway kept the traffic within national ISP peering networks, bypassing international hops. Dropping the latency to &lt;STRONG data-index-in-node="199" data-path-to-node="3,2,0"&gt;~41 ms&lt;/STRONG&gt; reduced SMB transaction overhead to normal operational levels, allowing GPOs to complete successfully within 6–8 minutes.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Thank you for your time, and I hope this information is helpful in your daily cybersecurity work. I would greatly appreciate your support by liking or accepting this as a useful post; it would help me a lot in becoming a CyberElite!&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;Best Regards,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Daniel Romero&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Senior Network/Security Engineer&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;PANW Partner&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 28 Jul 2026 19:30:13 GMT</pubDate>
    <dc:creator>DanielS.Romero</dc:creator>
    <dc:date>2026-07-28T19:30:13Z</dc:date>
    <item>
      <title>[SOLVED] GPUDATE /FORCE DOESN'T WORK WITH GLOBAL PROTECT</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/solved-gpudate-force-doesn-t-work-with-global-protect/m-p/1253712#M7373</link>
      <description>&lt;P&gt;Hello LiveCommunity Team!&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;I created this post to share my experience regarding an issue involving GlobalProtect users from Prisma Access who attempt to run &lt;STRONG&gt;gpupdate /force&lt;/STRONG&gt; to update GPO policies from the DC server, and who encounter the following error:&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;CMD ERROR GPUPDATE /FORCE&lt;BR /&gt;&lt;/STRONG&gt;C:\WINDOWS\system32&amp;gt;gpupdate /force&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Updating policy...&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;User policy cannot be updated successfully due to the following errors:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Group policy cannot be processed because it cannot connect to a domain controller over the network. This condition may be temporary. A success message may be generated once the computer connects to the domain controller and the group policy is processed successfully. Contact your administrator.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- Given this error, I checked the GlobalProtect source IP logs and everything appeared to be allowed.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Then, I tried pinging from an affected endpoint with a custom length and the DF "&lt;STRONG&gt;Don't Fragment&lt;/STRONG&gt;" bit active set to 1350 bytes, and the ping was dropped by fragmentation needed. as shown below:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;PING TEST WITH 1350 BYTES&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DanielSRomero_1-1778369596055.png" style="width: 756px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/71375iF1CDDCF26D31AF08/image-dimensions/756x170?v=v2" width="756" height="170" role="button" title="DanielSRomero_1-1778369596055.png" alt="DanielSRomero_1-1778369596055.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Then I try it with 1300 Bytes as the payload and the ping works!&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;PING TEST WITH 1300 BYTES&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DanielSRomero_2-1778369715172.png" style="width: 755px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/71376iCAD9B072C08BDF16/image-dimensions/755x234?v=v2" width="755" height="234" role="button" title="DanielSRomero_2-1778369715172.png" alt="DanielSRomero_2-1778369715172.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;So, as a test, I changed the Prisma Access GlobalProtect tunnel MTU to 1300 bytes (&lt;STRONG&gt;default is 1400 bytes&lt;/STRONG&gt;) and the &lt;STRONG&gt;gpupdate /force&lt;/STRONG&gt; command works!&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;PRISMA ACCESS GLOBAL PROTECT CONNECTION MTU ADJUSTMENT FROM 1400 TO 1300 BYTES&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DanielSRomero_4-1778370034165.png" style="width: 755px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/71378iD073ABA1DAFA9A0F/image-dimensions/755x251?v=v2" width="755" height="251" role="button" title="DanielSRomero_4-1778370034165.png" alt="DanielSRomero_4-1778370034165.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;CMD GPUPDATE /FORCE SUCCESFULLY&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;C:\Users\pcmolinaa&amp;gt;gpupdate /force&lt;BR /&gt;Updating policy...&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;The computer policy update completed successfully.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;Conclusions:&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;- Some device in the path, most likely the on-premises NGFW, was dropping the LDAP packets because it has a lower MTU and the packets are sent with the DF bit set, disabling IP fragmentation and forcing the drop by some peer.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Thank you for your time, and I hope this information is helpful in your daily cybersecurity work. I would greatly appreciate your support by liking or accepting this as a useful post; it would help me a lot in becoming a CyberElite!&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;Best Regards,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Daniel Romero&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Senior Network/Security Engineer&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;PANW Partner&lt;BR /&gt;&lt;BR /&gt;&lt;LI-PRODUCT title="Prisma Access" id="Prisma_Access"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="NGFW" id="NGFW"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="GlobalProtect" id="GlobalProtect"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 May 2026 00:08:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/solved-gpudate-force-doesn-t-work-with-global-protect/m-p/1253712#M7373</guid>
      <dc:creator>DanielS.Romero</dc:creator>
      <dc:date>2026-05-10T00:08:09Z</dc:date>
    </item>
    <item>
      <title>Re: [SOLVED] GPUDATE /FORCE DOESN'T WORK WITH GLOBAL PROTECT</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/solved-gpudate-force-doesn-t-work-with-global-protect/m-p/1253969#M7380</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/289674"&gt;@DanielS.Romero&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for sharing! Would love to share more of your insights.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2026 23:24:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/solved-gpudate-force-doesn-t-work-with-global-protect/m-p/1253969#M7380</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2026-05-13T23:24:00Z</dc:date>
    </item>
    <item>
      <title>Re: [SOLVED] GPUDATE /FORCE DOESN'T WORK WITH GLOBAL PROTECT</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/solved-gpudate-force-doesn-t-work-with-global-protect/m-p/1260255#M7447</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello LiveCommunity Team!&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;For additional information, we have implemented the following changes to improve GPO performance for mobile users:&lt;BR /&gt;&lt;BR /&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;Prisma Access GlobalProtect GPUPDATE Slowness Troubleshooting Steps:&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;1- Test GPO functionality with the preferred version of GlobalProtect, such as &lt;STRONG&gt;6.2.8-263&lt;/STRONG&gt;&amp;nbsp;to avoid buffer and performance issues (&lt;SPAN&gt;Didn't work&lt;/SPAN&gt;).&lt;BR /&gt;2- Reduce the virtual adapter MTU value from 1400 to 1300 bytes (&lt;SPAN&gt;Didn't work&lt;/SPAN&gt; completely).&lt;BR /&gt;3- Disable IPv6 on the physical adapter (&lt;SPAN&gt;Didn't work&lt;/SPAN&gt;).&lt;BR /&gt;4- Test using a mobile hotspot or a different Internet Service Provider (ISP) (&lt;SPAN&gt;Didn't work&lt;/SPAN&gt;).&lt;BR /&gt;5- Enable "&lt;STRONG&gt;Best Gateway Selection&lt;/STRONG&gt;" to use TCP instead of TLS when selecting the best available gateway (&lt;SPAN&gt;Didn't work&lt;/SPAN&gt;).&lt;BR /&gt;6- Enable manual selection of IPsec and SSL for the GlobalProtect connection (&lt;SPAN&gt;Didn't work&lt;/SPAN&gt;).&lt;BR /&gt;7- Enable &lt;STRONG&gt;DSRI&lt;/STRONG&gt; in the security rules (&lt;SPAN&gt;Didn't work&lt;/SPAN&gt;).&lt;BR /&gt;8- Change the GlobalProtect mode from "&lt;STRONG&gt;Tunnel and Proxy&lt;/STRONG&gt;" to "&lt;STRONG&gt;Tunnel Only&lt;/STRONG&gt;" (&lt;SPAN&gt;Didn't work&lt;/SPAN&gt;).&lt;BR /&gt;9- Create a custom application with TCP port 445 as the destination for SMB traffic, along with an application override rule created within the GlobalProtect scope (&lt;SPAN&gt;Didn't work&lt;/SPAN&gt;).&lt;BR /&gt;10- Verify QoS rules (Did not work).&lt;BR /&gt;&lt;SPAN&gt;11- Disable SMB Multichannel (SMBv3) on the clients/servers sides (Not scalable &amp;amp; recommended).&lt;BR /&gt;12-&amp;nbsp;Increase the GPO wait time on the server side (Not recommended).&lt;BR /&gt;13- The backend team increased the CPU version on the MU-SPN South America Ecuador Gateway node&amp;nbsp;(Didn't work).&lt;BR /&gt;14- Enable App Acceleration on Prisma Access to expedite only the IPv4 TCP traffic (Didn't work).&lt;BR /&gt;15- The backend team deploys and upgraded a new gateway node in the Central Colombia region., then&amp;nbsp;we setup the tunnel for the Colombia location and also tested with user connected to the GPGW Colombia location and saw significant improvement with GPO's finishing between 6-8 minutes sucessfully, as belows:&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;PRISMA ACCESS ARCHITECTURE&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DanielSRomero_4-1785263505888.png" style="width: 585px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/72126iB344BCE6553DC3E7/image-dimensions/585x392?v=v2" width="585" height="392" role="button" title="DanielSRomero_4-1785263505888.png" alt="DanielSRomero_4-1785263505888.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;PRISMA ACCESS GLOBALPROTECT LOCATIONS&lt;/STRONG&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DanielSRomero_3-1785263323838.png" style="width: 482px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/72125i70C42F986F4F8C70/image-dimensions/482x248?v=v2" width="482" height="248" role="button" title="DanielSRomero_3-1785263323838.png" alt="DanielSRomero_3-1785263323838.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;PRISMA ACCESS GW COLOMBIA CENTRAL PING TO GPO SERVER&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DanielSRomero_5-1785266171119.png" style="width: 482px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/72127i056784402DE15517/image-dimensions/482x567?v=v2" width="482" height="567" role="button" title="DanielSRomero_5-1785266171119.png" alt="DanielSRomero_5-1785266171119.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT size="5"&gt;Conclusions:&lt;/FONT&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;BR /&gt;-&amp;nbsp;&lt;SPAN&gt;Prisma Access offers worldwide locations for deployment, and a key best practice is to choose locations that are geographically closest to your users or NGFWs to connect with SC-CANs or RN-SPN nodes.&lt;BR /&gt;&lt;/SPAN&gt;&lt;BR /&gt;-&amp;nbsp;&lt;SPAN&gt;Deploying a gateway node in a region like Colombia Central directly addresses potential latency and performance issues by reducing the physical distance data needs to travel between the user and the Prisma Access service.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;-&amp;nbsp;&lt;SPAN&gt;This successful deployment demonstrates a well-executed troubleshooting step that directly aligns with Prisma Access best practices for optimizing mobile user connectivity and performance.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;-&amp;nbsp;SMB is a chattier protocol that performs poorly under elevated latency. The previous route via the &lt;STRONG data-index-in-node="121" data-path-to-node="7,0,0"&gt;MU-SPN South America Ecuador&lt;/STRONG&gt; gateway incurred round-trip times of &lt;STRONG data-index-in-node="187" data-path-to-node="7,0,0"&gt;~174 ms&lt;/STRONG&gt;, causing severe GPO processing delays and timeouts.&lt;BR /&gt;&lt;BR /&gt;-&amp;nbsp;Modifying client/firewall configurations (MTU adjustments, DSRI, IPv6 disabling, App-ID overrides, QoS, App Acceleration, and gateway CPU upgrades) did not mitigate the issue because the underlying constraint was physical propagation delay across regions.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT size="5"&gt;Why Colombia&amp;nbsp;Central Solved the Issue?&lt;BR /&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;- &lt;STRONG data-index-in-node="0" data-path-to-node="3,0,0"&gt;BGP Routing &amp;amp; Latency (~174 ms in Ecuador):&lt;/STRONG&gt; Traffic targeting Colombia-bound resources via the Ecuador gateway suffered from regional BGP routing paths. In South-America ISPs, cross-border traffic frequently hairpins through international NAPs (such as Miami) rather than taking direct terrestrial routes. This added massive physical propagation delay, raising RTT to &lt;STRONG data-index-in-node="379" data-path-to-node="3,0,0"&gt;~174 ms&lt;/STRONG&gt;.&lt;BR /&gt;&lt;BR /&gt;- &lt;STRONG data-index-in-node="0" data-path-to-node="3,1,0"&gt;SMB/GPO Protocol Sensitivity:&lt;/STRONG&gt; Group Policy Object updates rely heavily on &lt;STRONG data-index-in-node="83" data-path-to-node="3,1,0"&gt;SMB/CIFS (TCP 445)&lt;/STRONG&gt;. SMB is an inherently "chatty" protocol that requires hundreds of sequential round-trips to negotiate sessions and transfer data. At ~174 ms, this back-and-forth communication accumulated into severe application timeouts and failed GPO syncs.&lt;BR /&gt;&lt;BR /&gt;-&amp;nbsp;&lt;STRONG data-index-in-node="0" data-path-to-node="3,2,0"&gt;Direct Local Peering (~41 ms in Central Colombia):&lt;/STRONG&gt; Moving to the &lt;STRONG data-index-in-node="65" data-path-to-node="3,2,0"&gt;Central Colombia&lt;/STRONG&gt; gateway kept the traffic within national ISP peering networks, bypassing international hops. Dropping the latency to &lt;STRONG data-index-in-node="199" data-path-to-node="3,2,0"&gt;~41 ms&lt;/STRONG&gt; reduced SMB transaction overhead to normal operational levels, allowing GPOs to complete successfully within 6–8 minutes.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Thank you for your time, and I hope this information is helpful in your daily cybersecurity work. I would greatly appreciate your support by liking or accepting this as a useful post; it would help me a lot in becoming a CyberElite!&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;Best Regards,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Daniel Romero&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Senior Network/Security Engineer&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;PANW Partner&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2026 19:30:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/solved-gpudate-force-doesn-t-work-with-global-protect/m-p/1260255#M7447</guid>
      <dc:creator>DanielS.Romero</dc:creator>
      <dc:date>2026-07-28T19:30:13Z</dc:date>
    </item>
  </channel>
</rss>

