<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unable to connect to a single Prisma Access gateway location with MacOS in Prisma Access Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/unable-to-connect-to-a-single-prisma-access-gateway-location/m-p/472426#M315</link>
    <description>&lt;P&gt;Hey everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are experiencing an interesting issue and was curious if anyone else has come across something similar.&amp;nbsp; We have a mix of Windows and Mac endpoints, with multiple mobile user r&lt;SPAN&gt;egional gateway locations.&amp;nbsp; When connecting to one location (specifically UK location), our Mac systems simply will not connect.&amp;nbsp; GP client&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;continually 'loops' (connected/not connected/connecting).&amp;nbsp; Mac systems connecting to any other regional gateway location work as expected.&amp;nbsp; The issue does not appear for Windows systems -- those users can connect just fine to any gateway including UK.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I've had a TAC case open since September with limited success -- we are able to connect to a TAC UK gateway with our Mac's.&amp;nbsp; This leads me to think it's "something" in the policy (Wildfire Inline ML perhaps??).&amp;nbsp; This constant cycling between connected/reconnecting preventing us from fully deploying &lt;LI-PRODUCT title="Prisma Access" id="Prisma_Access"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Any thoughts/suggestions?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 11 Mar 2022 17:55:27 GMT</pubDate>
    <dc:creator>AaronRedd</dc:creator>
    <dc:date>2022-03-11T17:55:27Z</dc:date>
    <item>
      <title>Unable to connect to a single Prisma Access gateway location with MacOS</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/unable-to-connect-to-a-single-prisma-access-gateway-location/m-p/472426#M315</link>
      <description>&lt;P&gt;Hey everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are experiencing an interesting issue and was curious if anyone else has come across something similar.&amp;nbsp; We have a mix of Windows and Mac endpoints, with multiple mobile user r&lt;SPAN&gt;egional gateway locations.&amp;nbsp; When connecting to one location (specifically UK location), our Mac systems simply will not connect.&amp;nbsp; GP client&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;continually 'loops' (connected/not connected/connecting).&amp;nbsp; Mac systems connecting to any other regional gateway location work as expected.&amp;nbsp; The issue does not appear for Windows systems -- those users can connect just fine to any gateway including UK.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I've had a TAC case open since September with limited success -- we are able to connect to a TAC UK gateway with our Mac's.&amp;nbsp; This leads me to think it's "something" in the policy (Wildfire Inline ML perhaps??).&amp;nbsp; This constant cycling between connected/reconnecting preventing us from fully deploying &lt;LI-PRODUCT title="Prisma Access" id="Prisma_Access"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Any thoughts/suggestions?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 17:55:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/unable-to-connect-to-a-single-prisma-access-gateway-location/m-p/472426#M315</guid>
      <dc:creator>AaronRedd</dc:creator>
      <dc:date>2022-03-11T17:55:27Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to connect to a single Prisma Access gateway location with MacOS</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/unable-to-connect-to-a-single-prisma-access-gateway-location/m-p/483388#M337</link>
      <description>&lt;P&gt;As with prisma access only Palo Alto can do packet capture, check counters or flow logs the only thing you can check is the globalprotect agent PanGPS/PanGPA logs and on Panorma the Globalprotect logs. Also you can check the Portal config there is anything special for MAC devices as they can have a seperate policy even without HIP being enabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-apps/deploy-the-globalprotect-app-software/view-and-collect-globalprotect-logs" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-apps/deploy-the-globalprotect-app-software/view-and-collect-globalprotect-logs&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also I don't renember if you could do a policy trace for Prisma Access on the Panorama as yoiu may have some security policy blocking the vpn for UK for MAC devices for example&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also it is interesting where your cortex data lake is located if this could be related but maybe not as palo alto would have seen this.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2022 22:47:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/unable-to-connect-to-a-single-prisma-access-gateway-location/m-p/483388#M337</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2022-04-27T22:47:57Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to connect to a single Prisma Access gateway location with MacOS</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/unable-to-connect-to-a-single-prisma-access-gateway-location/m-p/483816#M342</link>
      <description>&lt;P&gt;Thanks for the info!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It turns out the UK gateway received a #.#.#.0 address, which is a valid IP based on the subnet mask, but something in the way that Mac's handle this is as if it's a broadcast address.&amp;nbsp; Palo Alto ended up changing the backend IP to an IP that did not end in zero.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Apr 2022 15:35:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/unable-to-connect-to-a-single-prisma-access-gateway-location/m-p/483816#M342</guid>
      <dc:creator>AaronRedd</dc:creator>
      <dc:date>2022-04-29T15:35:54Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to connect to a single Prisma Access gateway location with MacOS</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/unable-to-connect-to-a-single-prisma-access-gateway-location/m-p/484066#M343</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/153031"&gt;@nikoolayy1&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;As with prisma access only Palo Alto can do packet capture, check counters or flow logs the only thing you can check is the globalprotect agent PanGPS/PanGPA logs and on Panorma the Globalprotect logs. Also you can check the Portal config there is anything special for MAC devices as they can have a seperate policy even without HIP being enabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-apps/deploy-the-globalprotect-app-software/view-and-collect-globalprotect-logs" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-apps/deploy-the-globalprotect-app-software/view-and-collect-globalprotect-logs&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also I don't renember if you could do a policy trace for Prisma Access on the Panorama as yoiu may have some security policy blocking the vpn for UK for MAC devices for example&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also it is interesting where your cortex data lake is located if this could be related but maybe not as palo alto would have seen this.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Ohh thanks for the information sir,&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/161448"&gt;@AaronRedd&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&lt;SPAN&gt;It turns out the UK gateway received a #.#.#.0 address, which is a valid IP based on the subnet mask, but something in the way that Mac's handle this is as if it's a broadcast address.&amp;nbsp; Palo Alto ended up changing the backend IP to an IP that did not end in zero.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;what, That i really don't known&lt;/P&gt;</description>
      <pubDate>Mon, 02 May 2022 04:57:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/unable-to-connect-to-a-single-prisma-access-gateway-location/m-p/484066#M343</guid>
      <dc:creator>andrewwww</dc:creator>
      <dc:date>2022-05-02T04:57:22Z</dc:date>
    </item>
  </channel>
</rss>

