<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Global Protect connections fails after 20-30 seconds in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-connections-fails-after-20-30-seconds/m-p/598875#M119113</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;We have an issue with a Global Protect connection failing for some users in couple of seconds after we migrated from PA 3000 to 1410 series FW. &amp;nbsp;PA 3000 &amp;nbsp;was 10.2.9 and the new FW came with PANOS 11.1.2-h3 version.&lt;/P&gt;
&lt;P&gt;For the users with the problem, the connection is established correctly, they get the tunnel IP and can access resources, &amp;nbsp;but after 20 or 30 seconds, they get disconnected.&lt;/P&gt;
&lt;P&gt;In the traffic logs, we see action is &lt;STRONG&gt;allow&lt;/STRONG&gt;, but type &lt;STRONG&gt;“deny”&lt;/STRONG&gt; and the session end reason &lt;STRONG&gt;“Policy-denied”,&lt;/STRONG&gt; we also see the application &lt;STRONG&gt;“Web-browsing”&lt;/STRONG&gt; using port 443, these applications are allowed in the policy for all users, once the application is denied the connection is terminated for the users, attached the image from the FW log.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RafaelGarcia_0-1727368158358.png" style="width: 1248px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/62421i0C8B0BB6C5A478E2/image-dimensions/1248x234/is-moderation-mode/true?v=v2" width="1248" height="234" role="button" title="RafaelGarcia_0-1727368158358.png" alt="RafaelGarcia_0-1727368158358.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The strange part is that it is just for users from certain countries (Belize and India); all users in the USA can connect without any issue, no Geo-blocking policies in place, IPv6 has been already disabled but issue persist.&lt;/P&gt;
&lt;P&gt;We have tried upgrading to the latest PANOS preferred version 11.1.4-h1 and Global Protect 6.3.1 suspecting we might be hitting this bug but issue persist:&lt;/P&gt;
&lt;P&gt;PAN-242561: 'GlobalProtect tunnels disconnected shortly after being established when SSL was used as the transfer protocol.'&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the GPevent logs from the client shows :&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-teams="true"&gt;&lt;SPAN class="ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak"&gt;09/23/2024 12:34:42:883 [Info ]: Tunnel is down due to socket closed.&lt;BR /&gt;09/23/2024 12:34:42:883 [Info ]: Tunnel downtime is 19078 miliseconds&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-teams="true"&gt;In PANGPS we see similar:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-teams="true"&gt;&lt;SPAN class="ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak"&gt;Set state to Restoring VPN Connection&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-teams="true"&gt;&lt;SPAN class="ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak"&gt;(P21564-T24392)Info ( 147): 09/23/24 12:28:53:526 VPN: socket was closed&lt;BR /&gt;(P21564-T24392)Debug(1508): 09/23/24 12:28:53:526 --RecvFromSocket, socket closed&lt;BR /&gt;(P21564-T24392)Info (2193): 09/23/24 12:28:53:526 ProcPackets, RecvFromSocket() failed&lt;BR /&gt;(P21564-T24392)Info (2195): 09/23/24 12:28:53:526 VPN socket was closed&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-teams="true"&gt;&lt;SPAN class="ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak"&gt;Any suggestions or advice would be highly appreciated.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="GlobalProtect" id="GlobalProtect"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 26 Sep 2024 16:49:32 GMT</pubDate>
    <dc:creator>RafaelGarcia</dc:creator>
    <dc:date>2024-09-26T16:49:32Z</dc:date>
    <item>
      <title>Global Protect connections fails after 20-30 seconds</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-connections-fails-after-20-30-seconds/m-p/598875#M119113</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;We have an issue with a Global Protect connection failing for some users in couple of seconds after we migrated from PA 3000 to 1410 series FW. &amp;nbsp;PA 3000 &amp;nbsp;was 10.2.9 and the new FW came with PANOS 11.1.2-h3 version.&lt;/P&gt;
&lt;P&gt;For the users with the problem, the connection is established correctly, they get the tunnel IP and can access resources, &amp;nbsp;but after 20 or 30 seconds, they get disconnected.&lt;/P&gt;
&lt;P&gt;In the traffic logs, we see action is &lt;STRONG&gt;allow&lt;/STRONG&gt;, but type &lt;STRONG&gt;“deny”&lt;/STRONG&gt; and the session end reason &lt;STRONG&gt;“Policy-denied”,&lt;/STRONG&gt; we also see the application &lt;STRONG&gt;“Web-browsing”&lt;/STRONG&gt; using port 443, these applications are allowed in the policy for all users, once the application is denied the connection is terminated for the users, attached the image from the FW log.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RafaelGarcia_0-1727368158358.png" style="width: 1248px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/62421i0C8B0BB6C5A478E2/image-dimensions/1248x234/is-moderation-mode/true?v=v2" width="1248" height="234" role="button" title="RafaelGarcia_0-1727368158358.png" alt="RafaelGarcia_0-1727368158358.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The strange part is that it is just for users from certain countries (Belize and India); all users in the USA can connect without any issue, no Geo-blocking policies in place, IPv6 has been already disabled but issue persist.&lt;/P&gt;
&lt;P&gt;We have tried upgrading to the latest PANOS preferred version 11.1.4-h1 and Global Protect 6.3.1 suspecting we might be hitting this bug but issue persist:&lt;/P&gt;
&lt;P&gt;PAN-242561: 'GlobalProtect tunnels disconnected shortly after being established when SSL was used as the transfer protocol.'&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the GPevent logs from the client shows :&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-teams="true"&gt;&lt;SPAN class="ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak"&gt;09/23/2024 12:34:42:883 [Info ]: Tunnel is down due to socket closed.&lt;BR /&gt;09/23/2024 12:34:42:883 [Info ]: Tunnel downtime is 19078 miliseconds&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-teams="true"&gt;In PANGPS we see similar:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-teams="true"&gt;&lt;SPAN class="ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak"&gt;Set state to Restoring VPN Connection&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-teams="true"&gt;&lt;SPAN class="ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak"&gt;(P21564-T24392)Info ( 147): 09/23/24 12:28:53:526 VPN: socket was closed&lt;BR /&gt;(P21564-T24392)Debug(1508): 09/23/24 12:28:53:526 --RecvFromSocket, socket closed&lt;BR /&gt;(P21564-T24392)Info (2193): 09/23/24 12:28:53:526 ProcPackets, RecvFromSocket() failed&lt;BR /&gt;(P21564-T24392)Info (2195): 09/23/24 12:28:53:526 VPN socket was closed&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-teams="true"&gt;&lt;SPAN class="ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak"&gt;Any suggestions or advice would be highly appreciated.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="GlobalProtect" id="GlobalProtect"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2024 16:49:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-connections-fails-after-20-30-seconds/m-p/598875#M119113</guid>
      <dc:creator>RafaelGarcia</dc:creator>
      <dc:date>2024-09-26T16:49:32Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect connections fails after 20-30 seconds</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-connections-fails-after-20-30-seconds/m-p/598893#M119116</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/328215"&gt;@RafaelGarcia&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just wanted to check if you've had a chance to look into any potential problems with User-ID. We had a customer who ran into an issue where User-ID was accidentally deleting users from their IP addresses. This caused them to lose their GlobalProtect connection and get assigned to a different security policy.&lt;/P&gt;
&lt;P&gt;Have you had a chance to see if anything similar is happening in your environment?&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2024 18:30:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-connections-fails-after-20-30-seconds/m-p/598893#M119116</guid>
      <dc:creator>jpomachagua</dc:creator>
      <dc:date>2024-09-26T18:30:31Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect connections fails after 20-30 seconds</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-connections-fails-after-20-30-seconds/m-p/599329#M119190</link>
      <description>&lt;P&gt;When you say IPv6 was disabled was it disabled on the virtual GP adapter on the machine? I had a customer this was happening to and that work around worked.&amp;nbsp;&lt;BR /&gt;My guess is that you are not seeing it on users in the US is because they are able to connect using ipsec and not ssl.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2024 16:27:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-connections-fails-after-20-30-seconds/m-p/599329#M119190</guid>
      <dc:creator>JFonner</dc:creator>
      <dc:date>2024-10-02T16:27:56Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect connections fails after 20-30 seconds</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-connections-fails-after-20-30-seconds/m-p/599336#M119194</link>
      <description>&lt;P&gt;IPv6 is disabled on the GP adapter. All users are using SSL. We have tested with IPSec, but we had the same result&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2024 17:28:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-connections-fails-after-20-30-seconds/m-p/599336#M119194</guid>
      <dc:creator>RafaelGarcia</dc:creator>
      <dc:date>2024-10-02T17:28:42Z</dc:date>
    </item>
  </channel>
</rss>

