<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Concurrent users cannot connect in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/concurrent-users-cannot-connect/m-p/128442#M46702</link>
    <description>&lt;P&gt;plus, concurrent users work 100% guaranteed with GlobalProtect &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 23 Nov 2016 13:50:49 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2016-11-23T13:50:49Z</dc:date>
    <item>
      <title>Concurrent users cannot connect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/concurrent-users-cannot-connect/m-p/126049#M46481</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;GlobalProtect GW with x-auth is enabled for IPsec VPN client services. However, only one concurrent session per user is allowed and any subsequent sessions disconnects the previous session user. Same issue happens whether the user is a local account or an AD account. We need to have multiple sessions running with the same user account.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea how to fix this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Nov 2016 04:27:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/concurrent-users-cannot-connect/m-p/126049#M46481</guid>
      <dc:creator>Farzana</dc:creator>
      <dc:date>2016-11-14T04:27:04Z</dc:date>
    </item>
    <item>
      <title>Re: Concurrent users cannot connect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/concurrent-users-cannot-connect/m-p/126098#M46491</link>
      <description>&lt;P&gt;Hi Farzana&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;GlobalProtect allows multiple concurrent logins from the same username.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;do you possibly have a UserID agent (client/clientless) set to probing and included the IP range of the globalprotect clients ? it's possible the UserID agent is timing out the user mappings with probes, since GlobalProtect will allow concurrent sessions&lt;/P&gt;</description>
      <pubDate>Mon, 14 Nov 2016 09:58:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/concurrent-users-cannot-connect/m-p/126098#M46491</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-11-14T09:58:58Z</dc:date>
    </item>
    <item>
      <title>Re: Concurrent users cannot connect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/concurrent-users-cannot-connect/m-p/128001#M46628</link>
      <description>&lt;P&gt;Hello Reaper,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your suggestion. No probing is enabled in the User ID Agent Setup. Tried adding&amp;nbsp;&lt;SPAN&gt;an exception for the subnet used by VPN clients but the issue still occurred.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Using Cisco VPN ver 5.0.07.0290. Below log output shows Line 11 everything working OK, from line 12 is when another VPN client connects with the same username:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;IMG src="https://ip1.i.lithium.com/5f8b67cc6d42b977ee29b08c7502684f8c2a1585/68747470733a2f2f737570706f72742d616e7a2e6172726f772e636f6d2f696e6c696e65696d616765732f436f6e766572736174696f6e2f4e6f76323031362f32333333322f322e6a7067" border="0" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Looking forward to your response.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2016 04:08:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/concurrent-users-cannot-connect/m-p/128001#M46628</guid>
      <dc:creator>Farzana</dc:creator>
      <dc:date>2016-11-22T04:08:17Z</dc:date>
    </item>
    <item>
      <title>Re: Concurrent users cannot connect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/concurrent-users-cannot-connect/m-p/128004#M46629</link>
      <description>&lt;P&gt;In system logs we are getting:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;ike-nego-p2-proxy-id-bad&lt;/TD&gt;&lt;TD&gt;IKE phase-2 negotiation failed when processing proxy ID. received ID for remote-side type (IPv4_address_range) is not supported.&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;ike-nego-p2-start&lt;/TD&gt;&lt;TD&gt;IKE phase-2 negotiation is started as responder&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;ike-nego-p2-proxy-id-bad&lt;/TD&gt;&lt;TD&gt;IKE phase-2 negotiation failed when processing proxy ID. received ID for remote-side type (IPv4_address_range) is not supported.&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;ike-nego-p2-start&lt;/TD&gt;&lt;TD&gt;IKE phase-2 negotiation is started as responder&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Tue, 22 Nov 2016 04:44:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/concurrent-users-cannot-connect/m-p/128004#M46629</guid>
      <dc:creator>Farzana</dc:creator>
      <dc:date>2016-11-22T04:44:20Z</dc:date>
    </item>
    <item>
      <title>Re: Concurrent users cannot connect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/concurrent-users-cannot-connect/m-p/128044#M46632</link>
      <description>&lt;P&gt;&amp;nbsp;kind of looks like there's a configuration issue, proxy IDs are network subnet objects exchanged between 2 vpn peers to determine which local IP addresses are being used&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you may want to review which IP pool is being used for GP clients and if that subnet is routed elsewhere in the organization also&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;would you be able to share configuration snapshots without revealing too much sensitive info ?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2016 08:23:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/concurrent-users-cannot-connect/m-p/128044#M46632</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-11-22T08:23:49Z</dc:date>
    </item>
    <item>
      <title>Re: Concurrent users cannot connect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/concurrent-users-cannot-connect/m-p/128059#M46634</link>
      <description>&lt;P&gt;Hi Reaper,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your speedy reply.&amp;nbsp;&lt;SPAN&gt;The config in place is the same as the link below except that the portal is on a different port and a private IP, Nat’d behind the Palo’s outside interface because another device is using port 443. But that shouldn’t matter as that is only the portal web page, not the VPN traffic gateway.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Not using GP client...just IPsec/Cisco remote VPN.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/Videos/gp-qc1-video.html" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/Videos/gp-qc1-video.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2016 08:56:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/concurrent-users-cannot-connect/m-p/128059#M46634</guid>
      <dc:creator>Farzana</dc:creator>
      <dc:date>2016-11-22T08:56:02Z</dc:date>
    </item>
    <item>
      <title>Re: Concurrent users cannot connect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/concurrent-users-cannot-connect/m-p/128062#M46635</link>
      <description>&lt;P&gt;hm&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;have you tried using GlobalProtect ? &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i'm not sure about the implications when using a 3rd party vpn client&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2016 09:11:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/concurrent-users-cannot-connect/m-p/128062#M46635</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-11-22T09:11:17Z</dc:date>
    </item>
    <item>
      <title>Re: Concurrent users cannot connect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/concurrent-users-cannot-connect/m-p/128160#M46650</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper﻿&lt;/a&gt;&amp;nbsp;Please help...My Galaxy S7 isn't working with iOS10. &amp;nbsp;lol&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2016 15:18:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/concurrent-users-cannot-connect/m-p/128160#M46650</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-11-22T15:18:33Z</dc:date>
    </item>
    <item>
      <title>Re: Concurrent users cannot connect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/concurrent-users-cannot-connect/m-p/128255#M46673</link>
      <description>&lt;P&gt;A few things about this setup:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) If you are forming the IPSec connection through the Palo Alto Firewall just use GlobalProtect and setup the SSL VPN.&lt;/P&gt;&lt;P&gt;2) Don't use an unsupported Cisco client that has known security issues that will&amp;nbsp;&lt;STRONG&gt;NEVER&lt;/STRONG&gt; be fixed.&lt;/P&gt;&lt;P&gt;3) GP is a free product and way more servicable than IPSec connections. IPSec is great for Tunnels, but not to actively use on client devices trying to connect back to the office. You should really be moving away from IPSec as a whole.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2016 18:29:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/concurrent-users-cannot-connect/m-p/128255#M46673</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-11-22T18:29:30Z</dc:date>
    </item>
    <item>
      <title>Re: Concurrent users cannot connect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/concurrent-users-cannot-connect/m-p/128306#M46680</link>
      <description>&lt;P&gt;Hi Brandon,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I understand what you are trying to say...The thing is if client wants only Cisco VPN for their users&amp;nbsp;then being an ASC we don't have much of a say rather suggest to try using Global Protect Client.&lt;/P&gt;&lt;P&gt;I try to use this forum to get suggestions as PA being a fairly new product (compared to other vendors) not enough forums out there for many scenarios.&lt;/P&gt;&lt;P&gt;This kind of tongue-in-cheek humor puts me off to ask questions here &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Farzana&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2016 21:55:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/concurrent-users-cannot-connect/m-p/128306#M46680</guid>
      <dc:creator>Farzana</dc:creator>
      <dc:date>2016-11-22T21:55:21Z</dc:date>
    </item>
    <item>
      <title>Re: Concurrent users cannot connect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/concurrent-users-cannot-connect/m-p/128313#M46681</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/45418"&gt;@Farzana﻿&lt;/a&gt;&amp;nbsp;Pretty sure PA was the first purpose built application aware FW. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The platform has been around for sometime. &amp;nbsp;You "hid the lead" I'm having this problem...Oh by the way I'm trying to smash to unique/competiive vendor products and it's not working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's tounge and cheek because it's funny. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's good to know if senarios like this work and/or if they fail and under what circumstances of each, but come on...You gotta be a little more thick skinned than that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not to mention as an IT professional if you aren't going back to your client and telling them the solution they're trying to implement isn't how this should be done you're not doing right by your customer.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2016 22:06:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/concurrent-users-cannot-connect/m-p/128313#M46681</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-11-22T22:06:29Z</dc:date>
    </item>
    <item>
      <title>Re: Concurrent users cannot connect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/concurrent-users-cannot-connect/m-p/128315#M46682</link>
      <description>&lt;P&gt;Yes you are right Brandon.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Client uses IPSec because they connect to many client environments so it is non-trivial for them to implement GlobalProtect.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I will check if certificate was applied properly.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The first user can connect to VPN easily but when another user logs in then he gets kicked out.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2016 22:37:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/concurrent-users-cannot-connect/m-p/128315#M46682</guid>
      <dc:creator>Farzana</dc:creator>
      <dc:date>2016-11-22T22:37:46Z</dc:date>
    </item>
    <item>
      <title>Re: Concurrent users cannot connect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/concurrent-users-cannot-connect/m-p/128434#M46700</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/45418"&gt;@Farzana﻿&lt;/a&gt;&amp;nbsp;Sometimes we get a little out of hand &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I would just point out to the client that the legacy Cisco VPN is no longer supported and does not work properly with anything greater than Windows 7. Even if you do the legwork to get this to function it isn't a supported function; you also run into the issue of security when using a VPN client that is no longer being updated for known security holes.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2016 13:47:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/concurrent-users-cannot-connect/m-p/128434#M46700</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-11-23T13:47:10Z</dc:date>
    </item>
    <item>
      <title>Re: Concurrent users cannot connect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/concurrent-users-cannot-connect/m-p/128442#M46702</link>
      <description>&lt;P&gt;plus, concurrent users work 100% guaranteed with GlobalProtect &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2016 13:50:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/concurrent-users-cannot-connect/m-p/128442#M46702</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-11-23T13:50:49Z</dc:date>
    </item>
  </channel>
</rss>

