<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Have to reboot globalprotect client to connect. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/have-to-reboot-globalprotect-client-to-connect/m-p/139771#M48176</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have a similar issue with the 3.1.5 client. Once I went back to the 3.1.3 everything was good again. Looks like a bug to me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Fri, 27 Jan 2017 14:32:03 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2017-01-27T14:32:03Z</dc:date>
    <item>
      <title>Have to reboot globalprotect client to connect.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/have-to-reboot-globalprotect-client-to-connect/m-p/137284#M47777</link>
      <description>&lt;P&gt;WE have a problem with globalprotect-&amp;nbsp; The&amp;nbsp;users sometimes need to disable the globalprotect client in order to connect to another VPN.&amp;nbsp; Later when the globalprotect client is re-enabled, any attempt to authenticate immediately returns a username/password invalid error.&amp;nbsp; If the user reboots the computer, the globalprotect client works first try.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Some users have the same problem if their computer goes into sllep mode-&amp;nbsp; after waqking the computer up, the authentication fails until the computer is restarted.&amp;nbsp; After that it works fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's log before reboot:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2017-01-12 14:26:23.046 -0800 debug: pan_auth_request_process(pan_auth_state_engine.c:1540): Receive request: msg type PAN_AUTH_REQ_REMOTE_INIT_AUTH, conv id 79, body length 2156&lt;BR /&gt;2017-01-12 14:26:23.046 -0800 debug: pan_auth_request_process(pan_auth_state_engine.c:1563): Trying to authenticate: &amp;lt;profile: "Remote_ail(pan_auth_util.c:921): "fmurray" is a non-admin user with auth profile "Remote_Acess_Sequence" and vsys "vsys1"&lt;BR /&gt;2017-01-12 14:26:23.046 -0800 debug: _get_authseq_profile(pan_auth_util.c:809): Auth profile/vsys (Remote_Acess_Sequence/vsys1) is auth&amp;nbsp;sequence&lt;BR /&gt;2017-01-12 14:26:23.046 -0800 debug: _populate_authseq_auth_vec_n_vsys_vec(pan_auth_util.c:756): auth sequence "Remote_Acess_Sequence"&lt;BR /&gt;enabled flag: use-domain-find-profile2017-01-12 14:26:23.046 -0800 debug: _has_domain_in_request(pan_auth_util.c:692): Extracted domain&amp;nbsp;info "coanaheim" from user name "fmurray"&lt;BR /&gt;2017-01-12 14:26:23.046 -0800 debug: _get_auth_prof_id_in_seq_by_domain(pan_auth_util.c:726): Extracted domain info "coanaheim" from user input = user domain of profile/vsys: "RemoteAccess-LDAP/vsys1" in auth sequence&lt;BR /&gt;2017-01-12 14:26:23.046 -0800 debug: pan_auth_request_process(pan_auth_state_engine.c:1616): Using auth seq, saving original username fmurray from request&lt;BR /&gt;2017-01-12 14:26:23.047 -0800 debug: pan_auth_cache_user_is_allowed(pan_auth_cache_allowlist_n_grp.c:260): This is a single vsys platform, group check for allow list is performed on "vsys1"&lt;BR /&gt;2017-01-12 14:26:23.047 -0800 debug: pan_auth_cache_user_is_allowed(pan_auth_cache_allowlist_n_grp.c:263): user "fmurray" is a member of group "cn=domain users,cn=users,dc=anaheim,dc=intranet" on single vsys&lt;BR /&gt;2017-01-12 14:26:23.047 -0800 debug: pan_auth_cache_user_is_allowed(pan_auth_cache_allowlist_n_grp.c:271): user "fmurray" is in allow list of auth prof/vsys "RemoteAccess-LDAP/vsys1"&lt;BR /&gt;2017-01-12 14:26:23.047 -0800 debug: pan_allowlist_request_process(pan_auth_allow_lock.c:87): user "fmurray" is a member of "cn=domain users,cn=users,dc=anaheim,dc=intranet" in allow list of auth prof "RemoteAccess-LDAP"&lt;BR /&gt;2017-01-12 14:26:23.047 -0800 debug: _authenticate_by_localdb_or_remote_server(pan_auth_state_engine.c:1068): Authenticating user "fmurray" with &amp;lt;profile: "RemoteAccess-LDAP", vsys: "vsys1"&amp;gt;, which is Auth Profile 1 of 2 in &amp;lt;sequence "Remote_Acess_Sequence", vsys "vsys1"&amp;gt;&lt;BR /&gt;2017-01-12 14:26:23.047 -0800 debug: pan_auth_service_get_svr_ids(pan_auth_service.c:630): find auth server id vector for RemoteAccess-LDAP-vsys1&lt;BR /&gt;2017-01-12 14:26:23.047 -0800 debug: _get_AD_maxPwdAge(pan_authd_shared_ldap.c:658): getting maxPwdAge attr from AD with LDAD pointer =&amp;nbsp;0x9843eb0...&lt;BR /&gt;2017-01-12 14:26:23.048 -0800 debug: _parse_ldap_search_result(pan_authd_shared_ldap.c:386): DN in entry DC=anaheim,DC=intranet&lt;BR /&gt;2017-01-12 14:26:23.048 -0800 debug: _process_user_info(pan_authd_shared_ldap.c:294): found LDAP attribute: maxPwdAge&lt;BR /&gt;2017-01-12 14:26:23.048 -0800 debug: _process_user_info(pan_authd_shared_ldap.c:330): AD : Got value maxPwdAge : 77760000000000&lt;BR /&gt;2017-01-12 14:26:23.048 -0800 debug: pan_authd_ldap_authenticate(pan_authd_shared_ldap.c:965): searching basedn "DC=anaheim,DC=intranet&lt;BR /&gt;" for filter "(sAMAccountName=fmurray)", attrs "framedIPAddress", LDAPp=0x9843eb0&lt;BR /&gt;2017-01-12 14:26:23.048 -0800 Error:&amp;nbsp; _send_async_ldap_search(pan_authd_shared_ldap.c:629): Failed to search. filter (sAMAccountName=fmurray), attr[0] framedIPAddress. error code: -7, (Bad search filter)&lt;BR /&gt;2017-01-12 14:26:23.048 -0800 Error:&amp;nbsp; pan_authd_ldap_authenticate(pan_authd_shared_ldap.c:971): send userdn search request&lt;BR /&gt;2017-01-12 14:26:23.048 -0800 Error:&amp;nbsp; _start_sync_auth(pan_auth_service_handle.c:578): sync request for user "fmurray" is fai&lt;BR /&gt;led or possibly timed out against 172.20.1.36:389 with 0th VOIDp=0x9843eb0&lt;BR /&gt;2017-01-12 14:26:23.048 -0800 debug: pan_auth_response_process(pan_auth_state_engine.c:2337): auth status: auth state unknown&lt;BR /&gt;2017-01-12 14:26:23.048 -0800 debug: pan_auth_response_process(pan_auth_state_engine.c:2470): Auth sequence, start to try next auth profile: &amp;lt;profile: "PD_RemoteAccess-LDAP", vsys: "vsys1"&amp;gt; for user "fmurray"&lt;BR /&gt;2017-01-12 14:26:23.048 -0800 debug: pan_auth_request_process(pan_auth_state_engine.c:1540): Receive request: msg type PAN_AUTH_REQ_REMOTE_INIT_AUTH, conv id 79, body length 2156&lt;BR /&gt;2017-01-12 14:26:23.048 -0800 debug: pan_auth_request_process(pan_auth_state_engine.c:1556): Using auth sequence, copying original username fmurray into request&lt;BR /&gt;2017-01-12 14:26:23.048 -0800 debug: pan_auth_request_process(pan_auth_state_engine.c:1563): Trying to authenticate: &amp;lt;profile: "Remote_Acess_Sequence", vsys: "vsys1", username "fmurray"&amp;gt;&lt;BR /&gt;2017-01-12 14:26:23.048 -0800 debug: _get_auth_prof_detail(pan_auth_util.c:921): "fmurray" is a non-admin user with auth profile "Remote_Acess_Sequence" and vsys "vsys1"&lt;BR /&gt;2017-01-12 14:26:23.049 -0800 debug: pan_auth_cache_user_is_allowed(pan_auth_cache_allowlist_n_grp.c:260): This is a single vsys platform, group check for allow list is performed on "vsys1"&lt;BR /&gt;2017-01-12 14:26:23.049 -0800 debug: pan_auth_cache_user_is_allowed(pan_auth_cache_allowlist_n_grp.c:263): user "fmurray" is a member of group "cn=domain users,cn=users,dc=anaheim,dc=intranet" on single vsys&lt;BR /&gt;2017-01-12 14:26:23.049 -0800 debug: pan_auth_cache_user_is_allowed(pan_auth_cache_allowlist_n_grp.c:271): user "fmurray" is in allow list of auth prof/vsys "PD_RemoteAccess-LDAP/vsys1"&lt;BR /&gt;2017-01-12 14:26:23.049 -0800 debug: pan_allowlist_request_process(pan_auth_allow_lock.c:87): user "fmurray" is a member of "cn=domain users,cn=users,dc=anaheim,dc=intranet" in allow list of auth prof "PD_RemoteAccess-LDAP"&lt;BR /&gt;2017-01-12 14:26:23.049 -0800 debug: _authenticate_by_localdb_or_remote_server(pan_auth_state_engine.c:1068): Authenticating user "fmurray" with &amp;lt;profile: "PD_RemoteAccess-LDAP", vsys: "vsys1"&amp;gt;, which is Auth Profile 2 of 2 in &amp;lt;sequence "Remote_Acess_Sequence"&lt;BR /&gt;, vsys "vsys1"&amp;gt;&lt;BR /&gt;2017-01-12 14:26:23.049 -0800 debug: pan_auth_service_get_svr_ids(pan_auth_service.c:630): find auth server id vector for PD_RemoteAccess-LDAP-vsys1&lt;BR /&gt;2017-01-12 14:26:23.049 -0800 debug: _get_AD_maxPwdAge(pan_authd_shared_ldap.c:658): getting maxPwdAge attr from AD with LDAD pointer =&amp;nbsp;0xeeb04248...&lt;BR /&gt;2017-01-12 14:26:23.051 -0800 debug: _parse_ldap_search_result(pan_authd_shared_ldap.c:386): DN in entry DC=pd,DC=anaheim,DC=intranet&lt;BR /&gt;2017-01-12 14:26:23.051 -0800 debug: _process_user_info(pan_authd_shared_ldap.c:294): found LDAP attribute: maxPwdAge&lt;BR /&gt;2017-01-12 14:26:23.051 -0800 debug: _process_user_info(pan_authd_shared_ldap.c:330): AD : Got value maxPwdAge : 77760000000000&lt;BR /&gt;2017-01-12 14:26:23.051 -0800 debug: pan_authd_ldap_authenticate(pan_authd_shared_ldap.c:965): searching basedn "DC=pd,DC=anaheim,DC=intranet" for filter "(sAMAccountName=fmurray)", attrs "framedIPAddress", LDAPp=0xeeb04248&lt;BR /&gt;2017-01-12 14:26:23.051 -0800 Error:&amp;nbsp; _send_async_ldap_search(pan_authd_shared_ldap.c:629): Failed to search. filter (sAMAccountName=fmurray), attr[0] framedIPAddress. error code: -7, (Bad search filter)&lt;BR /&gt;2017-01-12 14:26:23.051 -0800 Error:&amp;nbsp; pan_authd_ldap_authenticate(pan_authd_shared_ldap.c:971): send userdn search request&lt;BR /&gt;2017-01-12 14:26:23.051 -0800 Error:&amp;nbsp; _start_sync_auth(pan_auth_service_handle.c:578): sync request for user "fmurray" is failed or possibly timed out against 10.2.32.121:389 with 0th VOIDp=0xeeb04248&lt;BR /&gt;2017-01-12 14:26:23.051 -0800 debug: pan_auth_response_process(pan_auth_state_engine.c:2337): auth status: auth state unknown&lt;BR /&gt;2017-01-12 14:26:23.051 -0800 debug: pan_auth_response_process(pan_auth_state_engine.c:2479): Auth sequence, all auth profiles tried and failed: &amp;lt;sequence profile: "Remote_Acess_Sequence", vsys: "vsys1"&amp;gt; for user "fmurray"&lt;BR /&gt;2017-01-12 14:26:23.051 -0800 failed authentication for user 'fmurray'.&amp;nbsp; Reason: Invalid username/password auth profile 'Remote_Acess_Sequence', vsys 'vsys1', server profile 'PD_SSL_VPN_PRIFILE', server address '10.2.32.121', From: 70.197.73.40.&lt;BR /&gt;2017-01-12 14:26:23.051 -0800 debug: _log_auth_respone(pan_auth_server.c:240): Sent FAILED auth response for user 'fmurray' (exp_in_days=-1 (-1 never; 0 within a day))&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Here's the log after reboot:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2017-01-12 14:30:03.532 -0800 debug: pan_auth_request_process(pan_auth_state_engine.c:1540): Receive request: msg type PAN_AUTH_REQ_REMOTE_INIT_AUTH, conv id 80, body length 2156&lt;BR /&gt;2017-01-12 14:30:03.532 -0800 debug: pan_auth_request_process(pan_auth_state_engine.c:1563): Trying to authenticate: &amp;lt;profile: "Remote_Acess_Sequence", vsys: "vsys1", username "fmurray"&amp;gt;&lt;BR /&gt;2017-01-12 14:30:03.532 -0800 debug: _get_auth_prof_detail(pan_auth_util.c:921): "fmurray" is a non-admin user with auth profile "Remote_Acess_Sequence" and vsys "vsys1"&lt;BR /&gt;2017-01-12 14:30:03.532 -0800 debug: _get_authseq_profile(pan_auth_util.c:809): Auth profile/vsys (Remote_Acess_Sequence/vsys1) is auth&amp;nbsp;sequence&lt;BR /&gt;2017-01-12 14:30:03.532 -0800 debug: _populate_authseq_auth_vec_n_vsys_vec(pan_auth_util.c:756): auth sequence "Remote_Acess_Sequence" enabled flag: use-domain-find-profile2017-01-12 14:30:03.532 -0800 debug: pan_auth_request_process(pan_auth_state_engine.c:1616): Usingving original username fmurray from request&lt;BR /&gt;2017-01-12 14:30:03.533 -0800 debug: pan_auth_cache_user_is_allowed(pan_auth_cache_allowlist_n_grp.c:260): This is a single vsys platform, group check for allow list is performed on "vsys1"&lt;BR /&gt;2017-01-12 14:30:03.533 -0800 debug: pan_auth_cache_user_is_allowed(pan_auth_cache_allowlist_n_grp.c:263): user "fmurray" is a member of group "cn=domain users,cn=users,dc=anaheim,dc=intranet" on single vsys&lt;BR /&gt;2017-01-12 14:30:03.533 -0800 debug: pan_auth_cache_user_is_allowed(pan_auth_cache_allowlist_n_grp.c:271): user "fmurray" is in allow list of auth prof/vsys "RemoteAccess-LDAP/vsys1"&lt;BR /&gt;2017-01-12 14:30:03.533 -0800 debug: pan_allowlist_request_process(pan_auth_allow_lock.c:87): user "fmurray" is a member of "cn=domain users,cn=users,dc=anaheim,dc=intranet" in allow list of auth prof "RemoteAccess-LDAP"&lt;BR /&gt;2017-01-12 14:30:03.533 -0800 debug: _authenticate_by_localdb_or_remote_server(pan_auth_state_engine.c:1068): Authenticating user "fmurray" with &amp;lt;profile: "RemoteAccess-LDAP", vsys: "vsys1"&amp;gt;, which is Auth Profile 1 of 2 in &amp;lt;sequence "Remote_Acess_Sequence", vsys "vsys1"&amp;gt;&lt;BR /&gt;2017-01-12 14:30:03.533 -0800 debug: pan_auth_service_get_svr_ids(pan_auth_service.c:630): find auth server id vector for RemoteAccess-LDAP-vsys1&lt;BR /&gt;2017-01-12 14:30:03.533 -0800 debug: _get_AD_maxPwdAge(pan_authd_shared_ldap.c:658): getting maxPwdAge attr from AD with LDAD pointer =&amp;nbsp;0x9843eb0...&lt;BR /&gt;2017-01-12 14:30:03.534 -0800 debug: _parse_ldap_search_result(pan_authd_shared_ldap.c:386): DN in entry DC=anaheim,DC=intranet&lt;BR /&gt;2017-01-12 14:30:03.534 -0800 debug: _process_user_info(pan_authd_shared_ldap.c:294): found LDAP attribute: maxPwdAge&lt;BR /&gt;2017-01-12 14:30:03.534 -0800 debug: _process_user_info(pan_authd_shared_ldap.c:330): AD : Got value maxPwdAge : 77760000000000&lt;BR /&gt;2017-01-12 14:30:03.534 -0800 debug: pan_authd_ldap_authenticate(pan_authd_shared_ldap.c:965): searching basedn "DC=anaheim,DC=intranet" for filter "(sAMAccountName=fmurray)", attrs "framedIPAddress", LDAPp=0x9843eb0&lt;BR /&gt;2017-01-12 14:30:03.535 -0800 debug: _parse_ldap_search_result(pan_authd_shared_ldap.c:386): DN in entry CN=Frank Murray,OU=Network Team,OU=HP,OU=Contractor,DC=anaheim,DC=intranet&lt;BR /&gt;2017-01-12 14:30:03.535 -0800 debug: _process_user_info(pan_authd_shared_ldap.c:294): found LDAP attribute: cn&lt;BR /&gt;2017-01-12 14:30:03.535 -0800 debug: _process_user_info(pan_authd_shared_ldap.c:294): found LDAP attribute: userAccountControl&lt;BR /&gt;2017-01-12 14:30:03.535 -0800 debug: _process_user_info(pan_authd_shared_ldap.c:337): AD : Got value userAccountControl : 512&lt;BR /&gt;2017-01-12 14:30:03.535 -0800 debug: _process_user_info(pan_authd_shared_ldap.c:294): found LDAP attribute: pwdLastSet&lt;BR /&gt;2017-01-12 14:30:03.535 -0800 debug: _process_user_info(pan_authd_shared_ldap.c:320): AD : Got value pwdLastSet : 131226705754141950&lt;BR /&gt;2017-01-12 14:30:03.535 -0800 debug: pan_authd_ldap_authenticate(pan_authd_shared_ldap.c:1029): Received user DN: "CN=Frank Murray,OU=Nor,DC=anaheim,DC=intranet"&lt;BR /&gt;2017-01-12 14:30:03.535 -0800 debug: pan_authd_ldap_authenticate(pan_authd_shared_ldap.c:1052): DN sent to LDAP server: CN=Frank Murray,OU=Network Team,OU=HP,OU=Contractor,DC=anaheim,DC=intranet&lt;BR /&gt;2017-01-12 14:30:03.537 -0800 debug: pan_authd_ldap_authenticate(pan_authd_shared_ldap.c:1077): User "fmurray" is ACCEPTED (msgid = 10,&amp;nbsp;LDAPp=0x9843eb0)&lt;BR /&gt;2017-01-12 14:30:03.537 -0800 debug: _get_AD_passwd_exp_in_days(pan_authd_shared_ldap.c:79): userAccountControl = 512 (not never expire)&lt;BR /&gt;2017-01-12 14:30:03.537 -0800 pwdlastset: 13122670575&lt;BR /&gt;2017-01-12 14:30:03.537 -0800 debug: _get_AD_passwd_exp_in_days(pan_authd_shared_ldap.c:139): AD pwd expires in days 20&lt;BR /&gt;2017-01-12 14:30:03.537 -0800 debug: pan_authd_ldap_authenticate(pan_authd_shared_ldap.c:1086): Got user expire-in-days: -1 (-1 means no expiration), passwd_exp in auth profile: 7&lt;BR /&gt;2017-01-12 14:30:03.537 -0800 debug: pan_authd_ldap_authenticate(pan_authd_shared_ldap.c:1131): binding back to PaloAltoServices@anaheim.intranet&lt;BR /&gt;2017-01-12 14:30:03.537 -0800 debug: pan_authd_ldap_bind(pan_authd_shared_ldap.c:569): binding with binddn PaloAltoServices@anaheim.intranet&lt;BR /&gt;2017-01-12 14:30:03.539 -0800 debug: pan_auth_response_process(pan_auth_state_engine.c:2337): auth status: auth success&lt;BR /&gt;2017-01-12 14:30:03.539 -0800 debug: pan_auth_response_process(pan_auth_state_engine.c:2397): Authentication success: &amp;lt;profile: "RemoteAccess-LDAP", vsys: "vsys1", username "fmurray"&amp;gt;&lt;BR /&gt;2017-01-12 14:30:03.540 -0800 authenticated for user 'fmurray'.&amp;nbsp;&amp;nbsp; auth profile 'Remote_Acess_Sequence', vsys 'vsys1', server profile 'SSL_VPN_PROFILE', server address '172.20.1.36', From: 70.197.73.40.&lt;BR /&gt;2017-01-12 14:30:03.541 -0800 debug: _log_auth_respone(pan_auth_server.c:240): Sent SUCCESS auth response for user 'fmurray' (exp_in_days=-1 (-1 never; 0 within a day)) (return domain 'coanaheim')&lt;BR /&gt;2017-01-12 14:30:04.005 -0800 debug: pan_auth_request_process(pan_auth_state_engine.c:1540): Receive request: msg type PAN_AUTH_REQ_REMOTE_INIT_AUTH, conv id 81, body length 2156&lt;BR /&gt;2017-01-12 14:30:04.005 -0800 debug: pan_auth_request_process(pan_auth_state_engine.c:1563): Trying to authenticate: &amp;lt;profile: "Remote_Acess_Sequence", vsys: "vsys1", username "fmurray"&amp;gt;&lt;BR /&gt;2017-01-12 14:30:04.005 -0800 debug: _get_auth_prof_detail(pan_auth_util.c:921): "fmurray" is a non-admin user with auth profile "Remote_Acess_Sequence" and vsys "vsys1"&lt;BR /&gt;2017-01-12 14:30:04.005 -0800 debug: _get_authseq_profile(pan_auth_util.c:809): Auth profile/vsys (Remote_Acess_Sequence/vsys1) is auth&amp;nbsp;sequence&lt;BR /&gt;2017-01-12 14:30:04.005 -0800 debug: _populate_authseq_auth_vec_n_vsys_vec(pan_auth_util.c:756): auth sequence "Remote_Acess_Sequence" enabled flag: use-domain-find-profile2017-01-12 14:30:04.005 -0800 debug: pan_auth_request_process(pan_auth_state_engine.c:1616): Using&amp;nbsp;auth seq, saving original username fmurray from request&lt;BR /&gt;2017-01-12 14:30:04.005 -0800 debug: pan_auth_cache_user_is_allowed(pan_auth_cache_allowlist_n_grp.c:260): This is a single vsys platfo&lt;BR /&gt;rm, group check for allow list is performed on "vsys1"&lt;BR /&gt;2017-01-12 14:30:04.005 -0800 debug: pan_auth_cache_user_is_allowed(pan_auth_cache_allowlist_n_grp.c:263): user "fmurray" is a member o&lt;BR /&gt;f group "cn=domain users,cn=users,dc=anaheim,dc=intranet" on single vsys&lt;BR /&gt;2017-01-12 14:30:04.005 -0800 debug: pan_auth_cache_user_is_allowed(pan_auth_cache_allowlist_n_grp.c:271): user "fmurray" is in allow l&lt;BR /&gt;ist of auth prof/vsys "RemoteAccess-LDAP/vsys1"&lt;BR /&gt;2017-01-12 14:30:04.005 -0800 debug: pan_allowlist_request_process(pan_auth_allow_lock.c:87): user "fmurray" is a member of "cn=domain&lt;BR /&gt;users,cn=users,dc=anaheim,dc=intranet" in allow list of auth prof "RemoteAccess-LDAP"&lt;BR /&gt;2017-01-12 14:30:04.006 -0800 debug: _authenticate_by_localdb_or_remote_server(pan_auth_state_engine.c:1068): Authenticating user "fmur&lt;BR /&gt;ray" with &amp;lt;profile: "RemoteAccess-LDAP", vsys: "vsys1"&amp;gt;, which is Auth Profile 1 of 2 in &amp;lt;sequence "Remote_Acess_Sequence", vsys "vsys1&lt;BR /&gt;"&amp;gt;&lt;BR /&gt;2017-01-12 14:30:04.006 -0800 debug: pan_auth_service_get_svr_ids(pan_auth_service.c:630): find auth server id vector for RemoteAccess-&lt;BR /&gt;LDAP-vsys1&lt;BR /&gt;2017-01-12 14:30:04.006 -0800 debug: _get_AD_maxPwdAge(pan_authd_shared_ldap.c:658): getting maxPwdAge attr from AD with LDAD pointer =&lt;BR /&gt;&amp;nbsp;0x9843eb0...&lt;BR /&gt;2017-01-12 14:30:04.007 -0800 debug: _parse_ldap_search_result(pan_authd_shared_ldap.c:386): DN in entry DC=anaheim,DC=intranet&lt;BR /&gt;2017-01-12 14:30:04.007 -0800 debug: _process_user_info(pan_authd_shared_ldap.c:294): found LDAP attribute: maxPwdAge&lt;BR /&gt;2017-01-12 14:30:04.007 -0800 debug: _process_user_info(pan_authd_shared_ldap.c:330): AD : Got value maxPwdAge : 77760000000000&lt;BR /&gt;2017-01-12 14:30:04.007 -0800 debug: pan_authd_ldap_authenticate(pan_authd_shared_ldap.c:965): searching basedn "DC=anaheim,DC=intranet&lt;BR /&gt;" for filter "(sAMAccountName=fmurray)", attrs "framedIPAddress", LDAPp=0x9843eb0&lt;BR /&gt;2017-01-12 14:30:04.008 -0800 debug: _parse_ldap_search_result(pan_authd_shared_ldap.c:386): DN in entry CN=Frank Murray,OU=Network Team,OU=HP,OU=Contractor,DC=anaheim,DC=intranet&lt;BR /&gt;2017-01-12 14:30:04.008 -0800 debug: _process_user_info(pan_authd_shared_ldap.c:294): found LDAP attribute: cn&lt;BR /&gt;2017-01-12 14:30:04.008 -0800 debug: _process_user_info(pan_authd_shared_ldap.c:294): found LDAP attribute: userAccountControl&lt;BR /&gt;2017-01-12 14:30:04.008 -0800 debug: _process_user_info(pan_authd_shared_ldap.c:337): AD : Got value userAccountControl : 512&lt;BR /&gt;2017-01-12 14:30:04.008 -0800 debug: _process_user_info(pan_authd_shared_ldap.c:294): found LDAP attribute: pwdLastSet&lt;BR /&gt;2017-01-12 14:30:04.008 -0800 debug: _process_user_info(pan_authd_shared_ldap.c:320): AD : Got value pwdLastSet : 131226705754141950&lt;BR /&gt;2017-01-12 14:30:04.008 -0800 debug: pan_authd_ldap_authenticate(pan_authd_shared_ldap.c:1029): Received user DN: "CN=Frank Murray,OU=Network Team,OU=HP,OU=Contractor,DC=anaheim,DC=intranet"&lt;BR /&gt;2017-01-12 14:30:04.008 -0800 debug: pan_authd_ldap_authenticate(pan_authd_shared_ldap.c:1052): DN sent to LDAP server: CN=Frank Murray,OU=Network Team,OU=HP,OU=Contractor,DC=anaheim,DC=intranet&lt;BR /&gt;2017-01-12 14:30:04.010 -0800 debug: pan_authd_ldap_authenticate(pan_authd_shared_ldap.c:1077): User "fmurray" is ACCEPTED (msgid = 14,&amp;nbsp;LDAPp=0x9843eb0)&lt;BR /&gt;2017-01-12 14:30:04.010 -0800 debug: _get_AD_passwd_exp_in_days(pan_authd_shared_ldap.c:79): userAccountControl = 512 (not never expire)&lt;BR /&gt;2017-01-12 14:30:04.010 -0800 pwdlastset: 13122670575&lt;BR /&gt;2017-01-12 14:30:04.010 -0800 debug: _get_AD_passwd_exp_in_days(pan_authd_shared_ldap.c:139): AD pwd expires in days 20&lt;BR /&gt;2017-01-12 14:30:04.010 -0800 debug: pan_authd_ldap_authenticate(pan_authd_shared_ldap.c:1086): Got user expire-in-days: -1 (-1 means no expiration), passwd_exp in auth profile: 7&lt;BR /&gt;2017-01-12 14:30:04.010 -0800 debug: pan_authd_ldap_authenticate(pan_authd_shared_ldap.c:1131): binding back to PaloAltoServices@anaheim.intranet&lt;BR /&gt;2017-01-12 14:30:04.010 -0800 debug: pan_authd_ldap_bind(pan_authd_shared_ldap.c:569): binding with binddn PaloAltoServices@anaheim.intranet&lt;BR /&gt;2017-01-12 14:30:04.011 -0800 debug: pan_auth_response_process(pan_auth_state_engine.c:2337): auth status: auth success&lt;BR /&gt;2017-01-12 14:30:04.011 -0800 debug: pan_auth_response_process(pan_auth_state_engine.c:2397): Authentication success: &amp;lt;profile: "Remote&lt;BR /&gt;Access-LDAP", vsys: "vsys1", username "fmurray"&amp;gt;&lt;BR /&gt;2017-01-12 14:30:04.011 -0800 authenticated for user 'fmurray'.&amp;nbsp;&amp;nbsp; auth profile 'Remote_Acess_Sequence', vsys 'vsys1', server profile 'SSL_VPN_PROFILE', server address '172.20.1.36', From: 70.197.73.40.&lt;BR /&gt;2017-01-12 14:30:04.011 -0800 debug: _log_auth_respone(pan_auth_server.c:240): Sent SUCCESS auth response for user 'fmurray' (exp_in_days=-1 (-1 never; 0 within a day)) (return domain 'coanaheim')&lt;BR /&gt;2017-01-12 14:30:04.036 -0800 debug: authd_sysd_localprofile_callback(pan_auth_sysd.c:706): localprofile sync triggered via sysd&lt;BR /&gt;2017-01-12 14:30:04.036 -0800 debug: authd_sysd_localprofile_callback(pan_auth_sysd.c:726): get local info for vsys1/Remote_Acess_Sequence&lt;BR /&gt;2017-01-12 14:30:04.036 -0800 Error:&amp;nbsp; pan_authd_profile_is_local(pan_auth_util.c:1115): get auth profile setting for profile Remote_Ace&lt;BR /&gt;ss_Sequence&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jan 2017 23:26:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/have-to-reboot-globalprotect-client-to-connect/m-p/137284#M47777</guid>
      <dc:creator>fmurray</dc:creator>
      <dc:date>2017-01-12T23:26:07Z</dc:date>
    </item>
    <item>
      <title>Re: Have to reboot globalprotect client to connect.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/have-to-reboot-globalprotect-client-to-connect/m-p/138739#M48016</link>
      <description>&lt;P&gt;You might be able to recover by stopping and starting&amp;nbsp;&lt;SPAN&gt;RPC Services on the workstation short of a reboot.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Jan 2017 23:08:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/have-to-reboot-globalprotect-client-to-connect/m-p/138739#M48016</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2017-01-22T23:08:23Z</dc:date>
    </item>
    <item>
      <title>Re: Have to reboot globalprotect client to connect.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/have-to-reboot-globalprotect-client-to-connect/m-p/139455#M48118</link>
      <description>&lt;P&gt;Yes I have this issue and a restart of PanGPS service is enough. &amp;nbsp;I still need to figure out a better solution though. &amp;nbsp;Trying different builds of GP right now. &amp;nbsp;7.1.5 I couldn't make work at all. &amp;nbsp;7.1.0 works with this issue. &amp;nbsp;Need to find time to try the versions in between.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 23:57:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/have-to-reboot-globalprotect-client-to-connect/m-p/139455#M48118</guid>
      <dc:creator>sjhwilkes</dc:creator>
      <dc:date>2017-01-25T23:57:34Z</dc:date>
    </item>
    <item>
      <title>Re: Have to reboot globalprotect client to connect.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/have-to-reboot-globalprotect-client-to-connect/m-p/139577#M48143</link>
      <description>&lt;P&gt;Have you tried running the 3.1.x globalprotect client or are you still running the 3.0.x?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2017 14:15:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/have-to-reboot-globalprotect-client-to-connect/m-p/139577#M48143</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-01-26T14:15:22Z</dc:date>
    </item>
    <item>
      <title>Re: Have to reboot globalprotect client to connect.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/have-to-reboot-globalprotect-client-to-connect/m-p/139636#M48156</link>
      <description>&lt;P&gt;Our probelm is with 3.1.5 and 3.1.0, 3.1.3 works OK. &amp;nbsp;&lt;/P&gt;&lt;P&gt;I think it's a bug with the way '&lt;SPAN&gt;Allow User to Continue with Invalid Portal Server Certificate' is handled. &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I'm currently testing on a temporary IP/Domain name so my cert isn't right. &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2017 21:11:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/have-to-reboot-globalprotect-client-to-connect/m-p/139636#M48156</guid>
      <dc:creator>sjhwilkes</dc:creator>
      <dc:date>2017-01-26T21:11:02Z</dc:date>
    </item>
    <item>
      <title>Re: Have to reboot globalprotect client to connect.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/have-to-reboot-globalprotect-client-to-connect/m-p/139771#M48176</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have a similar issue with the 3.1.5 client. Once I went back to the 3.1.3 everything was good again. Looks like a bug to me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2017 14:32:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/have-to-reboot-globalprotect-client-to-connect/m-p/139771#M48176</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2017-01-27T14:32:03Z</dc:date>
    </item>
  </channel>
</rss>

