<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect stopped to work after appliance reboot in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-stopped-to-work-after-appliance-reboot/m-p/237485#M68038</link>
    <description>&lt;P&gt;No, I can't ping it from the Internet.&lt;/P&gt;&lt;P&gt;But I can ping it from the external PaloAlto interface,&lt;/P&gt;&lt;P&gt;In the GUI, in the Traffic log there is nothing.&lt;/P&gt;</description>
    <pubDate>Sun, 28 Oct 2018 09:49:48 GMT</pubDate>
    <dc:creator>Filip_Fronczak</dc:creator>
    <dc:date>2018-10-28T09:49:48Z</dc:date>
    <item>
      <title>GlobalProtect stopped to work after appliance reboot</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-stopped-to-work-after-appliance-reboot/m-p/237468#M68035</link>
      <description>&lt;P&gt;The GlobalProtect Portal/Gateway had been working perfectly until tonight I have restarted the Palo Alto appliance.&lt;/P&gt;&lt;P&gt;After - I was not able to connect. The portal page -&amp;nbsp;ERR_CONNECTION_TIMED_OUT.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tryied to load older configs, I have even reinstalled the software version (8.0.13). No luck.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I the Session Browser I do not see anything that looks like any traffic to the GP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's 3AM and I feel quite helpless...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 28 Oct 2018 02:11:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-stopped-to-work-after-appliance-reboot/m-p/237468#M68035</guid>
      <dc:creator>Filip_Fronczak</dc:creator>
      <dc:date>2018-10-28T02:11:37Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect stopped to work after appliance reboot</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-stopped-to-work-after-appliance-reboot/m-p/237483#M68037</link>
      <description>&lt;P&gt;Can you ping the IP of GP from external?&lt;/P&gt;&lt;P&gt;What you see in traffic logs?&lt;/P&gt;</description>
      <pubDate>Sun, 28 Oct 2018 04:08:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-stopped-to-work-after-appliance-reboot/m-p/237483#M68037</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-10-28T04:08:45Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect stopped to work after appliance reboot</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-stopped-to-work-after-appliance-reboot/m-p/237485#M68038</link>
      <description>&lt;P&gt;No, I can't ping it from the Internet.&lt;/P&gt;&lt;P&gt;But I can ping it from the external PaloAlto interface,&lt;/P&gt;&lt;P&gt;In the GUI, in the Traffic log there is nothing.&lt;/P&gt;</description>
      <pubDate>Sun, 28 Oct 2018 09:49:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-stopped-to-work-after-appliance-reboot/m-p/237485#M68038</guid>
      <dc:creator>Filip_Fronczak</dc:creator>
      <dc:date>2018-10-28T09:49:48Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect stopped to work after appliance reboot</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-stopped-to-work-after-appliance-reboot/m-p/237498#M68039</link>
      <description>&lt;P&gt;&lt;FONT face="helvetica" size="3"&gt;So, the problem has been resolved or... worked around.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="helvetica" size="3"&gt;We have both GlobalProtect VPN and IPSec VPN running on loopback interfaces.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="helvetica" size="3"&gt;Both of them do not work after PaloAlto reboot.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="helvetica" size="3"&gt;It seems that PaloAlto is not refreshing the ARPs on the switch connecting it to the "World".&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="helvetica" size="3"&gt;Solution:&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="helvetica" size="3"&gt;ssh to PaloAlto and:&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;FONT face="courier new,courier" size="3"&gt;&lt;STRONG&gt;test arp gratuitous ip &lt;FONT color="#FF6600"&gt;&lt;EM&gt;loopbak_IP&lt;/EM&gt;&lt;/FONT&gt; interface &lt;FONT color="#FF6600"&gt;&lt;EM&gt;ethernet1/3&lt;/EM&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT face="courier new,courier" size="3"&gt;&lt;STRONG&gt;test vpn ike-sa gateway&amp;nbsp;&lt;FONT color="#FF6600"&gt;&lt;EM&gt;IKE_Gateway_Name&lt;/EM&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT face="helvetica" size="3" color="#000000"&gt;The first command refreshes the GlobalProtect ARP, the second - the IPSec ARP.&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT face="helvetica" size="3" color="#000000"&gt;Seems like a bug to me... I don't think we should do this every time we restart the appliance...&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Sun, 28 Oct 2018 14:27:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-stopped-to-work-after-appliance-reboot/m-p/237498#M68039</guid>
      <dc:creator>Filip_Fronczak</dc:creator>
      <dc:date>2018-10-28T14:27:24Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect stopped to work after appliance reboot</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-stopped-to-work-after-appliance-reboot/m-p/237504#M68044</link>
      <description>&lt;P&gt;Many Thanks for letting us know.&lt;/P&gt;&lt;P&gt;Great you find the fix and make it working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Helps other to learn.&lt;/P&gt;</description>
      <pubDate>Sun, 28 Oct 2018 14:49:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-stopped-to-work-after-appliance-reboot/m-p/237504#M68044</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-10-28T14:49:15Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect stopped to work after appliance reboot</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-stopped-to-work-after-appliance-reboot/m-p/237506#M68046</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56459"&gt;@Filip_Fronczak&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&lt;STRONG&gt;test vpn ike-sa gateway&amp;nbsp;&lt;FONT color="#FF6600"&gt;&lt;EM&gt;IKE_Gateway_Name&lt;/EM&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;This command actually is to create/build/connect IPSec Phase 1 to the specified gateway. The ARP refresh is only a side effect, that could be done also with your first command with the apropriate values.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But your right, this shouldn't be required after a reboot - and in my case also isn't required. I also use loopback interfaces and reboots/failovers work without problems. What PAN-OS version do currently use and what is your setup with the IPs on the loopbacks? Do you use single addresses in the network that is also configured on your physical interface?&lt;/P&gt;</description>
      <pubDate>Sun, 28 Oct 2018 19:33:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-stopped-to-work-after-appliance-reboot/m-p/237506#M68046</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-10-28T19:33:06Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect stopped to work after appliance reboot</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-stopped-to-work-after-appliance-reboot/m-p/237526#M68051</link>
      <description>&lt;P&gt;So does it mean for interstesting traffic to initate&amp;nbsp; which is phase 2 we use the&amp;nbsp; test ipsec&amp;nbsp; instead of ike?&lt;/P&gt;&lt;P&gt;Also arp here was used to build the phase 1 connection?&lt;/P&gt;&lt;P&gt;can we also use arp for phase 2?&lt;/P&gt;</description>
      <pubDate>Sun, 28 Oct 2018 22:03:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-stopped-to-work-after-appliance-reboot/m-p/237526#M68051</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-10-28T22:03:15Z</dc:date>
    </item>
  </channel>
</rss>

