<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global protect and Outlook 2016 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/286625#M76631</link>
    <description>&lt;P&gt;Are you still getting this message&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"we are unable to connect right now. please check your network and try again later"&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 04 Sep 2019 18:04:22 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2019-09-04T18:04:22Z</dc:date>
    <item>
      <title>Global protect and Outlook 2016</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/286558#M76615</link>
      <description>&lt;P&gt;Recently we observed an issue for users on GP and using outlook.&lt;/P&gt;&lt;P&gt;When the GP is etablished and if the user launches Outlook in less than 1 min the outlook throws the error&lt;/P&gt;&lt;P&gt;"we are unable to connect right now. please check your network and try again later"&lt;/P&gt;&lt;P&gt;The same user once connected to GP and tried to launch post 1 min the outlook works fine&lt;/P&gt;&lt;P&gt;I am unable to link to GP or generic Outlook behaviour, any pointed from the community is highly appreciated.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2019 13:07:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/286558#M76615</guid>
      <dc:creator>KarthikRamalingam</dc:creator>
      <dc:date>2019-09-04T13:07:29Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect and Outlook 2016</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/286566#M76617</link>
      <description>&lt;P&gt;are you using user-ID mapping?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2019 13:59:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/286566#M76617</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-09-04T13:59:01Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect and Outlook 2016</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/286567#M76618</link>
      <description>&lt;P&gt;Yes, GP auth then user-id maping for the same.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2019 14:01:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/286567#M76618</guid>
      <dc:creator>KarthikRamalingam</dc:creator>
      <dc:date>2019-09-04T14:01:39Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect and Outlook 2016</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/286568#M76619</link>
      <description>&lt;P&gt;is part of your outlook config cloud based...&amp;nbsp; &amp;nbsp;if so then it may be denying traffic as user ip mapping is not yet complete.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2019 14:03:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/286568#M76619</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-09-04T14:03:29Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect and Outlook 2016</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/286570#M76620</link>
      <description>&lt;P&gt;if a user disconnects and then reconnects immediately, does it still take 1 min ?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2019 14:07:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/286570#M76620</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-09-04T14:07:22Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect and Outlook 2016</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/286571#M76621</link>
      <description>&lt;P&gt;Yes, outlook is cloud based hybrid connections. logically the connection would take a min to be established post GP is connected and outbound access is user-id specific.&lt;/P&gt;&lt;P&gt;does user-id mapping takes close to a min to complete? i ran fw tests under a min trying to launch outlook and it does fail.&lt;/P&gt;&lt;P&gt;But the version on GP reminded with no recent upgrade, all i can pin is the latest office update the end user machine team did.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2019 14:16:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/286571#M76621</guid>
      <dc:creator>KarthikRamalingam</dc:creator>
      <dc:date>2019-09-04T14:16:22Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect and Outlook 2016</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/286572#M76622</link>
      <description>&lt;P&gt;user ID is almost instant...&amp;nbsp; but it will not take place until an event such as a drive mapping or domain authentication takes place.&lt;/P&gt;&lt;P&gt;this triggers an event to be written to the AD security log which includes the AD user ID and his/her/it's IP address. this is what the agent collects.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;there are other options like device probing WMI stuff but i cannot help with this...&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we allow access to all microsoft URL's without user ID required, that may be one option, or perhaps run a post VPN script that is included with GP such as GPUpdate...&amp;nbsp; &amp;nbsp;thats assuming mapping latency is the issue here...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;also...&amp;nbsp; &amp;nbsp; &amp;nbsp;set your mapping timeout higher... some suggest 8 to 12 hours but we use 24.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2019 14:25:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/286572#M76622</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-09-04T14:25:53Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect and Outlook 2016</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/286600#M76624</link>
      <description>&lt;P&gt;Well, i did test the connection to Microsoft URL's as a non user-id specific connection with a dedicated rule with source user group.&lt;/P&gt;&lt;P&gt;&amp;nbsp;The status is remaining the same, post GP connection comes live, the outlook once launched works fine post 1 min of GP establishment, but fails to authenticate outlook and prompts password if attemted within 1 min of GP coming up.&lt;/P&gt;&lt;P&gt;p.s. taken off any SSL decryption that were currently in place assuming decryption was playing any part.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2019 16:08:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/286600#M76624</guid>
      <dc:creator>KarthikRamalingam</dc:creator>
      <dc:date>2019-09-04T16:08:55Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect and Outlook 2016</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/286601#M76625</link>
      <description>&lt;P&gt;is this new..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;"and prompts password if attemted within 1 min of GP coming up."&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;as this was not mentioned in your first post...&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2019 16:13:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/286601#M76625</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-09-04T16:13:33Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect and Outlook 2016</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/286612#M76630</link>
      <description>&lt;P&gt;Yes, if outlook launched within 1 min of GP coming up the outlook says its offine and needs password (i.e., AD logon) to pass through&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2019 17:50:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/286612#M76630</guid>
      <dc:creator>KarthikRamalingam</dc:creator>
      <dc:date>2019-09-04T17:50:38Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect and Outlook 2016</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/286625#M76631</link>
      <description>&lt;P&gt;Are you still getting this message&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"we are unable to connect right now. please check your network and try again later"&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2019 18:04:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/286625#M76631</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-09-04T18:04:22Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect and Outlook 2016</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/286626#M76632</link>
      <description>&lt;P&gt;Yes, that's the error, tested it with ruleset permitting any generic users as suspected user-id mapping was causing anykind of slownes, but the status remains the same.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2019 18:09:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/286626#M76632</guid>
      <dc:creator>KarthikRamalingam</dc:creator>
      <dc:date>2019-09-04T18:09:50Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect and Outlook 2016</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/286629#M76633</link>
      <description>&lt;P&gt;So do you still have a source user group in the policy. If so then set the source user to any and test again.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2019 18:20:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/286629#M76633</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-09-04T18:20:12Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect and Outlook 2016</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/287322#M76705</link>
      <description>&lt;P&gt;Yes, we did tried with a rule set having no source user/group attached, but no luck hence had escalated with MS Outlook if there are any latest bus on their office updates.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2019 10:37:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/287322#M76705</guid>
      <dc:creator>KarthikRamalingam</dc:creator>
      <dc:date>2019-09-09T10:37:30Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect and Outlook 2016</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/295569#M77848</link>
      <description>&lt;P&gt;Any resolution to this issue?&amp;nbsp; We are running into this same issue with Prisma.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2019 20:00:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/295569#M77848</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2019-10-31T20:00:52Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect and Outlook 2016</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/304190#M79117</link>
      <description>&lt;P&gt;We have the same issue, but only if we use a full Globalprotect VPN and not if we use a split tunnel (default here).&lt;/P&gt;&lt;P&gt;I found out the reason is that the GlobalProtect network interface has no default gateway, but only routes are pushed.&lt;/P&gt;&lt;P&gt;Because of this, the Network Location Awareness service does not attempt to check if there is a connection to the internet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Office programs rely on the NLA service and don't check themselves if they are online. Because of this, the apps assume they are offline when you are connected via GlobalProtect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Other VPN service also have the same problem:&amp;nbsp;&lt;A href="https://superuser.com/questions/1447783/why-do-windows-10-apps-and-office-outlook-word-onedrive-etc-have-no-interne" target="_blank"&gt;https://superuser.com/questions/1447783/why-do-windows-10-apps-and-office-outlook-word-onedrive-etc-have-no-interne&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our clients are asking if they can use the full VPN more and more, but with this problem we can't provide them with it..&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2019 08:20:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/304190#M79117</guid>
      <dc:creator>mtijhoff</dc:creator>
      <dc:date>2019-12-18T08:20:50Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect and Outlook 2016</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/306517#M79626</link>
      <description>&lt;P&gt;Thanks for those pointers, we have this pushing with MS again, lets see how it turns out with NIC level modifications for the apps to work as expected.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2020 16:50:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/306517#M79626</guid>
      <dc:creator>KarthikRamalingam</dc:creator>
      <dc:date>2020-01-13T16:50:17Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect and Outlook 2016</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/321063#M82185</link>
      <description>&lt;P&gt;Has anyone found a fix for this? I can confirm, with full tunnel VPN MS Office thinks there is no internet.&amp;nbsp; With split tunnel VPN MS Office can see that there is an internet connection.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Apr 2020 20:42:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/321063#M82185</guid>
      <dc:creator>jambulo</dc:creator>
      <dc:date>2020-04-06T20:42:21Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect and Outlook 2016</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/321144#M82210</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had the similar issue and was able to to trace it down NCSI causing the problem, the probe HTTP was failing for me. You can check windows event logs to see if you are facing the same issue -&amp;nbsp;Microsoft-Windows-NCSI/Operational&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is logged in the event it was failing:&lt;/P&gt;&lt;P&gt;Capability change on {57a83755-d89b-4a01-a72d-d4786875d856} (0x6008009000000 Family: V4 Capability: None ChangeReason: ActiveHttpProbeFailedButDnsSucceeded)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to allow "&lt;A href="http://www.msftconnecttest.com&amp;quot;" target="_blank"&gt;www.msftconnecttest.com"&lt;/A&gt;&amp;nbsp;this site access in pre-logon policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For more info check this blog&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.microsoft.com/en-us/help/4494446/an-internet-explorer-or-edge-window-opens-when-your-computer-connects" target="_blank"&gt;https://support.microsoft.com/en-us/help/4494446/an-internet-explorer-or-edge-window-opens-when-your-computer-connects&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.ghacks.net/2014/02/07/disable-customize-windows-internet-connection-test-improve-privacy/" target="_blank"&gt;https://www.ghacks.net/2014/02/07/disable-customize-windows-internet-connection-test-improve-privacy/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-vista/cc766017(v=ws.10)?redirectedfrom=MSDN" target="_blank"&gt;https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-vista/cc766017(v=ws.10)?redirectedfrom=MSDN&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps fix your guys issue&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;RJ&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2020 05:33:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/321144#M82210</guid>
      <dc:creator>rajjair</dc:creator>
      <dc:date>2020-04-07T05:33:23Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect and Outlook 2016</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/321166#M82213</link>
      <description>&lt;P&gt;Yes, we had similar tweak done under the&amp;nbsp;Enforce GlobalProtect Connection for Network Access option under app in the GP agent profile by excluding the NLSA lookup DNS IP of Microsoft. We are still testing it though.&lt;/P&gt;&lt;P&gt;Split tunneling would eliminate this issue completely again, the above option we are testing with is very much in line with split tunneling &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2020 07:57:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-outlook-2016/m-p/321166#M82213</guid>
      <dc:creator>KarthikRamalingam</dc:creator>
      <dc:date>2020-04-07T07:57:02Z</dc:date>
    </item>
  </channel>
</rss>

