Optimization tips for GlobalProtect?

Reply
Highlighted
x
L1 Bithead

Optimization tips for GlobalProtect?

Hi Guys,

Does anyone have any optimization tips that they've done for GlobalProtect? Looking for ways to speed up auth in the event the client gets disconnected when the device switches from wifi to cellular network. What we are seeing is it disconnects but doesn't connect or it takes awhile before it reconnects. using it on iOS.

Thanks,

x
L1 Bithead

Re: Optimization tips for GlobalProtect?

I just found this but wouldn't mind hearing some optimization tips from some of the GP experts out there!

65401 —Resolved an issue where the GlobalProtect agent for iOS did not reconnect automatically when
switching between a WiFi network and a 3G network.

Source:

https://downloads.paloaltonetworks.com/software/GlobalProtect-2.1.1-RN.pdf?__gda__=1418272301_ff1658...

Thanks!

L6 Presenter

Re: Optimization tips for GlobalProtect?

Try the Authentication Modifier setting to "Cookie authentication for config refresh".

This option is on the Portal > Client Config > General tab.

It should help you speed up the connection.


Also check if the users are connecting using IPSec or if they fall back to SSL.

If they fall back to SSL, and there is a restriction where IPSec shouldn't be used, make sure to disable IPSec to prevent the Agent from trying over and over with IPSec until it fails back to SSL.

If your Gateway is behind NAT, make sure to forward TCP Port 443 for SSL and UDP Port 4501 for IPSec.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!