Cannot connect to GlobalProtect

Reply
Highlighted
L4 Transporter

Cannot connect to GlobalProtect

Hi,

 

Just need bit of a direction on what to check for this issue. Two users can't connect to the globalprotect vpn.

 

One user: Windows 8.1 - can't connect (shows connecting forever) and another one: Windows 10, seems to connect and disconnect straight away.

 

Logs from PANGP shows:

 

362): InitConnection ...
(T8796) 09/06/17 05:49:46:934 Error( 366): Cannot connect to service, error: 10022
(T8796) 09/06/17 05:49:51:934 Info ( 362): InitConnection ...
(T8796) 09/06/17 05:49:51:934 Error( 366): Cannot connect to service, error: 10022
(T8796) 09/06/17 05:49:56:934 Info ( 362): InitConnection ...
(T8796) 09/06/17 05:49:56:934 Error( 366): Cannot connect to service, error: 10022
(T8796) 09/06/17 05:49:57:934 Debug( 229): CPanSocket::onConnect - return error code = 10060.
(T8796) 09/06/17 05:50:01:934 Info ( 362): InitConnection ...
(T8796) 09/06/17 05:50:01:934 Info ( 370): Connecting to Pan MS Service end
(T8796) 09/06/17 05:50:05:028 Debug( 73): CTranslate: dwSidLen is 24
(T8796) 09/06/17 05:50:05:044 Error( 335): Failed to remove value 'LastUrl'
(T8796) 09/06/17 05:50:05:044 Debug( 73): CTranslate: dwSidLen is 24
(T8796) 09/06/17 05:50:05:044 Debug( 321): Proxy server auto config Url: h
(T8796) 09/06/17 05:50:05:044 Debug( 73): CTranslate: dwSidLen is 24
(T8796) 09/06/17 05:50:05:059 Debug( 435): CPanGASetting:OnBnClickedSave - resend credentials

Thanks in advance.

Highlighted
L3 Networker

Do you see PanGPS service running under the task manager for these users?

Highlighted
L4 Transporter

The users were able to connect before using GP ver 3.1.4-7.

Furthermore the users can login via a different PC using the same credential .

But from their pc they are not able to connect to GP using their or even some other account.

 

Any thoughts on this?

Highlighted
L3 Networker

This seems to be more of a client issue than anything related to firewall. From the logs that you posted earlier, it looks like the Pan agent is not able to start the pan gp service.

Could you please confirm if the PANGPS service is running under Task manager > Services.

Try uninstalling the software and get rid of the Palo Alto Networks folder in Program Files.

Re install and check if this resolves.  Open up a tac case if this does not work.

Highlighted
L1 Bithead

I have the same issue with this, Why have lots of this issue.

Highlighted
L3 Networker

There is a problem with the PanGPA service's connection to the PanGPS service on the same workstation.

 

 PanGPS service should be listening on localhost port 4767.  To check run the command on windows pc

 

netstat -an | find "4767"

output should be listening.

try telnet to the port 4767

pls try turning off end system firewall.

 

Highlighted
Cyber Elite

@pcharadia,

I wouldn't advise people to turn off the end-system firewall, even for testing that simply isn't a very good 'solution' to anything. 

Highlighted
Cyber Elite

@kowu,

With GlobalProtect issues the order of troubleshooting should really be the following: 

1) Verify that PANGPS service is running under Services. 

2) Uninstall GlobalProtect and delte the Palo Alto Networks folder in Program Files. 

3) Restart

4) Reinstall GlobalProtect

5) Verify Connectivity

If that doesn't work open up a TAC case so that they can take a look at it with you. GlobalProtect is a very picky program that can be tripped up by other software much easier than other VPN clients. 

Highlighted
L1 Bithead

After un-installation of antivirus and firewall,.. error still exist..

Highlighted
L1 Bithead

Windows 10 FU 1709--- GP Client 5.0.4
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!