- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-19-2019 01:13 PM - last edited on 03-19-2020 03:47 PM by jdelio
Hi, everybody!
I have a question regarding GlobalProtect 5.0 and the error message "Assign Private IP address failed" a user is getting when trying to connect from a mobile phone (both Android and iPhone).
I tried to explain to the user that this could be caused by IP overlapping, as this link tells:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClHMCA0
But he rejects that possibility and insists he has the error every time he tries (not just once in a while) and that the internal addresses he uses for VPN are only used for that.
What other things apart from IP overlapping could be causing this "Assign Private IP address failed" error?
Thanks a lot!
02-19-2019 01:24 PM - edited 02-19-2019 01:25 PM
You could also be getting that error message if you require the user to be in a certain AD group and this user is not a match. I recommend watching your system logs when they attempt to connect:
( subtype eq globalprotect ) and (time_generated in last-24-hrs) and ( description contains 'theirusername' )
02-19-2019 01:51 PM
IP Overlap is the only time that I've ever known this message to popup. An easy check would be to have them connect to a hotspot from say your phone and try that, so that you can verify that the IP pools don't overlap.
I've never seen this for what @hshawn is describing and won't expect this message if they weren't an authorized user as that's a completely seperate error message.
02-19-2019 01:54 PM
@BPry We see it from time to time. In fact the user gets authenticated and has an IP address of 0.0.0.0 then we tell the help desk to add them tot he VPN AD group and *poof* they have a real IP. When they have the 0.0.0.0 IP showing we see that message in the logs and we see them get booted and reconnect over and over again (we are using always on configs). We have also seen this with the overlap when someone is at a hotel that happens to use the same subnetting scheme for their internal network.
02-19-2019 02:08 PM
Hmm. Have you raised that with support at all? When the tunnel attempt to switch from the always-on user to the named user tunnel you shouldn't get stuck at 0.0.0.0 IP like that.
04-05-2020 05:04 PM
You are getting this message if the IP Pool is already full or runs out already.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!