02-22-2016 07:25 AM
Has anyone seen this error before?
I have a user who is using SSL VPN to the Palo Alto. Upon downloading the client, the initial connection works.
However, subsequent connections displays an error on the client "Failed to get default route entry". The logs on the Palo Alto Firewall don't suggest an issue an indicate the user is connected and an IP assigned. Yet the IPconfig on the laptop does not indicate the IP has been received.
I have other users connecting OK.
02-22-2016 02:05 PM - edited 02-22-2016 02:10 PM
can you raise debug on the client side? Should be enabled from the GP configuration for users, you can collect troubleshooting information for network configurations and routing table. It is worth investigating is there some conflict in third-party software as well (why is customer using SSL VPN? Are they using some IPsec VPN at the same time that sets default route with same metric...?) I am thinking, error is not the happiest description what happened - it might be having problems installing default route to the client...
Raising debug on client and investigating client's routing table would be my first steps, before I take it to the GP, especially if everything works with all/most of other clients, debugged logs should tell you more anyhow. I would also try using the latest version of client, 3.0 has been out for a few days - perhaps it will solve your problems.
03-24-2020 08:43 PM
How to fix this "Failed to get default route entry" issue?
04-08-2020 07:49 AM
Hi @SajidAliSajid ,
Luciano's previous comment is old but still valid. Please do some debugging on the client side. Collect the debug logs from the GP client and check there for starters.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!