Global Protect disconnect issue

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Global Protect disconnect issue

L3 Networker

3000 series FW, software 6.0.1, GP 2.0.1 -- GP continually disconnects/reconnects.. tried reinstalling client, rebooting, etc.. happens with some users at random times..then the issue will magically go away.  Anyone else experience?

8 REPLIES 8

@rshetty

I think you cannot compare your issues to the once in this topic (2 repectively 4 year old topic).

What versions PAN-OS and GlobalProtect are you using? How are the users connected when they complain about reconnects: wired, wireless, mobile?

@vsys_remo

I just wanted to know if this issue was resolved and what was the solution. 

 

 

PAN-OS  : 8.0.5

GlobalProtect : 4.0.5

All are connected via wireless. I suspected the issue was wireless but other users are also connected via wireless. 

 

Was just wondering what does this mean

(T188) 05/17/18 15:40:33:044 Debug( 402): Enforcer,Successfully Committed BreakAllExistingConnections Transaction.
(T188) 05/17/18 15:40:33:044 Debug(8965): PanMSService::UpdateGPEnforcer() - enforcer is blocking.

 

I have been seeing this evertime these is a reconnect

L4 Transporter

@rrau wrote:

3000 series FW, software 6.0.1, GP 2.0.1 -- GP continually disconnects/reconnects.. tried reinstalling client, rebooting, etc.. happens with some users at random times..then the issue will magically go away.  Anyone else experience?


 

I've seen this caused by some kinds of cable or DSL modems on the remote end.

 

It's got soemthing to do with the way some modems do UDP security - they allow the connection/authentication, but block the packets after the connection competes, resulting in a timeout and disconnect.

 

Once it disconnects, the client goes back to phase 1 and reconnects and discovers fine - but then times out again after 5 minutes.

 

The various modem/router manufaturers call the settings different things - ALG, PnP Security, some toher things. It's particularly common on DLink routers

 

I'm not sure if I can link to external dicsussions here - I'll try

 

Example 1, Example 2, Example 3

Just an FYI, for my disconnect issues we saw a lot of 

 

"(T16164) 05/17/18 13:32:21:064 Debug(1231): packet length 44 is less than udp length 64067: gateway route may get removed
(T16164) 05/17/18 13:32:21:064 Debug(1307): CheckDriverData() failed" before the tunnel between machine and GP goes down. 

GPC- 5274 Fixed an issue where GlobalProtect agents (versions 4.0.3 to 4.0.5) discarded fragmented UDP packets.

 

Wll be upgrading the GP to 4.0.8 and check if this still happens. 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!