GlobalProtect - RPC connections fail

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

GlobalProtect - RPC connections fail

L2 Linker

Hi All,

I seem to be unable to get this to work but when connected via GlobalProtect VPN remotely all RPC server communication fails. This can be seen with any of the following tasks:

Open Active Directory Users and Computers

Open Group Policy Management

Attempt to connect to a DFS file share

attempt to update group policy with GPUpdate command line options

Attempt to open the security tab in the properties of a folder on a shared network location

Any attempt to do name look-ups to Active Directory.

I have a support case open but was wondering if anyone else can confirm this as well? I have tried all versions of GPAgent from 1.2.7 through 2.0.3

4 REPLIES 4

L7 Applicator

With the type of services you list, I wonder if you are getting good internal DNS resolution after the Global Connect is started.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center

Hi, Yes DNS works fine and that had been my thoughts so I was playing with the DNS search list to no avail. I then found that in the months leading up to the problem this traffic was being logged in the threat log as informational (MS RPC is listed as a threat) but working with PA support we have found that a couple of weeks ago it changed from logging to dropping packets so they are looking into why this is now.

Interesting issue.  So did you end up with a custom profile to ignore this particular threat signature for the traffic until the signature is fixed?

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center

Unfortunately not as even removing all threat scanning and other profiles the traffic is still dropped. Sometimes it goes through and everything works just long enough for you to get your hopes up and think you fixed it then it stops again.

  • 3394 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!