Check what your default gateway or next hop in your agent. I have seen GP users get a virtual pool address, and then, their default gateway, is the next available IP from the virtual pool. Look at logs on the FW to see if you show any denies or similar in traffic logs.
It is best to consider getting a license for GP on the FW for allowing mobile devices to connect. I truly have not had much luck with the Group and XAuth.
Without seeing the logs or knowing the configuration this is hard to troubleshoot. I'd look at the logs as @SCantwell_IM mentioned and see if you even see any traffic reaching the firewall from the client or not. In addition, ensure that you have interzone-default logging enabled to view denied traffic so it actually shows up in the logs.
I'll also state that different devices do this very differently. Android device to android device behavior different, an iPhone behaves differently than Android, and it's just generally not worth it. As @SCantwell_IM mentioned once again, just buy a GlobalProtect subscription so that you have access to the mobile app.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!