I've got a new Global Protect portal/gateway. When I get connected to the gateway, I can see the connection via the GP monitor. Then if I go the to traffic monitor and search the source range 192.168.203.0/24 I only get traffic from previous testing that I've performed. I'm not getting the currently connected device to show up for some reason. It's connected as the remote user option in the network>gateway shows me connected and the ip of 192.168.203.2. However its not in the monitor. What do you all think?
It's kind of hard to guess without details. I have seen a few errata in the release notes for various versions about edge cases where traffic wasn't being logged, but I don't recall anything specific about new gateways. Maybe open a support ticket with PA where you can share the details with them and they can see if it is something obvious.
Hi @danoman2 ,
You probably have "log at session end" configured for your security policy rules. This is recommended. Monitor > Logs > Traffic will only show sessions that have ended. In order to see live sessions, go to Monitor > Session Browser.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!