I don't see any drops and suspect it is failing with connecting via authentication or something along those lines. Works fine but as soon as a user connects to GP, whiteboard sharing no longer works. Curious if anybody else has run into this?
Hi @jhwarren ,
You need to provide more information, with this poor explanation of the problem it is shooting in the dark.
- Do you use full tunnel or split-tunnel VPN?
- How is you security policy look like? Do you allow specific ports or using AppID?
- How is you GP gateway configured - are you route the traffic base on route, domain or application?
- Have you understand how whiteboard is working? Do you know what port, protocol is used? From which direction the traffic is initiated - is it possible that you need rule allowing traffic from inside to GP VPN?
You need to understand that GlobalProtect is just building logical connection from the user PC to the firewall, after that is down to basic network principles - do you have route, do you have fw rule allowing traffic, do you have reply routed back.
We're running into this issue as well but here's what I was able to dig up. Issue likely is related to the Microsoft NLA & NCSI protocols mentioned above. All the rest of our MS products seem to work except MS Whiteboard. I have a hunch that it has been fixed for other MS Products as the person who brought it to our attention stated, "OneNote had the same issue and was fixed some months ago." There was no intervention from us or anyone else that I'm aware.
Fails on both GP Split-Tunnel and Full Tunnel (we have both) set to loopback interfaces, Default Gateway 0.0.0.0. It works on our Anyconnect VPN client which has a numbered Default Gateway.
Its probably an application that is missing or the traffic is being decrypted. Either way make sure you have logging enabled on all of your policies to see where the traffic is getting blocked or decrypted.
If something is missing, it is not obvious -captures match-up and nothing is dropped that is apparent, I've compared captures from the PA with and without GP and they are similar, so no smoking gun on that front. Given the previous comment of somebody else who is also seeing this, their explanation sounds plausible. Thanks for giving it a think!
I was vague by intent - I was looking to see specifically if anybody (besides me) was seeing this issue with regards to GP. The reply from a user who also is experiencing this is what I was looking for. I'd also be interested if anybody is using GP and whiteboard does work under that scenario, for what it's worth.
We have a full sweet of cloud-services in-use from Microsoft and this is the only one that has given us any challenge. The usual captures, debugs and such have all failed to produce any reliable leads towards figuring this out.
I appreciate the response - I have looked through and compared a working client and non-working client and nothing jumps out in the captures. I created custom policies and wired them for sound (in terms of logging
How it works is a challenge - I am waiting on MS to weigh-in on that front but I may have a while before I hear back from them
Thanks for your insight,
I don't suppose you found a solution to this by chance did you? I have the same issue at present.
Not yet - the ticket with MS premier support is now at Tier-2 and they have asked for some diagnostics to be collected to help them analyze the issue (a 16-step process using Fiddler and a couple of other tools). I'll update once they respond to the information provided.
Ah great, thanks for the update - that sounds like a real pain, so I won't go down that route just yet unless you find yourself at a dead end!
This Microsoft article might be helpful as we have run into the same issue and are going to add RFC1918 addresses [intranet space] to the GPO
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!