- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
01-03-2022 05:17 AM
Hi,
We are facing issue with Global Protect VPN client connectivity for one of the user machine. Below are the details of the issue.
-> Global Protect VPN is very frequently getting disconnected
-> in Global Protect VPN connection stauts - can only see Packets Out , there are not Packets In.
In GP event logs can see "Tunnel is down due to keep-alive timeout" logs
Please let me know what can be the possible reason for GPVPN frequently disconnecting - but once connected there is no connectivity to corporate VPN over GPVPN.
Attaching the Global Protectlogs debug logs took from user n=machine during the time for issue.
Note: Issue is happening on for one user.For rest all users GPVPN is connecting fine.
07-26-2022 08:01 AM
Agree on the issue occurring since upgrading our firewalls to 10.1.6.
Issue was not present prior to upgrading 10.1.6. Immediately after 10.1.6 upgrade, my users experienced this issue. No change in GP client version as part of the upgrade. Currently using 5.2.x GP branch, tested using multiple versions, included latest 5.2.12.
Issue occurs regardless of wireless/wired connection at offsite location, regardless of internet providers at offsite locations, or different internet providers connected to the firewalls themselves.
Hope to open a ticket this week with support on the issue.
07-26-2022 08:24 AM
Update: Opened a ticket with TAC - looks like this is a known issue, although there is no resolution and only a workaround. Workaround= completely shutdown the device and power back on (not a reboot) or to downgrade to 10.1.5-h2 or another previous version. Here's the kicker. We downgraded our PA-3250s in an HA pair one at a time to 10.1.5-h2, and after we tested our Active FW on 10.1.5-h2, GP users were NOT being disconnected (great!) then we downgraded our passive FW, and now the passive FW will not connect to Panorama.
Looks like this is another bug and no work around yet. Still working with TAC....this is frustrating to say the least
07-30-2022 11:28 AM
Similar to @frankis .. on my support ticket, full shutdown, don't reboot...
so last night, shutdown one box, pulled power plugs for about 5 minutes.... plugged them back in and powered it back up...
currently, my laptop is connected via the VPN for over 5 hours without disconnecting.
08-02-2022 09:36 AM
@MattShuter Can you tell me the boxes you have? Are your boxes in HA pair? Are they 3200 series boxes?
08-02-2022 09:39 AM
5220s, not in HA pairs.. running at separate sites. Will shutdown my second box this weekend I think.
09-14-2022 05:54 AM
fixed in 10.1.7 for some models...as noted in release notes:
"(PA-3200 Series, PA-5200 Series, and PA-5400 Series firewalls only
10-24-2022 01:12 PM
We are also getting timeout errors on GlobalProtect connections after upgrading to 10.1.6-h6 on our PA-3220 happening at 45 mins with the inactivity logout set to 90 mins. Which coincides with the noted fix quoted above: "fixed in 10.1.7 for some models...as noted in release notes:
"(PA-3200 Series, PA-5200 Series, and PA-5400 Series firewalls only
Increased the inactivity timeout to 1200 mins as a work around. Still waiting to see if it fixes the issue.
01-25-2023 07:08 AM
Hello,
While I do not know of a solution, this is from another vendors recommendations:
Hope one of these might help.
01-26-2023 04:27 AM
What OS version are you running on your firewall? The issue was reportedly fixed in 10.1.7 for various models.
Prior to that, a shutdown/power off of the firewall resolved the issue, as recommended by support. *NOT a reboot*
As noted, if that is not possible to upgrade or pull the power at this time, you could increase the timeout period to double what is needed.
09-27-2024 08:05 AM
This seems to be not only for hardware firewalls. We implemented Prisma last year and after a lot of successful testing done by myself and others in the IT department we started rolling it out to Gen Pop. So far have around 60 users connecting via Global Protect. Only 2 of our users have reported random frequent disconnects. They're both located in New England and both use Comcast Xfinity as their ISP. I'm in central Ohio and use Spectrum and have not had any issues for over a year. Fortunately, if I google Comcast Global Protect Disconnects, I'm not the only one that has this exact problem. Unfortunately, I have not found a resolution.
I did open a case with Palo Support today. Provided logs from both user machines.
Anyone else know or have similar issues with certain ISPs and their home routers?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!