02-19-2021 01:35 AM
Hi All,
Having just deployed version 5.2.5 when I connect on Globalprotect I get a pop up stating "The network connection is unreliable and GlobalProtect reconnected using an alternate method......". This did not appear before and was not present on 5.2.4. We need version 5.2.5 for O365 split tunneling, there is an issue using 5.2.3 and 5.2.4.
I have noticed I'm connecting as SSL even though the gateway is configured for "enable Ipsec" and the rule has Ipsec in it's app field.
Is there a way to remove this notification (having looked I can't see anything obvious)? I will shortly be pushing this client out to 3500 users.
Regards
Adrian
04-15-2021 01:57 PM
As someone who just upgraded to 5.2.6 I can tell you that upgrading doesn't fix it! 🙂
I am tired of being asked what this message means. So I am throwing in the towel and unchecking IPSec.
PA support - please fix it. Super annoying.
04-16-2021 12:25 AM
Hi
afaik you have to disable it in the Portal > Agent > App
Per default it's still enabled.
Think this switch is only working with 5.2.5-c84 and 5.2.6.
04-16-2021 06:58 PM - edited 04-16-2021 10:35 PM
Still seeing this after activating 5.2.6 from PAN-OS 8.1.6 and running GlobalProtect Version 5.2.6-87.
To change this on the Portal, go to Network tab>GlobalProtect>Portals>choose the Portal>from GlobalProtect Portal Configuration screen, click on Agent>select relevant option under Configs>click on App tab>the option is called "Display IPSec to SSL Fallback Notification" by default this is set to Yes, change to No>click on OK>click on OK again>repeat for any other Portals where this change is required>Commit changes to Panorama or to the Firewall as required to suppress message as needed.
As mentioned from user Emr_1 to suppress this message, this needs to be disabled from the Gateway, from Network tab>GlobalProtect>Gateways>Agent>under Tunnel Settings tab, uncheck the Enable IPSec>repeat for any other Gateways where this change is required>Commit changes to Panorama or to the Firewall as required to suppress message as needed.
Another point to consider, which I ran into, is whether or not you are having issues with GlobalProtect traffic dropping IPSec connections, using UDP Port 4501.
When GlobalProtect client will try to connect, first, it will try to connect over IPSec, using UDP, the faster protocol, if this fails, then GlobalProtect will fallback to SSL, over TCP, the slower protocol. The message that is shown, is because GlobalProtect client is failing back from IPSec to SSL for the VPN connection.
Performed a collect of GPClient logs from Windows laptop and searched in PANGPS.log for "Trying to do IPsec" found that this was generating failed to receive keep alive, then followed by Disconnect udp socket, then few lines down we see ipsec failed to start then we see IPSec fallback reason is IPSec connection failed.
Upon further investigation on the Traffic Monitor, we saw that traffic to UDP port 4501 is being denied for the GlobalProtect security policy, as a result, the IPSec Tunnel will fail and fallback to SSL will occur.
Proceeded to modify the GlobalProtect Security Policy that we had in place, added in the IPSec application, then changed the GlobalProtect>Gateways>Agent>under Tunnel Settings tab, re-checked the Enable IPSec>Committed changes.
This time, when my client connected to the GlobalProtect VPN, I saw IPSec as the Connection type, no longer seeing Notification Warning message. Repeated the same process for my other Gateways, left Portal to have Notification for Fallback set to No and this worked.
Need to keep in mind why the message is appearing, as sometimes this can be an indication of an underlying configuration issue that you should focus on, so as to provide an optimal user experience. Thanks to Harish Krishan, Technical Support Engineer from Palo Alto for help working through this scenario.
04-30-2021 06:59 AM
Hello
We still have users who receive the warning. Portal config was adjusted, GP is 5.2.5-c84.
The agent log (PanGPA.log) holds the following line:
<display-tunnel-fallback-notification>no</display-tunnel-fallback-notification>
So I would assume, everythig is configured as required.
Any idea on this?
05-06-2021 05:54 AM
I've just updated to 5.2.5-c84 and I'm getting the message as others have reported. I did find a solution that was presented on another forum. In a nut shell it appears that there needs to be a u-turn nat to the public IP for GP portal address to udp 4501. Detailed here: GlobalProtect: how to disable alert that connection is unrealiable : paloaltonetworks (reddit.com)
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!