- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
11-04-2024 08:21 AM
My company uses GlobalProtect VPN and I have a problem that needs help connecting Globalprotect on MacOS.
On the company device, it requires a GlobalProtect VPN connection to access company systems, allowed applications. But on MacOS, every time the employee takes the device out of the office and uses a wifi network other than internal wifi, all websites accessed by browser cannot be accessed, it reports an error: This site can't be reached. However, all applications installed on the device still connect normally such as: Teams, Outlook, Lark,...etc. I ping and nslookup the website, the IP has a signal but cannot access. I have tried many ways such as: setting the router's fixed DNS, Google DNS, AWS DNS, using the command sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder to clear DNS cache on MacOS, disable connect and reconnect, refresh VPN connection and uninstall GlobalProtect then reinstall but all failed.
The only way is to wait for the device for about 1-2 hours and it will automatically access the websites again.
The same thing happens when an employee successfully accesses the website using an external wifi and the next day reconnects to the internal wifi but still cannot access the website using the browser.
11-04-2024 08:30 AM
You manage Palo firewall in the company?
Do devices inside the network establish IPSec tunnel or have Internal Host Detection enabled?
Does GlobalProtect connect while using external wifi?
Do website names resolve to IP while using external wifi?
11-04-2024 08:40 AM
You manage Palo firewall in the company?
- Yes I can access and check, basic configuration on the firewall, but I don't fully understand how it works.
Do devices inside the network establish IPSec tunnel or have Internal Host Detection enabled?
- Sorry I don't know where to check it from. Can you give me more information so I can check it.
Does GlobalProtect connect while using external wifi?
- GlobalProtect must always be connected to be able to access the internet from the company device. If the connection fails or is connected, the internet cannot be accessed.
Do website names resolve to IP while using external wifi?
- Yes. I use nslookup from the website to resolve to IP with external websites as well as internal websites.
11-04-2024 11:09 AM
Try to access Internet from outside the company.
Then check Palo logs (Monitor > Traffic).
Do you see sessions from Mac GlobalProtect IP towards Internet?
Is action allow?
Is source nat applied (you can check session details if you click on a mag glass on left side of traffic log).
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!