GlobalProtect don't access LAN

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

GlobalProtect don't access LAN

L2 Linker

Hi all,

I'm relatively new to Palo Alto solutions and I run into a problem that I can't find which may be causing the connection to fail.

 

I have a configured GP gateway and in it I have 3 pools with different subnets. One of these networks cannot access services on the LAN. I see in the logs the access being accepted in the policies but the connection is not established.
I revalidated the settings and didn't find what could be a failure. Any idea what it might be?

4 REPLIES 4

L3 Networker

Does the LAN have a route to that GP subnet?

Hi MikeC,

Describing the settings a little more, the 3 networks I have configured in the GP are 10.x.x.x / 24, / 25 and / 27. In the routing table I have a route for 10.0.0.0/8 and that route points to one of the ethernet interfaces and not to the tunnel.

L2 Linker

Hi Connelly,

 

I find it strange as it is because there have been no changes in the firewall since December and this problem arose yesterday, in addition other networks in the pool of the same GP gateway are working perfectly.

L2 Linker

Still in this investigation I noticed a strange new behavior.

 

This is the scenario:
- I have gateways 01 and 02 for the GP.
- AD groups called Grupo1 and Grupo2.
- Test user named Fred.

 

When user Fred is in Group1 he has normal access to the environment through the two gateways.
When that same user is in Group2 he has normal access only through gateways 01. If you use 02 he does not access anything.

I reviewed the LDAP settings but did not find any unique references to the groups I have.

What can I not be seeing?

 

  • 2743 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!