GlobalProtect issue when try to connect many agents behind one home router

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

GlobalProtect issue when try to connect many agents behind one home router

L2 Linker

Hello all, 

 

we have let say 10 users behind one home internet router.

They can ping the portal and so on but just one of them can  connect. The error of the others is that there is a network problem trying to reach the portal.

Are there any limitations? Was someone experienced the same issues ?

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

@stef,

There's no built-in limitation on a single public IP address having multiple GlobalProtect sessions associated, that's actually really common to come across. The first thing that I would look at is if it's just this one router in question, or if you can actually duplicate this behavior. It's possible that the NAT type of the home router simply isn't allowing anyone else to form a tunnel to the same public IP address.

The other thing to look at, however if enabled I would hope you would be getting alerts for it, is if you're possibly hitting a DoS limit you have configured. You could have a max-concurrent limit configured so your firewall isn't allowing any additional sessions from that public IP address or something similar. 

View solution in original post

2 REPLIES 2

L7 Applicator

does that device connect OK when it is the only one connecting.

The GP logs will assist you here, can the user browse to the portal?

check pangps log fo further help.

 

I do not know of any restriction.

Cyber Elite
Cyber Elite

@stef,

There's no built-in limitation on a single public IP address having multiple GlobalProtect sessions associated, that's actually really common to come across. The first thing that I would look at is if it's just this one router in question, or if you can actually duplicate this behavior. It's possible that the NAT type of the home router simply isn't allowing anyone else to form a tunnel to the same public IP address.

The other thing to look at, however if enabled I would hope you would be getting alerts for it, is if you're possibly hitting a DoS limit you have configured. You could have a max-concurrent limit configured so your firewall isn't allowing any additional sessions from that public IP address or something similar. 

  • 1 accepted solution
  • 2465 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!