GlobalProtect Issues with Hotspot Users

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

GlobalProtect Issues with Hotspot Users

L1 Bithead

 

  • Two different users reported problems when connecting to GlobalProtect when using an iPhone as a hotspot.  The users can connect to GP, but are then unable to use HTTPS or ssh to connect to internal assets via the VPN.  If the user uses the same laptop and connects via wifi (not using hotspot), GP works fine.  Tests with several other users using iPhone hotspots were successful.  The users are on Mac OS laptops with GP version 5.0.8.  An upgrade of the GP version did not help.  Both users have iPhone 7 running IOS 14.2.  
  • Testing showed that the user successfully connects to GP and is able to ping devices over the tunnel.  DNS resolution works fine.  But connections using ssh or https were unsuccessful.  Further testing seemed to indicate an MTU problem.  We attempted to have the user change their GP VPN adapter MTU without success.  
  • Solution:  In GP version 5.2, there is a new feature to centrally modify MTU.  The solution involved having the user upgrade GP to version 5.2.4.  In addition to the existing GP Portal Agent, we created an additional GP Portal Agent that contained only the two users.  This portal agent was placed before the general Portal Agent used by everyone else.  In the new Portal Agent, under the App tab, we changed the GlobalProtect Connection MTU (bytes) from the default 1400 bytes to 1360.  In both cases, the user was now able to successfully use GP over the hotspot.

peppywoll_0-1610157455136.png

 

 

 

3 REPLIES 3

L1 Bithead

Hi

 

Similar issue with GP (5.2.11, 5.2.12 and 6.0.3) using an iPhone 11 or higher as a hotspot  fow Windows 10 with Outlook 365 services. With previous iPhone versions worked well. Tested with iPhone 8 (ios 15/16) without problems. Same tests with iPhone 11 failed, and mails don't be sent.

 

Change the MTU to 1360 solved the problem.

 

L2 Linker

Thanks having a similar issue with hotspot user.  I will try this MTU hack.

L0 Member

Hi 

 

Thanks for sharing. I found similar issue with panos version 10.1.8 / gp linux vesion 5.3.4 / connection via iPhone hotspot. User can connect GP and ping to server but cannot ssh to server.

 

Try to change GlobalProtect Connection MTU to 1360 solved the problem.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!