GlobalProtect Reporting Port Exhaustion on Win 10?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

GlobalProtect Reporting Port Exhaustion on Win 10?

L2 Linker

Anyone else seeing a lot of this lately?  I've been researching this over and over again for about 2 weeks and all signs point to Windows being the culrpit, but the only time we ever see this happen is when users are connect to GlobalProtect.

 

Here's the culprit log from GPS:

connect failed with error 10055(An operation on a socket could not be performed because the system lacked sufficient buffer space or because a queue was full.)

 

Things I can verify:

  • Reboot fixes (winsock reset also fixes it, but requires a reboot anyways)
    • Sometimes 2
  • Users don't lose active sessions
  • Users can no longer browse anything via DNS
  • New connections can be made via telnet
  • Internet access is still available (ping and traceroute show that affected devices are traversing public hops and can reach them)
  • Local network is also affected
  • Port exhaustion has not actually occurred
    • One user had 80 of 16,000+ ports in use (clearly not exhausted)
2 REPLIES 2

L1 Bithead

That's interesting. What version of Windows and build are you on? Also what does netstat show on the end user machine?

Netstat shows that only 80 ports were in use (out of 16,000+ total - checked that via the CLI to make sure it wasn't something small).

 

Windows builds are 9309 all around 1909 18369.959

 

The only common denominator seems to be GlobalProtect.

 

I saw a new error today which resulted in a disconnect with the same symptoms:

 

Bio Enum Databases failed. hr = 0x0

 

 

 

What still intrigues me is the fact that it seems like affected machines just seem to lose DNS.  Public hops works, everything seems to be functioning except no browsing (DNS related).  All signs point away from GPC, but none of our non-vpn users are having this issue and they remotely connect in different ways.

  • 2682 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!