- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-01-2022 12:15 PM
Hi Everyone
One of our user is experiencing the issue with GlobalProtect. When the user connect with globalprotect over public WiFi, he can only ping the LDAP server in the network and nothing else. I am wondering what can cause this issue and why the user cannot access the other network resources. Can someone please share your thoughts about this that what areas should we look into for this kind of problem. Also what settings we need to check for global protect.
Any help in this regard will be highly appreciated.
Thank you in Advance.
02-01-2022 06:37 PM
What do you see in your traffic logs on the firewall, do you see the other traffic even coming across the tunnel? When troubleshooting with the user have you verified that the endpoint route table is being updated properly and you don't have any overlapping going on if you have split-tunnel or local network access enabled?
02-02-2022 09:34 AM
Thanks for your response. Yes i see the global protect logs from all the users. We are troubleshooting this particular case over the public wifi. This user mentioned that he is able to ping the LDAP server which means routing is working fine as he is able to ping the network but not everything so the global protect session is kind of incomplete so this being said "pre-logon" is working but incomplete.
02-02-2022 10:23 AM
Hi @GQMerdian ,
Please also verify the "endpoint route table" that @BPry mentioned. On Windows, this is "route print" and on macOS/Linux it is "netstat -r". If GP works fine for everyone else, then it may be a conflicting route injected by the public WiFi. Adding that same route to GP split tunnel will cause it to inject a route with a better metric on the endpoint and fix the issue.
Thanks,
Tom
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!