Incomplete network connection with Global Protect Over Public WiFi

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Incomplete network connection with Global Protect Over Public WiFi

L1 Bithead

Hi Everyone

One of our user is experiencing the issue with GlobalProtect. When the user connect with globalprotect over public WiFi, he can only ping the LDAP server in the network and nothing else. I am wondering what can cause this issue and why the user cannot access the other network resources. Can someone please share your thoughts about this that what areas should we look into for this kind of problem. Also what settings we need to check for global protect. 

Any help in this regard will be highly appreciated. 

 

Thank you in Advance. 

3 REPLIES 3

Cyber Elite
Cyber Elite

@GQMerdian,

What do you see in your traffic logs on the firewall, do you see the other traffic even coming across the tunnel? When troubleshooting with the user have you verified that the endpoint route table is being updated properly and you don't have any overlapping going on if you have split-tunnel or local network access enabled? 

Thanks for your response. Yes i see the global protect logs from all the users. We are troubleshooting this particular case over the public wifi. This user mentioned that he is able to ping the LDAP server which means routing is working fine as he is able to ping the network but not everything so the global protect session is kind of incomplete so this being said "pre-logon" is working but incomplete. 

Cyber Elite
Cyber Elite

Hi @GQMerdian ,

 

Please also verify the "endpoint route table" that @BPry mentioned.  On Windows, this is "route print" and on macOS/Linux it is "netstat -r".  If GP works fine for everyone else, then it may be a conflicting route injected by the public WiFi.  Adding that same route to GP split tunnel will cause it to inject a route with a better metric on the endpoint and fix the issue.

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!