Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

PanGPA and PanGPS logs

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

PanGPA and PanGPS logs

L0 Member

We now have more cases of users complaining of GP disconnect or slowness. 

Need assistance reading the Global protect logs from the Agent. 

Are there any know codes for Dump , Debug and Info that i should be looking out for when going through the log file.

1 accepted solution

Accepted Solutions

L6 Presenter

You can take a look at:

 

 

LIVEcommunity - Knowledge sharing: Globalprotect troubleshooting/investgation. Split tunnel,Globalpr...

 

 

 

Also for Globalprotect 5.2 and Palo Alto 9.1 you can see performance and latency from the Gateway Firewall:

 

 

GlobalProtect Gateway Latency Reporting (paloaltonetworks.com)

 

 

Also if you see many disconnect from the log you may a bottleneck in your network or if there is downgrade in the logs from ipsec to ssl it is bad as SSL is worse for performance.

 

How to detect when Global Protect client fails to establish IPS... - Knowledge Base - Palo Alto Netw...

 

Troubleshooting GlobalProtect - Knowledge Base - Palo Alto Networks

 

 

In rare cases changing the MTU of the globalprotect can help:

 

 

Troubleshooting GlobalProtect MTU issues | Palo Alto Networks

 

 

Edit:

 

 

Also there is a nice subscription feature you may consider to use "GlobalProtect App Log Collection for Troubleshooting":

 

 

GlobalProtect App Log Collection for Troubleshooting (paloaltonetworks.com)

View solution in original post

1 REPLY 1

L6 Presenter

You can take a look at:

 

 

LIVEcommunity - Knowledge sharing: Globalprotect troubleshooting/investgation. Split tunnel,Globalpr...

 

 

 

Also for Globalprotect 5.2 and Palo Alto 9.1 you can see performance and latency from the Gateway Firewall:

 

 

GlobalProtect Gateway Latency Reporting (paloaltonetworks.com)

 

 

Also if you see many disconnect from the log you may a bottleneck in your network or if there is downgrade in the logs from ipsec to ssl it is bad as SSL is worse for performance.

 

How to detect when Global Protect client fails to establish IPS... - Knowledge Base - Palo Alto Netw...

 

Troubleshooting GlobalProtect - Knowledge Base - Palo Alto Networks

 

 

In rare cases changing the MTU of the globalprotect can help:

 

 

Troubleshooting GlobalProtect MTU issues | Palo Alto Networks

 

 

Edit:

 

 

Also there is a nice subscription feature you may consider to use "GlobalProtect App Log Collection for Troubleshooting":

 

 

GlobalProtect App Log Collection for Troubleshooting (paloaltonetworks.com)

  • 1 accepted solution
  • 2557 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!