Give more info, please. You mean the Globalprotect application or the SSL clientless vpn access? Is there an authentication policy on the Firewall that uses a transperant captive portal? https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/user-identification/device-user-identification-captive-portal-settings.html 1. Also does the customer have a proxy as it may have issues with the globalprotect vpn traffic passing through it: https://docs.paloaltonetworks.com/globalprotect/4-1/globalprotect-app-new-features/new-features-released-in-gp-agent-4_1/tunnel-connections-over-proxies 2. Or is there a proxy after the Firewall. For example after the VPN is started the customer traffic to goes first to the firewall by the VPN tunnel then before Internet the customer traffic goes to a proxy.
... View more