hello team, we have this client running his ISP thru E1/3 (secondary ISP service), he wants to allow the Global Protect client thru this conection, however, after configure the portal and gateway in the PA-500, we test in the agent installed and we got the follow logs from the GP Client engine: (T22764) 09/26/19 19:56:27:735 Debug(4523): No need to check gateway route since no tunnel. (T22764) 09/26/19 19:56:30:758 Debug(5218): NetworkConnectionMonitorThread: m_state = 0, m_bOnDemand=0, m_bAgentEnabled=1, m_bJustResumed is 1, m_bHibernate is 0, m_bAgentEnabled is 1, m_bDisconnect is 0, IsConnected() is 0, IsVPNInRetry() is 0. (T22764) 09/26/19 19:56:30:758 Debug(4523): No need to check gateway route since no tunnel. (T22764) 09/26/19 19:56:30:758 Debug(5235): NetworkConnectionMonitorThread: Detected route change, but skip network discovery. (T22764) 09/26/19 19:56:34:723 Debug(5157): NetworkConnectionMonitorThread: route change detected. Wait for 3 seconds. (T22764) 09/26/19 19:56:34:723 Debug(4523): No need to check gateway route since no tunnel. (T22764) 09/26/19 19:56:37:725 Debug(5218): NetworkConnectionMonitorThread: m_state = 0, m_bOnDemand=0, m_bAgentEnabled=1, m_bJustResumed is 1, m_bHibernate is 0, m_bAgentEnabled is 1, m_bDisconnect is 0, IsConnected() is 0, IsVPNInRetry() is 0. (T22764) 09/26/19 19:56:37:725 Debug(4523): No need to check gateway route since no tunnel. (T22764) 09/26/19 19:56:37:725 Debug(5235): NetworkConnectionMonitorThread: Detected route change, but skip network discovery. (T22764) 09/26/19 19:56:40:571 Debug(5157): NetworkConnectionMonitorThread: route change detected. Wait for 3 seconds. (T22764) 09/26/19 19:56:40:571 Debug(4523): No need to check gateway route since no tunnel. (T5392) 09/26/19 19:56:42:041 Debug( 301): Received session change, event type 8, session 1 (T22764) 09/26/19 19:56:43:572 Debug(5218): NetworkConnectionMonitorThread: m_state = 0, m_bOnDemand=0, m_bAgentEnabled=1, m_bJustResumed is 1, m_bHibernate is 0, m_bAgentEnabled is 1, m_bDisconnect is 0, IsConnected() is 0, IsVPNInRetry() is 0. (T22764) 09/26/19 19:56:43:572 Debug(4523): No need to check gateway route since no tunnel. (T22764) 09/26/19 19:56:43:572 Debug(5235): NetworkConnectionMonitorThread: Detected route change, but skip network discovery. (T9888) 09/26/19 19:57:00:241 Info ( 246): HipCheckThread: got check hip event or time out. (T9888) 09/26/19 19:57:00:241 Debug( 258): HipCheckThread: WAIT_TIMEOUT (T9888) 09/26/19 19:57:00:241 Debug( 270): HipCheckThread: m_bHipPolicyReady is false, coninue; (T9888) 09/26/19 19:57:00:241 Debug( 216): HipCheckThread: wait for hip check event for 3600000 ms); (T22764) 09/26/19 20:08:59:228 Debug(5157): NetworkConnectionMonitorThread: route change detected. Wait for 3 seconds. (T22764) 09/26/19 20:08:59:228 Debug(4523): No need to check gateway route since no tunnel. (T22764) 09/26/19 20:09:02:230 Debug(5218): NetworkConnectionMonitorThread: m_state = 0, m_bOnDemand=0, m_bAgentEnabled=1, m_bJustResumed is 1, m_bHibernate is 0, m_bAgentEnabled is 1, m_bDisconnect is 0, IsConnected() is 0, IsVPNInRetry() is 0. (T22764) 09/26/19 20:09:02:230 Debug(4523): No need to check gateway route since no tunnel. (T22764) 09/26/19 20:09:02:230 Debug(5235): NetworkConnectionMonitorThread: Detected route change, but skip network discovery. (T22764) 09/26/19 20:09:02:373 Debug(5157): NetworkConnectionMonitorThread: route change detected. Wait for 3 seconds. (T22764) 09/26/19 20:09:02:373 Debug(4523): No need to check gateway route since no tunnel. in the PA using CLI we validate the conection between E1/3 (PA500) and the e1/4 from rhe RV20 Cisco from ISP and below is the ping results: @Server-PA> ping source 2xx.1xx.69.44 host 2xx.1xx.69.41 PING 2xx.1xx.69.41 (2xx.1xx.69.41) from 2xx.1xx.69.44 : 56(84) bytes of data. 64 bytes from 2xx.1xx.69.41: icmp_seq=1 ttl=255 time=1.08 ms 64 bytes from 2xx.1xx.69.41: icmp_seq=2 ttl=255 time=0.997 ms ^C --- 2xx.1xx.69.41 ping statistics --- 8 packets transmitted, 8 received, 0% packet loss, time 7069ms rtt min/avg/max/mdev = 0.997/2.856/15.404/4.743 ms @Server-PA> @Server-PA> @Server-PA> @Server-PA> @Server-PA> ping source 2xx.1xx.69.44 host 8.8.4.4 PING 8.8.4.4 (8.8.4.4) from 2xx.1xx.69.44 : 56(84) bytes of data. ^C --- 8.8.4.4 ping statistics --- 257 packets transmitted, 0 received, 100% packet loss, time 256151ms @Server-PA> were the 2xx.1xx.69.41 is the GW router. ISP provider said "you need to put our DNS servers IP's on the next device (in this case the PA-500) in order to get INternet traffic flow", we haven't tested this option , due the fact that the client has their own DNS servers. by the way, client also has another IPS at E1/1 which has an specific NAT rule mapped to service 80,443 for their web portal servcies, we also pointed the in first try the GP thru that interface mapped to service :8443, and again Global protect message: Portal Not found. any ideas how to solve this? cordially jose
... View more