Palo Alto Networks Knowledgebase: Connect button in the Option List of GlobalProtect Agent inactive after Portal IP address change

Connect button in the Option List of GlobalProtect Agent inactive after Portal IP address change

4831
Created On 02/07/19 23:50 PM - Last Updated 02/07/19 23:50 PM
GlobalProtect GlobalProtect cloud service
Resolution

Issue

 

If Global Protect VPN realized in “on-demand” mode remote GlobalProtect Agent clients will be able to connect to VPN network by doing a right click on GlobalProtect Agent icon on the Taskbar and choosing the “Connect” option from the drop down list, as shown in the following picture:

 

gpa-option1.png 

 

If remote user changes IP address of Portal field in GlobalProtect Agent, the ”Connect” option from the dropdown list will become inactive and it would not be possible to use it to connect to VPN. Instead we would need to select the option “Open” in order to open the whole GlobalProtect Agent application and navigate to Settings in order to establish a connection:

gpa-option2.png

 

 

Explanation

If Portal’s IP address in GlobalProtect Agent is changed to a new one, GlobalProtect Agent flushes the existing configuration considering it obsolete, since it was given by the old Portal.

 

This basically means that it reset the original "on-demand" mode and instead fell back to the default user-logon mode, until new configuration is downloaded. And, in user-logon mode, the "Connection" button will always be greyed out until GlobalProtect Agent connects. If the connection is established, then the "Disable" button turns active. 



Attachments
Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClQPCA0&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Attachments
Choose Language