USB devices disconnected after connecting to Global Protect

USB devices disconnected after connecting to Global Protect

9826
Created On 01/23/20 17:42 PM - Last Modified 10/07/20 23:55 PM


Symptom


The client has all of its USB devices disconnected/removed from the system after the Global Protect tunnel is established.

Environment


  • PA-3020
  • PANOS 8.1.11
  • Global Protect agent 5.0.5


Cause


From Global protect agent logs we see the device is removed: "DBT_DEVICEREMOVECOMPLETE, device"
(T13928) 12/02/19 16:00:21:168 Debug( 371): Receive gps message with type status.
(T13928) 12/02/19 16:00:21:168 Debug(1216): ===> response sent to GPI = <response><type>status</type><state>Connected
 </state><error></error><disabled>no</disabled></response>
(T13928) 12/02/19 16:00:21:181 Debug(2130): pangps status is Connected.
(T13928) 12/02/19 16:00:21:181 Debug( 403): Portal is connected.
(T13928) 12/02/19 16:00:21:181 Debug( 568): CPanBaseConfigMgr::AddPortal - portal domain.domain.com is already in list.
(T13928) 12/02/19 16:00:21:181 Debug( 568): CPanBaseConfigMgr::AddPortal - portal domain.domain.com is already in list.
(T13928) 12/02/19 16:00:21:182 Debug(2599): receive resize message from 1, and new height is 243.
(T13928) 12/02/19 16:00:22:772 Debug( 766): CAC, type is 0007, data=0000000000000000
(T13928) 12/02/19 16:00:22:773 Debug( 766): CAC, type is 0007, data=0000000000000000
(T13928) 12/02/19 16:00:22:987 Debug( 766): CAC, type is 8004, data=0000001ECB0FF8D0
(T13928) 12/02/19 16:00:22:987 Debug( 810): CAC, DBT_DEVICEREMOVECOMPLETE, device type=00000005, cacUnplugLogout=0
(T13928) 12/02/19 16:00:22:987 Debug( 851): CAC, do nothing for device remove message
(T13928) 12/02/19 16:00:23:412 Debug( 766): CAC, type is 8000, data=0000001ECB0FF8D0
(T13928) 12/02/19 16:00:23:413 Debug( 692): CAC, name is USB


 


Resolution


  1. From Firewall, click on GUI: Network> Portal > Agent > Select the agent configs > App
  • There is a feature called: Retain connection on smart card Removal (windows only)
  • The default is selected to "Yes"
  1. Change the feature: Retain connection on smart card Removal (windows only) to "No"
  2. Commit the changes.


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PONMCA4&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language