GlobalProtect connection fails with the error "Access to the network from this device has been restricted per your organizations security policy" for multiple users

GlobalProtect connection fails with the error "Access to the network from this device has been restricted per your organizations security policy" for multiple users

5967
Created On 01/31/22 15:50 PM - Last Modified 06/13/25 20:20 PM


Symptom


  • GlobalProtect users are getting the error "Access to the network from this device has been restricted per your organization's security policy. Please contact your IT Administrator"
    User-added image
  • This is due to the option "Block login for quarantine device" enabled on the gateway.
     GUI: Network < GlobalProtect < Gateway < [gateway-name]  < Authentication
    User-added image


Environment


  • PAN-OS 10.0 and above
  • GlobalProtect Gateway
  • GlobalProtect App


Cause


The device is quarantined either manually or automatically.



Resolution


Remove the device from the quarantine list using following methods:

  1. From the CLI

admin@PA-VM-II(active)> request device-quarantine-list delete host <enter the host id>
Device is deleted from quarantine list

  1. From the Web-GUI

GUI: Device > Device quarantine  => Remove the device from the GUI.



Additional Information


  • The following log is generated when the device is added to the quarantine list.


User-added image

  • Quarantine list can be seen from the GUI under Device > Device Quarantine. It can also be seen under CLI command "request device-quarantine-list show all"


User-added image

  • If the device is in quarantine and the gateway connection gets disconnected, a similar log entry can be expected. 

 

User-added image

  • Similarly a log entry can be observed in the gateway firewall after removal.


User-added image



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004N2dCAE&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language