GlobalProtect app is not connecting to internal gateway after enabling internal wired connection whilst external wireless connection is still up

GlobalProtect app is not connecting to internal gateway after enabling internal wired connection whilst external wireless connection is still up

22186
Created On 04/21/22 21:20 PM - Last Modified 01/24/24 03:45 AM


Symptom


GlobalProtect app is not connecting to internal gateway after enabling internal wired connection whilst the external wireless connection is still up.
 


Environment


  • GlobalProtect (GP) App
  • Supported App versions


Cause


When an existing GlobalProtect connection is not disrupted, the GP connection will stay up even when another network connection is added.

Example:
  • "en16: 172.21.20.26" assigned by internal wired network
  • "en0: 192.168.20.106" assigned by external wireless network
  • GlobalProtect virtual interface "192.168.135.122"
  • The connection to gateway "gpvpn.panw.com" was established using the external wireless IP address 192.168.20.106 as seen in the globalprotect logs.
P1052-T13831 03/09/2022 14:10:59:929 Debug(2984): Gateway: gpvpn.panw.com, client IP: 192.168.20.106
  • At 14:26, the internal wired interface was enabled. The logs below demonstrate that the external wireless connection was still up and not affected by the wired connection. Thus the existing GP connection was not disrupted.
P1052-T19207 03/09/2022 14:26:31:166 Debug(1430): Route change message RTM_NEWADDR: address being added to iface en16: 172.21.20.26
P1052-T18439 03/09/2022 14:26:31:454 Debug(6657): NetworkConnectionMonitorThread: m_state = 0, m_bOnDemand=0, m_bAgentEnabled=1, m_bJustResumed is 0,
 m_bHibernate is 0, m_bAgentEnabled is 1, m_bDisconnect is 0, IsConnected() is 1, IsVPNInRetry() is 0.
P1052-T18439 03/09/2022 14:26:31:454 Debug( 203): interface en0 ip 192.168.20.106/255.255.255.0
P1052-T18439 03/09/2022 14:26:31:459 Debug(6692): NetworkConnectionMonitorThread: Detected route change, but skip network discovery.
P1052-T18439 03/09/2022 14:26:31:459 Debug(6596): NetworkConnectionMonitorThread: route change detected. Wait for 3 seconds.
P1052-T18439 03/09/2022 14:26:31:459 Debug( 203): interface en0 ip 192.168.20.106/255.255.255.0


Resolution


  1. Turn off the external wireless connection automatically (OS setting) or manually after enabling internal wired connection to trigger a flap in the network causing a network discovery.
  2. Perform "Refresh Connection" through GlobalProtect app to trigger a new network discovery.


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004OELCA2&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language