GlobalProtect App debug_drv.log shows "Found pangpd device ROOT\PANGPD\0000, remove it now." and fails to connect GlobalProtect gateway
6085
Created On 09/18/20 01:55 AM - Last Modified 12/02/24 20:43 PM
Symptom
- GlobalProtect App fails to connect to GlobalProtect gateway.
- The error "Could not connect to the GlobalProtect gateway. Please contact your IT administrator." is displayed,
- Restart the GlobalProtect Client resolves the issue.
- debug_drv.log shows "Found pangpd device ROOT\PANGPD\0000, remove it now." and failed to connect GlobalProtect until restart the GlobalProtect Client as shown in the Logs below.
"debug_drv.log" when the issue was seen:
[Debug 375]: Set debug level as 4
[Debug 1196]: Driver status is: 1.
[Debug 565]: Found pangpd device ROOT\PANGPD\0000, remove it now.
[Debug 1196]: Driver status is: 1.
[Debug 565]: Found pangpd device ROOT\PANGPD\0000, remove it now.
[Debug 944]: Disable adapter be called.
[Debug 375]: Set debug level as 4
[Debug 1196]: Driver status is: 1.
[Debug 565]: Found pangpd device ROOT\PANGPD\0000, remove it now.
[Debug 1196]: Driver status is: 1.
[Debug 565]: Found pangpd device ROOT\PANGPD\0000, remove it now.
[Debug 944]: Disable adapter be called.
"pan_gp_event.log" when the issue was seen:
[Info ]: GlobalProtect service started (client version: 5.2.2-4, OS version: Microsoft Windows 10 Enterprise , 64-bit).
[Info ]: Portal login completed with address mobile.aisingroup.com and conect method of user-logon.
[Info ]: Network discovery started.
[Error]: Gateway Japan Central: Could not connect to the GlobalProtect gateway. Please contact your IT administrator.
[Info ]: Network discovery started.Environment
- GlobalProtect App (Windows)
- 3rd Party endpoint security software (Virus Buster corporate edition XG)
- Management Server Version:12.0.5474 Service Pack 1
- Client Version:12.0.5464 Service Pack 1,12.0.5474 Service Pack 1
Cause
3rd Party endpoint security software interferes to GlobalProtect.
Resolution
Configure exception of scan by 3rd Party endpoint security software against following GlobalProtect folders.
- "C:\Program Files\Palo Alto Networks\GlobalProtect"
- "C:\Program Files (x86)\Palo Alto Networks\GlobalProtect" (If 32bit GlobalProtect Installer is used)
- "C:\Users\<username>\AppData\Local\Palo Alto Networks\GlobalProtect"
Additional Information
"debug_drv.log" when the issue was resolved by a restart:
[Info 304]: Init get adapter instance id {580B6BAC-2820-44DA-8D9D-2D75E74E8257}.
[Info 375]: Set debug level as 4
[Info 967]: Register returns MAC 02:50:41:00:00:01.
[Info 305]: Move binding order to the top
[Debug 384]: No need to adjust binding order
[Debug 431]: Found vif, index 11
[Debug 502]: Enable IPv4 weak host send mode for interface 15
[Debug 502]: Enable IPv4 weak host send mode for interface 28
[Debug 502]: Enable IPv4 weak host send mode for interface 6
[Info 204]: Register ends.
[Debug 944]: Disable adapter be called.
[Debug 957]: Enable adapter be called.
[Debug 838]: Enable Adapter success.
[Info 147]: Adapter device started. 0x0180200b
[Info 151]: ----Driver Control is being started
[Info 336]: Driver file version is 5.0.0.24.
[Info 498]: Access driver events.
[Info 509]: Device control set driver events.
[Info 532]: Device control set debug level as 3.
[Info 369]: Load driver control parameter 0x1.
[Info 579]: Device control set control parameter as 0x1.
[Info 555]: Device control set medium status as 1.
[Debug 771]: Device control get mac 02:50:41:00:00:01, size 6.
[Debug 923]: Device control get stat ends.
[Info 393]: Driver version: 0x600, MTU: 1400, Flags: 0x3, others: 1024-0-1.
[Info 177]: Service callback table gets set.
[Debug 1020]: New SendThread priority 2.
[Info 375]: Set debug level as 4
"pan_gp_event.log" when the issue was resolved by a restart:
[Info ]: GlobalProtect service started (client version: 5.2.2-4, OS version: Microsoft Windows 10 Enterprise , 64-bit).
[Info ]: Portal login completed with address mobile.aisingroup.com and conect method of user-logon.
[Info ]: Network discovery started.
[Info ]: Auto Gateway login finished with address xxxxxxxxxxxxxxxxxxxxxxxxxxx.gw.gpcloudservice.com and user xxxxxxxxx (connect-before-logon).
[Info ]: IPSec tunnel creation finished with Gateway xxxxxxxxxxxxxxxxxxxxxxxxxxx.gw.gpcloudservice.com.
[Info ]: Completed HIP Report check with Gateway xxxxxxxxxxxxxxxxxxxxxxxxxxx.gw.gpcloudservice.com.