GlobalProtect App debug_drv.log shows "Found pangpd device ROOT\PANGPD\0000, remove it now." and fails to connect GlobalProtect gateway

GlobalProtect App debug_drv.log shows "Found pangpd device ROOT\PANGPD\0000, remove it now." and fails to connect GlobalProtect gateway

6085
Created On 09/18/20 01:55 AM - Last Modified 12/02/24 20:43 PM


Symptom


  • GlobalProtect App fails to connect to GlobalProtect gateway.
  • The error "Could not connect to the GlobalProtect gateway. Please contact your IT administrator." is displayed,
  • Restart the GlobalProtect Client resolves the issue.
  • debug_drv.log shows "Found pangpd device ROOT\PANGPD\0000, remove it now." and failed to connect GlobalProtect until restart the GlobalProtect Client as shown in the Logs below.
"debug_drv.log" when the issue was seen:
[Debug  375]: Set debug level as 4
[Debug 1196]: Driver status is: 1.
[Debug  565]: Found pangpd device ROOT\PANGPD\0000, remove it now.
[Debug 1196]: Driver status is: 1.
[Debug  565]: Found pangpd device ROOT\PANGPD\0000, remove it now.
[Debug  944]: Disable adapter be called.
[Debug  375]: Set debug level as 4
[Debug 1196]: Driver status is: 1.
[Debug  565]: Found pangpd device ROOT\PANGPD\0000, remove it now.
[Debug 1196]: Driver status is: 1.
[Debug  565]: Found pangpd device ROOT\PANGPD\0000, remove it now.
[Debug  944]: Disable adapter be called.
"pan_gp_event.log" when the issue was seen:
[Info ]: GlobalProtect service started (client version: 5.2.2-4, OS version: Microsoft Windows 10 Enterprise , 64-bit).
[Info ]: Portal login completed with address mobile.aisingroup.com and conect method of user-logon.
[Info ]: Network discovery started.
[Error]: Gateway Japan Central: Could not connect to the GlobalProtect gateway. Please contact your IT administrator.
[Info ]: Network discovery started.


Environment


  • GlobalProtect App (Windows)
  • 3rd Party endpoint security software (Virus Buster corporate edition XG)
  • Management Server Version:12.0.5474 Service Pack 1
  • Client Version:12.0.5464 Service Pack 1,12.0.5474 Service Pack 1


Cause


3rd Party endpoint security software interferes to GlobalProtect.

Resolution


Configure exception of scan by 3rd Party endpoint security software against following GlobalProtect folders.

  1. "C:\Program Files\Palo Alto Networks\GlobalProtect"
  2. "C:\Program Files (x86)\Palo Alto Networks\GlobalProtect" (If 32bit GlobalProtect Installer is used)
  3. "C:\Users\<username>\AppData\Local\Palo Alto Networks\GlobalProtect"


Additional Information


"debug_drv.log" when the issue was resolved by a restart:

[Info   304]: Init get adapter instance id {580B6BAC-2820-44DA-8D9D-2D75E74E8257}.
[Info   375]: Set debug level as 4
[Info   967]: Register returns MAC 02:50:41:00:00:01.
[Info   305]: Move binding order to the top
[Debug  384]: No need to adjust binding order
[Debug  431]: Found vif, index 11
[Debug  502]: Enable IPv4 weak host send mode for interface 15
[Debug  502]: Enable IPv4 weak host send mode for interface 28
[Debug  502]: Enable IPv4 weak host send mode for interface 6
[Info   204]: Register ends.
[Debug  944]: Disable adapter be called.
[Debug  957]: Enable adapter be called.
[Debug  838]: Enable Adapter success.
[Info   147]: Adapter device started. 0x0180200b
[Info   151]: ----Driver Control is being started
[Info   336]: Driver file version is 5.0.0.24.
[Info   498]: Access driver events.
[Info   509]: Device control set driver events.
[Info   532]: Device control set debug level as 3.
[Info   369]: Load driver control parameter 0x1.
[Info   579]: Device control set control parameter as 0x1.
[Info   555]: Device control set medium status as 1.
[Debug  771]: Device control get mac 02:50:41:00:00:01, size 6.
[Debug  923]: Device control get stat ends.
[Info   393]: Driver version: 0x600, MTU: 1400, Flags: 0x3, others: 1024-0-1.
[Info   177]: Service callback table gets set.
[Debug 1020]: New SendThread priority 2.
[Info   375]: Set debug level as 4


"pan_gp_event.log" when the issue was resolved by a restart:

[Info ]: GlobalProtect service started (client version: 5.2.2-4, OS version: Microsoft Windows 10 Enterprise , 64-bit).
[Info ]: Portal login completed with address mobile.aisingroup.com and conect method of user-logon.
[Info ]: Network discovery started.
[Info ]: Auto Gateway login finished with address xxxxxxxxxxxxxxxxxxxxxxxxxxx.gw.gpcloudservice.com and user xxxxxxxxx (connect-before-logon).
[Info ]: IPSec tunnel creation finished with Gateway xxxxxxxxxxxxxxxxxxxxxxxxxxx.gw.gpcloudservice.com.
[Info ]: Completed HIP Report check with Gateway xxxxxxxxxxxxxxxxxxxxxxxxxxx.gw.gpcloudservice.com.



 



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HAlwCAG&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language