Log Collection for Split Tunneling Issues on Windows Clients

Log Collection for Split Tunneling Issues on Windows Clients

26963
Created On 07/27/21 23:49 PM - Last Modified 07/10/26 00:53 AM


Objective


This article provides the steps to collect the necessary data to troubleshoot split tunneling issues on Windows GlobalProtect clients.

Environment


  • PAN-OS 8.1 and above
  • GlobalProtect App 5.1.8 and above
  • Windows clients


Procedure


  1. Download and install DebugView on your Windows client. Run DebugView as Administrator and go to Capture, enable Capture Kernel, Enable Verbose Kernel Output, Pass-Through and Capture Events. Output can be logged to a file by selecting File > Log to File or save it to a text file later. 
https://docs.microsoft.com/en-us/sysinternals/downloads/debugview
 
  1. Set the GlobalProtect App logging level to Dump. (Settings -> Troubleshooting -> Logging Level)
  2. Set up packet capture on both the Internet / External interface and PanGP virtual interface simultaneously. In Wireshark, use Capture > Options and select both the interfaces.
NOTE: Use the ipconfig/all command output to select the correct interfaces in Wireshark. For example, PanGP virtual interface can be Ethernet2 and external interface can be WiFi or Ethernet. It varies from PC to PC and depending on the type of interface used. 
 
  1. From command prompt, issue the command ipconfig/flushdns to flush the DNS cache. This will help capture the DNS queries better in the pcap for domain based split tunneling. 
  2. Capture wfp logs :
    Open command prompt as Administrator. Enable WFP packet capture using command “netsh.exe wfp capture start”.

  3. Generate the intended traffic. If testing domain based split tunneling, use private browsing or incognito mode in case the browser caches any DNS queries. 
  4. Once the test is completed, save the DebugView output, GlobalProtect dump level logs and packet capture. 
  5. Stop WFP packet capture from cmd using command “netsh.exe wfp capture stop”. The wfpdiag.cab log file will be saved in the same directory where command was ran.
  6. Collect a screenshot of the Details tab of the following system file. Right click > Properties > Details
C:\WINDOWS\system32\DRIVERS\gpfltdrv.sys
 
  1. Upload the following to the TAC support case:
  • DebugView log
  • GlobalProtect dump level log
  • Wireshark capture
  • wfpdiag.cab log file
  • Screenshot of the gpfltdrv.sys file
  • For checking the third party softeware , check the ProcessInfo.txt on gp logs , Or run the following command for on windows device to get all the services running on Global Protect : sc query state= all > C:\Temp\services.txt


Additional Information


Log Collection for macOS Split Tunneling Issues



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000oMMiCAM&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language