USB devices disconnected after connecting to Global Protect
14224
Created On 01/23/20 17:42 PM - Last Modified 10/07/20 23:55 PM
Symptom
The client has all of its USB devices disconnected/removed from the system after the Global Protect tunnel is established.
Environment
- PA-3020
- PANOS 8.1.11
- Global Protect agent 5.0.5
Cause
From Global protect agent logs we see the device is removed: "DBT_DEVICEREMOVECOMPLETE, device"
(T13928) 12/02/19 16:00:21:168 Debug( 371): Receive gps message with type status. (T13928) 12/02/19 16:00:21:168 Debug(1216): ===> response sent to GPI = <response><type>status</type><state>Connected </state><error></error><disabled>no</disabled></response> (T13928) 12/02/19 16:00:21:181 Debug(2130): pangps status is Connected. (T13928) 12/02/19 16:00:21:181 Debug( 403): Portal is connected. (T13928) 12/02/19 16:00:21:181 Debug( 568): CPanBaseConfigMgr::AddPortal - portal domain.domain.com is already in list. (T13928) 12/02/19 16:00:21:181 Debug( 568): CPanBaseConfigMgr::AddPortal - portal domain.domain.com is already in list. (T13928) 12/02/19 16:00:21:182 Debug(2599): receive resize message from 1, and new height is 243. (T13928) 12/02/19 16:00:22:772 Debug( 766): CAC, type is 0007, data=0000000000000000 (T13928) 12/02/19 16:00:22:773 Debug( 766): CAC, type is 0007, data=0000000000000000 (T13928) 12/02/19 16:00:22:987 Debug( 766): CAC, type is 8004, data=0000001ECB0FF8D0 (T13928) 12/02/19 16:00:22:987 Debug( 810): CAC, DBT_DEVICEREMOVECOMPLETE, device type=00000005, cacUnplugLogout=0 (T13928) 12/02/19 16:00:22:987 Debug( 851): CAC, do nothing for device remove message (T13928) 12/02/19 16:00:23:412 Debug( 766): CAC, type is 8000, data=0000001ECB0FF8D0 (T13928) 12/02/19 16:00:23:413 Debug( 692): CAC, name is USB
Resolution
- From Firewall, click on GUI: Network> Portal > Agent > Select the agent configs > App
- There is a feature called: Retain connection on smart card Removal (windows only)
- The default is selected to "Yes"
- Change the feature: Retain connection on smart card Removal (windows only) to "No"
- Commit the changes.