Palo Alto GlobalProtect VPN - What DoIT will need to troubleshoot client connectivity issues

If a user is having problems connecting to a Palo Alto VPN termination point using the GlobalProtect VPN client. DoIT will need the following information in order to figure out what is happening from both the client's point of view and the VPN appliance.
Things to gather from the VPN user are:

  1. The users full name, NetID and the time the problem was seen.
  2. What VPN are they connecting to.  (ie: uwmadison.vpn.wisc.edu)
  3. IP address shown in https://www.google.com/search?q=what+is+my+IP
  4. We'll also need the output from "Collect Logs".  This can be gathered using the following steps.
    1. Right-click on the GlobalProtect VPN Client icon in the system tray
    2. Click "Collect Logs"
    3. Have the log sent to the ticket owner for review.
  5. What are you default log settings? (Please don't do the following before the above is complete, it erases the existing logs and starts over)
    1. Right-click on the GlobalProtect VPN Client icon in the system tray
    2. Click "Show Panel"
    3. Click the "Troubleshooting" tab
    4. Click "Logs" radio button
    5. What is the Debug Level set to on the right-side for both of the log types "PanGP Service" and "PanGP Agent"?
    6. Please send this to the ticket owner.
  6. (Not always needed) Open up the GlobalProtect folder on your machine, IE: C:\Program Files\Palo Alto Networks\GlobalProtect
    1. Send the following files to the ticket owner, if they exist:
    2. "PanGPS.log.old"
    3. "PanGPA.log.old"
    4. "PanGPUninstaller.log"
    5. "PanGpHip.log.old"






Keywords:
Palo Alto globalprotect VPN wiscvpn hrs department ipsec troubleshoot client connectivity issues 
Doc ID:
76263
Owned by:
Scott B. in Network Services
Created:
2017-08-31
Updated:
2022-07-20
Sites:
DoIT Help Desk, Network Services, Systems & Network Control Center