GlobalProtect Troubleshooting

Use these checks when users cannot connect, authenticate, receive an IP address, or pass traffic after connecting.

Gateway and portal status

show global-protect-gateway current-user
show global-protect-gateway current-user user <username>
show global-protect-portal current-user

Logs to review

In the GUI, check:

  • Monitor > System for authentication, portal, and gateway events.
  • Monitor > Traffic for connected-user traffic.
  • Monitor > GlobalProtect where available.

Common checks

  • Portal and gateway certificates are valid.
  • Authentication profile and group mapping are working.
  • Client IP pool has free addresses.
  • Security policy allows traffic from the GlobalProtect zone.
  • Routes and split tunnel settings include the expected prefixes.