Dear McAfee or community
I found an old thread from @kerrigon_isaacs but I am giving it a shot anyway putting this here too.
I am experiencing the same issue wherePAGP (Palo Alto Global Protect) spins and does not connect. I found that the culprit is McAfee ENS Threat Prevention.
Observations of this problem/issue:
This issue arises only when PAGP (Palo Alto Global Protect) has been idle for sometime. If someone turns on their device, PAGP works right away and no other issues are observed. However, if client(s) don't connect to VPN right away and wait X amount of time, then PAGP spins and never connects or prompts for authentication. Our annoying workaround to our clients has been to instruct them to reboot their device. As you can see, this is a not very productive way of doing business.
I am certain that the issue is McAfee ENS Threat Prevention because I have left it disabled for more than a week. PAGP works like a charm throughout the day and time.
Technical Details.
OS client: macOS Mojave 10.14.6
McAfee products were issue persists: McAfee ENS Treat Prevention versions 10.6.5 to 10.7
PAGP (Palo Alto Global Protect): 5.0 to 5.1.1-12
McAfee, please solve this obnoxious issue!!
Solved! Go to Solution.
AJ,
Thank you for replying and sharing this info.
I turns out that Palo Alto Global Protect (VPN client) prior 5.1.2 uses kext too. This causes issues with ENS Treat Prevention. However, Palo Alto GP VPN client 5.1.3 and above solves this issues, it won't freeze anymore.
Thank you,
Hi @SuperAdmin-mhc,
Thank you for the update 🙂
Glad to know the issue is resolved.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Hi @SuperAdmin-mhc,
Good day to you!
I would recommend you to start by switching the ENS to a kext less mode. The steps on how to perform this are available in the below document.
Does the PAGP perform the same functionality as ENS? If yes, then it may be an expected behavior as we do not recommend multiple AVs on a single machine.
https://kc.mcafee.com/corporate/index?page=content&id=KB73182
If the PAGP is not the same as ENS, then please perform the provided action plan and if the issue persists, please open an SR with the debug enabled MER logs from the machine to check further.
Thanks,
AJ
AJ,
Thank you for replying and sharing this info.
I turns out that Palo Alto Global Protect (VPN client) prior 5.1.2 uses kext too. This causes issues with ENS Treat Prevention. However, Palo Alto GP VPN client 5.1.3 and above solves this issues, it won't freeze anymore.
Thank you,
Hi @SuperAdmin-mhc,
Thank you for the update 🙂
Glad to know the issue is resolved.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA