GlobalProtect VPN Self-Service & Troubleshooting Guide

This guide provides self-service troubleshooting steps to help you resolve common GlobalProtect VPN connection, authentication, and configuration issues on both Windows and macOS.

 


What You Need

Before starting, ensure you have the following:

 

  • Your University NetID and password.

  • A stable home or public internet connection.

  • The GlobalProtect client installed on your device.

  • Basic familiarity with your computer's System Settings (macOS) or Control Panel (Windows).


General Connectivity & Quick Checks

  • Verify Internet Stability: Confirm you have a stable internet connection before launching the VPN. Tunnels can amplify network instability. Run a quick internet speed test to check bandwidth.

  • Check if VPN is Necessary: Most standard Brandeis apps (Gmail, Google Drive, Workday, and standard Brandeis Login services) do not require a VPN. VPN is mainly required for departmental file shares (files.brandeis.edu), library databases, and protected internal web pages.

  • Wired vs. Wireless: If experiencing frequent Wi-Fi drops, switch to a wired Ethernet connection. If using Wi-Fi, restart your computer and reconnect to your network before launching GlobalProtect.


Installation & Managed Devices

Managed Macs (Jamf)

  • Do not download the installer from the web.

  • Open the Self Service app and click Reinstall on GlobalProtect to re-run the policy.

  • System Extension Approval: If macOS blocks the software, go to System Settings > Privacy & Security and click Allow near the "Palo Alto Networks" alert.

Personal Devices (BYOD)


Authentication & Duo MFA Issues

  • Username Format: Enter only your NetID username (e.g., louisbrandeis), not your full email address.

  • Stuck or Blank SSO Screen: In GlobalProtect, click the menu icon, go to Settings > Troubleshooting, and select Clear Browser Cache.

  • Duo Push Loop / Clock Sync: If Duo pushes are approved but the VPN still fails, ensure your device's Date & Time settings are set to Set Automatically.

  • Duo Passcode Method (Offline): If a Duo push doesn't arrive, append a passcode to your password field using the format: YourPassword,123456 (where 123456 is the passcode generated in your Duo app).

  • Account Lockout: If locked out after multiple failed attempts, check your account status at identity.brandeis.edu.


Session Limits & Resource Access

  • Session Timeouts:

     
    • Undergraduates: 6-hour limit.

    • Faculty, Staff, & Graduate Students: 10-hour limit.

    • Daily Reset: A 24-hour global session limit applies to all users, requiring a daily re-authentication.

  • Access Denied to File Shares: Ensure you are using the Fully Qualified Domain Name (e.g., files.brandeis.edu rather than just files).


Operating System Specific Troubleshooting

Basic Steps

  1. Restart your computer.

  2. Verify that your portal address in GlobalProtect settings is set to vpn-connect.brandeis.edu.

  3. Ensure no secondary personal VPNs (e.g., NordVPN, ExpressVPN) are running concurrently.

  4. Disable IPv6 on your active connection (see steps below).


Disabling IPv6

Windows

  1. Open Settings > Network & internet.

  2. Click Advanced network settings > More network adapter options.

  3. Right-click your active adapter (Wi-Fi or Ethernet) and select Properties.

  4. Uncheck Internet Protocol Version 6 (TCP/IPv6).

  5. Click OK and restart your PC.

macOS

  1. Open System Settings > Network.

  2. Select your active network (Wi-Fi or Ethernet) and click Details / Advanced.

  3. Navigate to the TCP/IP tab.

  4. Set Configure IPv6 to Link-local only.

  5. Click OK / Apply and restart your Mac.


Troubleshooting Common Errors

Issue / Error Message Cause / Solution
"VPN connection could not be established"

Restart your device and attempt to sign in again.

"The virtual adapter was not set up correctly"

System timing issue; wait one minute or restart your computer.

Stuck on "Connecting"

Check if your current Wi-Fi network blocks VPNs (e.g., hotel/flight Wi-Fi) or try a mobile hotspot.

iCloud Private Relay Conflict (Mac)

Go to System Settings > Network > [Your Network] and toggle off Limit IP address tracking.

No Duo Prompt

Verify portal address is vpn-connect.brandeis.edu, then select Refresh Connection from the GlobalProtect menu.


If issues persist after following these steps, please contact the ITS Help Desk for further assistance.