Question

GlobalProtect VPN not working with T-Mobile


Userlevel 2
Badge

I have seen several posts about VPNs not working with T-Mobile Home Internet. What is T-Mobile's plan to address this? I contacted my corporate IT department and they said it's not their VPN. All works fine on my old ATT home internet and Verizon Hotspot (work cell). Maybe I should drop T-Mobile Home Internet and go back to ATT.


54 replies

Got my Tmobile Home Internet yesterday and having same issue, will call Tmobile to rollback the firmware for Global VPN fix. Any issues on network speed by rolling back the firmware?

No need to rollback. Update to the latest 1609 version instead.

Yes, called Tmobile and updated my firmware to .1609 and Global VPN works now.
But I do notice that my speed is reduced when connected to the Global VPN, download speed reduces by a factor 2x and upload speed reduces by a factor of 10x. So when working on my remote desktop through VPN connection it is choppy/laggy.
Hoping this is a temporary issue hate to switch back to spectrum as Tmobile is faster and cheaper.  

So anything that's a live app through the tunnel will be like that cause of the translations needed to take place it cause some packet loss in the process

By the way solved means you have a solution to the problem not that you finally figured out what the problem actually is

SOLVED! After days with my IT department and then with Global Protect in Pali Alto, here’s the bottom line. T-Mobile High speed broadband can’t handle IPv6 dynamic IPs therefore can’t communicate in internet. Global Protect can only handle IPv4.

There are no settings on T-Mobile gate way to make it just use IPv4.
Global Protect doesn’t have a fix/VON software to fix this advanced IPv6 communication 

I can access my company’s server for data files, outlook for email etc, but cannot access internet based apps like one login or any websites. Except MSN.com - explain that. Not even Google. Com.

Have to switch to my Verizon cell data hotspot to my company laptop to access internet. Then switch back to T-mobile when done with internet  

T-Mobile is using advanced technology that companies are not ready to handle, and will take them a long time to become compatible.

Since most users don’t have IOv6, there’s no rush to upgrade corporately. For example, they advise that all the scanner guns in our warehouse aren’t compatible with IPv6, so if they upgrade VPNs now, none of the equipment would work in the warehouse.

Nor are VPN providers putting resources into IPv6 compatibility.

im so annoyed that I switched to the T-Mobile high speed broadband new technology that NO ONE at T-Mobile advised this would be an issue. Even calling tech support, they had no idea what the issue would be. After my IT department figured it out I HAD TO CALL BACK T-MOBILE AND BRUNG THEM UP TO SPEED.  Am I in the twilight zone? Ridiculous 

So much for all this infrastructure across the US. If we get this new technology, then can’t connect with old technology being used by 99% of corporations, then we’re screwed until they decide to upgrade.

How can this be such a mystery in 2021. IPv6 has been in development for more than 10 years.  WHAT’s the holdup and lack of warning of the issue.

So annoyed that I switched to this with no heads up. I’m screwed now unless I switch back to my unreliable Cox cable internet that had service outages at least twice a week while I’ve been working from home.   

 

 

T this is the same problem my wife and I agree having cause her job is such in three past and using global protect which doesn't support the new thing and there's no way we're going back to Cox (suckers) as I call them. Over charging me for service they cuts out and is never the speed I pay for.   We to have Verizon phones but at our house it's LTE and with 1 bar if we're lucky.   TMobile out the box in a bag signal location was 50 mbps better then both of them.  It says that you can set up VPN  on the TMobile router I just want to know is a specific VPN does it have NAT or dual stack capabilities? I know proton VPN does

 

 

I got the router replaced to the Arcadyan one last week Thursday and did not have any issues connecting to work VPN from home so far.

When I had the Sagemcom router, I noticed that I had connectivity issues at home mostly on the day after I work from office. 

 

So today is the first day I went to work using the office connection. Will try tonight or tomorrow to connect from home. Fingers crossed 🤞. 

I spoke with a T-Mobile support person on 19-FEB-2024 who said the MTU setting needs to be 1300. This is what I did and it works for me (W10); your mileage may vary.

  1. Disconnect from GlobalProtect VPN
  2. Open Windows Control Panel
  3. Open Network and Sharing Center
  4. Click Change Adapter Settings
  5. Right-click the ethernet connection with the subheading PANGP Virtual Ethernet Adapter Secure
  6. Select Properties
  7. Click Yes
  8. Click Configure
  9. Click the Advanced tab
  10. Click MTU
  11. Change the value to 1300
  12. Click OK
  13. Close all windows
  14. Connect to GlobalProtect VPN and wait several minutes to ensure you don’t lose internet connectivity

Thats great. I tried that, but it didn't work. I first tried the 1300, did not do anything, but when I changed it to 1350 it worked for a couple of minutes. After that it didn't. No Internet when connected to LAN.

What happened to me was that at some random moments, MTU moved back to what it was, so I had to change again

When I spoke with escalated tech support, they mentioned that the issue between VPN and T mobile home Internet persists. So I need to switch to another Service provider, unfortunately. 

It was working fine until three months ago. Until then I had only one network that is 2.4 GHz. Then I changed it to a 5 GHz , that's when problem started. Ever since then, I tried multiple things. Reset router to factory settings, created 2  separate networks for 5 GHz and 2.4 GHz. 

I tried connecting to the router using a LAN cable, it worked for a few minutes, but eventually that also stopped. 

Sorry, VPN

Thats great. I tried that, but it didn't work. I first tried the 1300, did not do anything, but when I changed it to 1350 it worked for a couple of minutes. After that it didn't. No Internet when connected to LAN.

Same issue.

Just FYI, adjusting MTU as mentioned on this topic, resolved for me

Same issue.

Good grief.  My router had been working for 4 years with Global Protect and the same problem showed up suddenly last week…  Upgrading the firmware did not fix the problem.  Getting a new router and hope the problem would go away.  I’m wondering what kind of tests did Palo Alto Networks do w/ major carriers…

Well looks like two years later and this is still an issue…

 

Tried calling T-Mobile tech support and they couldn't downgrade or upgrade my firmware. So they put in a ticket to engineering. Fingers crossed. 

Good, my support guy wouldn't even do that. Then I got a survey where I said that I was dissatisfied and that my issue remains, they asked if they could get in contact, to which I said yes... But they never dis

Well looks like two years later and this is still an issue…

 

Tried calling T-Mobile tech support and they couldn't downgrade or upgrade my firmware. So they put in a ticket to engineering. Fingers crossed. 

Not sure if other people continue to have this issue, but I moved to T-mobile a couple months ago, and it has been a nightmare with Global Protect.

Just called T support, and they said they cannot do the ipv6 fix or the firmware update, which doesn’t make any sense to me. They even refused to check this thread and see the solutions that were already mentioned.

My last chance is trying to get the fix with my employer IT support making the adjustments on the MTU.

Did someone had any other solutions more recently? Or found a way to update firmware version without having to go through T-mobile support?

I was able to find a fix for my VPN. I have GlobalProtect VPN for my work. I was having trouble accessing my work network other than email and Teams. I have a router. I went in and turned on my VPN on my router, which is a no brainer. I also switched my IPv6 from disable to passthrough and my VPN works now. Has been for a while. It is a little slower but not much. Try the pass through on the IPv6 and see if it helps. It helped me. 

A fix here...hopefully I can help. I have the square 5G Home Internet Gateway. 

 

I was close to modifying the MTU size as discussed in previous posts. Spoke to Ali from T-Mobile Support and he took some time with me.

 

Any speedtest through the Global Protect client was getting .2M up and .2M down. Internal business sites for my work over the VPN performed horribly...wouldn’t even come up. Support had me logon to the 5G gateway from another device like my iPad (usually browsing to http://192.168.12.1). Go to Wi-Fi Networks, Logon...Password should be on the bottom of the gateway device. 

Split the wireless network in 5GHz and 2.4GHz. Save the configuration. Then attach to the the SSID for 5GHz. Global Protect VPN worked like a champ. 

Thanks T-Mobile Support!

 

 

I was having a similar issue with the square gateway (KVD21). While my GlobalProtect would connect and I could use RDP (though choppy) and download files from my work computer, the speed was 1/10th the speed of downloading from my Cloud storage with the VPN off.

I tried splitting the network into 5Ghz and 2.4Ghz, and selected the 5Ghz network, but no change in speed or reliability. Then out of a whim I chose the 2.4Ghz. While my overall speed slowed a little, my VPN speed was now only half of my non-VPN speed, and my RDP and work computer connection was stable and useable. Go figure. At least I have an acceptable workaround.

A fix here...hopefully I can help. I have the square 5G Home Internet Gateway. 

 

I was close to modifying the MTU size as discussed in previous posts. Spoke to Ali from T-Mobile Support and he took some time with me.

 

Any speedtest through the Global Protect client was getting .2M up and .2M down. Internal business sites for my work over the VPN performed horribly...wouldn’t even come up. Support had me logon to the 5G gateway from another device like my iPad (usually browsing to http://192.168.12.1). Go to Wi-Fi Networks, Logon...Password should be on the bottom of the gateway device. 

Split the wireless network in 5GHz and 2.4GHz. Save the configuration. Then attach to the the SSID for 5GHz. Global Protect VPN worked like a champ. 

Thanks T-Mobile Support!

 

 

I am on *338 firmware and data traffic via VPN  (via Global Protect) does not work. I tried changing MTU size to value which works with pings (and below) and still no help. Once I disconnect from VPN (used mostly for remote work), everything fine . 

I’ll be calling T Mobile support tomorrow. Not sure what to tell them.

 

How can I tell which firmware version I’m on? I looked in the TM Home Internet app under More→ Gateway Info and it says my version is 1.00.16. That doesn’t look like anything others are posting. 

@kiki25, is your MTU still lowered to 1350?

Thanks!

I had this issue in August 2021, and getting my IT department to lower the MTU to 1350 worked (I had the .0178 firmware version) for my GlobalProtect VPN.

My firm recently switched to our VPN being “always on” - i.e. we didn’t have to connect to it separately after logging in to the computer. The issues with GlobalProtect returned - so basically no internet-based application worked on my computer even though it was connected to my T-mobile wifi.

 

My T-mobile firmware automatically upgraded to firmware version 1.2103.00.0338 and there are no longer any issues with GlobalProtect :) 

Just tried changing the MTU for my Ethernet and WiFi to 1300 and it worked! Thanks for the tip! You either have to get your IT to go in and do it on your computer or if you have Admin rights on your computer like i did you can go in to the command prompt and follow the steps GlobalProtect-PlayNICE listed earlier

Try lowering you MTU value on the VPN connection. I could connect with Global Connect and use network resources, but couldnt use internet or teams video while connected. Which really sucked as some of our stuff is web based. So I was constantly connecting and un-connecting to VPN depending on what info I needed, and where it was (web or office network) After running a ping test, I had to lower my MTU to around 1340 from the default of 1500. Once I did that, I stopped losing internet connection everytime I connected to VPN, and video in Teams worked as well. I stay connected to VPN for my work day with no issues now. I noticed that even outside of VPN, the router doesnt accept the default 1500 MTU size. I lowered it to around 1460 I believe. Not a lot, but it stopped the bottleneck at the router. I have the latest firmware for comparison.

for Windows, go to a command prompt and type this in

ping www.yahoo.com -f -l 1500

If it comes back saying fragmented, run it again dropping it to 1400. Keep dropping it until the ping successfully completes. Then move the value back up by 10 until it fragments again. Then back it down by 1 or 5 until it completes again. Once you find it, that is the optimum MTU value your router will successfully pass while running VPN. Anything larger, and you will get a packet bottleneck at the router, degrading some of your services like internet etc.

look up how to change the MTU value on the network interface once you find it. Make sure you run the test WHILE VPN is connected, as that interface is only running while connected to VPN.

Badge

Got my Tmobile Home Internet yesterday and having same issue, will call Tmobile to rollback the firmware for Global VPN fix. Any issues on network speed by rolling back the firmware?

No need to rollback. Update to the latest 1609 version instead.

Yes, called Tmobile and updated my firmware to .1609 and Global VPN works now.
But I do notice that my speed is reduced when connected to the Global VPN, download speed reduces by a factor 2x and upload speed reduces by a factor of 10x. So when working on my remote desktop through VPN connection it is choppy/laggy.
Hoping this is a temporary issue hate to switch back to spectrum as Tmobile is faster and cheaper.  

Most VPNs adds overhead to the internet connection that usually slows down your internet speed throughput. Maybe ask your work if they can enable split-tunneling for their VPN? That might help with the internet speed throughput reduction with VPN.

Got my Tmobile Home Internet yesterday and having same issue, will call Tmobile to rollback the firmware for Global VPN fix. Any issues on network speed by rolling back the firmware?

No need to rollback. Update to the latest 1609 version instead.

Yes, called Tmobile and updated my firmware to .1609 and Global VPN works now.
But I do notice that my speed is reduced when connected to the Global VPN, download speed reduces by a factor 2x and upload speed reduces by a factor of 10x. So when working on my remote desktop through VPN connection it is choppy/laggy.
Hoping this is a temporary issue hate to switch back to spectrum as Tmobile is faster and cheaper.  

Reply