Advertisement
Guest User

Untitled

a guest
Apr 18th, 2016
1,926
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 34.47 KB | None | 0 0
  1.  
  2. (T5696) 04/18/16 16:36:50:407 Debug( 319): PanGpHipMp.exe exit for checking misssing patches.
  3. (T5696) 04/18/16 16:36:50:407 Debug( 386): CheckHipMissingPatchInOtherProcess(): exits.
  4. (T5696) 04/18/16 16:36:50:407 Debug( 467): Hip missing patch checking duration is 18
  5. (T5696) 04/18/16 16:37:26:407 Debug( 432): HipMissingPatchThread: now is 1460990246, last hip check is 1460990192, hip check interval is 3600000
  6. (T5696) 04/18/16 16:37:26:407 Debug( 437): HipMissingPatchThread: wait 3510000 ms
  7. T1992) 04/18/16 16:37:42:829 Info ( 412): msgtype = portal
  8. (T1992) 04/18/16 16:37:42:829 Debug(1147): ServerThread: ProcessServerPortal
  9. (T1992) 04/18/16 16:37:42:829 Debug(1149): Reset portal user auth cookie.
  10. (T1992) 04/18/16 16:37:42:829 Debug(1197): checkupdate tag exists with value no
  11. (T1992) 04/18/16 16:37:42:829 Debug(1201): bCheckUpdate is false.
  12. )(T1992) 04/18/16 16:37:42:829 Debug(1212): portal-certificate-verification tag exists with value yes
  13. (T1992) 04/18/16 16:37:42:829 Debug(1221): m_bVerifyPortalCertificate and m_bAdditionalCheck are true.
  14. )(T1992) 04/18/16 16:37:42:829 Debug(1231): allow-cached-portal tag exists with value yes
  15. (T1992) 04/18/16 16:37:42:829 Debug(1235): bAllowCachedPortal is true.
  16. )(T1992) 04/18/16 16:37:42:829 Debug(1241): Reset network discover ready event.
  17. (T1992) 04/18/16 16:37:42:829 Debug(1261): This portal message is not from prelogon thread
  18. (T1992) 04/18/16 16:37:42:829 Debug(1264): Clear lastErrStr
  19. (T1992) 04/18/16 16:37:42:829 Debug(1267): m_szNewWinUser is admin.peter.kienzer, m_szWinUser is
  20. (T1992) 04/18/16 16:37:42:829 Debug(1268): m_bPreviousSwitchOffMsg is 0
  21. (T1992) 04/18/16 16:37:42:829 Debug(3315): StopThreads():
  22. (T1992) 04/18/16 16:37:42:829 Debug( 685): Logging out gateway, reason is StopThreads
  23. (T1992) 04/18/16 16:37:42:829 Debug( 715): Logging out gateway over
  24. (T1608) 04/18/16 16:37:42:829 Debug(2439): NetworkDiscoverThread: got exit event.
  25. (T1608) 04/18/16 16:37:42:829 Debug(2704): NetworkDiscoverThread: quits.
  26. (T3692) 04/18/16 16:37:42:829 Debug(3086): NetworkConnectionMonitorThread: got exit event.
  27. (T3692) 04/18/16 16:37:42:829 Debug(3098): NetworkConnectionMonitorThread: quits.
  28. (T3352) 04/18/16 16:37:42:829 Debug(2813): HipReportThread: got exit event.
  29. (T3352) 04/18/16 16:37:42:829 Debug(2971): HipReportThread: HipReportThread quits (pos 2).
  30. (T1992) 04/18/16 16:37:42:929 Debug(3330): threads are gracefully stopped.
  31. (T5128) 04/18/16 16:37:42:929 Debug( 226): HipCheckThread: got thread exist event.
  32. (T2788) 04/18/16 16:37:42:929 Debug( 403): HipMonitor gets quit event.
  33. (T2788) 04/18/16 16:37:42:929 Debug( 420): Unregister -- WscUnRegisterChanges
  34. (T5696) 04/18/16 16:37:42:930 Debug( 446): HipMissingPatchThread: Hip check missiing patch thread quits.
  35. (T5128) 04/18/16 16:37:42:931 Debug( 282): HipCheckThread: Hip check thread quits.
  36. (T2788) 04/18/16 16:37:42:932 Debug( 729): HipMonitorThread quits.
  37. (T1992) 04/18/16 16:37:42:932 Info ( 135): All hip collect threads quit gracefully.
  38. (T1992) 04/18/16 16:37:42:932 Debug(3277): StartThreads():
  39. (T1992) 04/18/16 16:37:42:932 Debug(3282): start a network discover thread
  40. (T1992) 04/18/16 16:37:42:932 Debug( 23): Thread 4684 has been created.
  41. (T1992) 04/18/16 16:37:42:932 Info ( 26): create thread 0000000000000490
  42. (T1992) 04/18/16 16:37:42:932 Debug(3290): start a HIP report thread
  43. (T1992) 04/18/16 16:37:42:932 Debug( 23): Thread 4948 has been created.
  44. (T1992) 04/18/16 16:37:42:932 Info ( 26): create thread 0000000000000494
  45. (T1992) 04/18/16 16:37:42:932 Debug(3298): start a network conenction monitor thread
  46. (T4948) 04/18/16 16:37:42:932 Debug(2761): HipReportThread: HipReportThread starts up.
  47. (T4948) 04/18/16 16:37:42:932 Debug(2783): HipReportThread: wait for HIP report ready event.
  48. (T4684) 04/18/16 16:37:42:932 Debug(2407): NetworkDiscoverThread: network discover thread starts.
  49. (T4684) 04/18/16 16:37:42:932 Debug(2429): NetworkDiscoverThread: wait for network discover event.
  50. (T1992) 04/18/16 16:37:42:932 Debug( 23): Thread 5740 has been created.
  51. (T1992) 04/18/16 16:37:42:932 Info ( 26): create thread 000000000000030C
  52. (T1992) 04/18/16 16:37:42:932 Debug( 87): start a HIP check thread
  53. (T5740) 04/18/16 16:37:42:932 Debug(2979): NetworkConnectionMonitorThread: network connection monitor thread starts.
  54. (T1992) 04/18/16 16:37:42:932 Debug( 23): Thread 5064 has been created.
  55. (T1992) 04/18/16 16:37:42:932 Info ( 26): create thread 0000000000000468
  56. (T1992) 04/18/16 16:37:42:932 Debug( 96): start a HIP missing patch thread
  57. (T5064) 04/18/16 16:37:42:932 Info ( 170): Start CPanHipCollect::HipCheckThread
  58. (T5064) 04/18/16 16:37:42:932 Debug( 213): HipCheckThread started...
  59. (T5064) 04/18/16 16:37:42:932 Debug( 219): HipCheckThread: wait for hip check event for 3600000 ms);
  60. (T1992) 04/18/16 16:37:42:932 Debug( 23): Thread 5708 has been created.
  61. (T1992) 04/18/16 16:37:42:932 Info ( 26): create thread 0000000000000294
  62. (T1992) 04/18/16 16:37:42:932 Debug( 105): start a HIP monitor thread
  63. (T5708) 04/18/16 16:37:42:932 Info ( 179): Start CPanHipCollect::HipMissingPatchThread
  64. (T5708) 04/18/16 16:37:42:932 Debug( 397): HipMissingPatchThread started...
  65. (T1992) 04/18/16 16:37:42:932 Debug( 23): Thread 2628 has been created.
  66. (T1992) 04/18/16 16:37:42:932 Info ( 26): create thread 00000000000002D8
  67. (T1992) 04/18/16 16:37:42:932 Debug(1314): User logon domain is MAXIM-IC
  68. (T1992) 04/18/16 16:37:42:932 Debug( 217): pid of PanGPA is 5024, m_dwPanGpAgentPid is 5024
  69. (T1992) 04/18/16 16:37:42:932 Debug(1335): gets user name Peter.Kienzer.
  70. (T1992) 04/18/16 16:37:42:932 Debug(1513): empty domain name.
  71. (T1992) 04/18/16 16:37:42:932 Info (1591): Received manual select gateway portal message
  72. (T1992) 04/18/16 16:37:42:932 Debug(3399): Set state to Retrieving configuration...
  73. (T2628) 04/18/16 16:37:42:932 Info ( 189): Start CPanHipCollect::HipMonitorThread
  74. (T2628) 04/18/16 16:37:42:932 Info ( 725): HipMonitorThread starts
  75. (T2628) 04/18/16 16:37:42:932 Debug( 382): Wscapi.dll is loaded.
  76. (T2628) 04/18/16 16:37:42:932 Debug( 396): Register -- WscRegisterForChanges
  77. (T1992) 04/18/16 16:37:42:932 Debug(3602): ServerThread: ProcessServerPortal -- GetConfigFromPortal
  78. (T1992) 04/18/16 16:37:42:932 Debug(3942): entering.
  79. (T1992) 04/18/16 16:37:42:932 Debug(1284): Proxy auto detect is not needed
  80. (T1992) 04/18/16 16:37:42:932 Debug(3977): SSO enable status is 0, user name is Peter.Kienzer, domain name is .
  81. (T1992) 04/18/16 16:37:42:932 Debug(3980): reset user authentication status to true.
  82. (T1992) 04/18/16 16:37:42:932 Debug(1568): open http session.
  83. (T1992) 04/18/16 16:37:42:932 Debug( 355): set WINHTTP_OPTION_SECURE_PROTOCOLS
  84. (T1992) 04/18/16 16:37:42:932 Debug(1304): Auto detect proxy for host one.maximintegrated.com
  85. (T1992) 04/18/16 16:37:42:932 Debug(1317): CPanMSServiceWin::SetProxyForHost: fAutoDetect: 0 url: proxy: bypass:
  86. url:https://one.maximintegrated.com/ returned proxystr:
  87. (T1992) 04/18/16 16:37:42:932 Debug(1342): m_proxyInfo.dwAccessType is 0, m_proxyInfo.lpszProxy is (null)
  88. (T1992) 04/18/16 16:37:42:933 Debug(3437): Pre-login...,verifyportalcert=yes
  89. (T1992) 04/18/16 16:37:42:933 Debug( 64): pan_get_full_path(): full path in multibyte char is C:\Program Files\Palo Alto Networks\GlobalProtect\tca.cer
  90. (T2628) 04/18/16 16:37:42:933 Info ( 398): HipMonitorThread wait for exit event.
  91. (T2628) 04/18/16 16:37:42:933 Debug( 400): before WaitForMultipleObjects
  92. (T1992) 04/18/16 16:37:42:933 Debug(1214): File C:\Program Files\Palo Alto Networks\GlobalProtect\tca.cer exists. File is tca.cer
  93. (T1992) 04/18/16 16:37:42:933 Debug( 363): set trusted root ca file C:\Program Files\Palo Alto Networks\GlobalProtect\tca.cer
  94. (T5708) 04/18/16 16:37:42:934 Debug( 336): Active session id is 1
  95. (T1992) 04/18/16 16:37:42:935 Debug( 42): WSAGetLastError() returns 10035
  96. (T5708) 04/18/16 16:37:42:935 Debug( 260): Found PanGPA pid 5024
  97. (T5708) 04/18/16 16:37:42:935 Debug( 264): Found active PanGPA pid is 5024
  98. (T5708) 04/18/16 16:37:42:935 Debug( 55): Session id is 1 for pid 5024
  99. (T5708) 04/18/16 16:37:42:935 Debug( 95): User profile directory is C:\Users\Admin.Peter.Kienzer
  100. (T5708) 04/18/16 16:37:42:935 Debug( 110): Found session 1
  101. (T1992) 04/18/16 16:37:43:442 Debug(5723): CheckServerCert(): Sever certificate has been verified with trusted root ca.
  102. (T1992) 04/18/16 16:37:43:442 Debug(5732): CheckServerCert() returns TRUE
  103. (T1992) 04/18/16 16:37:43:442 Debug(2018): portal proxyparam is empty
  104. (T1992) 04/18/16 16:37:43:442 Debug(2069): IPADDR=one.maximintegrated.com,PORT=443,URL=/global-protect/prelogin.esp,POST=1,PROXY_AUTO=0,PROXY_CFGURL=NULL,PROXY=NULL,PROXY_BYPASS=NULL,PROXY_USER=NULL,PROXY_PASS=****,VERIFY_CERT=0,ADDITIONAL_CHECK=1
  105. (T1992) 04/18/16 16:37:43:442 Debug( 805): Send response to client for request https_request
  106. (T1992) 04/18/16 16:37:43:442 Debug(2095): gpapintimeout not set, set it to 600 seconds
  107. (T1992) 04/18/16 16:37:43:544 Debug(2163): receive pan_msg_ping, 3
  108. (T1992) 04/18/16 16:37:43:950 Debug(2163): receive pan_msg_ping, 3
  109. (T5708) 04/18/16 16:37:45:186 Error( 135): NetUserGetInfo is unknown error
  110. (T5708) 04/18/16 16:37:45:186 Debug( 148): info4_buf is NULL
  111. (T5708) 04/18/16 16:37:45:186 Debug( 150): profileInfo username admin.peter.kienzer, profile path (null), server (null)
  112. (T5708) 04/18/16 16:37:45:203 Debug( 164): User profile loaded.
  113. (T5708) 04/18/16 16:37:45:203 Debug( 180): Impersonated logged on user.
  114. (T5708) 04/18/16 16:37:45:203 Debug( 182): Profile type is 0
  115. (T5708) 04/18/16 16:37:45:203 Debug( 225): User profile unloaded
  116. (T5708) 04/18/16 16:37:45:203 Debug( 64): pan_get_full_path(): full path in multibyte char is C:\Windows\system32\config\systemprofile\AppData\Local\Palo Alto Networks\GlobalProtect\PanGpMPR.dat
  117. (T5708) 04/18/16 16:37:45:203 Debug( 432): HipMissingPatchThread: now is 1460990265, last hip check is 1460990192, hip check interval is 3600000
  118. (T5708) 04/18/16 16:37:45:203 Debug( 437): HipMissingPatchThread: wait 3527000 ms
  119. (T1992) 04/18/16 16:37:54:051 Debug(2163): receive pan_msg_ping, 3
  120. (T1992) 04/18/16 16:37:56:151 Debug(2321): HTTP_RPC, len=0, result is
  121. (NULL)...
  122. (T1992) 04/18/16 16:37:56:151 Debug(3457): prelogin to portal result is
  123. (null)
  124. (T1992) 04/18/16 16:37:56:151 Debug(3562): Failed to pre-login to the portal one.maximintegrated.com. Error 0
  125. (T1992) 04/18/16 16:37:56:151 Debug(1593): close WinHttp close handle.
  126. (T1992) 04/18/16 16:37:56:151 Debug(4106): failed to get portal config from portal one.maximintegrated.com. Try to restore last portal config from file.
  127. (T1992) 04/18/16 16:37:56:151 Debug(1214): File C:\Users\Admin.Peter.Kienzer\AppData\Local\Palo Alto Networks\GlobalProtect\PanPortalCfg_9ce5492785de65c0969697772ff6f8.dat exists. File is PanPortalCfg_9ce5492785de65c0969697772ff6f8.dat
  128. (T1992) 04/18/16 16:37:56:151 Debug( 71): CTranslate: dwSidLen is 24
  129. (T1992) 04/18/16 16:37:56:151 Debug( 73): CTranslate: sid is S-1-5-21-910271070-3409302211-1964584949
  130. (T1992) 04/18/16 16:37:56:151 Debug( 444): pan_read_text_from_file(): File is successfully decrypted. File: C:\Users\Admin.Peter.Kienzer\AppData\Local\Palo Alto Networks\GlobalProtect\PanPortalCfg_9ce5492785de65c0969697772ff6f8.dat
  131. (T1992) 04/18/16 16:37:56:151 Debug(4111): last portal config is restored from file C:\Users\Admin.Peter.Kienzer\AppData\Local\Palo Alto Networks\GlobalProtect\PanPortalCfg_9ce5492785de65c0969697772ff6f8.dat.
  132. (T1992) 04/18/16 16:37:56:152 Debug( 234): Collect hip data is true
  133. (T1992) 04/18/16 16:37:56:152 Debug( 293): No third party vpn clients defined
  134. (T1992) 04/18/16 16:37:56:152 Debug( 389): No internal gateway defined
  135. (T1992) 04/18/16 16:37:56:152 Debug( 407): Optional client-cert does not exist
  136. (T1992) 04/18/16 16:37:56:153 Debug( 71): CTranslate: dwSidLen is 24
  137. (T1992) 04/18/16 16:37:56:153 Debug( 73): CTranslate: sid is S-1-5-21-910271070-3409302211-1964584949
  138. (T1992) 04/18/16 16:37:56:153 Debug( 201): pan_write_text_to_file(): don't check pre-existance.
  139. (T1992) 04/18/16 16:37:56:153 Debug( 206): pan_write_text_to_file(): wrote 35088 of 35088 bytes to file C:\Users\Admin.Peter.Kienzer\AppData\Local\Palo Alto Networks\GlobalProtect\PanPortalCfg_9ce5492785de65c0969697772ff6f8.dat.
  140. (T1992) 04/18/16 16:37:56:153 Debug( 62): Saved portal config to file C:\Users\Admin.Peter.Kienzer\AppData\Local\Palo Alto Networks\GlobalProtect\PanPortalCfg_9ce5492785de65c0969697772ff6f8.dat.
  141. (T1992) 04/18/16 16:37:56:154 Debug(4951): RefreshPortalConfig is yes, RefreshPortalConfigInterval is 24
  142. (T1992) 04/18/16 16:37:56:154 Info ( 167): Failed to find attribute 'mdm-address'
  143. (T1992) 04/18/16 16:37:56:154 Debug(4994): Failed to get mdm-address from config, try local
  144. (T1992) 04/18/16 16:37:56:154 Debug(5878): Set mdm address as empty
  145. (T1992) 04/18/16 16:37:56:154 Debug(4977): MDM is disabled
  146. (T1992) 04/18/16 16:37:56:154 Debug(4117): this version of portal config is supported.
  147. (T1992) 04/18/16 16:37:56:154 Debug(4140): portal status is Using cached portal config.
  148. (T1992) 04/18/16 16:37:56:154 Debug(4141): returns 1.
  149. (T1992) 04/18/16 16:37:56:154 Debug(4730): entering ExportTrustedCA.
  150. (T1992) 04/18/16 16:37:56:154 Debug( 64): pan_get_full_path(): full path in multibyte char is C:\Program Files\Palo Alto Networks\GlobalProtect\tca.cer
  151. (T1992) 04/18/16 16:37:56:154 Debug(1214): File C:\Program Files\Palo Alto Networks\GlobalProtect\tca.cer exists. File is tca.cer
  152. (T1992) 04/18/16 16:37:56:154 Debug(4737): Delete the previous trusted root ca file C:\Program Files\Palo Alto Networks\GlobalProtect\tca.cer
  153. (T1992) 04/18/16 16:37:56:154 Debug( 82): write 1988 bytes into file C:\Program Files\Palo Alto Networks\GlobalProtect\tca.cer.
  154. (T1992) 04/18/16 16:37:56:154 Debug( 82): write 2000 bytes into file C:\Program Files\Palo Alto Networks\GlobalProtect\tca.cer.
  155. (T1992) 04/18/16 16:37:56:154 Debug( 82): write 2106 bytes into file C:\Program Files\Palo Alto Networks\GlobalProtect\tca.cer.
  156. (T1992) 04/18/16 16:37:56:155 Debug( 82): write 1781 bytes into file C:\Program Files\Palo Alto Networks\GlobalProtect\tca.cer.
  157. (T1992) 04/18/16 16:37:56:155 Debug( 82): write 1659 bytes into file C:\Program Files\Palo Alto Networks\GlobalProtect\tca.cer.
  158. (T1992) 04/18/16 16:37:56:155 Debug( 82): write 1809 bytes into file C:\Program Files\Palo Alto Networks\GlobalProtect\tca.cer.
  159. (T1992) 04/18/16 16:37:56:155 Debug( 82): write 1501 bytes into file C:\Program Files\Palo Alto Networks\GlobalProtect\tca.cer.
  160. (T1992) 04/18/16 16:37:56:155 Debug( 82): write 1054 bytes into file C:\Program Files\Palo Alto Networks\GlobalProtect\tca.cer.
  161. (T1992) 04/18/16 16:37:56:155 Debug( 82): write 1448 bytes into file C:\Program Files\Palo Alto Networks\GlobalProtect\tca.cer.
  162. (T1992) 04/18/16 16:37:56:155 Debug( 82): write 2687 bytes into file C:\Program Files\Palo Alto Networks\GlobalProtect\tca.cer.
  163. (T1992) 04/18/16 16:37:56:155 Debug( 82): write 2638 bytes into file C:\Program Files\Palo Alto Networks\GlobalProtect\tca.cer.
  164. (T1992) 04/18/16 16:37:56:155 Debug(4761): quits.
  165. (T1992) 04/18/16 16:37:56:155 Debug(3692): ExportedMTU trusted CA.
  166. (T1992) 04/18/16 16:37:56:155 Debug( 64): pan_get_full_path(): full path in multibyte char is C:\Program Files\Palo Alto Networks\GlobalProtect\cc.cer
  167. (T1992) 04/18/16 16:37:56:155 Info (1206): File C:\Program Files\Palo Alto Networks\GlobalProtect\cc.cer does not exist.
  168. (T1992) 04/18/16 16:37:56:155 Debug( 64): pan_get_full_path(): full path in multibyte char is C:\Program Files\Palo Alto Networks\GlobalProtect\cc.pfx
  169. (T1992) 04/18/16 16:37:56:155 Info (1206): File C:\Program Files\Palo Alto Networks\GlobalProtect\cc.pfx does not exist.
  170. (T1992) 04/18/16 16:37:56:155 Debug(4830): returns true.
  171. (T1992) 04/18/16 16:37:56:155 Debug( 64): pan_get_full_path(): full path in multibyte char is C:\Program Files\Palo Alto Networks\GlobalProtect\cc.pfx
  172. (T1992) 04/18/16 16:37:56:155 Error(1798): Failed to get client cert issuer.
  173. (T1992) 04/18/16 16:37:56:156 Debug( 336): Active session id is 1
  174. (T1992) 04/18/16 16:37:56:158 Debug( 260): Found PanGPA pid 5024
  175. (T1992) 04/18/16 16:37:56:158 Debug( 264): Found active PanGPA pid is 5024
  176. (T1992) 04/18/16 16:37:56:158 Debug( 55): Session id is 1 for pid 5024
  177. (T1992) 04/18/16 16:37:56:158 Debug( 95): User profile directory is C:\Users\Admin.Peter.Kienzer
  178. (T1992) 04/18/16 16:37:56:158 Debug( 110): Found session 1
  179. (T1992) 04/18/16 16:37:56:159 Error( 135): NetUserGetInfo is unknown error
  180. (T1992) 04/18/16 16:37:56:159 Debug( 148): info4_buf is NULL
  181. (T1992) 04/18/16 16:37:56:159 Debug( 150): profileInfo username admin.peter.kienzer, profile path (null), server (null)
  182. (T1992) 04/18/16 16:37:56:178 Debug( 164): User profile loaded.
  183. (T1992) 04/18/16 16:37:56:178 Debug( 180): Impersonated logged on user.
  184. (T1992) 04/18/16 16:37:56:178 Debug( 182): Profile type is 0
  185. (T1992) 04/18/16 16:37:56:178 Error(1876): ExportClientCert():Error 2147942487 in CryptUIWizImport
  186. (T1992) 04/18/16 16:37:56:179 Debug( 225): User profile unloaded
  187. (T1992) 04/18/16 16:37:56:179 Error(3694): Failed to export client cert.
  188. (T1992) 04/18/16 16:37:56:179 Debug(3696): NetworkDiscoverThread: Exported client cert.
  189. (T1992) 04/18/16 16:37:56:179 Debug(3700): ServerThread: ProcessServerPortal -- GetHipPolicyCopy();
  190. (T1992) 04/18/16 16:37:56:179 Debug(4233): enters GetPolicyForClient().
  191. (T1992) 04/18/16 16:37:56:179 Info (4281): On-Demand mode is on
  192. (T1992) 04/18/16 16:37:56:179 Info (4293): Connect method is On-Demand
  193. (T1992) 04/18/16 16:37:56:179 Info (4308): On-demand mode is true.
  194. (T1992) 04/18/16 16:37:56:179 Debug(5057): Old Portal is one.maximintegrated.com, PrelogonEnabled is 0
  195. (T1992) 04/18/16 16:37:56:179 Debug( 71): CTranslate: dwSidLen is 24
  196. (T1992) 04/18/16 16:37:56:179 Debug( 73): CTranslate: sid is S-1-5-21-910271070-3409302211-1964584949
  197. (T1992) 04/18/16 16:37:56:179 Debug( 64): pan_get_full_path(): full path in multibyte char is C:\Program Files\Palo Alto Networks\GlobalProtect\HipPolicy.dat
  198. (T1992) 04/18/16 16:37:56:179 Debug( 201): pan_write_text_to_file(): don't check pre-existance.
  199. (T1992) 04/18/16 16:37:56:179 Debug( 206): pan_write_text_to_file(): wrote 480 of 480 bytes to file C:\Program Files\Palo Alto Networks\GlobalProtect\HipPolicy.dat.
  200. (T1992) 04/18/16 16:37:56:179 Debug( 144): Saved hip policy to file HipPolicy.dat.
  201. (T1992) 04/18/16 16:37:56:179 Debug(4339): RetrieveHipCheckInterval
  202. (T1992) 04/18/16 16:37:56:179 Info (4341): Hip check interval is 3600000 ms.
  203. (T1992) 04/18/16 16:37:56:179 Debug(4345): Set check hip event
  204. (T1992) 04/18/16 16:37:56:179 Debug( 775): m_bScheduleFlag is set to 0
  205. (T1992) 04/18/16 16:37:56:179 Debug( 292): Set hip check event.
  206. (T1992) 04/18/16 16:37:56:179 Debug(4347): Set hip missing patch check event.
  207. (T5064) 04/18/16 16:37:56:179 Info ( 230): HipCheckThread: got check hip event or time out.
  208. (T5064) 04/18/16 16:37:56:179 Debug( 239): HipCheckThread: Got CheckHipEvent.
  209. (T5064) 04/18/16 16:37:56:179 Debug( 753): SetNextScheduledHipCheckTime to 1460993876
  210. (T5064) 04/18/16 16:37:56:179 Debug( 260): Last hip check event wakeup tick is 1460990276
  211. (T5064) 04/18/16 16:37:56:179 Debug( 262): HipCheckThread: check hip in other process.
  212. (T5064) 04/18/16 16:37:56:179 Debug( 301): CheckHipInOtherProcess()
  213. (T5064) 04/18/16 16:37:56:179 Debug( 305): Need to collect hip data
  214. (T5708) 04/18/16 16:37:56:179 Debug( 442): HipMissingPatchThread: Got CheckHipMissingPatchEvent.
  215. (T1992) 04/18/16 16:37:56:179 Debug(3935): Portal user auth cookie file name is C:\Users\Admin.Peter.Kienzer\AppData\Local\Palo Alto Networks\GlobalProtect\PanPUAC_9ce5492785de65c0969697772ff6f8.dat
  216. (T5708) 04/18/16 16:37:56:179 Debug( 376): CheckHipMissingPatchInOtherProcess()
  217. (T5708) 04/18/16 16:37:56:179 Debug( 379): Need to check missing patch.
  218. (T5064) 04/18/16 16:37:56:179 Debug( 64): pan_get_full_path(): full path in multibyte char is C:\Program Files\Palo Alto Networks\GlobalProtect\PanGpHip.exe
  219. (T5064) 04/18/16 16:37:56:179 Debug( 122): Starting process PanGpHip.exe
  220. (T5708) 04/18/16 16:37:56:179 Debug( 64): pan_get_full_path(): full path in multibyte char is C:\Program Files\Palo Alto Networks\GlobalProtect\PanGpHipMp.exe
  221. (T5708) 04/18/16 16:37:56:179 Debug( 296): CheckHipMissingPatchInOtherProcess(): Starting process PanGpHipMp.exe
  222. (T1992) 04/18/16 16:37:56:180 Debug( 71): CTranslate: dwSidLen is 24
  223. (T1992) 04/18/16 16:37:56:180 Debug( 73): CTranslate: sid is S-1-5-21-910271070-3409302211-1964584949
  224. (T1992) 04/18/16 16:37:56:180 Debug(1122): Portal user auth cookie has been encrypted.
  225. (T1992) 04/18/16 16:37:56:180 Debug(1127): Serialized portal user auth cookie to file C:\Users\Admin.Peter.Kienzer\AppData\Local\Palo Alto Networks\GlobalProtect\PanPUAC_9ce5492785de65c0969697772ff6f8.dat. 16 bytes.
  226. (T1992) 04/18/16 16:37:56:180 Debug(3911): Portal prelogon auth cookie file name is PanPPAC_db41238a8c568a99818ddc25ba511.dat
  227. (T1992) 04/18/16 16:37:56:181 Debug( 71): CTranslate: dwSidLen is 24
  228. (T1992) 04/18/16 16:37:56:181 Debug( 73): CTranslate: sid is S-1-5-21-910271070-3409302211-1964584949
  229. (T1992) 04/18/16 16:37:56:181 Debug( 64): pan_get_full_path(): full path in multibyte char is C:\Program Files\Palo Alto Networks\GlobalProtect\PanPPAC_db41238a8c568a99818ddc25ba511.dat
  230. (T1992) 04/18/16 16:37:56:181 Debug( 201): pan_write_text_to_file(): don't check pre-existance.
  231. (T1992) 04/18/16 16:37:56:181 Debug( 206): pan_write_text_to_file(): wrote 16 of 16 bytes to file C:\Program Files\Palo Alto Networks\GlobalProtect\PanPPAC_db41238a8c568a99818ddc25ba511.dat.
  232. (T1992) 04/18/16 16:37:56:181 Debug(1006): SerializePortalPrelogonAuthCookie
  233. (T1992) 04/18/16 16:37:56:181 Info ( 167): Failed to find attribute 'user-switch-tunnel-rename-timeout'
  234. (T1992) 04/18/16 16:37:56:181 Debug(4994): Failed to get user-switch-tunnel-rename-timeout from config, try local
  235. (T1992) 04/18/16 16:37:56:181 Debug(4426): Cannot retrieve user-switch-tunnel-rename-timeout
  236. (T1992) 04/18/16 16:37:56:181 Debug(4438): The value of can-continue-if-portal-cert-invalid is yes
  237. (T1992) 04/18/16 16:37:56:181 Debug(4450): returns true.
  238. (T1992) 04/18/16 16:37:56:181 Debug(3718): prelogon status is 0
  239. (T1992) 04/18/16 16:37:56:181 Debug(3723): Gateway MD5 is DF01FB22-4EF2F140-D9C72B39-AB679FC5
  240. (T1992) 04/18/16 16:37:56:181 Debug(3725): m_bPreviousSwitchOffMsg is 0
  241. (T1992) 04/18/16 16:37:56:181 Debug(3806): Previous message is not switch-off
  242. (T1992) 04/18/16 16:37:56:181 Debug(3811): Gateway MD5 is DF01FB22-4EF2F140-D9C72B39-AB679FC5
  243. (T1992) 04/18/16 16:37:56:181 Debug(3812): ServerThread: ProcessServerPortal -- SetEvent(m_hNetworkDiscoverEvent);
  244. (T1992) 04/18/16 16:37:56:181 Debug(1335): Auto detect proxy is not needed for host one.maximintegrated.com
  245. (T1992) 04/18/16 16:37:56:181 Debug(1342): m_proxyInfo.dwAccessType is 0, m_proxyInfo.lpszProxy is (null)
  246. (T4684) 04/18/16 16:37:56:181 Debug( 358): Set hip report quit event
  247. (T4684) 04/18/16 16:37:56:181 Debug(2445): NetworkDiscoverThread: got network discover event.
  248. (T4684) 04/18/16 16:37:56:181 Debug( 753): SetNextScheduledHipCheckTime to 0
  249. (T4684) 04/18/16 16:37:56:181 Debug( 775): m_bScheduleFlag is set to 0
  250. (T4684) 04/18/16 16:37:56:181 Debug(2457): finish check host reachable
  251. (T1992) 04/18/16 16:37:56:182 Debug(1335): Auto detect proxy is not needed for host 69.26.46.21
  252. (T1992) 04/18/16 16:37:56:182 Debug(1342): m_proxyInfo.dwAccessType is 0, m_proxyInfo.lpszProxy is (null)
  253. (T1992) 04/18/16 16:37:56:182 Debug(1335): Auto detect proxy is not needed for host 64.254.121.212
  254. (T1992) 04/18/16 16:37:56:182 Debug(1342): m_proxyInfo.dwAccessType is 0, m_proxyInfo.lpszProxy is (null)
  255. (T1992) 04/18/16 16:37:56:182 Debug(1335): Auto detect proxy is not needed for host 213.215.202.253
  256. (T1992) 04/18/16 16:37:56:182 Debug(1342): m_proxyInfo.dwAccessType is 0, m_proxyInfo.lpszProxy is (null)
  257. (T1992) 04/18/16 16:37:56:182 Debug(1335): Auto detect proxy is not needed for host 204.17.143.20
  258. (T1992) 04/18/16 16:37:56:182 Debug(1342): m_proxyInfo.dwAccessType is 0, m_proxyInfo.lpszProxy is (null)
  259. (T1992) 04/18/16 16:37:56:182 Debug(1335): Auto detect proxy is not needed for host 118.102.240.35
  260. (T1992) 04/18/16 16:37:56:182 Debug(1342): m_proxyInfo.dwAccessType is 0, m_proxyInfo.lpszProxy is (null)
  261. (T1992) 04/18/16 16:37:56:182 Debug(1335): Auto detect proxy is not needed for host 184.183.5.117
  262. (T1992) 04/18/16 16:37:56:182 Debug(1342): m_proxyInfo.dwAccessType is 0, m_proxyInfo.lpszProxy is (null)
  263. (T1992) 04/18/16 16:37:56:182 Debug(1335): Auto detect proxy is not needed for host 222.127.0.147
  264. (T1992) 04/18/16 16:37:56:182 Debug(1342): m_proxyInfo.dwAccessType is 0, m_proxyInfo.lpszProxy is (null)
  265. (T1992) 04/18/16 16:37:56:182 Debug(1335): Auto detect proxy is not needed for host 4.16.146.246
  266. (T1992) 04/18/16 16:37:56:182 Debug(1342): m_proxyInfo.dwAccessType is 0, m_proxyInfo.lpszProxy is (null)
  267. (T1992) 04/18/16 16:37:56:182 Debug(1335): Auto detect proxy is not needed for host 116.12.251.179
  268. (T1992) 04/18/16 16:37:56:182 Debug(1342): m_proxyInfo.dwAccessType is 0, m_proxyInfo.lpszProxy is (null)
  269. (T1992) 04/18/16 16:37:56:182 Debug(3843): ServerThread: ProcessServerPortal -- return SendResponseToClient(socket, PAN_SERVER_HIP);
  270. (T1992) 04/18/16 16:37:56:182 Debug( 805): Send response to client for request hip
  271. (T1992) 04/18/16 16:37:56:182 Debug(5948): Set m_bPreviousSwitchOffMsg to 0
  272. (T5064) 04/18/16 16:37:56:182 Debug( 139): Wait for the ready event of hip report generated in other process.
  273. (T4684) 04/18/16 16:37:56:182 Debug(2461): NetworkDiscover SN is 49
  274. (T4684) 04/18/16 16:37:56:182 Debug(3399): Set state to Discovering network...
  275. (T4684) 04/18/16 16:37:56:183 Debug(2469): Logout gateways before network discover...
  276. (T4684) 04/18/16 16:37:56:183 Debug( 685): Logging out gateway, reason is Network discover
  277. (T4684) 04/18/16 16:37:56:183 Debug( 715): Logging out gateway over
  278. (T4684) 04/18/16 16:37:56:183 Debug(1335): Auto detect proxy is not needed for host one.maximintegrated.com
  279. (T4684) 04/18/16 16:37:56:183 Debug(1342): m_proxyInfo.dwAccessType is 0, m_proxyInfo.lpszProxy is (null)
  280. (T4684) 04/18/16 16:37:56:188 Debug(1335): Auto detect proxy is not needed for host 69.26.46.21
  281. (T4684) 04/18/16 16:37:56:188 Debug(1342): m_proxyInfo.dwAccessType is 0, m_proxyInfo.lpszProxy is (null)
  282. (T4684) 04/18/16 16:37:56:188 Debug(1335): Auto detect proxy is not needed for host 64.254.121.212
  283. (T4684) 04/18/16 16:37:56:188 Debug(1342): m_proxyInfo.dwAccessType is 0, m_proxyInfo.lpszProxy is (null)
  284. (T4684) 04/18/16 16:37:56:188 Debug(1335): Auto detect proxy is not needed for host 213.215.202.253
  285. (T4684) 04/18/16 16:37:56:188 Debug(1342): m_proxyInfo.dwAccessType is 0, m_proxyInfo.lpszProxy is (null)
  286. (T4684) 04/18/16 16:37:56:188 Debug(1335): Auto detect proxy is not needed for host 204.17.143.20
  287. (T4684) 04/18/16 16:37:56:188 Debug(1342): m_proxyInfo.dwAccessType is 0, m_proxyInfo.lpszProxy is (null)
  288. (T4684) 04/18/16 16:37:56:188 Debug(1335): Auto detect proxy is not needed for host 118.102.240.35
  289. (T4684) 04/18/16 16:37:56:188 Debug(1342): m_proxyInfo.dwAccessType is 0, m_proxyInfo.lpszProxy is (null)
  290. (T4684) 04/18/16 16:37:56:188 Debug(1335): Auto detect proxy is not needed for host 184.183.5.117
  291. (T4684) 04/18/16 16:37:56:188 Debug(1342): m_proxyInfo.dwAccessType is 0, m_proxyInfo.lpszProxy is (null)
  292. (T4684) 04/18/16 16:37:56:188 Debug(1335): Auto detect proxy is not needed for host 222.127.0.147
  293. (T4684) 04/18/16 16:37:56:188 Debug(1342): m_proxyInfo.dwAccessType is 0, m_proxyInfo.lpszProxy is (null)
  294. (T4684) 04/18/16 16:37:56:188 Debug(1335): Auto detect proxy is not needed for host 4.16.146.246
  295. (T4684) 04/18/16 16:37:56:188 Debug(1342): m_proxyInfo.dwAccessType is 0, m_proxyInfo.lpszProxy is (null)
  296. (T4684) 04/18/16 16:37:56:188 Debug(1335): Auto detect proxy is not needed for host 116.12.251.179
  297. (T4684) 04/18/16 16:37:56:188 Debug(1342): m_proxyInfo.dwAccessType is 0, m_proxyInfo.lpszProxy is (null)
  298. (T4684) 04/18/16 16:37:56:188 Debug(2477): NetworkDiscoverThread: got network discover event.
  299. (T4684) 04/18/16 16:37:56:188 Debug(2531): NetworkDiscoverThread: network type is external.
  300. (T4684) 04/18/16 16:37:56:188 Debug(2596): NetworkDiscoverThread: Discover external network.
  301. (T4684) 04/18/16 16:37:56:188 Debug( 247): gateway count is 10.
  302. (T4684) 04/18/16 16:37:56:188 Info ( 250): Connect to manual gateway Milan in network discovery
  303. (T4684) 04/18/16 16:37:56:188 Debug(2041): ProcessManualSetGateway
  304. (T4684) 04/18/16 16:37:56:188 Debug( 753): SetNextScheduledHipCheckTime to 0
  305. (T4684) 04/18/16 16:37:56:188 Debug( 775): m_bScheduleFlag is set to 0
  306. (T4684) 04/18/16 16:37:56:188 Debug(2046): Reset just resumed
  307. (T4684) 04/18/16 16:37:56:188 Debug( 762): GetExternalGatewayItemByIP: gatewayIP is Milan
  308. (T4684) 04/18/16 16:37:56:188 Debug( 770): pGatewayItem->GetGatewayStr() is one.maximintegrated.com
  309. (T4684) 04/18/16 16:37:56:188 Debug( 770): pGatewayItem->GetGatewayStr() is 69.26.46.21
  310. (T4684) 04/18/16 16:37:56:188 Debug( 770): pGatewayItem->GetGatewayStr() is 64.254.121.212
  311. (T4684) 04/18/16 16:37:56:188 Debug( 770): pGatewayItem->GetGatewayStr() is 213.215.202.253
  312. (T4684) 04/18/16 16:37:56:188 Debug( 770): pGatewayItem->GetGatewayStr() is 204.17.143.20
  313. (T4684) 04/18/16 16:37:56:188 Debug( 770): pGatewayItem->GetGatewayStr() is 118.102.240.35
  314. (T4684) 04/18/16 16:37:56:188 Debug( 770): pGatewayItem->GetGatewayStr() is 184.183.5.117
  315. (T4684) 04/18/16 16:37:56:188 Debug( 770): pGatewayItem->GetGatewayStr() is 222.127.0.147
  316. (T4684) 04/18/16 16:37:56:188 Debug( 770): pGatewayItem->GetGatewayStr() is 4.16.146.246
  317. (T4684) 04/18/16 16:37:56:188 Debug( 770): pGatewayItem->GetGatewayStr() is 116.12.251.179
  318. (T4684) 04/18/16 16:37:56:188 Debug( 786): pGatewayItem->GetDescription() is Dallas
  319. (T4684) 04/18/16 16:37:56:188 Debug( 786): pGatewayItem->GetDescription() is UK
  320. (T4684) 04/18/16 16:37:56:188 Debug( 786): pGatewayItem->GetDescription() is Hong Kong
  321. (T4684) 04/18/16 16:37:56:188 Debug( 786): pGatewayItem->GetDescription() is Milan
  322. (T4684) 04/18/16 16:37:56:188 Debug( 788): Found it
  323. (T4684) 04/18/16 16:37:56:188 Debug( 358): Set hip report quit event
  324. (T4684) 04/18/16 16:37:56:193 Info (2951): RemoveGatewayInRouteTable(vnicIdx=29)
  325. (T4684) 04/18/16 16:37:56:193 Debug( 725): m_pBestGateway is NULL.
  326. (T4684) 04/18/16 16:37:56:193 Debug(2086): dwRemoteHost is 0 for gateway 213.215.202.253. Retrieve client ip.
  327. (T4684) 04/18/16 16:37:56:193 Debug(1699): GetClientIpForGateway 213.215.202.253
  328. (T4684) 04/18/16 16:37:56:193 Info (1731): Gateway: 213.215.202.253, client IP: 192.168.0.105
  329. (T4684) 04/18/16 16:37:56:193 Debug(3399): Set state to Connecting...
  330. (T4684) 04/18/16 16:37:56:194 Debug(1515): retrieve info of gateway 213.215.202.253
  331. (T4684) 04/18/16 16:37:56:194 Debug(1568): open http session.
  332. (T4684) 04/18/16 16:37:56:194 Debug( 355): set WINHTTP_OPTION_SECURE_PROTOCOLS
  333. (T4684) 04/18/16 16:37:56:194 Debug(1526): Skip setting proxy for creating tunnel to gateway 213.215.202.253
  334. (T4684) 04/18/16 16:37:56:194 Debug(2099): Pre-login gateway...
  335. (T4684) 04/18/16 16:37:56:194 Debug( 64): pan_get_full_path(): full path in multibyte char is C:\Program Files\Palo Alto Networks\GlobalProtect\tca.cer
  336. (T4684) 04/18/16 16:37:56:194 Debug(1214): File C:\Program Files\Palo Alto Networks\GlobalProtect\tca.cer exists. File is tca.cer
  337. (T4684) 04/18/16 16:37:56:194 Debug( 363): set trusted root ca file C:\Program Files\Palo Alto Networks\GlobalProtect\tca.cer
  338. (T4684) 04/18/16 16:37:56:195 Debug( 42): WSAGetLastError() returns 10035
  339. (T4684) 04/18/16 16:37:56:351 Debug(5723): CheckServerCert(): Sever certificate has been verified with trusted root ca.
  340. (T4684) 04/18/16 16:37:56:351 Debug(5732): CheckServerCert() returns TRUE
  341. (T4684) 04/18/16 16:37:56:351 Debug(5776): Gateway count is not 1. Check gateway cert for 213.215.202.253
  342. (T4684) 04/18/16 16:37:56:351 Debug(1988): gatewayitem0000000002C15728 proxyparam is 0000000002C16F68
  343. (T4684) 04/18/16 16:37:56:351 Debug(2002): gateway proxyparam is empty
  344. (T4684) 04/18/16 16:37:56:351 Debug(2069): IPADDR=213.215.202.253,PORT=443,URL=/ssl-vpn/prelogin.esp,POST=1,PROXY_AUTO=0,PROXY_CFGURL=NULL,PROXY=NULL,PROXY_BYPASS=NULL,PROXY_USER=NULL,PROXY_PASS=****,VERIFY_CERT=0,ADDITIONAL_CHECK=1
  345. (T4684) 04/18/16 16:37:58:283 Debug( 805): Send response to client for request https_request
  346. (T4684) 04/18/16 16:37:58:283 Debug(2095): gpapintimeout not set, set it to 600 seconds
  347. (T4684) 04/18/16 16:37:58:384 Debug(2163): receive pan_msg_ping, 3
  348. (T4684) 04/18/16 16:37:58:487 Debug(2163): receive pan_msg_ping, 3
  349. (T5064) 04/18/16 16:38:06:846 Debug( 143): Got hip report in other process ready event.
  350. (T5064) 04/18/16 16:38:06:846 Debug( 162): Read output from PanGpHip.exe
  351. (T5064) 04/18/16 16:38:06:846 Debug( 199): write hip file now
  352. (T5064) 04/18/16 16:38:06:846 Debug( 210): CheckHipInOtherProcess() sets hip report ready event.
  353. (T5064) 04/18/16 16:38:06:846 Debug( 139): Wait for the ready event of hip report generated in other process.
  354. (T4948) 04/18/16 16:38:06:846 Debug(2788): HipReportThread: got HIP report ready event.
  355. (T4948) 04/18/16 16:38:06:846 Debug(2805): HipReportThread: wait for network discover ready event.
  356. (T4684) 04/18/16 16:38:07:787 Debug(2321): HTTP_RPC, len=0, result is
  357. (NULL)...
  358. (T4684) 04/18/16 16:38:07:787 Debug(2196): Failed to pre-login to the gateway 213.215.202.253
  359. (T4684) 04/18/16 16:38:07:787 Error(1549): Failed to retrieve info for gateway 213.215.202.253.
  360. (T4684) 04/18/16 16:38:07:787 Debug(1593): close WinHttp close handle.
  361. (T4684) 04/18/16 16:38:07:787 Debug(1556): tunnel to 213.215.202.253 is not created.
  362. (T4684) 04/18/16 16:38:07:787 Debug(3399): Set state to Disconnected
  363. (T4684) 04/18/16 16:38:07:790 Debug( 789): GetNicInfo(): NIC count is 4.
  364. (T4684) 04/18/16 16:38:07:790 Debug( 550): Hip report changed. Include it in status message to client.
  365. (T4684) 04/18/16 16:38:07:791 Debug(2117): Create tunnel failed for manual gateway 213.215.202.253.
  366. (T4684) 04/18/16 16:38:07:791 Debug(2124): On demand mode. Skip setting network discover event.
  367. (T4684) 04/18/16 16:38:07:791 Error(2633): NetworkDiscoverThread: failed to discover external network.
  368. (T4684) 04/18/16 16:38:07:791 Debug(3399): Set state to Disconnected
  369. (T4684) 04/18/16 16:38:07:792 Debug(2668): NetworkDiscoverThread: m_nPortalStatus is 2, m_bHasLoggedOnGateway is 0
  370. (T4684) 04/18/16 16:38:07:792 Debug(2670): NetworkDiscoverThread: ((PORTAL_CACHED_CONFIG == m_nPortalStatus) && !m_bHasLoggedOnGateway)
  371. (T4684) 04/18/16 16:38:07:792 Debug(2684): Network discovery is not ready, set GP VPN status as disconnected
  372. (T5064) 04/18/16 16:38:11:864 Debug( 147): Got event for PanGpHip process has quited.
  373. (T5064) 04/18/16 16:38:11:864 Debug( 328): CheckHip over
  374. (T5064) 04/18/16 16:38:11:864 Debug( 277): Hip checking is not initiated by clicking resubmit host profile.
  375. (T5064) 04/18/16 16:38:11:864 Debug( 219): HipCheckThread: wait for hip check event for 3600000 ms);
  376. (T4684) 04/18/16 16:38:12:793 Debug(2725): NetworkDiscoverThread: Network discover is not successful. Retry.
  377. (T4684) 04/18/16 16:38:12:793 Info (2741): On-demoand mode, skip retry network discovery.
  378. (T4684) 04/18/16 16:38:12:793 Debug(2429): NetworkDiscoverThread: wait for network discover event.
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement