Recommended Free Tools
GlobalProtect can show “Could not connect to the GlobalProtect service”, “Connection Failed”, or “Cannot connect to service, error: 61” even when your internet connection works. These messages usually describe a failure between the GlobalProtect interface and its local PanGPS service—not automatically a problem with your VPN portal, gateway, password, or internet connection.
Use the checks below to identify which part is failing before reinstalling anything. Windows and macOS use different service mechanisms, so follow the section for your computer.
First, identify whether the local service is running
GlobalProtect’s user interface communicates with the PanGPS service over the loopback address 127.0.0.1. PanGPS should listen on local TCP port 4767.
Windows
- Open Command Prompt. You do not need to test the VPN portal first.
- Run:
netstat -an | find "4767"
A working listener should look similar to:
TCP 127.0.0.1:4767 0.0.0.0:0 LISTENING
macOS
Open Terminal and run:
netstat -an | grep 4767
Expected output includes:
tcp4 0 0 127.0.0.1.4767 *.* LISTEN
| Result | What it means | Next step |
|---|---|---|
| No listener on port 4767 | PanGPS did not start correctly, or the installation/operating-system configuration is interfering with startup. | Follow the Windows or Mac service-start checks below and inspect/reinstall the client if necessary. |
| Port 4767 is listening | PanGPS started, but the UI may be blocked from reaching it. | Test the local connection and check endpoint-firewall rules. |
| Local service works, but the portal or gateway fails | This is not primarily a “service not running” problem. | Troubleshoot the portal, gateway, authentication, certificate, or network path separately. |
These local-service checks are based on Palo Alto Networks’ troubleshooting guidance for PanGPA-to-PanGPS communication (Palo Alto Networks).
#1 Best Overall
- 40 Gbps 2000 Mhz High Speed: The Cat 8 ethernet cable support max. 40 Gbps data transfer and 2000 MHz Brandwith, ideal for gaming and streaming, greatly improving upload and download speed, sound, image and resolution quality
- Excellent Anti-interference: The ethernet cable comes with 4 shielded foiled twisted pairs (F/FTP), pure copper core and gold-plated RJ45 connector, reducing interference, noise and crosstalk, making network speed faster and more stable
- Marvelous Durability: Internet cable wrapped with quality cotton braided cord, which makes the LAN cable stronger and more durable. The test proves that this internet cable can be bent at least 10000 times without broken, very suitable for long-term use
- PoE Supported: All lengths of ethernet cord can support the PoE power supply function except 65ft. You don't need additional power supply when installing a PoE camera, which is very convenient and safe
- Wide Compatibility: With the RJ45 Connector, network cable can be perfectly compatible with computers, laptops, modems, routers, PS5, X-Box and other networking devices. It can also be fully backward compatible with Cat7, Cat6e, Cat6, Cat5e, Cat5
Windows fixes
1. Check the local firewall if port 4767 is listening
If netstat shows LISTENING, test whether the client can open the local connection. If Telnet is installed, run:
telnet 127.0.0.1:4767
If the connection fails despite the listener being present, inspect Windows Firewall and any endpoint-security product for dropped loopback traffic involving GlobalProtect or PanGPS. Palo Alto describes temporarily disabling the workstation firewall only as a diagnostic test. Do not leave the firewall disabled as the fix.
If disabling the firewall makes GlobalProtect work, turn it back on and have your administrator create the appropriate exception. Corporate endpoint-security software may continue blocking the connection even when Windows Firewall is not responsible.
2. Restart Windows and test again
A reboot is worth trying after an interrupted GlobalProtect update or a Windows update, but reopening the GlobalProtect window is not the same as restarting PanGPS. The interface and service are separate processes. After restarting Windows, repeat the port check rather than assuming the service recovered.
3. Use the complete reinstall procedure for a damaged installation
Use this procedure when PanGPS repeatedly fails to start, a GlobalProtect upgrade was interrupted, drivers appear corrupted, or simpler checks have not helped. It requires administrator access and modifies Windows Management Instrumentation data and the registry. Back up important data and involve your IT administrator on a managed work computer.
- Press
Win + R, typeservices.msc, and press Enter. - Find Windows Management Instrumentation (WMI), right-click it, and select Stop.
- Delete the contents of:
C:WindowsSystem32wbemRepository
Deleting the WMI repository is a destructive system-management operation. It is not a routine first fix for every GlobalProtect connection error.
Rank #2
- Cat 6 performance at a Cat5e price but with higher bandwidth
- High Performance Cat6, 30 AWG, RJ45 Ethernet Patch Cable provides universal connectivity for LAN network components such as PCs,computer servers,printers,routers,switch boxes,network media players,NAS,VoIP phones
- Jadaol cat6 standard cable support Cat8 and Cat7 network and provides performance of up to 250 MHz 10Gbps and is suitable for 10BASE-T, 100BASE-TX (Fast Ethernet), 1000BASE-T/1000BASE-TX (Gigabit Ethernet) and 10GBASE-T (10-Gigabit Ethernet)
- UTP(Unshielded Twisted Pair) patch cable with RJ45 gold-plated Connectors and are made of 100% bare copper wire, ensure minimal noise and interference
- The unique flat cable shape allows for a cleaner and safer installation. You can easily and seamlessly make the cable run along walls, follow edges & corners or even make it completely invisible by sliding it under a carpet.
- Open Registry Editor by running
regeditas an administrator. - Remove the Palo Alto Networks folder under each applicable location:
HKEY_LOCAL_MACHINESoftware
HKEY_CURRENT_USERSoftware
HKEY_USERS<user>Software
- Open the classic Programs and Features Control Panel interface and uninstall GlobalProtect.
- Check the network-adapter list and confirm that the GlobalProtect virtual adapter is no longer present.
- Restart Windows.
- Reinstall GlobalProtect using the installer supplied by your organization, running the installation with administrator privileges.
- Return to
services.mscand confirm that WMI is running.
This sequence comes from Palo Alto Networks’ documented Windows cleanup procedure (Windows uninstall and reinstall guidance).
macOS fixes
1. Allow Palo Alto Networks to run in the background
On macOS Ventura or later, macOS can prevent the background component that GlobalProtect needs to communicate with its service. If the menu bar app shows Connection Failed or says it cannot connect to the service:
- Open the Apple menu and choose System Settings.
- Open General.
- Select Login Items.
- Under Allow to run in the Background, enable Palo Alto Networks.
- Quit and reopen GlobalProtect, or restart the Mac.
This is the current Ventura-and-later permission path. Do not treat older kernel-extension approval commands as a universal replacement for this setting. The relevant documented instructions are available from UC Berkeley’s GlobalProtect support guidance.
2. Check that the GlobalProtect processes exist
In Terminal, run:
ps -ef | grep -i globalprotect
Palo Alto expects to see processes corresponding to:
/Applications/GlobalProtect.app/Contents/Resources/PanGPS
/Applications/GlobalProtect.app/Contents/MacOS/GlobalProtect
If neither process appears, continue with the file and launch-agent checks.
3. Check the application files and launch agents
Run these commands:
ls -lth /Library/LaunchAgents/com.paloaltonetworks.gp.pangpa.plist
ls -lth /Library/LaunchAgents/com.paloaltonetworks.gp.pangps.plist
ls -lth /Applications/GlobalProtect.app/Contents/Resources/PanGPS
ls -lth /Applications/GlobalProtect.app/Contents/MacOS/GlobalProtect
If any file is missing, the installation is incomplete. Palo Alto’s documented action in that situation is to uninstall and reinstall GlobalProtect rather than manually creating replacement files.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
- Designed for Outdoor & Direct Burial Installations – Heavy-duty double-shielded Cat8 Ethernet cable minimizes EMI/RFI interference and delivers stable long-distance performance. Waterproof, anti-corrosion PVC jacket allows safe direct burial and reliable use in outdoor or indoor environments.
- 26AWG for Stable High-Load Networks – Thicker 26AWG conductors provide faster, more stable data transmission than standard 32AWG cables. Ideal for high-performance home networks, gaming setups, smart homes, and data-intensive applications.
- F/FTP Shielding & Hyper-Speed Performance: Cat8 Ethernet cable constructed with 4 shielded foiled twisted pairs and 26AWG OFC conductors; supports bandwidth up to 2000 MHz and data transmission speeds up to 40 Gbps, effectively reducing signal interference and ensuring stable connections. Ideal for low-latency gaming, 4K/8K streaming, and high-speed internet connections.
- RJ45 Connectors & Wide Compatibility: Cat8 Ethernet cable with two shielded RJ45 connectors; compatible with networking switches, IP cameras, routers, Nintendo Switch, modems, PS3, PS4, Xbox, patch panels, servers, smart TVs, and more; works with Cat7, Cat6, Cat5e, and Cat5 devices
- Weatherproof & UV Resistant: Outdoor-rated Cat8 Ethernet cable with UV-resistant PVC jacket; withstands direct sunlight, extreme cold, humidity, and hot weather; anti-aging and durable; Includes 18-month support.
4. Check whether launch agents are disabled
First obtain your logged-in user’s numeric UID:
id -u
Suppose the command returns 501. Replace 501 below with your actual result:
launchctl print-disabled user/501 | grep pangp
Blank output, or output showing both services as false, is expected:
"com.paloaltonetworks.gp.pangps" => false
"com.paloaltonetworks.gp.pangpa" => false
If the agents are not disabled, load them:
launchctl load /Library/LaunchAgents/com.paloaltonetworks.gp.pangps.plist
launchctl load /Library/LaunchAgents/com.paloaltonetworks.gp.pangpa.plist
If either service is shown as disabled with true, enable and load it:
launchctl load -w /Library/LaunchAgents/com.paloaltonetworks.gp.pangps.plist
launchctl load -w /Library/LaunchAgents/com.paloaltonetworks.gp.pangpa.plist
Then check again:
ps -ef | grep -i globalprotect
A Load failed message can mean the service is disabled, a plist is missing, the installation is incomplete, or macOS is restricting launch control. Check the files and disabled-state output before jumping to a reinstall. If the services still do not start, review macOS Security settings and your organization’s endpoint-management restrictions.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →5. Reinstall GlobalProtect on the Mac
Use reinstall cleanup when the launch agents or executables are missing, an upgrade left the app in a broken state, or the launch services cannot be repaired.
- Uninstall the GlobalProtect application using the method provided by your organization.
- Delete the Palo Alto folder under your user account’s Application Support directory:
/Users/<your-user-name>/Library/Application Support/PaloAltoNetworks
NUID in Palo Alto’s procedure is a placeholder for the account directory; it is not a folder name to type literally.
Rank #4
- Cat 8 Speed, Cat 5/5e Value Enjoy Cat 8 Ethernet cable performance at a Cat 5/5e-level value. With up to 40Gbps speed and 2000MHz bandwidth, this high speed internet cable delivers more bandwidth than standard Cat 5 and Cat 5e cables, helping support smooth gaming, streaming, video calls, large file transfers and everyday wired network use.
- 40Gbps Speed, Wide Compatibility This Cat 8 Ethernet cable supports up to 40Gbps data transfer and 2000MHz bandwidth for fast, reliable internet performance. Standard RJ45 connectors are backward compatible with Cat7, Cat6, Cat6a and Cat5e devices, including routers, modems, switches, gaming PCs, PS5, PS4, Xbox, smart TVs, laptops and printers.
- Stable U/FTP Shielding Each of the 4 twisted pairs is individually wrapped with aluminum foil to help reduce crosstalk, noise, and signal interference. Combined with RJ45 connectors on both ends, the U/FTP design helps maintain cleaner signal transmission for a stable and reliable wired network connection.
- Nylon Braided Durability The nylon braided jacket adds everyday durability while keeping the cable flexible and easy to route. Reinforced construction helps the cord handle bending, pulling and frequent plugging, making it a reliable choice for desks, gaming rooms, home offices and long-term network setups.
- 50ft Reach for More Setups The 50 ft length makes it easier to connect devices across rooms, along walls, under desks or around corners. Great for router-to-PC connections, modem-to-TV setups, gaming consoles, workstations, printers and other home network equipment that needs a longer Ethernet cable.
- Restart the Mac.
- Install the approved GlobalProtect package again.
- Recheck Login Items, the processes, and port
4767.
See Palo Alto’s macOS cleanup guidance and launch-agent troubleshooting procedure.
Mac users on GlobalProtect 6.0 through 6.0.4
Palo Alto documented a startup race in GlobalProtect App 6.0 and later: PanGPA could start before PanGPS, causing the service error even though the application was installed. The issue was fixed in GlobalProtect 6.0.5 under defect GPC-16392, which added a grace period so PanGPS could launch first.
If the problem began after installing an older 6.0 release, update to a version approved by your VPN administrator. Do not install a random public package if your organization supplies a customized portal-specific client.
When the service is running but the VPN still will not connect
Once port 4767 is listening and the local client can reach it, stop treating the issue as a service-start failure. Check the separate VPN path:
- Confirm the portal address is correct.
- Check whether the portal or gateway is reachable from the current network.
- Verify credentials, multifactor authentication, certificates, and device posture requirements.
- Test another network if permitted by your organization.
- Ask the VPN administrator whether the gateway is rejecting the device or user.
Being online only proves that general internet access works. It does not prove that the GlobalProtect portal or gateway is reachable, and conversely, a portal problem does not prove that PanGPS is stopped.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What to give your IT administrator
For a faster diagnosis, report the exact error and include:
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
- [Flat Design, Zero Cable Clutter] - Lies perfectly flat against walls, under rugs, along baseboards, and through tight spaces without kinks, tangles, or messy coils. Customers praise it for effortless installation and clean cable management that blends into any room.
- [REINFORCED BRAIDED CONSTRUCTION FOR LONG‑LASTING PERFORMANCE] - Premium cotton braided jacket paired with reinforced RJ45 connectors delivers outstanding durability, rigorously tested for over 15,000 bend cycles. Many customers describe this ethernet cable as rock‑solid and well‑crafted, ideal for long‑term daily use with no worries about premature wear‑and‑tear or connection failure
- [10GBPS SPEED & 600MHZ BANDWIDTH — GAMING, STREAMING & FIBER READY] - Delivers 10Gbps data transfer rate with 600MHz bandwidth for PS5, Xbox, 4K streaming, and fiber internet. Customers report stable performance and fast speeds. Backward compatible with Cat 6 and Cat 5e devices
- [STP SHIELDING & GOLD-PLATED RJ45 — MINIMIZES EMI/RFI INTERFERENCE] - 100% bare copper STP shielding helps protect signal integrity when routed near power cords. Gold-plated RJ45 connectors resist corrosion. Compatible with 2.5GB network card
- [Works with Everything — Router, Modem, PS5, Xbox, PC, Smart TV, Printer More ] - Full backward compatibility with Cat7, Cat6, Cat6a, and Cat5e devices means this one cable works with all your home or office equipment today, and future upgrades tomorrow. Works with 10/100/1000/10G/40G BASE-T speeds. Includes 36-month warranty with free replacement support
- Your operating system and GlobalProtect version.
- Whether port
4767is listening. - On macOS, the output of
ps -ef | grep -i globalprotectand the launch-agent file checks. - Whether the error started after a GlobalProtect or operating-system update.
- Whether disabling the local firewall for a brief controlled test changed the result.
- Whether the service works but the portal or gateway connection fails.
FAQ
Why does GlobalProtect say the service is not running when my internet works?
The GlobalProtect interface communicates with the local PanGPS service over 127.0.0.1:4767. That local communication can fail independently of normal internet access. Check whether port 4767 is listening before troubleshooting the VPN portal.
What does “Cannot connect to service, error: 61” mean?
It indicates that the GlobalProtect UI could not connect to the local PanGPS service. It does not, by itself, prove that your credentials, VPN gateway, portal, or internet connection is the cause.
How do I know whether PanGPS is running?
On Windows, run netstat -an | find “4767” and look for 127.0.0.1:4767 in LISTENING state. On macOS, run netstat -an | grep 4767 and look for a LISTEN result.
What should I do if port 4767 is listening but GlobalProtect still reports a service error?
Test the local connection with telnet 127.0.0.1:4767 if Telnet is available. If it fails, check Windows Firewall, macOS firewall controls, and endpoint-security software for blocked loopback traffic.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsWhy is Palo Alto Networks missing from Mac Login Items?
The GlobalProtect installation may be incomplete, the background component may be restricted, or an upgrade may have removed or damaged its launch agents. Check the two plist files under /Library/LaunchAgents and reinstall if required.
Should I delete the Windows WMI Repository immediately?
No. Deleting C:WindowsSystem32wbemRepository is a destructive operation that Palo Alto places inside a complete uninstall/reinstall procedure for corrupted installation or driver-related data. It is not a routine first fix.
Can restarting the GlobalProtect window restart the VPN service?
Not necessarily. PanGPA/GlobalProtect and PanGPS are separate processes. Verify the PanGPS listener on local port 4767 instead of assuming that reopening the interface restarted the service.
The Bottom Line
Start with the local test: GlobalProtect should have PanGPS listening on 127.0.0.1:4767. No listener points to a service-start, installation, launch-agent, or operating-system problem. A listener that cannot be reached points to local firewall or endpoint-security interference. If the listener works, troubleshoot the portal or gateway instead. Use the complete Windows WMI cleanup or macOS reinstall only when the simpler checks identify a damaged or incomplete installation.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteQuick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

