Hi,
We're seeing some strange behaviour where some users are not able to check out their ArcGIS Pro licenses depending on where they are (on which network they are I assume, otherwise I'm going nuts for real)..
One user that's been able to communicate with the License Server Administrator and get Pro-license without issues for weeks were today, from a new location/network, unable to get a license for instance.
Has anyone else experienced similar behaviour?
I've tried some debugging but can't really see what the issue is. The user can ping the server running license manager (connected via Global Protect).
Can some ISP's deny some protocols/traffic while others let the traffic through? We're currently not tunneling all traffic through the GP-VPN but that might be an option going forward.
I've tried to open up some ports on the router the user was using today but that didn't work either.
I can't recreate the issue on my laptop, even though I've tried a number of different networks and hotspots in Stockholm today (RIP our cyber security manager), I always get a license when I'm starting Pro.
I've used Wireshark on the clients computer to try to sort things out but I can't see any TCP-traffic (or other) to the server hosting the LMA during a failed attempt, while we get loads of traffic during a successful attempt.
The set-up is that Portal and LSA is residing on different servers so according to the article: (ESRI) Named User the first call is made to Portal to see if the user is allowed to have a license and then to the LSA to actually check out a license, and then start Pro.
Does anyone know what kind of traffic that is generated to check with the LSA? For the first call to Portal it says it uses HTTPS.

We're on Enterprise 10.9.1 with LSA 2022.0.
The users are connected to out network with GP the whole time.
All input is welcome at this stage as we're running out of ideas here really. Thanks!