You should contact Palo Alto support to determine whether the Global Protect mobile client disrupts the internet connectivity on your phone such that it cannot respond to the Duo Push request. There is nothing you could do in Duo to make your phone send back the response if the GP client prevents it.
You mentioned you tried adding a second device. That would work if that second device is activated for Duo Push and one of the following is true:
- the second device is first in the list of phones when you view the user in the Duo Admin Panel (as Duo’s automatic push defaults to the first activated device in the list)
- the second device is not the first in the list but you specify use of it by appending it to your password like
password,push2
to send the push to the second phone in the list.
Duo’s service won’t try a push to the second device in the list in a single authentication attempt if a push to the first one fails - they are alternate auth devices, not failover auth devices.