<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GP Issue Gateway Fake in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-issue-gateway-fake/m-p/451032#M2209</link>
    <description>&lt;P&gt;Hi&amp;nbsp; AnalysisMan,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for sharing the solution but there I have one more concern. What I did there was I used my credential in another system's GPVPN and I see the same error and then I tried his credential in my machine's GPVPN what I see My GPVPN is connecting without any issue and error. Could you please help me here to understand where the issue is getting?&lt;/P&gt;</description>
    <pubDate>Thu, 02 Dec 2021 19:10:05 GMT</pubDate>
    <dc:creator>chanderjain</dc:creator>
    <dc:date>2021-12-02T19:10:05Z</dc:date>
    <item>
      <title>GP Issue Gateway Fake</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-issue-gateway-fake/m-p/449759#M2175</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am facing the issue with Pan GP where I get an error&amp;nbsp;Gateway Fake: Could not connect to the GlobalProtect gateway. Please contact your IT administrator.&lt;/P&gt;&lt;P&gt;I tried to remove the certificate and also reinstall it multiple times and delete the Palo alto network file also and re-install the Pan GP but no luck. Uninstall all applications but no solution I find. It was working fine before that but suddenly start the error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chanderjain_0-1638027354282.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37822iE165B4062F959D9B/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="chanderjain_0-1638027354282.png" alt="chanderjain_0-1638027354282.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I getting these logs from the files.&lt;/P&gt;&lt;P&gt;11/27/0021 20:17:50.979 [Info ]: GlobalProtect service started (client version: 5.1.1-12, OS version: Microsoft Windows 10 Pro , 64-bit).&lt;BR /&gt;11/27/0021 20:19:24.121 [Info ]: Portal login completed with address 203.122.6.28 and conect method of user-logon.&lt;BR /&gt;11/27/0021 20:19:24.199 [Info ]: Network discovery started.&lt;BR /&gt;11/27/0021 20:19:25.708 [Error]: Gateway Fake: Could not connect to the GlobalProtect gateway. Please contact your IT administrator.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11/27/21 20:17:46:733[Debug 743]: No oem .inf existing.&lt;BR /&gt;11/27/21 20:17:47:629[Debug 306]: Driver inf file is installed successfully.&lt;BR /&gt;11/27/21 20:17:49:667[Debug 359]: Driver gets installed successfully.&lt;BR /&gt;11/27/21 20:17:50:204[Debug 375]: Set debug level as 4&lt;BR /&gt;11/27/21 20:17:50:766[Debug 1196]: Driver status is: 4.&lt;BR /&gt;11/27/21 20:17:50:776[Debug 565]: Found pangpd device ROOT\PANGPD\0000, remove it now.&lt;BR /&gt;11/27/21 20:17:50:778[Debug 1196]: Driver status is: 4.&lt;BR /&gt;11/27/21 20:17:50:787[Debug 565]: Found pangpd device ROOT\PANGPD\0000, remove it now.&lt;BR /&gt;11/27/21 20:17:50:788[Debug 944]: Disable adapter be called.&lt;BR /&gt;11/27/21 20:17:50:868[Debug 824]: Disable Adapter success.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(T12520)Debug(2278): 11/27/21 20:17:58:741 No user, using SSO&lt;BR /&gt;(T12520)Debug(9709): 11/27/21 20:17:58:742 Saved password is empty.&lt;BR /&gt;(T12520)Debug(2338): 11/27/21 20:17:58:742 Portal 203.122.6.28, user , logonDomain DESKTOP-8H9MAI8, saved user , path C:\Users\Chander Jain\AppData\Local\Palo Alto Networks\GlobalProtect\&lt;BR /&gt;(T12520)Debug(2404): 11/27/21 20:17:58:742 use proxy is 1&lt;BR /&gt;(T12520)Debug(2462): 11/27/21 20:17:58:742 Pre-logon-then-on-demand value is no&lt;BR /&gt;(T12520)Debug(1469): 11/27/21 20:17:58:742 SSO starts.&lt;BR /&gt;(T12520)Info (1498): 11/27/21 20:17:58:743 SSO ----- PanCredGet failed with error Element not found.&lt;BR /&gt;(T12520)Debug(1509): 11/27/21 20:17:58:744 SSO GetSsoCredential starts.&lt;BR /&gt;(T12520)Info (1539): 11/27/21 20:17:58:744 SSO ----- PanCredGet failed with error Element not found.&lt;/P&gt;&lt;P&gt;(T12520)Debug(9726): 11/27/21 20:17:58:744 SSO password is empty&lt;BR /&gt;(T12520)Debug(2568): 11/27/21 20:17:58:744 Empty username&lt;BR /&gt;(T12520)Debug(2600): 11/27/21 20:17:58:744 m_preUsername&lt;BR /&gt;(T12520)Debug(9686): 11/27/21 20:17:58:744 Password is empty.&lt;BR /&gt;(T12520)Debug(7091): 11/27/21 20:17:58:744 Empty user for GetCachedPortalCfgOldNewFileName&lt;BR /&gt;(T12520)Debug(2621): 11/27/21 20:17:58:744 CheckCachedPortalForPrelogon 0, PrelogonNeedTimeout 0, RenameTimeout -1, userName ___empty_username___, preUsername&lt;BR /&gt;(T12520)Debug(2762): 11/27/21 20:17:58:744 Use ssl tunnel is no&lt;BR /&gt;(T12520)Debug(6140): 11/27/21 20:17:58:745 --Set state to Retrieving configuration...&lt;BR /&gt;(T8776)Debug( 413): 11/27/21 20:17:58:766 HipMonitorThread wait for exit event.&lt;BR /&gt;(T12520)Debug(7188): 11/27/21 20:17:58:768 SSO enable status is 1, user name is ___empty_username___, domain name is .&lt;BR /&gt;(T12520)Debug(2131): 11/27/21 20:17:58:768 open http session. agent is PAN GlobalProtect/5.1.1-12 (Microsoft Windows 10 Pro , 64-bit)&lt;BR /&gt;(T12520)Debug( 456): 11/27/21 20:17:58:771 winhttp SetSecureProtocol, hSession=2cafe1b0, bAllProtocol=0, gbFips=0&lt;BR /&gt;(T12520)Debug( 456): 11/27/21 20:17:58:771 winhttp SetSecureProtocol, hSession=2cb00b80, bAllProtocol=0, gbFips=0&lt;BR /&gt;(T12520)Debug(1604): 11/27/21 20:17:58:773 SetProxyForHost(&lt;A href="https://203.122.6.28/" target="_blank"&gt;https://203.122.6.28/&lt;/A&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; timeout:5 AutoDetect:1 url: proxy: bypass: proxystr:&lt;BR /&gt;(T12520)Debug(6185): 11/27/21 20:17:58:773 ----Portal Pre-login starts----&lt;BR /&gt;(T12756)Debug(4651): 11/27/21 20:17:58:773 CaptivePortalDetectionThread: IsDetectingCaptivePortal=1, PreLoginIsDone=0&lt;BR /&gt;(T12756)Debug(4628): 11/27/21 20:17:58:773 CaptivePortalDetectionThread: wait (2000 ms) for captive portal detection event.&lt;BR /&gt;(T12520)Debug( 550): 11/27/21 20:17:58:781 Network is reachable&lt;BR /&gt;(T12520)Debug(6211): 11/27/21 20:17:58:783 Pre-login...,verifyportalcert=yes&lt;BR /&gt;(T12520)Debug(10107): 11/27/21 20:17:58:783 Check cert of server 203.122.6.28&lt;BR /&gt;(T12520)Debug(10122): 11/27/21 20:17:58:783 File C:\Program Files\Palo Alto Networks\GlobalProtect\tca.cer does not exist.&lt;BR /&gt;(T12520)Debug( 777): 11/27/21 20:17:58:783 SSL connecting to 203.122.6.28&lt;BR /&gt;(T12520)Debug( 550): 11/27/21 20:17:58:790 Network is reachable&lt;BR /&gt;(T12520)Debug(1242): 11/27/21 20:17:59:027 Failed to X509_LOOKUP_load_file&lt;BR /&gt;(T12520)Debug( 363): 11/27/21 20:17:59:027 Open_SSL_connection: subject '/CN=203.122.6.28'&lt;BR /&gt;(T12520)Debug( 367): 11/27/21 20:17:59:027 Open_SSL_connection: issuer '/CN=203.122.6.28'&lt;BR /&gt;(T12520)Debug( 987): 11/27/21 20:17:59:027 Hostname 203.122.6.28 doesn't match sub alt name or no sub alt name, fallback to CN&lt;BR /&gt;(T12520)Debug(1023): 11/27/21 20:17:59:027 Hostname 203.122.6.28 match 203.122.6.28&lt;BR /&gt;(T12520)Debug(1318): 11/27/21 20:17:59:027 OpenSSL alert write&lt;span class="lia-unicode-emoji" title=":warning:"&gt;⚠️&lt;/span&gt;close notify&lt;BR /&gt;(T12520)Debug(2574): 11/27/21 20:17:59:027 encpostdata, encpostdata=0000028D2C035280, encpostdatalen=160&lt;BR /&gt;(T12520)Debug(2744): 11/27/21 20:17:59:028 REQID=1,IPADDR=203.122.6.28,PORT=443,URL=/global-protect/prelogin.esp,POST=1,PROXY_AUTO=1,PROXY_CFGURL=NULL,PROXY=NULL,PROXY_BYPASS=NULL,PROXY_USER=NULL,PROXY_PASS=****,VERIFY_CERT=1,ADDITIONAL_CHECK=1,SCEP_CERT=,oid=&lt;BR /&gt;(T12520)Debug(1399): 11/27/21 20:17:59:028 Send response to client for request https_request&lt;BR /&gt;(T12520)Debug(2854): 11/27/21 20:17:59:182 receive pan_msg_ping, 3&lt;BR /&gt;(T12520)Debug(3006): 11/27/21 20:17:59:501 winhttpObj, cert error, 00000008.&lt;BR /&gt;(T12520)Debug(3011): 11/27/21 20:17:59:501 winhttpObj, cert erro is 00000008&lt;BR /&gt;(T12520)Debug(6322): 11/27/21 20:17:59:501 prelogin to portal result is&lt;BR /&gt;(null)&lt;BR /&gt;(T12520)Debug(6573): 11/27/21 20:17:59:501 Failed to pre-login to the portal 203.122.6.28 with return value 0(0).&lt;BR /&gt;(T12520)Debug(7416): 11/27/21 20:17:59:501 Try to restore last portal config from file.&lt;BR /&gt;(T12520)Debug(7463): 11/27/21 20:17:59:502 Skip retrieve cached portal configuration for empty user&lt;BR /&gt;(T12520)Debug(6645): 11/27/21 20:17:59:502 Need to send portal certificate verification message to PanGPA.&lt;BR /&gt;(T12520)Debug(6647): 11/27/21 20:17:59:502 Set state to Disconnected&lt;BR /&gt;(T12520)Debug(6140): 11/27/21 20:17:59:502 --Set state to Disconnected&lt;BR /&gt;(T12520)Debug(1006): 11/27/21 20:17:59:502 Display hip report V4 on the UI&lt;BR /&gt;(T12520)Debug(1399): 11/27/21 20:17:59:503 Send response to client for request portal-certificate-verification&lt;BR /&gt;(T12756)Debug(4539): 11/27/21 20:18:00:788 CPD, reset cp detection history&lt;BR /&gt;(T12756)Debug( 550): 11/27/21 20:18:00:897 Network is reachable&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 27 Nov 2021 15:44:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-issue-gateway-fake/m-p/449759#M2175</guid>
      <dc:creator>chanderjain</dc:creator>
      <dc:date>2021-11-27T15:44:59Z</dc:date>
    </item>
    <item>
      <title>Re: GP Issue Gateway Fake</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-issue-gateway-fake/m-p/450197#M2178</link>
      <description>&lt;P&gt;Hi Chanderjain,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If the GP configurations are okay, then the following steps should resolve the issue.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;• Disable&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;WMI&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;services: run -&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;services.msc&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;- Windows Management Instrumentation(WMI) - stop the service.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;• Delete the files under&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;C:\Windows\System32\wbem\Repository&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;• Open Windows Registry (&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Regedit&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Go to&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;HKEY_LOCAL_MACHINE &amp;gt; Software and HKEY_CURRENT_USER &amp;gt; Software&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;. Delete the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;Palo Alto Networks&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;folder.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;• Delete the same if the same folder is present in any other user under&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;HKEY_USERS&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;• Un-install&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;GlobalProtect&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;from Windows '&lt;/SPAN&gt;&lt;STRONG&gt;Programs and Features&lt;/STRONG&gt;&lt;SPAN&gt;.'&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;• Make sure that the virtual adapter is not present in the Network adapter settings.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;•&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Reboot&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;the machine.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;•&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Reinstall&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;GlobalProtect with admin privileges.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;• Confirm that&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;WMI&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;service is running.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;Hope this helps!&lt;/P&gt;</description>
      <pubDate>Mon, 29 Nov 2021 22:33:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-issue-gateway-fake/m-p/450197#M2178</guid>
      <dc:creator>AnalysisMan</dc:creator>
      <dc:date>2021-11-29T22:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: GP Issue Gateway Fake</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-issue-gateway-fake/m-p/451032#M2209</link>
      <description>&lt;P&gt;Hi&amp;nbsp; AnalysisMan,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for sharing the solution but there I have one more concern. What I did there was I used my credential in another system's GPVPN and I see the same error and then I tried his credential in my machine's GPVPN what I see My GPVPN is connecting without any issue and error. Could you please help me here to understand where the issue is getting?&lt;/P&gt;</description>
      <pubDate>Thu, 02 Dec 2021 19:10:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-issue-gateway-fake/m-p/451032#M2209</guid>
      <dc:creator>chanderjain</dc:creator>
      <dc:date>2021-12-02T19:10:05Z</dc:date>
    </item>
  </channel>
</rss>

