<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect SSL error in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-ssl-error/m-p/464958#M2458</link>
    <description>&lt;P&gt;Thanks BPry, I'll see if we can get this test in place.&lt;/P&gt;</description>
    <pubDate>Thu, 10 Feb 2022 16:35:40 GMT</pubDate>
    <dc:creator>thetechknowg</dc:creator>
    <dc:date>2022-02-10T16:35:40Z</dc:date>
    <item>
      <title>GlobalProtect SSL error</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-ssl-error/m-p/464579#M2450</link>
      <description>&lt;LI-CODE lang="markup"&gt;(P19520-T11728)Dump (1338): 02/09/22 16:16:12:010 SSL_connect: initialization
(P19520-T11728)Dump (1338): 02/09/22 16:16:12:010 SSL_connect: write client hello A
(P19520-T11728)Dump (1355): 02/09/22 16:16:12:059 SSL_connect:error in SSLv2/v3 read server hello A
(P19520-T11728)Debug( 324): 02/09/22 16:16:12:059 SSL connect failed
(P19520-T11728)Debug(  60): 02/09/22 16:16:12:059 detailed SSL error info:
(P19520-T11728)Debug( 801): 02/09/22 16:16:12:059 connect() failed
(P19520-T11728)Dump ( 822): 02/09/22 16:16:12:059 Disconnect tcp socket &lt;/LI-CODE&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Please can someone help me with this GlobalProtect error. The logs don't seem to show any detailed SSL error information. It is blank. I can let you know what I have tried, bearing in mind this is a test portal + gateway, we have a production portal + gateway on the same PA-5220 that works perfectly fine.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Both GP and GW certs have been reissued just in-case&lt;/LI&gt;&lt;LI&gt;Tried 3 different GP clients (5.0.5, 5.2.5 and 5.2.10).&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;What else can I do to help with the troubleshooting process.&lt;/P&gt;&lt;P&gt;Please and thank you&lt;/P&gt;&lt;P&gt;G.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Feb 2022 17:03:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-ssl-error/m-p/464579#M2450</guid>
      <dc:creator>thetechknowg</dc:creator>
      <dc:date>2022-02-09T17:03:33Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect SSL error</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-ssl-error/m-p/464738#M2455</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/209019"&gt;@thetechknowg&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Looks like GlobalProtects logging is cutting off the error number that would/should be getting returned. I would use openssl to validate that you can complete the handshake properly from the same client outside of the Globalprotect Agent. My guess is that this isn't really a Globalprotect Agent issue and you'll see the same handshake failure in your openssl test.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Feb 2022 04:03:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-ssl-error/m-p/464738#M2455</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-02-10T04:03:43Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect SSL error</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-ssl-error/m-p/464958#M2458</link>
      <description>&lt;P&gt;Thanks BPry, I'll see if we can get this test in place.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Feb 2022 16:35:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-ssl-error/m-p/464958#M2458</guid>
      <dc:creator>thetechknowg</dc:creator>
      <dc:date>2022-02-10T16:35:40Z</dc:date>
    </item>
  </channel>
</rss>

