<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Problem with GlobalProtect after certificate renew in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/problem-with-globalprotect-after-certificate-renew/m-p/474297#M2602</link>
    <description>&lt;P&gt;Hello there,&lt;/P&gt;&lt;P&gt;Yesterday our certificates used for GlobalProtect expired. I reneved them like last time and then - we lost possibility to connect to our institution from endpoints. Nothing more were changed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39737iD5CE13D3B6B7F273/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="1.jpg" alt="1.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Error seen on endpoint:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.png" style="width: 200px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39740iBA1D2D4C8E593129/image-size/small/is-moderation-mode/true?v=v2&amp;amp;px=200" role="button" title="3.png" alt="3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now nobody can connect via GlobalProtect using AD credentials.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently our settings in Agent config looks like:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.jpg" style="width: 799px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39738iFEF05F2B67F31FBD/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2.jpg" alt="2.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;When I set user settings to "Any" GlobalProtect starts to work again, but we cannot have this set to "Any" cos we must have control who have possibility to connect to company actually.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have no idea what can I do to make this work again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 18 Mar 2022 08:46:35 GMT</pubDate>
    <dc:creator>Damiano</dc:creator>
    <dc:date>2022-03-18T08:46:35Z</dc:date>
    <item>
      <title>Problem with GlobalProtect after certificate renew</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/problem-with-globalprotect-after-certificate-renew/m-p/474297#M2602</link>
      <description>&lt;P&gt;Hello there,&lt;/P&gt;&lt;P&gt;Yesterday our certificates used for GlobalProtect expired. I reneved them like last time and then - we lost possibility to connect to our institution from endpoints. Nothing more were changed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39737iD5CE13D3B6B7F273/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="1.jpg" alt="1.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Error seen on endpoint:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.png" style="width: 200px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39740iBA1D2D4C8E593129/image-size/small/is-moderation-mode/true?v=v2&amp;amp;px=200" role="button" title="3.png" alt="3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now nobody can connect via GlobalProtect using AD credentials.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently our settings in Agent config looks like:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.jpg" style="width: 799px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39738iFEF05F2B67F31FBD/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2.jpg" alt="2.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;When I set user settings to "Any" GlobalProtect starts to work again, but we cannot have this set to "Any" cos we must have control who have possibility to connect to company actually.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have no idea what can I do to make this work again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2022 08:46:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/problem-with-globalprotect-after-certificate-renew/m-p/474297#M2602</guid>
      <dc:creator>Damiano</dc:creator>
      <dc:date>2022-03-18T08:46:35Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with GlobalProtect after certificate renew</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/problem-with-globalprotect-after-certificate-renew/m-p/474327#M2603</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/213189"&gt;@Damiano&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;May I know what is the Authentication which you are using like LDAP, SAML, Radius or any other method?&lt;BR /&gt;Can you check how is the firewall creating the IP-to-User mapping while having the 'user/user group' set as 'Any'? ----&amp;gt;run the following command after user is connected '&lt;EM&gt;show user ip-user-mapping all type GP'&lt;/EM&gt;&lt;BR /&gt;The way you have added the user is called as 'sAMAccountName'. However, the mapping can be also learned in different ways such as UPN format (udername@domain.com) or simply just the username.&lt;BR /&gt;If the mapping is learned in a different format we can try checking the below document.&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000boHMCAY" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000boHMCAY&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2022 11:15:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/problem-with-globalprotect-after-certificate-renew/m-p/474327#M2603</guid>
      <dc:creator>ahandoo</dc:creator>
      <dc:date>2022-03-18T11:15:56Z</dc:date>
    </item>
  </channel>
</rss>

