<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Failing to connect to portal for particular user on Windows after upgrade in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/failing-to-connect-to-portal-for-particular-user-on-windows/m-p/482183#M2695</link>
    <description>&lt;P&gt;Hi, I recently started having issues with my account connecting from Windows after an upgrade. The account logs in fine still from MacOS. I've tried multiple Windows machines and all exhibit the same behavior. Creating a new test account worked from the same Windows machine. The device is a PA-3220 and was upgraded from 10.0.0.5 to 10.0.1.3. The GP version is 6.0.0, previously it was 5.2.10.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any way to fix the original account or should it be delete/recreated to resolve?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Enclosed/below is a screenshot of the Wireshark packet capture which shows a TCP RST after the client/server SSL negotiation.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Picture1.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40280i4590C9FDE200793A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Picture1.png" alt="Picture1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the "&lt;FONT face="courier new,courier"&gt;----Gateway Login starts----&lt;/FONT&gt;" section of PanGPS.log where the error occurs. The error appears to be "unknown private header internal-error. Gateway &amp;lt;GATEWAY_FQDN&amp;gt;, status code -1". Note - environment specifics have been obsfuctated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Set to service bUseCCUserGateway 0 and ccUserNameGateway&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Update user name from &amp;lt;VPN_USERNAME&amp;gt; to &amp;lt;VPN_USERNAME&amp;gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;OtpSaveCredential is save_credential&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;External network gateway without OTP authentication&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Fallback portal user credential.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Roaming profile is false&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;profileInfo username DoD_Admin, profile path (null), server (null)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Unserialized empty cookie for portal &amp;lt;GATEWAY_FQDN&amp;gt; and user &amp;lt;VPN_USERNAME&amp;gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Unserialized empty cookie for portal &amp;lt;GATEWAY_FQDN&amp;gt; and pre-logon user.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bIsEmptyUser is 0, bDPGCforManualOnlyGateway is 0, bDPGCNotforManualOnlyGateway is 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Gateway auth method: saml, auth src: IDP&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Set to service bUseCCUserGateway 0 and ccUserNameGateway&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;m_nEncryptedPasswordLen is 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Roaming profile is false&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;profileInfo username DoD_Admin, profile path (null), server (null)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Unserialized empty cookie for portal &amp;lt;GATEWAY_FQDN&amp;gt; and user &amp;lt;VPN_USERNAME&amp;gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Unserialized empty cookie for portal &amp;lt;GATEWAY_FQDN&amp;gt; and pre-logon user.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;use cached deviceSN&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Get preferred IPv4 for gateway &amp;lt;GATEWAY_IP&amp;gt; and user &amp;lt;VPN_USERNAME&amp;gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Get preferred IPv6 for gateway &amp;lt;GATEWAY_IP&amp;gt; and user &amp;lt;VPN_USERNAME&amp;gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Actual user for gateway login is &amp;lt;DOMAIN_NAME&amp;gt;\&amp;lt;VPN_USERNAME&amp;gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Gateway selection type is auto&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;use cached deviceSN&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Need to check gateway cert for &amp;lt;GATEWAY_FQDN&amp;gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;encpostdata, encpostdata=000001E15B0439E0, encpostdatalen=688&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;REQID=22,IPADDR=&amp;lt;GATEWAY_FQDN&amp;gt;,PORT=443,URL=/ssl-vpn/login.esp,POST=1,PROXY_AUTO=0,PROXY_CFGURL=NULL,PROXY=NULL,PROXY_BYPASS=NULL,PROXY_USER=NULL,PROXY_PASS=****,VERIFY_CERT=0,ADDITIONAL_CHECK=1,SCEP_CERT=,oid=&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Send response to client for request https_request&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;receive pan_msg_ping, 1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Status code: -1, private header: internal-error&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;unknown private header internal-error. Gateway &amp;lt;GATEWAY_FQDN&amp;gt;, status code -1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;pszXmlConfig is NULL. 4278&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;pszXmlConfig is NULL, m_bInvalidUserCredential is false.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Failed to retrieve info for gateway &amp;lt;GATEWAY_FQDN&amp;gt;.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;tunnel to &amp;lt;GATEWAY_FQDN&amp;gt; is not created.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;NetworkDiscoverThread: failed to discover external network.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Network discovery failed, set error as The network connection is unreachable or the gateway is unresponsive. Check the network connection and reconnect.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;--Set state to Disconnected&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Setting debug level to 5&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;NetworkDiscoverThread: PortalStatus is 1, HasLoggedOnGateway is 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Network discovery is not ready, set GP VPN status as disconnected&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;SetVpnStatus called with new status=0, Previous Status=0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;UpdatePrelogonStateForSSO() - tunnel state = Disconnected&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;msgtype = disable&lt;/FONT&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 24 Apr 2022 14:11:23 GMT</pubDate>
    <dc:creator>aarismendi</dc:creator>
    <dc:date>2022-04-24T14:11:23Z</dc:date>
    <item>
      <title>Failing to connect to portal for particular user on Windows after upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/failing-to-connect-to-portal-for-particular-user-on-windows/m-p/482183#M2695</link>
      <description>&lt;P&gt;Hi, I recently started having issues with my account connecting from Windows after an upgrade. The account logs in fine still from MacOS. I've tried multiple Windows machines and all exhibit the same behavior. Creating a new test account worked from the same Windows machine. The device is a PA-3220 and was upgraded from 10.0.0.5 to 10.0.1.3. The GP version is 6.0.0, previously it was 5.2.10.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any way to fix the original account or should it be delete/recreated to resolve?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Enclosed/below is a screenshot of the Wireshark packet capture which shows a TCP RST after the client/server SSL negotiation.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Picture1.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40280i4590C9FDE200793A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Picture1.png" alt="Picture1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the "&lt;FONT face="courier new,courier"&gt;----Gateway Login starts----&lt;/FONT&gt;" section of PanGPS.log where the error occurs. The error appears to be "unknown private header internal-error. Gateway &amp;lt;GATEWAY_FQDN&amp;gt;, status code -1". Note - environment specifics have been obsfuctated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Set to service bUseCCUserGateway 0 and ccUserNameGateway&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Update user name from &amp;lt;VPN_USERNAME&amp;gt; to &amp;lt;VPN_USERNAME&amp;gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;OtpSaveCredential is save_credential&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;External network gateway without OTP authentication&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Fallback portal user credential.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Roaming profile is false&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;profileInfo username DoD_Admin, profile path (null), server (null)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Unserialized empty cookie for portal &amp;lt;GATEWAY_FQDN&amp;gt; and user &amp;lt;VPN_USERNAME&amp;gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Unserialized empty cookie for portal &amp;lt;GATEWAY_FQDN&amp;gt; and pre-logon user.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bIsEmptyUser is 0, bDPGCforManualOnlyGateway is 0, bDPGCNotforManualOnlyGateway is 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Gateway auth method: saml, auth src: IDP&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Set to service bUseCCUserGateway 0 and ccUserNameGateway&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;m_nEncryptedPasswordLen is 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Roaming profile is false&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;profileInfo username DoD_Admin, profile path (null), server (null)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Unserialized empty cookie for portal &amp;lt;GATEWAY_FQDN&amp;gt; and user &amp;lt;VPN_USERNAME&amp;gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Unserialized empty cookie for portal &amp;lt;GATEWAY_FQDN&amp;gt; and pre-logon user.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;use cached deviceSN&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Get preferred IPv4 for gateway &amp;lt;GATEWAY_IP&amp;gt; and user &amp;lt;VPN_USERNAME&amp;gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Get preferred IPv6 for gateway &amp;lt;GATEWAY_IP&amp;gt; and user &amp;lt;VPN_USERNAME&amp;gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Actual user for gateway login is &amp;lt;DOMAIN_NAME&amp;gt;\&amp;lt;VPN_USERNAME&amp;gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Gateway selection type is auto&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;use cached deviceSN&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Need to check gateway cert for &amp;lt;GATEWAY_FQDN&amp;gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;encpostdata, encpostdata=000001E15B0439E0, encpostdatalen=688&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;REQID=22,IPADDR=&amp;lt;GATEWAY_FQDN&amp;gt;,PORT=443,URL=/ssl-vpn/login.esp,POST=1,PROXY_AUTO=0,PROXY_CFGURL=NULL,PROXY=NULL,PROXY_BYPASS=NULL,PROXY_USER=NULL,PROXY_PASS=****,VERIFY_CERT=0,ADDITIONAL_CHECK=1,SCEP_CERT=,oid=&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Send response to client for request https_request&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;receive pan_msg_ping, 1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Status code: -1, private header: internal-error&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;unknown private header internal-error. Gateway &amp;lt;GATEWAY_FQDN&amp;gt;, status code -1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;pszXmlConfig is NULL. 4278&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;pszXmlConfig is NULL, m_bInvalidUserCredential is false.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Failed to retrieve info for gateway &amp;lt;GATEWAY_FQDN&amp;gt;.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;tunnel to &amp;lt;GATEWAY_FQDN&amp;gt; is not created.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;NetworkDiscoverThread: failed to discover external network.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Network discovery failed, set error as The network connection is unreachable or the gateway is unresponsive. Check the network connection and reconnect.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;--Set state to Disconnected&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Setting debug level to 5&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;NetworkDiscoverThread: PortalStatus is 1, HasLoggedOnGateway is 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Network discovery is not ready, set GP VPN status as disconnected&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;SetVpnStatus called with new status=0, Previous Status=0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;UpdatePrelogonStateForSSO() - tunnel state = Disconnected&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;msgtype = disable&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Apr 2022 14:11:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/failing-to-connect-to-portal-for-particular-user-on-windows/m-p/482183#M2695</guid>
      <dc:creator>aarismendi</dc:creator>
      <dc:date>2022-04-24T14:11:23Z</dc:date>
    </item>
  </channel>
</rss>

