<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: RHEL 8: Cannot connect to local gpd service in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/rhel-8-cannot-connect-to-local-gpd-service/m-p/578688#M5045</link>
    <description>&lt;P&gt;The Linux client comes with no instructions or documentation.&lt;/P&gt;
&lt;P&gt;How do I set the logging level ?&lt;/P&gt;
&lt;P&gt;From a fresh reboot, I tried running the following commands:&lt;/P&gt;
&lt;PRE&gt;globalprotect launch-ui&lt;BR /&gt;globalprotect&lt;/PRE&gt;
&lt;P&gt;I also ran&lt;/P&gt;
&lt;PRE&gt;/opt/paloaltonetworks/globalprotect/PanGPA start &amp;amp;&lt;/PRE&gt;
&lt;P&gt;a few times.&amp;nbsp; The quick response each time was&lt;/P&gt;
&lt;PRE&gt;[1]+ Done&amp;nbsp;/opt/paloaltonetworks/globalprotect/PanGPA start&lt;/PRE&gt;
&lt;P&gt;and my process table:&lt;/P&gt;
&lt;PRE&gt;$ ps -ef | grep global&lt;BR /&gt;root 1151 1 0 17:38 ? 00:00:00 /opt/paloaltonetworks/globalprotect/PanGPS&lt;BR /&gt;&amp;lt;userid&amp;gt; 2547 2231 0 17:40 tty2 00:00:00 dbus-run-session /opt/paloaltonetworks/globalprotect/PanGPUI&lt;BR /&gt;&amp;lt;userid&amp;gt; 2568 2547 0 17:40 tty2 00:00:00 /opt/paloaltonetworks/globalprotect/PanGPUI&lt;/PRE&gt;
&lt;P&gt;Now for the log files:&lt;/P&gt;
&lt;P&gt;From my home directory:&lt;/P&gt;
&lt;PRE&gt;$ cat .GlobalProtect/PanGPI.log &lt;BR /&gt;P3029-T1837705024 02/28/2024 17:45:46:522 Info ( 226): ##############Run GPI into direct mode.##############&lt;BR /&gt;P3029-T1817569024 02/28/2024 17:45:46:522 Info ( 687): debug thread starts&lt;BR /&gt;chmod: cannot access '/*.log': No such file or directory&lt;BR /&gt;P3029-T1837705024 02/28/2024 17:45:46:523 Error( 80): CPanMsgQueue::create - failed to open message queue. error = 2&lt;BR /&gt;P3029-T1837705024 02/28/2024 17:45:46:523 Error( 50): ConnectToGPA fail with error 2.&lt;BR /&gt;P3029-T1817569024 02/28/2024 17:45:47:524 Info ( 693): debug thread ends&lt;BR /&gt;P3035-T-620284096 02/28/2024 17:45:54:501 Info ( 212): ##############Run GPI into prompt mode.##############&lt;BR /&gt;P3035-T-640420096 02/28/2024 17:45:54:501 Info ( 687): debug thread starts&lt;BR /&gt;chmod: cannot access '/*.log': No such file or directory&lt;BR /&gt;P3035-T-620284096 02/28/2024 17:45:54:501 Error( 80): CPanMsgQueue::create - failed to open message queue. error = 2&lt;BR /&gt;P3035-T-620284096 02/28/2024 17:45:54:501 Error( 50): ConnectToGPA fail with error 2.&lt;BR /&gt;P3035-T-640420096 02/28/2024 17:45:55:501 Info ( 693): debug thread ends&lt;/PRE&gt;
&lt;P&gt;and&lt;/P&gt;
&lt;PRE&gt;&lt;BR /&gt;$ cat .GlobalProtect/PanGPUI.log &lt;BR /&gt;P2568-T1132455680 02/28/2024 17:40:06:094 Info ( 687): debug thread starts&lt;BR /&gt;P2568-T2009580416 02/28/2024 17:43:07:303 Error( 89): Socket unable to connect to PanGPA&lt;BR /&gt;P2568-T2009580416 02/28/2024 17:43:07:303 Info ( 90): Retrying connection to PanGPA. Number of retries: 181&lt;/PRE&gt;
&lt;P&gt;What is it trying to access to run a "chmod" on ?&lt;/P&gt;
&lt;P&gt;Why am I getting "failed to open message queue" ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and from /opt/paloaltonetworks:&lt;/P&gt;
&lt;PRE&gt;$ cat /opt/paloaltonetworks/globalprotect/pan_gp_event.log&lt;BR /&gt;02/28/2024 17:38:43:863 [Info ]: GlobalProtect service started (client version: 6.1.4-711, OS version: Linux Red Hat Enterprise Linux 8.9).&lt;/PRE&gt;
&lt;P&gt;and finally&lt;/P&gt;
&lt;PRE&gt;$ cat /opt/paloaltonetworks/globalprotect/PanGPS.log&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:528 Debug( 336): PanGPS, working directory is /opt/paloaltonetworks/globalprotect/&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:529 Info ( 539): ####################### Start PanGPS service (ver: 6.1.4-711) #######################&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:529 Info ( 540): Debug level is 5, log path is /opt/paloaltonetworks/globalprotect/&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:530 Info ( 541): User is (null), home is /root, login is (null)&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:530 Info ( 150): Predeployed log-path-service is not set&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:530 Info ( 439): Get OS info: Red Hat Enterprise Linux 8.9&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:536 Debug( 464): Serial number is VMware-&amp;lt;redacted&amp;gt;&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:536 Debug( 107): IsDaemon is 1&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:541 Info ( 121): PrelogonEnabled is 0&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:541 Info ( 504): cannot open /var/run/PanGPS.pid, assume no old instance running&lt;BR /&gt;P1151-T711235328 02/28/2024 17:38:43:541 Info ( 687): debug thread starts&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:548 Debug( 285): stopping split tunnel feature!&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:548 Debug( 27): split tunnel script dir /opt/paloaltonetworks/globalprotect/network/config&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:551 Debug( 397): Uninstalling iptables DNS chain...&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:630 Debug( 27): split tunnel script dir /opt/paloaltonetworks/globalprotect/network/config&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:630 Debug( 459): Uninstalling iptables Split Tunnel chain &amp;amp; routing tables...&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:773 Debug( 306): split tunnel stopped!&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:773 Debug( 61): psv init called&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:833 Info (2458): CPanMSServiceLinux::findJoinDomain: szDomainName is : &amp;lt;DOMAIN&amp;gt;&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:833 Debug( 69): PanMSServiceLinux:ctor: m_szJoinDomain &amp;lt;DOMAIN&amp;gt;, m_szJoinDomainRaw &amp;lt;DOMAIN&amp;gt;&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:833 Debug( 72): PanMSServiceLinux:ctor: m_domainName &amp;lt;DOMAIN&amp;gt;, m_domainNameRaw &amp;lt;DOMAIN&amp;gt;&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:839 Debug( 683): Service-only is no&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:839 Debug( 735): Kerberos auth, stopOnKerberosFail=0()&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:839 Debug( 740): Prefer ipv6 is yes.&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:839 Debug( 763): CPanMSService::Init connect timeout 5, received timeout 30, portal timeout 5 &lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:839 Debug( 800): CPanMSService::Init fips: fipsc-cc-mode-enabled &lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:839 Debug( 810): CPanMSService::Init enable-fips-cc-mode &lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:839 Debug( 821): CPanMSService::Init fips: m_bFipsModeRequired 0 &lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:839 Debug( 238): GetValueBinary size 6&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:839 Debug( 899): Mac address is &amp;lt;00-00-00-00-00-00 redacted&amp;gt;&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:839 Debug(2402): pan_get_gp_user_agent szGpUserAgent ua is PAN GlobalProtect/6.1.4-711 (Linux Red Hat Enterprise Linux 8.9).&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:839 Info (10860): CheckPrelogon: Portal is , PrelogonEnabled is no&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:861 Debug( 949): override-cc-username is no&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:862 Debug(5123): event log file is /opt/paloaltonetworks/globalprotect//pan_gp_event.log&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:863 Debug( 959): Event log thread started&lt;BR /&gt;P1151-T702842624 02/28/2024 17:38:43:863 Debug(5092): event log thread started.&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:863 Debug( 167): Time zone GMT offset is 0&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:865 Info (10749): Portal config does not exist, try registry/plist&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:865 Debug( 354): default cert path is /etc/pki/tls/certs&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:865 Debug( 379): default private key path is /etc/pki/tls/private&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:865 Debug(1485): cfg no client cert.&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:865 Debug( 259): DLSA- agent is enable, restore lar during start up&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:865 Debug( 261): DLSA- Pan LAR file is /opt/paloaltonetworks/globalprotect/pan_lar.dat&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:866 Debug( 266): LAR file does not exist. &lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:866 Debug( 72): CControlManagerLinux::StartServer() isFipsModeRequired() 0&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:866 Debug( 554): Start tunnel driver.&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:881 Info ( 114): Service callback table gets set.&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:881 Debug( 230): set virtual interface driver started as yes&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:881 Debug( 592): Virtual interface is started&lt;BR /&gt;P1151-T686057216 02/28/2024 17:38:43:883 Info ( 102): Start ServerThread&lt;BR /&gt;P1151-T694449920 02/28/2024 17:38:43:883 Debug( 440): RecvThread started.&lt;BR /&gt;P1151-T686057216 02/28/2024 17:38:43:885 Debug( 84): thread StartPanGPAThread is created.&lt;BR /&gt;P1151-T686057216 02/28/2024 17:38:43:885 Debug(10886): CPanMSService::StartPrelogonThread DaemonProcess: yes, InPrelogon: no&lt;BR /&gt;P1151-T686057216 02/28/2024 17:38:43:885 Debug(13470): Enforcer is not enabled&amp;nbsp;&amp;nbsp;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;RHEL 8 does not use iptables.&lt;/P&gt;
&lt;P&gt;It uses nftables (and firewalld)&lt;/P&gt;
&lt;P&gt;What is it trying to do with Kerberos ?&lt;/P&gt;
&lt;P&gt;Where should the portal config be and what is the syntax / content ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have lots more questions and I am still looking for answers, please.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 28 Feb 2024 18:15:01 GMT</pubDate>
    <dc:creator>D.White003479</dc:creator>
    <dc:date>2024-02-28T18:15:01Z</dc:date>
    <item>
      <title>RHEL 8: Cannot connect to local gpd service</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/rhel-8-cannot-connect-to-local-gpd-service/m-p/578488#M5027</link>
      <description>&lt;P&gt;RHEL 8.9&lt;/P&gt;
&lt;P&gt;GlobalProtect_UI_focal_rpm-6.1.4.0-711.rpm&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any "globalprotect" command on the command line returns:&lt;/P&gt;
&lt;P&gt;Cannot connect to local gpd service.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The&amp;nbsp;PanGPA "service" exits very quickly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any suggestions ?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 13:39:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/rhel-8-cannot-connect-to-local-gpd-service/m-p/578488#M5027</guid>
      <dc:creator>D.White003479</dc:creator>
      <dc:date>2024-02-27T13:39:07Z</dc:date>
    </item>
    <item>
      <title>Re: RHEL 8: Cannot connect to local gpd service</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/rhel-8-cannot-connect-to-local-gpd-service/m-p/578609#M5030</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1633538495"&gt;@D.White003479&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;RH 8.9 is not listed on the compatibility matrix.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Guess it's not (yet) supported:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/compatibility-matrix/globalprotect/where-can-i-install-the-globalprotect-app" target="_blank"&gt;https://docs.paloaltonetworks.com/compatibility-matrix/globalprotect/where-can-i-install-the-globalprotect-app&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 09:25:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/rhel-8-cannot-connect-to-local-gpd-service/m-p/578609#M5030</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2024-02-28T09:25:00Z</dc:date>
    </item>
    <item>
      <title>Re: RHEL 8: Cannot connect to local gpd service</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/rhel-8-cannot-connect-to-local-gpd-service/m-p/578628#M5031</link>
      <description>&lt;P&gt;It is not explicitly listed, but then neither is 8.2, 8.5, 8.6, or 8.8&lt;/P&gt;
&lt;P&gt;Sorry, not helpful.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 11:40:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/rhel-8-cannot-connect-to-local-gpd-service/m-p/578628#M5031</guid>
      <dc:creator>D.White003479</dc:creator>
      <dc:date>2024-02-28T11:40:24Z</dc:date>
    </item>
    <item>
      <title>Re: RHEL 8: Cannot connect to local gpd service</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/rhel-8-cannot-connect-to-local-gpd-service/m-p/578652#M5034</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1633538495"&gt;@D.White003479&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sounds like PanGPA isn't actually running anymore.&amp;nbsp; Can you confirm ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;$ ps -ef | grep -i pangpa&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If not, can you try this to start PanGPA manually and see if that works ?:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;$ source /etc/profile.d/PanMSInit.sh (might be located in another path ... not sure about that).&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 14:01:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/rhel-8-cannot-connect-to-local-gpd-service/m-p/578652#M5034</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2024-02-28T14:01:58Z</dc:date>
    </item>
    <item>
      <title>Re: RHEL 8: Cannot connect to local gpd service</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/rhel-8-cannot-connect-to-local-gpd-service/m-p/578655#M5037</link>
      <description>&lt;P&gt;The file&amp;nbsp;/etc/profile.d/PanMSInit.sh contains:&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;#!/bin/bash&lt;BR /&gt;PANGPA=/opt/paloaltonetworks/globalprotect/PanGPA&lt;BR /&gt;pgrep -u $USER PanGPA &amp;gt; /dev/null 2&amp;gt;&amp;amp;1&lt;BR /&gt;if [ $? -ne 0 ]; then&lt;BR /&gt;    if [ -f $PANGPA ]; then &lt;BR /&gt;        $PANGPA start &amp;amp;&lt;BR /&gt;    fi&lt;BR /&gt;fi&lt;/PRE&gt;
&lt;P&gt;That binary exits only a few seconds after running it.&lt;/P&gt;
&lt;P&gt;Is there any known way to debug this ?&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 14:20:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/rhel-8-cannot-connect-to-local-gpd-service/m-p/578655#M5037</guid>
      <dc:creator>D.White003479</dc:creator>
      <dc:date>2024-02-28T14:20:34Z</dc:date>
    </item>
    <item>
      <title>Re: RHEL 8: Cannot connect to local gpd service</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/rhel-8-cannot-connect-to-local-gpd-service/m-p/578668#M5040</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1633538495"&gt;@D.White003479&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Seems like the script isn't being initialised by the correct user.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you check if the user table actually shows your logged in user ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;&amp;gt; who -u&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Make sure to run globalprotect as the same user running&amp;nbsp;PanGPA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Similar issue discussed here:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/globalprotect-cannot-connect-to-local-gpd-service/m-p/247199#M70350" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-topics/globalprotect-cannot-connect-to-local-gpd-service/m-p/247199#M70350&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 15:28:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/rhel-8-cannot-connect-to-local-gpd-service/m-p/578668#M5040</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2024-02-28T15:28:08Z</dc:date>
    </item>
    <item>
      <title>Re: RHEL 8: Cannot connect to local gpd service</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/rhel-8-cannot-connect-to-local-gpd-service/m-p/578672#M5041</link>
      <description>&lt;P&gt;PanGPA will not stay running.&lt;/P&gt;
&lt;P&gt;Why ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 15:56:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/rhel-8-cannot-connect-to-local-gpd-service/m-p/578672#M5041</guid>
      <dc:creator>D.White003479</dc:creator>
      <dc:date>2024-02-28T15:56:23Z</dc:date>
    </item>
    <item>
      <title>Re: RHEL 8: Cannot connect to local gpd service</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/rhel-8-cannot-connect-to-local-gpd-service/m-p/578686#M5044</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1633538495"&gt;@D.White003479&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You might get more information increasing to debug log level and checking the panGPA.log file.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 17:16:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/rhel-8-cannot-connect-to-local-gpd-service/m-p/578686#M5044</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2024-02-28T17:16:40Z</dc:date>
    </item>
    <item>
      <title>Re: RHEL 8: Cannot connect to local gpd service</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/rhel-8-cannot-connect-to-local-gpd-service/m-p/578688#M5045</link>
      <description>&lt;P&gt;The Linux client comes with no instructions or documentation.&lt;/P&gt;
&lt;P&gt;How do I set the logging level ?&lt;/P&gt;
&lt;P&gt;From a fresh reboot, I tried running the following commands:&lt;/P&gt;
&lt;PRE&gt;globalprotect launch-ui&lt;BR /&gt;globalprotect&lt;/PRE&gt;
&lt;P&gt;I also ran&lt;/P&gt;
&lt;PRE&gt;/opt/paloaltonetworks/globalprotect/PanGPA start &amp;amp;&lt;/PRE&gt;
&lt;P&gt;a few times.&amp;nbsp; The quick response each time was&lt;/P&gt;
&lt;PRE&gt;[1]+ Done&amp;nbsp;/opt/paloaltonetworks/globalprotect/PanGPA start&lt;/PRE&gt;
&lt;P&gt;and my process table:&lt;/P&gt;
&lt;PRE&gt;$ ps -ef | grep global&lt;BR /&gt;root 1151 1 0 17:38 ? 00:00:00 /opt/paloaltonetworks/globalprotect/PanGPS&lt;BR /&gt;&amp;lt;userid&amp;gt; 2547 2231 0 17:40 tty2 00:00:00 dbus-run-session /opt/paloaltonetworks/globalprotect/PanGPUI&lt;BR /&gt;&amp;lt;userid&amp;gt; 2568 2547 0 17:40 tty2 00:00:00 /opt/paloaltonetworks/globalprotect/PanGPUI&lt;/PRE&gt;
&lt;P&gt;Now for the log files:&lt;/P&gt;
&lt;P&gt;From my home directory:&lt;/P&gt;
&lt;PRE&gt;$ cat .GlobalProtect/PanGPI.log &lt;BR /&gt;P3029-T1837705024 02/28/2024 17:45:46:522 Info ( 226): ##############Run GPI into direct mode.##############&lt;BR /&gt;P3029-T1817569024 02/28/2024 17:45:46:522 Info ( 687): debug thread starts&lt;BR /&gt;chmod: cannot access '/*.log': No such file or directory&lt;BR /&gt;P3029-T1837705024 02/28/2024 17:45:46:523 Error( 80): CPanMsgQueue::create - failed to open message queue. error = 2&lt;BR /&gt;P3029-T1837705024 02/28/2024 17:45:46:523 Error( 50): ConnectToGPA fail with error 2.&lt;BR /&gt;P3029-T1817569024 02/28/2024 17:45:47:524 Info ( 693): debug thread ends&lt;BR /&gt;P3035-T-620284096 02/28/2024 17:45:54:501 Info ( 212): ##############Run GPI into prompt mode.##############&lt;BR /&gt;P3035-T-640420096 02/28/2024 17:45:54:501 Info ( 687): debug thread starts&lt;BR /&gt;chmod: cannot access '/*.log': No such file or directory&lt;BR /&gt;P3035-T-620284096 02/28/2024 17:45:54:501 Error( 80): CPanMsgQueue::create - failed to open message queue. error = 2&lt;BR /&gt;P3035-T-620284096 02/28/2024 17:45:54:501 Error( 50): ConnectToGPA fail with error 2.&lt;BR /&gt;P3035-T-640420096 02/28/2024 17:45:55:501 Info ( 693): debug thread ends&lt;/PRE&gt;
&lt;P&gt;and&lt;/P&gt;
&lt;PRE&gt;&lt;BR /&gt;$ cat .GlobalProtect/PanGPUI.log &lt;BR /&gt;P2568-T1132455680 02/28/2024 17:40:06:094 Info ( 687): debug thread starts&lt;BR /&gt;P2568-T2009580416 02/28/2024 17:43:07:303 Error( 89): Socket unable to connect to PanGPA&lt;BR /&gt;P2568-T2009580416 02/28/2024 17:43:07:303 Info ( 90): Retrying connection to PanGPA. Number of retries: 181&lt;/PRE&gt;
&lt;P&gt;What is it trying to access to run a "chmod" on ?&lt;/P&gt;
&lt;P&gt;Why am I getting "failed to open message queue" ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and from /opt/paloaltonetworks:&lt;/P&gt;
&lt;PRE&gt;$ cat /opt/paloaltonetworks/globalprotect/pan_gp_event.log&lt;BR /&gt;02/28/2024 17:38:43:863 [Info ]: GlobalProtect service started (client version: 6.1.4-711, OS version: Linux Red Hat Enterprise Linux 8.9).&lt;/PRE&gt;
&lt;P&gt;and finally&lt;/P&gt;
&lt;PRE&gt;$ cat /opt/paloaltonetworks/globalprotect/PanGPS.log&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:528 Debug( 336): PanGPS, working directory is /opt/paloaltonetworks/globalprotect/&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:529 Info ( 539): ####################### Start PanGPS service (ver: 6.1.4-711) #######################&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:529 Info ( 540): Debug level is 5, log path is /opt/paloaltonetworks/globalprotect/&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:530 Info ( 541): User is (null), home is /root, login is (null)&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:530 Info ( 150): Predeployed log-path-service is not set&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:530 Info ( 439): Get OS info: Red Hat Enterprise Linux 8.9&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:536 Debug( 464): Serial number is VMware-&amp;lt;redacted&amp;gt;&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:536 Debug( 107): IsDaemon is 1&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:541 Info ( 121): PrelogonEnabled is 0&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:541 Info ( 504): cannot open /var/run/PanGPS.pid, assume no old instance running&lt;BR /&gt;P1151-T711235328 02/28/2024 17:38:43:541 Info ( 687): debug thread starts&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:548 Debug( 285): stopping split tunnel feature!&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:548 Debug( 27): split tunnel script dir /opt/paloaltonetworks/globalprotect/network/config&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:551 Debug( 397): Uninstalling iptables DNS chain...&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:630 Debug( 27): split tunnel script dir /opt/paloaltonetworks/globalprotect/network/config&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:630 Debug( 459): Uninstalling iptables Split Tunnel chain &amp;amp; routing tables...&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:773 Debug( 306): split tunnel stopped!&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:773 Debug( 61): psv init called&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:833 Info (2458): CPanMSServiceLinux::findJoinDomain: szDomainName is : &amp;lt;DOMAIN&amp;gt;&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:833 Debug( 69): PanMSServiceLinux:ctor: m_szJoinDomain &amp;lt;DOMAIN&amp;gt;, m_szJoinDomainRaw &amp;lt;DOMAIN&amp;gt;&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:833 Debug( 72): PanMSServiceLinux:ctor: m_domainName &amp;lt;DOMAIN&amp;gt;, m_domainNameRaw &amp;lt;DOMAIN&amp;gt;&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:839 Debug( 683): Service-only is no&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:839 Debug( 735): Kerberos auth, stopOnKerberosFail=0()&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:839 Debug( 740): Prefer ipv6 is yes.&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:839 Debug( 763): CPanMSService::Init connect timeout 5, received timeout 30, portal timeout 5 &lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:839 Debug( 800): CPanMSService::Init fips: fipsc-cc-mode-enabled &lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:839 Debug( 810): CPanMSService::Init enable-fips-cc-mode &lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:839 Debug( 821): CPanMSService::Init fips: m_bFipsModeRequired 0 &lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:839 Debug( 238): GetValueBinary size 6&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:839 Debug( 899): Mac address is &amp;lt;00-00-00-00-00-00 redacted&amp;gt;&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:839 Debug(2402): pan_get_gp_user_agent szGpUserAgent ua is PAN GlobalProtect/6.1.4-711 (Linux Red Hat Enterprise Linux 8.9).&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:839 Info (10860): CheckPrelogon: Portal is , PrelogonEnabled is no&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:861 Debug( 949): override-cc-username is no&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:862 Debug(5123): event log file is /opt/paloaltonetworks/globalprotect//pan_gp_event.log&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:863 Debug( 959): Event log thread started&lt;BR /&gt;P1151-T702842624 02/28/2024 17:38:43:863 Debug(5092): event log thread started.&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:863 Debug( 167): Time zone GMT offset is 0&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:865 Info (10749): Portal config does not exist, try registry/plist&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:865 Debug( 354): default cert path is /etc/pki/tls/certs&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:865 Debug( 379): default private key path is /etc/pki/tls/private&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:865 Debug(1485): cfg no client cert.&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:865 Debug( 259): DLSA- agent is enable, restore lar during start up&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:865 Debug( 261): DLSA- Pan LAR file is /opt/paloaltonetworks/globalprotect/pan_lar.dat&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:866 Debug( 266): LAR file does not exist. &lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:866 Debug( 72): CControlManagerLinux::StartServer() isFipsModeRequired() 0&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:866 Debug( 554): Start tunnel driver.&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:881 Info ( 114): Service callback table gets set.&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:881 Debug( 230): set virtual interface driver started as yes&lt;BR /&gt;P1151-T733546304 02/28/2024 17:38:43:881 Debug( 592): Virtual interface is started&lt;BR /&gt;P1151-T686057216 02/28/2024 17:38:43:883 Info ( 102): Start ServerThread&lt;BR /&gt;P1151-T694449920 02/28/2024 17:38:43:883 Debug( 440): RecvThread started.&lt;BR /&gt;P1151-T686057216 02/28/2024 17:38:43:885 Debug( 84): thread StartPanGPAThread is created.&lt;BR /&gt;P1151-T686057216 02/28/2024 17:38:43:885 Debug(10886): CPanMSService::StartPrelogonThread DaemonProcess: yes, InPrelogon: no&lt;BR /&gt;P1151-T686057216 02/28/2024 17:38:43:885 Debug(13470): Enforcer is not enabled&amp;nbsp;&amp;nbsp;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;RHEL 8 does not use iptables.&lt;/P&gt;
&lt;P&gt;It uses nftables (and firewalld)&lt;/P&gt;
&lt;P&gt;What is it trying to do with Kerberos ?&lt;/P&gt;
&lt;P&gt;Where should the portal config be and what is the syntax / content ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have lots more questions and I am still looking for answers, please.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 18:15:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/rhel-8-cannot-connect-to-local-gpd-service/m-p/578688#M5045</guid>
      <dc:creator>D.White003479</dc:creator>
      <dc:date>2024-02-28T18:15:01Z</dc:date>
    </item>
  </channel>
</rss>

