<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic GP Connection Failed - gateway could not verify the server certiticate of the gateway. in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-connection-failed-gateway-could-not-verify-the-server/m-p/582798#M5228</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;I have GP setup and working like a dream..... most of the times.&lt;/P&gt;
&lt;P&gt;however i have a strange issue.. and seems to only affect Azure cloud PCs at the moment, normal users with laptops and desktops can connect no problem.&lt;/P&gt;
&lt;P&gt;my certs are all valid and signed by an external CA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;however on Azure cloud PC's the connections are very intermittent.. works maybe 1/6 attempts. most of the time users get the error around unable to verify the certificate on the gateway.&lt;/P&gt;
&lt;P&gt;pan-os running 10.1.10-h2&lt;/P&gt;
&lt;P&gt;gp app version is 6.1.2&lt;/P&gt;
&lt;P&gt;windows cloud PC running windows 365 enterprise, 2vCPU, 8gb and 256 GB SSD&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;tried deleting dat files on local drive, no luck.&lt;/P&gt;
&lt;P&gt;tried unistall / reinstall GP app no luck.&lt;/P&gt;
&lt;P&gt;tried with full admin rights, same issue.&lt;/P&gt;
&lt;P&gt;tried installing the certs locally to the PC's in the certificate store.. no luck.&lt;/P&gt;
&lt;P&gt;from these cloud PC's, i can log into the portal fine and no complaints about certificate&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;any ideas doubt there are much testing around these as yet.. might have to log a call with MS also.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks in adv&lt;/P&gt;</description>
    <pubDate>Fri, 05 Apr 2024 14:21:25 GMT</pubDate>
    <dc:creator>PA_nts</dc:creator>
    <dc:date>2024-04-05T14:21:25Z</dc:date>
    <item>
      <title>GP Connection Failed - gateway could not verify the server certiticate of the gateway.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-connection-failed-gateway-could-not-verify-the-server/m-p/582798#M5228</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;I have GP setup and working like a dream..... most of the times.&lt;/P&gt;
&lt;P&gt;however i have a strange issue.. and seems to only affect Azure cloud PCs at the moment, normal users with laptops and desktops can connect no problem.&lt;/P&gt;
&lt;P&gt;my certs are all valid and signed by an external CA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;however on Azure cloud PC's the connections are very intermittent.. works maybe 1/6 attempts. most of the time users get the error around unable to verify the certificate on the gateway.&lt;/P&gt;
&lt;P&gt;pan-os running 10.1.10-h2&lt;/P&gt;
&lt;P&gt;gp app version is 6.1.2&lt;/P&gt;
&lt;P&gt;windows cloud PC running windows 365 enterprise, 2vCPU, 8gb and 256 GB SSD&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;tried deleting dat files on local drive, no luck.&lt;/P&gt;
&lt;P&gt;tried unistall / reinstall GP app no luck.&lt;/P&gt;
&lt;P&gt;tried with full admin rights, same issue.&lt;/P&gt;
&lt;P&gt;tried installing the certs locally to the PC's in the certificate store.. no luck.&lt;/P&gt;
&lt;P&gt;from these cloud PC's, i can log into the portal fine and no complaints about certificate&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;any ideas doubt there are much testing around these as yet.. might have to log a call with MS also.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks in adv&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2024 14:21:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-connection-failed-gateway-could-not-verify-the-server/m-p/582798#M5228</guid>
      <dc:creator>PA_nts</dc:creator>
      <dc:date>2024-04-05T14:21:25Z</dc:date>
    </item>
    <item>
      <title>Re: GP Connection Failed - gateway could not verify the server certiticate of the gateway.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-connection-failed-gateway-could-not-verify-the-server/m-p/582807#M5229</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do verify, is your Gateway certificate a public cert or just the portal? And do you Azure machines trust this public root/intermediate certificate?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would also check the GlobalProtect logs on the firewall gateway and see if there is any more error information that points to anything.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;I would also check the clients GlobalProtect debug logs, specfically the pangps and pangpa logs, as there should be more information related to specifically what it didnt like.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Claw4609_0-1712332483560.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58867iAF642BEC861892BE/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Claw4609_0-1712332483560.png" alt="Claw4609_0-1712332483560.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2024 15:54:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-connection-failed-gateway-could-not-verify-the-server/m-p/582807#M5229</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2024-04-05T15:54:50Z</dc:date>
    </item>
    <item>
      <title>Re: GP Connection Failed - gateway could not verify the server certiticate of the gateway.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-connection-failed-gateway-could-not-verify-the-server/m-p/1220923#M6476</link>
      <description>&lt;P&gt;Did you ever find a fix for this? I am dealing with the same problem. Thanks.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2025 14:09:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-connection-failed-gateway-could-not-verify-the-server/m-p/1220923#M6476</guid>
      <dc:creator>matt</dc:creator>
      <dc:date>2025-02-19T14:09:10Z</dc:date>
    </item>
    <item>
      <title>Re: GP Connection Failed - gateway could not verify the server certiticate of the gateway.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-connection-failed-gateway-could-not-verify-the-server/m-p/1221090#M6488</link>
      <description>&lt;P&gt;Hey Matt,&lt;/P&gt;
&lt;P&gt;shu long time ago..&lt;/P&gt;
&lt;P&gt;yes it was resolved and the issue in our case was down to the users not having the correct permissions on the cloud PCs to install the certs locally.&lt;/P&gt;
&lt;P&gt;I think the Application teams in the end included the certs to install when they did a cloud pc rollout/deployment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;rgds&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2025 06:40:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-connection-failed-gateway-could-not-verify-the-server/m-p/1221090#M6488</guid>
      <dc:creator>PA_nts</dc:creator>
      <dc:date>2025-02-20T06:40:36Z</dc:date>
    </item>
    <item>
      <title>Re: GP Connection Failed - gateway could not verify the server certiticate of the gateway.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-connection-failed-gateway-could-not-verify-the-server/m-p/1221118#M6492</link>
      <description>&lt;P&gt;Thank you for taking the time to reply.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;If you are able to provide any further insight then please do, this issue is getting old fast and I want it resolved!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2025 10:40:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-connection-failed-gateway-could-not-verify-the-server/m-p/1221118#M6492</guid>
      <dc:creator>matt</dc:creator>
      <dc:date>2025-02-20T10:40:39Z</dc:date>
    </item>
    <item>
      <title>Re: GP Connection Failed - gateway could not verify the server certiticate of the gateway.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-connection-failed-gateway-could-not-verify-the-server/m-p/1221127#M6494</link>
      <description>&lt;P&gt;I dont have more info unfortunately.. &lt;/P&gt;
&lt;P&gt;what you can do however, is export the cert from the portal, then connect to the cloud PC. and see if you can install said certificate from your portal to your local certificate store with the account that does not work.. chances are&amp;nbsp; you wont be able to due to insufficient permissions..&lt;/P&gt;
&lt;P&gt;If this is the case, then try and elevate the permissions to admin rights or similar and retry the cert install - if this works and install then log out, change your permissions back to what it was.. log back in and test.. if this works then you have found your issue.. &lt;/P&gt;
&lt;P&gt;then you will need to work with the system admin to allow users to add this cert to their local cert store.. another option is for them to do this via the group policy (assuming you are running windows ad) to install the certs locally on these machines.&lt;/P&gt;
&lt;P&gt;sorry it is all the info i have atm &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;good luck.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2025 11:41:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-connection-failed-gateway-could-not-verify-the-server/m-p/1221127#M6494</guid>
      <dc:creator>PA_nts</dc:creator>
      <dc:date>2025-02-20T11:41:08Z</dc:date>
    </item>
    <item>
      <title>Re: GP Connection Failed - gateway could not verify the server certiticate of the gateway.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-connection-failed-gateway-could-not-verify-the-server/m-p/1245808#M7219</link>
      <description>&lt;P&gt;I ran into this same issue adding an external local datecenter gateway to our prisma services. I couldn't find a resolution from my palo PS service so I went troubleshooting:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The resolution is to add the gateway certificate to the Portal under: Network Tab, GlobalProtect, Portals, open the GlobalProtect Portal Configuration, Click on Agent, and under "TRUSTED ROOT CA" add the Gateway certificate and check "INSTALL LOCAL ROOT CERTIFICATE STORE"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This will install the certificate to the client when it connects to the portal and allow the client to verify the certificate when connecting to the gateway.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jan 2026 22:34:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-connection-failed-gateway-could-not-verify-the-server/m-p/1245808#M7219</guid>
      <dc:creator>M.omweno</dc:creator>
      <dc:date>2026-01-16T22:34:57Z</dc:date>
    </item>
  </channel>
</rss>

