<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem Using New Digitally Signed Certificate in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/problem-using-new-digitally-signed-certificate/m-p/583447#M5245</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/257048"&gt;@kiwi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Configuration for&amp;nbsp;&lt;SPAN&gt;remote2.watsons.com.ph seems to be inplace.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;What else can you suggest we need to check?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please see attached picture&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 702px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59021i81B38212476A9137/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 12 Apr 2024 00:49:58 GMT</pubDate>
    <dc:creator>NickoKristian</dc:creator>
    <dc:date>2024-04-12T00:49:58Z</dc:date>
    <item>
      <title>Problem Using New Digitally Signed Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/problem-using-new-digitally-signed-certificate/m-p/582604#M5216</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One of our client has signed and imported a new certificate. It is showing as valid.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But when we apply necessary changes to use this certificate and try to connect. It is displaying this error&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"Connection Failed:Gateway isp2-gw: Could not verify the server certificate of the gateway. If the issue persists, contact your administrator."&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have extracted debug logs for this and I am seeing this error.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(P5156-T19156)Debug(3644): 04/02/24 17:15:24:568 ----Gateway Pre-login starts----&lt;BR /&gt;(P5156-T19156)Debug(13345): 04/02/24 17:15:24:568 Check cert of server 202.57.50.146&lt;BR /&gt;(P5156-T19156)Debug( 931): 04/02/24 17:15:24:569 SSL connecting to 202.57.50.146&lt;BR /&gt;(P5156-T19156)Debug( 571): 04/02/24 17:15:24:574 Network is reachable&lt;BR /&gt;(P5156-T16668)Debug( 136): 04/02/24 17:15:24:594 Wait for the ready event of hip report generated in other process.&lt;BR /&gt;(P5156-T19156)Debug(1500): 04/02/24 17:15:25:295 Unable to verify server cert. Result is unable to get local issuer certificate &lt;BR /&gt;(P5156-T19156)Debug(1043): 04/02/24 17:15:25:295 Hostname 202.57.50.146 doesn't matche sub alt name remote2.watsons.com.ph&lt;BR /&gt;(P5156-T19156)Debug(1058): 04/02/24 17:15:25:295 CheckServerCertName: bFips false, validExtensionCount 1&lt;BR /&gt;(P5156-T19156)Debug(1066): 04/02/24 17:15:25:295 Hostname 202.57.50.146 doesn't match sub alt name or no sub alt name, fallback to CN &lt;BR /&gt;(P5156-T19156)Debug(1106): 04/02/24 17:15:25:295 Hostname 202.57.50.146 NOT match remote2.watsons.com.ph &lt;BR /&gt;(P5156-T19156)Debug(1537): 04/02/24 17:15:25:295 OpenSSL alert write&lt;span class="lia-unicode-emoji" title=":warning:"&gt;⚠️&lt;/span&gt;close notify&lt;BR /&gt;(P5156-T19156)Debug(6529): 04/02/24 17:15:25:295 pretunnel latency (manual gateway) is 513&lt;BR /&gt;(P5156-T19156)Error(3702): 04/02/24 17:15:25:295 Failed to verify server certificate of gateway 202.57.50.146.&lt;BR /&gt;(P5156-T19156)Debug(5851): 04/02/24 17:15:25:295 Show Gateway isp2-gw: Could not verify the server certificate of the gateway. If the issue persists, contact your administrator.&lt;BR /&gt;(P5156-T19156)Info (2701): 04/02/24 17:15:25:295 Failed to retrieve info for gateway 202.57.50.146.&lt;BR /&gt;(P5156-T19156)Debug(2712): 04/02/24 17:15:25:295 tunnel to 202.57.50.146 is not created.&lt;BR /&gt;(P5156-T19156)Error(6907): 04/02/24 17:15:25:295 NetworkDiscoverThread: failed to discover external network.&lt;BR /&gt;(P5156-T19156)Debug(7986): 04/02/24 17:15:25:295 --Set state to Disconnected&lt;BR /&gt;(P5156-T19156)Debug(6971): 04/02/24 17:15:25:296 NetworkDiscoverThread: PortalStatus is 2, HasLoggedOnGateway is 0&lt;BR /&gt;(P5156-T19156)Debug(6973): 04/02/24 17:15:25:296 NetworkDiscoverThread: ((PORTAL_CACHED_CONFIG == m_nPortalStatus) &amp;amp;&amp;amp; !m_bHasLoggedOnGateway)&lt;BR /&gt;(P5156-T19156)Debug(6994): 04/02/24 17:15:25:296 Network discovery is not ready, set GP VPN status as disconnected&lt;BR /&gt;(P5156-T19156)Debug(13515): 04/02/24 17:15:25:296 SetVpnStatus called with new status=0, Previous Status=0&lt;BR /&gt;(P5156-T7096)Debug(2625): 04/02/24 17:15:25:296 Setting debug level to 5&lt;BR /&gt;(P5156-T19156)Debug(4503): 04/02/24 17:15:25:296 UpdatePrelogonStateForSSO() - tunnel state = Disconnected&lt;BR /&gt;(P5156-T19156)Debug(11258): 04/02/24 17:15:25:296 CPanMSService::OnVpnStatusProxyAgent: tunnel only, stop the proxy.&lt;BR /&gt;(P5156-T20316)Debug(6101): 04/02/24 17:15:26:571 CPD, reset cp detection history&lt;BR /&gt;(P5156-T20316)Debug(2410): 04/02/24 17:15:26:571 pan_get_gp_user_agent szGpUserAgent ua is PAN GlobalProtect/6.2.1-132 (Microsoft Windows 11 Pro , 64-bit).&lt;BR /&gt;(P5156-T20316)Debug( 571): 04/02/24 17:15:27:178 Network is reachable&lt;BR /&gt;(P5156-T20316)Debug( 149): 04/02/24 17:15:27:442 CPD, pan_http_captive_portal_detection: status is 200&lt;BR /&gt;(P5156-T20316)Debug( 162): 04/02/24 17:15:27:442 CPD, pan_http_captive_portal_detection() - captive portal isn't detected against server.&lt;BR /&gt;(P5156-T20316)Debug(6114): 04/02/24 17:15:27:443 CPD, index=0, iRet=-1, lastError=0&lt;BR /&gt;(P5156-T20316)Debug(6132): 04/02/24 17:15:27:443 CPD, CaptivePortalDetectionThread: captive portal is not detected for CP server. iStatus = 200&lt;BR /&gt;(P5156-T20316)Debug(2410): 04/02/24 17:15:27:443 pan_get_gp_user_agent szGpUserAgent ua is PAN GlobalProtect/6.2.1-132 (Microsoft Windows 11 Pro , 64-bit).&lt;BR /&gt;(P5156-T20316)Debug( 571): 04/02/24 17:15:27:534 Network is reachable&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anything Significant we can look into this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am trying to look for articles similar to "Hostname 202.57.50.146 doesn't matche sub alt name remote2.watsons.com.ph" &amp;lt;-- because I think this is the cause.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But I cannot find any steps/guide to tshoot this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Need your help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Nicko&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="GlobalProtect" id="GlobalProtect"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2024 06:52:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/problem-using-new-digitally-signed-certificate/m-p/582604#M5216</guid>
      <dc:creator>NickoKristian</dc:creator>
      <dc:date>2024-04-04T06:52:09Z</dc:date>
    </item>
    <item>
      <title>Re: Problem Using New Digitally Signed Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/problem-using-new-digitally-signed-certificate/m-p/583243#M5241</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/295338"&gt;@NickoKristian&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The error "&lt;SPAN&gt;Hostname &lt;/SPAN&gt;ABC &lt;SPAN&gt;doesn't match sub alt name XYZ" is usually an indication that the server certificate used in the SSL/TLS profile for gateway is incorrect.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I'd check the following:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;Navigate to the portal settings &amp;gt; Agent &amp;gt; Agent config &amp;gt; External Gateways.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Verify the FQDN for the gateway, provided in the above setting is matching the CN(common name) in the certificate called in the SSL/TLS profile, in the firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please use the appropriate certificate in the SSL/TLS profile with a CN (common name) that corresponds to the data given in the aforementioned portal settings.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;Kim.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2024 15:53:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/problem-using-new-digitally-signed-certificate/m-p/583243#M5241</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2024-04-10T15:53:42Z</dc:date>
    </item>
    <item>
      <title>Re: Problem Using New Digitally Signed Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/problem-using-new-digitally-signed-certificate/m-p/583447#M5245</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/257048"&gt;@kiwi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Configuration for&amp;nbsp;&lt;SPAN&gt;remote2.watsons.com.ph seems to be inplace.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;What else can you suggest we need to check?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please see attached picture&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 702px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59021i81B38212476A9137/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2024 00:49:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/problem-using-new-digitally-signed-certificate/m-p/583447#M5245</guid>
      <dc:creator>NickoKristian</dc:creator>
      <dc:date>2024-04-12T00:49:58Z</dc:date>
    </item>
    <item>
      <title>Re: Problem Using New Digitally Signed Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/problem-using-new-digitally-signed-certificate/m-p/594037#M5631</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;NS Lookup to google shows it at a&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Name: remote2.watsons.com.ph&lt;BR /&gt;Address: 202.57.50.146&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;if your local endpoint cannot use DNS make this resolution, it will fail. For example If you are handing up to umbrella or some other dns filtering and the&amp;nbsp;&amp;nbsp;url remote2.watsons.com.ph classified as malware or some other filtered category, resolution will fail and cause a disconnect between the url and the CN/SAN in the cert. . If that is not the case, run nslookup or dig against the record on the&amp;nbsp; local host and see if it resolves to the correct address. I suspect a DNS issue.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Edit:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Also make sure you are using the DNS name in the GP Portal field and not the IP address.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2024 20:10:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/problem-using-new-digitally-signed-certificate/m-p/594037#M5631</guid>
      <dc:creator>NSutfin</dc:creator>
      <dc:date>2024-08-05T20:10:28Z</dc:date>
    </item>
  </channel>
</rss>

