<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Gateway Unresponsive or unreachable. in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gateway-unresponsive-or-unreachable/m-p/606905#M5970</link>
    <description>&lt;P&gt;Unable to connect to one of our global protect gateways. Debug log of PanGPS attached with its attempt to connect to the gateway. I have checked all the gateway settings, and they match the working gateway, so I am at a loss on what to look for. The working Gateway is on a HA pair of 5220 in active/passive mode, and the non working gateway is on a HA pair of 3420 in active/passive mode.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(P4512-T18044)Debug(5680): 10/18/24 09:30:16:912 getaddrinfo host.GetString() &amp;lt;correct external ip&amp;gt; &lt;BR /&gt;(P4512-T18044)Debug(5804): 10/18/24 09:30:16:951 Gateway &amp;lt;correct external ip&amp;gt;(&amp;lt;correct external ip&amp;gt;): ipv4 &amp;lt;correct external ip&amp;gt;, ipv6 , FQDN yes&lt;BR /&gt;(P4512-T18044)Debug(4987): 10/18/24 09:30:16:951 Reset saml auth status for manual gateway&lt;BR /&gt;(P4512-T18044)Debug(4992): 10/18/24 09:30:16:951 dwRemoteHost is 0 for gateway &amp;lt;correct external ip&amp;gt;. Retrieve client ip.&lt;BR /&gt;(P4512-T18044)Debug(3106): 10/18/24 09:30:16:951 Gateway: &amp;lt;correct external ip&amp;gt;, client IP: 172.22.145.27&lt;BR /&gt;(P4512-T18044)Debug(7993): 10/18/24 09:30:16:951 --Set state to Connecting...&lt;BR /&gt;(P4512-T18044)Debug(2645): 10/18/24 09:30:16:951 retrieve info of gateway &amp;lt;correct external ip&amp;gt;&lt;BR /&gt;(P4512-T18044)Debug(2410): 10/18/24 09:30:16:951 pan_get_gp_user_agent szGpUserAgent ua is PAN GlobalProtect/6.2.2-259 (Microsoft Windows 10 Enterprise , 64-bit).&lt;BR /&gt;(P4512-T18044)Debug(2468): 10/18/24 09:30:16:951 open http session. agent is PAN GlobalProtect/6.2.2-259 (Microsoft Windows 10 Enterprise , 64-bit)&lt;BR /&gt;(P4512-T18044)Debug(2410): 10/18/24 09:30:16:951 pan_get_gp_user_agent szGpUserAgent ua is PAN GlobalProtect/6.2.2-259 (Microsoft Windows 10 Enterprise , 64-bit).&lt;BR /&gt;(P4512-T18044)Debug( 476): 10/18/24 09:30:16:956 winhttp SetSecureProtocol, hSession=f7b78da0, bAllProtocol=0, gbFips=0&lt;BR /&gt;(P4512-T18044)Debug(2656): 10/18/24 09:30:16:956 Skip setting proxy for creating tunnel to gateway &amp;lt;correct external ip&amp;gt;&lt;BR /&gt;(P4512-T18044)Debug(3599): 10/18/24 09:30:16:956 m_msp-&amp;gt;IsInPreserveTunnel() 0, m_msp-&amp;gt;IsPrelogonRenameAuthFail() 0&lt;BR /&gt;(P4512-T18044)Debug(16119): 10/18/24 09:30:16:956 Set m_bPrelogonRenameAuthFail to 0&lt;BR /&gt;(P4512-T18044)Debug(3629): 10/18/24 09:30:16:956 CPanGateway::RetrieveGatewayInfo portal default-browser value is 0, support yes &lt;BR /&gt;(P4512-T18044)Debug(3644): 10/18/24 09:30:16:956 ----Gateway Pre-login starts----&lt;BR /&gt;(P4512-T18044)Debug(13355): 10/18/24 09:30:16:956 Check cert of server &amp;lt;correct external ip&amp;gt;&lt;BR /&gt;(P4512-T18044)Debug(13370): 10/18/24 09:30:16:956 File C:\Program Files\Palo Alto Networks\GlobalProtect\tca.cer does not exist.&lt;BR /&gt;(P4512-T18044)Debug( 931): 10/18/24 09:30:16:956 SSL connecting to &amp;lt;correct external ip&amp;gt;&lt;BR /&gt;(P4512-T18044)Debug( 571): 10/18/24 09:30:16:960 Network is reachable&lt;BR /&gt;(P4512-T18044)Debug( 104): 10/18/24 09:30:21:989 connect failed with 5 seconds timeout.&lt;BR /&gt;(P4512-T18044)Debug( 626): 10/18/24 09:30:21:989 Failed to connect to &amp;lt;correct external ip&amp;gt; on 443 with return value -1 and socket error 0(0)&lt;BR /&gt;(P4512-T18044)Debug( 936): 10/18/24 09:30:21:989 do_tcp_connect() failed&lt;BR /&gt;(P4512-T18044)Error(13402): 10/18/24 09:30:21:989 ConnectSSL: Failed to connect to '&amp;lt;correct external ip&amp;gt;:443'. Disconnect ssl.&lt;BR /&gt;(P4512-T18044)Debug(13415): 10/18/24 09:30:21:989 Cannot get server cert of &amp;lt;correct external ip&amp;gt;&lt;BR /&gt;(P4512-T18044)Debug(6518): 10/18/24 09:30:21:989 Already tried both ipv4 and ipv6 for gateway &amp;lt;correct external ip&amp;gt;&lt;BR /&gt;(P4512-T18044)Debug(6529): 10/18/24 09:30:21:989 pretunnel latency (manual gateway) is 1&lt;BR /&gt;(P4512-T18044)Error(3695): 10/18/24 09:30:21:989 Failed to connect to gateway &amp;lt;correct external ip&amp;gt;.&lt;BR /&gt;(P4512-T18044)Debug(5837): 10/18/24 09:30:21:989 pg, error message for manual select gateway will not show.&lt;BR /&gt;(P4512-T18044)Debug(5851): 10/18/24 09:30:21:989 Show Gateway &amp;lt;correct external ip&amp;gt;: The network connection is unreachable or the gateway is unresponsive. Check the network connection and reconnect.&lt;/P&gt;</description>
    <pubDate>Fri, 18 Oct 2024 14:51:16 GMT</pubDate>
    <dc:creator>M.Caudle</dc:creator>
    <dc:date>2024-10-18T14:51:16Z</dc:date>
    <item>
      <title>Gateway Unresponsive or unreachable.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gateway-unresponsive-or-unreachable/m-p/606905#M5970</link>
      <description>&lt;P&gt;Unable to connect to one of our global protect gateways. Debug log of PanGPS attached with its attempt to connect to the gateway. I have checked all the gateway settings, and they match the working gateway, so I am at a loss on what to look for. The working Gateway is on a HA pair of 5220 in active/passive mode, and the non working gateway is on a HA pair of 3420 in active/passive mode.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(P4512-T18044)Debug(5680): 10/18/24 09:30:16:912 getaddrinfo host.GetString() &amp;lt;correct external ip&amp;gt; &lt;BR /&gt;(P4512-T18044)Debug(5804): 10/18/24 09:30:16:951 Gateway &amp;lt;correct external ip&amp;gt;(&amp;lt;correct external ip&amp;gt;): ipv4 &amp;lt;correct external ip&amp;gt;, ipv6 , FQDN yes&lt;BR /&gt;(P4512-T18044)Debug(4987): 10/18/24 09:30:16:951 Reset saml auth status for manual gateway&lt;BR /&gt;(P4512-T18044)Debug(4992): 10/18/24 09:30:16:951 dwRemoteHost is 0 for gateway &amp;lt;correct external ip&amp;gt;. Retrieve client ip.&lt;BR /&gt;(P4512-T18044)Debug(3106): 10/18/24 09:30:16:951 Gateway: &amp;lt;correct external ip&amp;gt;, client IP: 172.22.145.27&lt;BR /&gt;(P4512-T18044)Debug(7993): 10/18/24 09:30:16:951 --Set state to Connecting...&lt;BR /&gt;(P4512-T18044)Debug(2645): 10/18/24 09:30:16:951 retrieve info of gateway &amp;lt;correct external ip&amp;gt;&lt;BR /&gt;(P4512-T18044)Debug(2410): 10/18/24 09:30:16:951 pan_get_gp_user_agent szGpUserAgent ua is PAN GlobalProtect/6.2.2-259 (Microsoft Windows 10 Enterprise , 64-bit).&lt;BR /&gt;(P4512-T18044)Debug(2468): 10/18/24 09:30:16:951 open http session. agent is PAN GlobalProtect/6.2.2-259 (Microsoft Windows 10 Enterprise , 64-bit)&lt;BR /&gt;(P4512-T18044)Debug(2410): 10/18/24 09:30:16:951 pan_get_gp_user_agent szGpUserAgent ua is PAN GlobalProtect/6.2.2-259 (Microsoft Windows 10 Enterprise , 64-bit).&lt;BR /&gt;(P4512-T18044)Debug( 476): 10/18/24 09:30:16:956 winhttp SetSecureProtocol, hSession=f7b78da0, bAllProtocol=0, gbFips=0&lt;BR /&gt;(P4512-T18044)Debug(2656): 10/18/24 09:30:16:956 Skip setting proxy for creating tunnel to gateway &amp;lt;correct external ip&amp;gt;&lt;BR /&gt;(P4512-T18044)Debug(3599): 10/18/24 09:30:16:956 m_msp-&amp;gt;IsInPreserveTunnel() 0, m_msp-&amp;gt;IsPrelogonRenameAuthFail() 0&lt;BR /&gt;(P4512-T18044)Debug(16119): 10/18/24 09:30:16:956 Set m_bPrelogonRenameAuthFail to 0&lt;BR /&gt;(P4512-T18044)Debug(3629): 10/18/24 09:30:16:956 CPanGateway::RetrieveGatewayInfo portal default-browser value is 0, support yes &lt;BR /&gt;(P4512-T18044)Debug(3644): 10/18/24 09:30:16:956 ----Gateway Pre-login starts----&lt;BR /&gt;(P4512-T18044)Debug(13355): 10/18/24 09:30:16:956 Check cert of server &amp;lt;correct external ip&amp;gt;&lt;BR /&gt;(P4512-T18044)Debug(13370): 10/18/24 09:30:16:956 File C:\Program Files\Palo Alto Networks\GlobalProtect\tca.cer does not exist.&lt;BR /&gt;(P4512-T18044)Debug( 931): 10/18/24 09:30:16:956 SSL connecting to &amp;lt;correct external ip&amp;gt;&lt;BR /&gt;(P4512-T18044)Debug( 571): 10/18/24 09:30:16:960 Network is reachable&lt;BR /&gt;(P4512-T18044)Debug( 104): 10/18/24 09:30:21:989 connect failed with 5 seconds timeout.&lt;BR /&gt;(P4512-T18044)Debug( 626): 10/18/24 09:30:21:989 Failed to connect to &amp;lt;correct external ip&amp;gt; on 443 with return value -1 and socket error 0(0)&lt;BR /&gt;(P4512-T18044)Debug( 936): 10/18/24 09:30:21:989 do_tcp_connect() failed&lt;BR /&gt;(P4512-T18044)Error(13402): 10/18/24 09:30:21:989 ConnectSSL: Failed to connect to '&amp;lt;correct external ip&amp;gt;:443'. Disconnect ssl.&lt;BR /&gt;(P4512-T18044)Debug(13415): 10/18/24 09:30:21:989 Cannot get server cert of &amp;lt;correct external ip&amp;gt;&lt;BR /&gt;(P4512-T18044)Debug(6518): 10/18/24 09:30:21:989 Already tried both ipv4 and ipv6 for gateway &amp;lt;correct external ip&amp;gt;&lt;BR /&gt;(P4512-T18044)Debug(6529): 10/18/24 09:30:21:989 pretunnel latency (manual gateway) is 1&lt;BR /&gt;(P4512-T18044)Error(3695): 10/18/24 09:30:21:989 Failed to connect to gateway &amp;lt;correct external ip&amp;gt;.&lt;BR /&gt;(P4512-T18044)Debug(5837): 10/18/24 09:30:21:989 pg, error message for manual select gateway will not show.&lt;BR /&gt;(P4512-T18044)Debug(5851): 10/18/24 09:30:21:989 Show Gateway &amp;lt;correct external ip&amp;gt;: The network connection is unreachable or the gateway is unresponsive. Check the network connection and reconnect.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Oct 2024 14:51:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gateway-unresponsive-or-unreachable/m-p/606905#M5970</guid>
      <dc:creator>M.Caudle</dc:creator>
      <dc:date>2024-10-18T14:51:16Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway Unresponsive or unreachable.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gateway-unresponsive-or-unreachable/m-p/613919#M6001</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/614537389"&gt;@M.Caudle&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It looks like the issue might be the SSL cert. The log shows, “Cannot get server cert,” I’d recommend double-checking that the SSL/TLS certificate on the non-working gateway is set up properly and matches the one on your working gateway. Also, make sure the certificate chain is complete and trusted by the client.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2024 15:17:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gateway-unresponsive-or-unreachable/m-p/613919#M6001</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2024-10-23T15:17:20Z</dc:date>
    </item>
  </channel>
</rss>

