<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to reach Palo Alto - Global Protect Portal. in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/unable-to-reach-palo-alto-global-protect-portal/m-p/1241352#M7118</link>
    <description>&lt;P&gt;if you just run a continuous ping against your public IP, are you then seeing new sessions being created for ping? could be yourVPC hasn't been set up correctly, or your SG is blocking inbound connections ?&lt;/P&gt;</description>
    <pubDate>Thu, 06 Nov 2025 09:30:09 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2025-11-06T09:30:09Z</dc:date>
    <item>
      <title>Unable to reach Palo Alto - Global Protect Portal.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/unable-to-reach-palo-alto-global-protect-portal/m-p/1241271#M7115</link>
      <description>&lt;P&gt;Hey everyone,&lt;BR /&gt;I’m currently deploying a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;GlobalProtect VPN&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;on a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Palo Alto VM-Series&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;firewall running&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;PAN-OS 10.2.16-h4&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;AWS&lt;/STRONG&gt;.&lt;BR /&gt;Everything seems correctly configured according to the official&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;GlobalProtect Admin Guide&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(portal, gateway, SSL/TLS certs, interfaces, routes, and security policies), but the portal is still unreachable via browser or&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;Test-NetConnection&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;on port 443.&lt;/P&gt;
&lt;P&gt;Current setup:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Portal interface:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;ethernet1/1 — IP&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="relative pointer-events-auto a cursor-pointer
  
  
  
  
  underline
  " href="http://16.54.17.200/" target="_blank" rel="noopener nofollow noreferrer ugc"&gt;16.54.17.200&lt;/A&gt;, zone&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;untrust&lt;/EM&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Gateway interface:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;same (ethernet1/1)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Tunnel interface:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;tunnel.1 — zone&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;corp-vpn&lt;/EM&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Mgmt profile:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;HTTPS enabled&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Security rule:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;allows any from untrust → untrust (for testing)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Certificate:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;self-signed assigned to SSL/TLS profile used by both Portal and Gateway&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Routing:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;default VR configured correctly&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Processes running:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;sslvpn_ngx&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;sslmgr&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;confirmed running&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Ping to&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="relative pointer-events-auto a cursor-pointer
  
  
  
  
  underline
  " href="http://8.8.8.8/" target="_blank" rel="noopener nofollow noreferrer ugc"&gt;&lt;STRONG&gt;8.8.8.8&lt;/STRONG&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;works&lt;/STRONG&gt;, but portal (&lt;A class="relative pointer-events-auto a cursor-pointer
  
  
  
  
  underline
  " href="https://16.54.17.200/" target="_blank" rel="noopener nofollow noreferrer ugc"&gt;https://16.54.17.200&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;or&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="relative pointer-events-auto a cursor-pointer
  
  
  
  
  underline
  " href="https://vpn.trustedgateway.org/" target="_blank" rel="noopener nofollow noreferrer ugc"&gt;https://vpn.trustedgateway.org&lt;/A&gt;) doesn’t respond.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;What I’ve already tried:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Restarted web-server, sslmgr, and management-server processes.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Recreated Portal/Gateway from scratch.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Verified NAT, Security, and Virtual Router configs.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Updated PAN-OS from 10.2.13-h4 → 10.2.16-h4 (still same issue).&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Logs:&lt;/P&gt;
&lt;P&gt;No active sessions on port 443.&lt;/P&gt;
&lt;P&gt;"admin@PA-VM-CA&amp;gt; show session all filter destination&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="relative pointer-events-auto a cursor-pointer
  
  
  
  
  underline
  " href="http://16.54.17.200/" target="_blank" rel="noopener nofollow noreferrer ugc"&gt;16.54.17.200&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;destination-port 443&lt;/P&gt;
&lt;P&gt;No Active Sessions".&lt;/P&gt;
&lt;P&gt;Question:&lt;/P&gt;
&lt;P&gt;Has anyone faced a similar issue where the GlobalProtect portal won’t respond on HTTPS, even when the services and config look fine?&lt;/P&gt;
&lt;P&gt;Could this be related to a PAN-OS bug or certificate binding issue?&lt;/P&gt;
&lt;P&gt;Any suggestions or debug commands to trace portal traffic at process level would be appreciated.&lt;/P&gt;
&lt;P&gt;Preciate any help since I cant create a support ticket on Palo alto!.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Nov 2025 16:59:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/unable-to-reach-palo-alto-global-protect-portal/m-p/1241271#M7115</guid>
      <dc:creator>asamboni</dc:creator>
      <dc:date>2025-11-05T16:59:21Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to reach Palo Alto - Global Protect Portal.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/unable-to-reach-palo-alto-global-protect-portal/m-p/1241352#M7118</link>
      <description>&lt;P&gt;if you just run a continuous ping against your public IP, are you then seeing new sessions being created for ping? could be yourVPC hasn't been set up correctly, or your SG is blocking inbound connections ?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Nov 2025 09:30:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/unable-to-reach-palo-alto-global-protect-portal/m-p/1241352#M7118</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2025-11-06T09:30:09Z</dc:date>
    </item>
  </channel>
</rss>

