<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Subject: GlobalProtect Connection Issue After SSL/TLS Certificate Renewal in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/subject-globalprotect-connection-issue-after-ssl-tls-certificate/m-p/1235235#M6147</link>
    <description>&lt;P data-start="162" data-end="173"&gt;Hello Team,&lt;/P&gt;
&lt;P data-start="175" data-end="358"&gt;We’re currently experiencing an issue where GlobalProtect is not accessible after renewing the server certificate associated with the SSL/TLS profile used by our GlobalProtect portal.&lt;/P&gt;
&lt;P data-start="360" data-end="518"&gt;&lt;STRONG data-start="360" data-end="378"&gt;Error message:&lt;/STRONG&gt;&lt;BR data-start="378" data-end="381" /&gt;&lt;EM data-start="381" data-end="518"&gt;GlobalProtect: Connection Failed. The network is unreachable or the portal is unresponsive. Check the network connection and reconnect.&lt;/EM&gt;&lt;/P&gt;
&lt;P data-start="520" data-end="603"&gt;The portal is also not loading in a web browser, returning a &lt;CODE data-start="581" data-end="596"&gt;ERR_TIMED_OUT&lt;/CODE&gt; error.&lt;/P&gt;
&lt;P data-start="605" data-end="628"&gt;&lt;STRONG data-start="605" data-end="628"&gt;Additional details:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-start="629" data-end="973"&gt;
&lt;LI data-start="629" data-end="716"&gt;
&lt;P data-start="631" data-end="716"&gt;We confirmed that traffic is reaching the firewall and hitting the correct interface.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="717" data-end="856"&gt;
&lt;P data-start="719" data-end="856"&gt;We have two portals configured on different interfaces. The second portal (which still uses the old certificate) is functioning normally.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="857" data-end="940"&gt;
&lt;P data-start="859" data-end="940"&gt;We’ve already restarted &lt;CODE data-start="883" data-end="891"&gt;sslmgr&lt;/CODE&gt;, &lt;CODE data-start="893" data-end="912"&gt;sslvpn-web-server&lt;/CODE&gt;, and the management server.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="941" data-end="973"&gt;
&lt;P data-start="943" data-end="973"&gt;PAN-OS version: &lt;STRONG data-start="959" data-end="973"&gt;11.1.4-h13&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-start="975" data-end="1100"&gt;Has anyone encountered a similar issue after a certificate renewal? Any suggestions or insights would be greatly appreciated.&lt;/P&gt;
&lt;P data-start="1102" data-end="1112"&gt;Thank you!&lt;/P&gt;</description>
    <pubDate>Fri, 01 Aug 2025 22:18:34 GMT</pubDate>
    <dc:creator>Jagdeep1</dc:creator>
    <dc:date>2025-08-01T22:18:34Z</dc:date>
    <item>
      <title>Subject: GlobalProtect Connection Issue After SSL/TLS Certificate Renewal</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/subject-globalprotect-connection-issue-after-ssl-tls-certificate/m-p/1235235#M6147</link>
      <description>&lt;P data-start="162" data-end="173"&gt;Hello Team,&lt;/P&gt;
&lt;P data-start="175" data-end="358"&gt;We’re currently experiencing an issue where GlobalProtect is not accessible after renewing the server certificate associated with the SSL/TLS profile used by our GlobalProtect portal.&lt;/P&gt;
&lt;P data-start="360" data-end="518"&gt;&lt;STRONG data-start="360" data-end="378"&gt;Error message:&lt;/STRONG&gt;&lt;BR data-start="378" data-end="381" /&gt;&lt;EM data-start="381" data-end="518"&gt;GlobalProtect: Connection Failed. The network is unreachable or the portal is unresponsive. Check the network connection and reconnect.&lt;/EM&gt;&lt;/P&gt;
&lt;P data-start="520" data-end="603"&gt;The portal is also not loading in a web browser, returning a &lt;CODE data-start="581" data-end="596"&gt;ERR_TIMED_OUT&lt;/CODE&gt; error.&lt;/P&gt;
&lt;P data-start="605" data-end="628"&gt;&lt;STRONG data-start="605" data-end="628"&gt;Additional details:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-start="629" data-end="973"&gt;
&lt;LI data-start="629" data-end="716"&gt;
&lt;P data-start="631" data-end="716"&gt;We confirmed that traffic is reaching the firewall and hitting the correct interface.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="717" data-end="856"&gt;
&lt;P data-start="719" data-end="856"&gt;We have two portals configured on different interfaces. The second portal (which still uses the old certificate) is functioning normally.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="857" data-end="940"&gt;
&lt;P data-start="859" data-end="940"&gt;We’ve already restarted &lt;CODE data-start="883" data-end="891"&gt;sslmgr&lt;/CODE&gt;, &lt;CODE data-start="893" data-end="912"&gt;sslvpn-web-server&lt;/CODE&gt;, and the management server.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="941" data-end="973"&gt;
&lt;P data-start="943" data-end="973"&gt;PAN-OS version: &lt;STRONG data-start="959" data-end="973"&gt;11.1.4-h13&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-start="975" data-end="1100"&gt;Has anyone encountered a similar issue after a certificate renewal? Any suggestions or insights would be greatly appreciated.&lt;/P&gt;
&lt;P data-start="1102" data-end="1112"&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 01 Aug 2025 22:18:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/subject-globalprotect-connection-issue-after-ssl-tls-certificate/m-p/1235235#M6147</guid>
      <dc:creator>Jagdeep1</dc:creator>
      <dc:date>2025-08-01T22:18:34Z</dc:date>
    </item>
    <item>
      <title>Re: Subject: GlobalProtect Connection Issue After SSL/TLS Certificate Renewal</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/subject-globalprotect-connection-issue-after-ssl-tls-certificate/m-p/1235251#M6148</link>
      <description>&lt;P&gt;I've seen this issue before. The fact that the other portal works points directly to the new certificate or its configuration on the affected portal. The &lt;CODE&gt;ERR_TIMED_OUT&lt;/CODE&gt; error is likely a symptom of a failed SSL handshake.&lt;/P&gt;
&lt;P&gt;Here's a quick checklist to troubleshoot:&lt;/P&gt;
&lt;OL start="1"&gt;
&lt;LI&gt;
&lt;P&gt;Certificate Chain:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Confirm the new certificate and its intermediate CAs are all correctly installed and linked. A missing intermediate cert is the most common cause.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;SSL/TLS Profile:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Verify the new certificate is correctly assigned in the SSL/TLS Profile for that portal.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Check for any restrictive TLS versions or cipher suites in the profile.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Logs and Packet Capture:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Review the firewall's system, GlobalProtect, and &lt;CODE&gt;sslvpn-web-server&lt;/CODE&gt; logs for specific errors.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Run a packet capture on the external interface to see where the SSL handshake is failing.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;This issue is almost always a certificate or profile misconfiguration. Let's start by methodically checking those first.&lt;/P&gt;</description>
      <pubDate>Sun, 03 Aug 2025 17:19:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/subject-globalprotect-connection-issue-after-ssl-tls-certificate/m-p/1235251#M6148</guid>
      <dc:creator>Mudhireddy</dc:creator>
      <dc:date>2025-08-03T17:19:15Z</dc:date>
    </item>
  </channel>
</rss>

