<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN Client with PANOS8 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-with-panos8/m-p/469653#M102951</link>
    <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;I've recently had someone complain that the native macOS/OSX VPN&lt;BR /&gt;client wouldn't connect to the VPN (PANOS 8.0.6). Turns out that they&lt;BR /&gt;were using an unsupported macOS version, and weren't using the&lt;BR /&gt;globalprotect client 'because it didn't work'. The official response&lt;BR /&gt;to them is a) get a supported version of macOS b) use the&lt;BR /&gt;GlobalProtect client.&lt;/P&gt;&lt;P&gt;But it got me curious.&lt;/P&gt;&lt;P&gt;Way back when we replaced a very crufty VPN box with the Palo Altos, I&lt;BR /&gt;spent some time testing various VPN clients and the macOS native VPN&lt;BR /&gt;client worked fine. Does anyone know if Apple have 'done something' to&lt;BR /&gt;break it? Know of a fix?&lt;/P&gt;&lt;P&gt;I'm suspecting it's Apple to blame here - 3rd party VPN clients such&lt;BR /&gt;as Linux (Fedora Core 26) vnpc, Android (vpnzilla), and iOS&lt;BR /&gt;(reportedly) all work fine.&lt;/P&gt;&lt;P&gt;The experience on a macOS device is that the VPN client successfully&lt;BR /&gt;connects, but no packets appear to flow either way.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;✓ msm@TrwynMochyn» ifconfig utun1
utun1: flags=8051&amp;lt;UP,POINTOPOINT,RUNNING,MULTICAST&amp;gt; mtu 1280
options=6403&amp;lt;RXCSUM,TXCSUM,CHANNEL_IO,PARTIAL_CSUM,ZEROINVERT_CSUM&amp;gt;
inet 148.197.84.55 --&amp;gt; 148.197.84.55 netmask 0xffffffff 
✓ msm@TrwynMochyn» netstat -in | grep utun1
utun1 1280 &amp;lt;Link#15&amp;gt; 0 0 0 0 0
utun1 1280 148.197.84.55 148.197.84.55 0 - 0 - -
✓ msm@TrwynMochyn» ping 148.197.84.55
PING 148.197.84.55 (148.197.84.55): 56 data bytes
Request timeout for icmp_seq 0
Request timeout for icmp_seq 1
Request timeout for icmp_seq 2
Request timeout for icmp_seq 3
Request timeout for icmp_seq 4
Request timeout for icmp_seq 5
Request timeout for icmp_seq 6
^C
--- 148.197.84.55 ping statistics ---
8 packets transmitted, 0 packets received, 100.0% packet loss&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Wed, 02 Mar 2022 03:53:34 GMT</pubDate>
    <dc:creator>dolonipo</dc:creator>
    <dc:date>2022-03-02T03:53:34Z</dc:date>
    <item>
      <title>VPN Client with PANOS8</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-with-panos8/m-p/469653#M102951</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;I've recently had someone complain that the native macOS/OSX VPN&lt;BR /&gt;client wouldn't connect to the VPN (PANOS 8.0.6). Turns out that they&lt;BR /&gt;were using an unsupported macOS version, and weren't using the&lt;BR /&gt;globalprotect client 'because it didn't work'. The official response&lt;BR /&gt;to them is a) get a supported version of macOS b) use the&lt;BR /&gt;GlobalProtect client.&lt;/P&gt;&lt;P&gt;But it got me curious.&lt;/P&gt;&lt;P&gt;Way back when we replaced a very crufty VPN box with the Palo Altos, I&lt;BR /&gt;spent some time testing various VPN clients and the macOS native VPN&lt;BR /&gt;client worked fine. Does anyone know if Apple have 'done something' to&lt;BR /&gt;break it? Know of a fix?&lt;/P&gt;&lt;P&gt;I'm suspecting it's Apple to blame here - 3rd party VPN clients such&lt;BR /&gt;as Linux (Fedora Core 26) vnpc, Android (vpnzilla), and iOS&lt;BR /&gt;(reportedly) all work fine.&lt;/P&gt;&lt;P&gt;The experience on a macOS device is that the VPN client successfully&lt;BR /&gt;connects, but no packets appear to flow either way.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;✓ msm@TrwynMochyn» ifconfig utun1
utun1: flags=8051&amp;lt;UP,POINTOPOINT,RUNNING,MULTICAST&amp;gt; mtu 1280
options=6403&amp;lt;RXCSUM,TXCSUM,CHANNEL_IO,PARTIAL_CSUM,ZEROINVERT_CSUM&amp;gt;
inet 148.197.84.55 --&amp;gt; 148.197.84.55 netmask 0xffffffff 
✓ msm@TrwynMochyn» netstat -in | grep utun1
utun1 1280 &amp;lt;Link#15&amp;gt; 0 0 0 0 0
utun1 1280 148.197.84.55 148.197.84.55 0 - 0 - -
✓ msm@TrwynMochyn» ping 148.197.84.55
PING 148.197.84.55 (148.197.84.55): 56 data bytes
Request timeout for icmp_seq 0
Request timeout for icmp_seq 1
Request timeout for icmp_seq 2
Request timeout for icmp_seq 3
Request timeout for icmp_seq 4
Request timeout for icmp_seq 5
Request timeout for icmp_seq 6
^C
--- 148.197.84.55 ping statistics ---
8 packets transmitted, 0 packets received, 100.0% packet loss&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 02 Mar 2022 03:53:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-with-panos8/m-p/469653#M102951</guid>
      <dc:creator>dolonipo</dc:creator>
      <dc:date>2022-03-02T03:53:34Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Client with PANOS8</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-with-panos8/m-p/469921#M102972</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/211253"&gt;@dolonipo&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Just FYI, you really need to update that firewall. PAN-OS 8.0 was EoL way back on October 31st of 2019.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As to your question, macOS recently had a number of certificate modifications that changed the default validity to 398 days.&amp;nbsp;&lt;A href="https://support.apple.com/en-us/HT211025" target="_blank"&gt;https://support.apple.com/en-us/HT211025&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Mar 2022 21:47:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-with-panos8/m-p/469921#M102972</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-03-02T21:47:26Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Client with PANOS8</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-with-panos8/m-p/470070#M102987</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/211253"&gt;@dolonipo&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Just FYI, you really need to update that firewall. PAN-OS 8.0 was EoL way back on October 31st of 2019.&lt;/P&gt;&lt;P&gt;&lt;A href="https://wordle.onl" target="_self"&gt;&lt;FONT size="1 2 3 4 5 6 7" color="#FFFFFF"&gt;Wordle&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;As to your question, macOS recently had a number of certificate modifications that changed the default validity to 398 days.&amp;nbsp;&lt;A href="https://support.apple.com/en-us/HT211025" target="_blank" rel="noopener"&gt;https://support.apple.com/en-us/HT211025&lt;/A&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Thanks! I will work on it.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2022 09:05:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-with-panos8/m-p/470070#M102987</guid>
      <dc:creator>selinaclay</dc:creator>
      <dc:date>2022-03-03T09:05:24Z</dc:date>
    </item>
  </channel>
</rss>

