<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Add new portal to Linux GlobalProtect app in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/add-new-portal-to-linux-globalprotect-app/m-p/477591#M103685</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm trying to set up two different VPN relying on two different accounts on the same Linux (Linux Mint 20.2 Uma, base: Ubuntu 20.04 focal), but I'm having some issues.&lt;/P&gt;&lt;P&gt;From what I understood (as the VPN rely on different emails) I need to create different portals.&lt;/P&gt;&lt;P&gt;I have already one portal setup on my laptop using &lt;LI-PRODUCT title="GlobalProtect" id="GlobalProtect"&gt;&lt;/LI-PRODUCT&gt;, but when when I try to follow the commands indicated here &lt;A href="https://docs.paloaltonetworks.com/globalprotect/5-3/globalprotect-app-user-guide/globalprotect-app-for-linux/use-the-globalprotect-app-for-linux.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/globalprotect/5-3/globalprotect-app-user-guide/globalprotect-app-for-linux/use-the-globalprotect-app-for-linux.html&lt;/A&gt;) I get the following error:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;$ globalprotect connect --portal XXXXXX&lt;BR /&gt;Cannot parse your input. The valid CLI commands that you can now use are:&lt;BR /&gt;collect-log&lt;BR /&gt;import-certificate&lt;BR /&gt;launch-ui [--recover]&lt;BR /&gt;show --version&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So it seems that the 'connect' command is not recognized. How so?&lt;BR /&gt;I'm using &lt;LI-PRODUCT title="GlobalProtect" id="GlobalProtect"&gt;&lt;/LI-PRODUCT&gt; version 5.3.1-36&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Fri, 01 Apr 2022 15:37:42 GMT</pubDate>
    <dc:creator>mgabriel</dc:creator>
    <dc:date>2022-04-01T15:37:42Z</dc:date>
    <item>
      <title>Add new portal to Linux GlobalProtect app</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/add-new-portal-to-linux-globalprotect-app/m-p/477591#M103685</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm trying to set up two different VPN relying on two different accounts on the same Linux (Linux Mint 20.2 Uma, base: Ubuntu 20.04 focal), but I'm having some issues.&lt;/P&gt;&lt;P&gt;From what I understood (as the VPN rely on different emails) I need to create different portals.&lt;/P&gt;&lt;P&gt;I have already one portal setup on my laptop using &lt;LI-PRODUCT title="GlobalProtect" id="GlobalProtect"&gt;&lt;/LI-PRODUCT&gt;, but when when I try to follow the commands indicated here &lt;A href="https://docs.paloaltonetworks.com/globalprotect/5-3/globalprotect-app-user-guide/globalprotect-app-for-linux/use-the-globalprotect-app-for-linux.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/globalprotect/5-3/globalprotect-app-user-guide/globalprotect-app-for-linux/use-the-globalprotect-app-for-linux.html&lt;/A&gt;) I get the following error:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;$ globalprotect connect --portal XXXXXX&lt;BR /&gt;Cannot parse your input. The valid CLI commands that you can now use are:&lt;BR /&gt;collect-log&lt;BR /&gt;import-certificate&lt;BR /&gt;launch-ui [--recover]&lt;BR /&gt;show --version&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So it seems that the 'connect' command is not recognized. How so?&lt;BR /&gt;I'm using &lt;LI-PRODUCT title="GlobalProtect" id="GlobalProtect"&gt;&lt;/LI-PRODUCT&gt; version 5.3.1-36&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 01 Apr 2022 15:37:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/add-new-portal-to-linux-globalprotect-app/m-p/477591#M103685</guid>
      <dc:creator>mgabriel</dc:creator>
      <dc:date>2022-04-01T15:37:42Z</dc:date>
    </item>
    <item>
      <title>Re: Add new portal to Linux GlobalProtect app</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/add-new-portal-to-linux-globalprotect-app/m-p/478311#M103738</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/214755"&gt;@mgabriel&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The PanGPLinux package contains both UI and non-UI versions.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I recall correctly the "globalprotect connect" option is not available in the UI package.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Hope this helps,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Kiwi.&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Tue, 05 Apr 2022 11:05:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/add-new-portal-to-linux-globalprotect-app/m-p/478311#M103738</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2022-04-05T11:05:53Z</dc:date>
    </item>
    <item>
      <title>Re: Add new portal to Linux GlobalProtect app</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/add-new-portal-to-linux-globalprotect-app/m-p/478317#M103740</link>
      <description>Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;,&lt;BR /&gt;&lt;BR /&gt;Yes, that is correct. I unistalled theUI version and I moved to the CLI&lt;BR /&gt;one. This allowed me to use the `connect` command.&lt;BR /&gt;&lt;BR /&gt;However, now I'm stuck my another issue: while one of the VPN requires&lt;BR /&gt;2FA and works correctly using the CLI version, the other one requires a&lt;BR /&gt;certificate.&lt;BR /&gt;Even if I first import the certificate with (run in the location where&lt;BR /&gt;the certificate is located):&lt;BR /&gt;&lt;BR /&gt;$ globalprotect import-certificate --location .&lt;BR /&gt;Please input passcode:&lt;BR /&gt;Import certificate is successful.&lt;BR /&gt;&lt;BR /&gt;I then get this message:&lt;BR /&gt;&lt;BR /&gt;$ globalprotect connect --portal YYYYYYYY&lt;BR /&gt;Retrieving configuration...&lt;BR /&gt;Retrieving configuration...&lt;BR /&gt;Failed to connect to YYYYYYYY.&lt;BR /&gt;Error: A valid client certificate is required for authentication. If the&lt;BR /&gt;issue&lt;BR /&gt;persists, contact your administrator.&lt;BR /&gt;&lt;BR /&gt;I've tried with multiple certificates (even newly generated), but the&lt;BR /&gt;issue persists.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 05 Apr 2022 12:00:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/add-new-portal-to-linux-globalprotect-app/m-p/478317#M103740</guid>
      <dc:creator>mgabriel</dc:creator>
      <dc:date>2022-04-05T12:00:45Z</dc:date>
    </item>
    <item>
      <title>Re: Add new portal to Linux GlobalProtect app</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/add-new-portal-to-linux-globalprotect-app/m-p/478333#M103741</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/214755"&gt;@mgabriel&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm assuming the client certificate was created by the CA.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Verify that the certificate is installed properly in the globalprotect directory.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I would turn on debugging and check if&amp;nbsp;PanGPS.log can provide some additional information on why it failed to connect.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cheers!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Kiwi.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2022 13:33:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/add-new-portal-to-linux-globalprotect-app/m-p/478333#M103741</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2022-04-05T13:33:25Z</dc:date>
    </item>
    <item>
      <title>Re: Add new portal to Linux GlobalProtect app</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/add-new-portal-to-linux-globalprotect-app/m-p/479301#M103883</link>
      <description>Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;,&lt;BR /&gt;&lt;BR /&gt;Thanks for your help!&lt;BR /&gt;&lt;BR /&gt;Yes, the certificate was created by the CA.&lt;BR /&gt;&lt;BR /&gt;What folder do you mean? I see only a folder "~/.GlobalProtect" with&lt;BR /&gt;only the logs and three dat files. One of them is called&lt;BR /&gt;"PanPortalCfg_*.dat" so it might seems that it has something to do with&lt;BR /&gt;the portals configuration, but it's binary so I have not found a way to&lt;BR /&gt;read it.&lt;BR /&gt;&lt;BR /&gt;I've tried to copy the p12 certificate in this folder and import it from&lt;BR /&gt;here, but the result is still the same:&lt;BR /&gt;&lt;BR /&gt;Retrieving configuration...&lt;BR /&gt;Retrieving configuration...&lt;BR /&gt;Failed to connect to gp-dica.vpn.polimi.it.&lt;BR /&gt;Error: A valid client certificate is required for authentication. If the&lt;BR /&gt;issue persists, contact your administrator.&lt;BR /&gt;&lt;BR /&gt;Looking at the PanGPi.log file I read this message, where VPN1 is the&lt;BR /&gt;vpn service which requires the 2FA and is working, while VPN2 is the one&lt;BR /&gt;which requires the certificate and is not working:&lt;BR /&gt;&lt;BR /&gt;P11533-T150869760 04/07/2022 08:29:19:541 Debug( 118): From GPA:&lt;BR /&gt;statusDisconnectedA valid&lt;BR /&gt;client certificate is required for authentication. If the issue&lt;BR /&gt;persists, contact your&lt;BR /&gt;administrator.ni-ext-gw.vpn.VPN1ni-ext-gw.vpn.VPN1yesnodc-ext-gw.vpn.VPN1dc-ext-gw.vpn.VPN1yesnoClient&lt;BR /&gt;Cert&lt;BR /&gt;Requiredgp-dica.vpn.VPN2noyes.&lt;BR /&gt;&lt;BR /&gt;By looking at them on the line it makes me think that there must be some&lt;BR /&gt;sort of mixup with the portals. Could this be the case?&lt;BR /&gt;&lt;BR /&gt;Also I saw in the PanGPA.log the user for VPN2, which however I did not&lt;BR /&gt;remember writing anywhere and, for this reason, I think it was read by&lt;BR /&gt;the certificate...&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 08 Apr 2022 12:51:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/add-new-portal-to-linux-globalprotect-app/m-p/479301#M103883</guid>
      <dc:creator>mgabriel</dc:creator>
      <dc:date>2022-04-08T12:51:02Z</dc:date>
    </item>
  </channel>
</rss>

