<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Global Protect doesnt connect to any portal after connecting to a client certificate authentication portal in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-doesnt-connect-to-any-portal-after-connecting-to/m-p/509105#M105972</link>
    <description>&lt;P&gt;There's portal A without client certificate auth&lt;/P&gt;
&lt;P&gt;There's portal B with client certificate auth,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;when i do the following:&lt;/P&gt;
&lt;P&gt;Successfully connect to portal A,&lt;/P&gt;
&lt;P&gt;Successfully connect to portal B, select a certificate and all of that,&lt;/P&gt;
&lt;P&gt;Now im no longer allowed to connect to portal A, or any other portal thats password based, only to portal B.&lt;/P&gt;
&lt;P&gt;(The only way to fix this, is to reinstall globalprotect client, and then its the same, but its very tedious)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The error that global protect gives is just that&amp;nbsp;the certificate is not signed by a trusted certifying authority and it doesnt allow to install it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How could this issue be fixed?&lt;/P&gt;</description>
    <pubDate>Sat, 16 Jul 2022 00:33:07 GMT</pubDate>
    <dc:creator>GabrielMontiel</dc:creator>
    <dc:date>2022-07-16T00:33:07Z</dc:date>
    <item>
      <title>Global Protect doesnt connect to any portal after connecting to a client certificate authentication portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-doesnt-connect-to-any-portal-after-connecting-to/m-p/509105#M105972</link>
      <description>&lt;P&gt;There's portal A without client certificate auth&lt;/P&gt;
&lt;P&gt;There's portal B with client certificate auth,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;when i do the following:&lt;/P&gt;
&lt;P&gt;Successfully connect to portal A,&lt;/P&gt;
&lt;P&gt;Successfully connect to portal B, select a certificate and all of that,&lt;/P&gt;
&lt;P&gt;Now im no longer allowed to connect to portal A, or any other portal thats password based, only to portal B.&lt;/P&gt;
&lt;P&gt;(The only way to fix this, is to reinstall globalprotect client, and then its the same, but its very tedious)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The error that global protect gives is just that&amp;nbsp;the certificate is not signed by a trusted certifying authority and it doesnt allow to install it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How could this issue be fixed?&lt;/P&gt;</description>
      <pubDate>Sat, 16 Jul 2022 00:33:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-doesnt-connect-to-any-portal-after-connecting-to/m-p/509105#M105972</guid>
      <dc:creator>GabrielMontiel</dc:creator>
      <dc:date>2022-07-16T00:33:07Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect doesnt connect to any portal after connecting to a client certificate authentication portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-doesnt-connect-to-any-portal-after-connecting-to/m-p/509114#M105976</link>
      <description>&lt;P&gt;- Are requiring user login and certificate or just certificate at the portal stage (Portals-&amp;gt;Authentication-&amp;gt;Client Authentication)?&lt;/P&gt;
&lt;P&gt;- On portal B, are you sending Trusted Root CAs to the client (Portals-&amp;gt;Agent-&amp;gt;Trusted Root CA)?&lt;/P&gt;
&lt;P&gt;- On portal B, are you sending client certificates to the client (Portals-&amp;gt;Agent-&amp;gt;[config]-&amp;gt;Authentication)?&lt;/P&gt;
&lt;P&gt;- If, after logging in to/out of portal B, no longer able to log into portal A. If you point your browser at portal A, do you get a certificate error?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Jul 2022 02:56:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-doesnt-connect-to-any-portal-after-connecting-to/m-p/509114#M105976</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-07-16T02:56:41Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect doesnt connect to any portal after connecting to a client certificate authentication portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-doesnt-connect-to-any-portal-after-connecting-to/m-p/509131#M105982</link>
      <description>&lt;P&gt;I cannot give any details about portal B since we're only providers for such client, portal A is the one we're responsible for, and where i could dig more details if needed,&lt;BR /&gt;&lt;BR /&gt;But yes after connecting to portal B the browser gives certificate error on the portal A website, i had the guess that maybe portal B somehow was deleting portal A certificate or changing the default certificate folder, but after manually installing the portal A certificate in the trusted root certificate folder it was still giving me errors.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this is the pangps log file after the portal B connection trying to connect to portal A:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;(P11592-T13892)&lt;/SPAN&gt;&lt;SPAN&gt;Debug&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN&gt;1792&lt;/SPAN&gt;&lt;SPAN&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; &lt;/SPAN&gt;&lt;SPAN&gt;07&lt;/SPAN&gt;&lt;SPAN&gt;/&lt;/SPAN&gt;&lt;SPAN&gt;15&lt;/SPAN&gt;&lt;SPAN&gt;/&lt;/SPAN&gt;&lt;SPAN&gt;22&lt;/SPAN&gt; &lt;SPAN&gt;14:18:36&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;524&lt;/SPAN&gt;&lt;SPAN&gt; Send response to client for request https_request&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;(P11592-T13892)&lt;/SPAN&gt;&lt;SPAN&gt;Debug&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN&gt;2997&lt;/SPAN&gt;&lt;SPAN&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; &lt;/SPAN&gt;&lt;SPAN&gt;07&lt;/SPAN&gt;&lt;SPAN&gt;/&lt;/SPAN&gt;&lt;SPAN&gt;15&lt;/SPAN&gt;&lt;SPAN&gt;/&lt;/SPAN&gt;&lt;SPAN&gt;22&lt;/SPAN&gt; &lt;SPAN&gt;14:18:36&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;631&lt;/SPAN&gt;&lt;SPAN&gt; receive pan_msg_ping, &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;(P11592-T13892)&lt;/SPAN&gt;&lt;SPAN&gt;Debug&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN&gt;3172&lt;/SPAN&gt;&lt;SPAN&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; &lt;/SPAN&gt;&lt;SPAN&gt;07&lt;/SPAN&gt;&lt;SPAN&gt;/&lt;/SPAN&gt;&lt;SPAN&gt;15&lt;/SPAN&gt;&lt;SPAN&gt;/&lt;/SPAN&gt;&lt;SPAN&gt;22&lt;/SPAN&gt; &lt;SPAN&gt;14:18:36&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;746&lt;/SPAN&gt;&lt;SPAN&gt; winhttpObj, cert error, &lt;/SPAN&gt;&lt;SPAN&gt;00000008&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;(P11592-T13892)&lt;/SPAN&gt;&lt;SPAN&gt;Debug&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN&gt;3177&lt;/SPAN&gt;&lt;SPAN&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; &lt;/SPAN&gt;&lt;SPAN&gt;07&lt;/SPAN&gt;&lt;SPAN&gt;/&lt;/SPAN&gt;&lt;SPAN&gt;15&lt;/SPAN&gt;&lt;SPAN&gt;/&lt;/SPAN&gt;&lt;SPAN&gt;22&lt;/SPAN&gt; &lt;SPAN&gt;14:18:36&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;746&lt;/SPAN&gt;&lt;SPAN&gt; winhttpObj, cert erro is &lt;/SPAN&gt;&lt;SPAN&gt;00000008&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;(P11592-T13892)&lt;/SPAN&gt;&lt;SPAN&gt;Debug&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN&gt;7100&lt;/SPAN&gt;&lt;SPAN&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; &lt;/SPAN&gt;&lt;SPAN&gt;07&lt;/SPAN&gt;&lt;SPAN&gt;/&lt;/SPAN&gt;&lt;SPAN&gt;15&lt;/SPAN&gt;&lt;SPAN&gt;/&lt;/SPAN&gt;&lt;SPAN&gt;22&lt;/SPAN&gt; &lt;SPAN&gt;14:18:36&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;746&lt;/SPAN&gt;&lt;SPAN&gt; prelogin to portal result is &lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN&gt;null&lt;/SPAN&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Sat, 16 Jul 2022 22:36:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-doesnt-connect-to-any-portal-after-connecting-to/m-p/509131#M105982</guid>
      <dc:creator>GabrielMontiel</dc:creator>
      <dc:date>2022-07-16T22:36:02Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect doesnt connect to any portal after connecting to a client certificate authentication portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-doesnt-connect-to-any-portal-after-connecting-to/m-p/509407#M106050</link>
      <description>&lt;P&gt;Are your portals using third-party signed certificates or internal CA signed certificates? It is hard to tell from the description, and not having access to portal B complicates diagnosing, but it sounds like whatever portal B is doing is breaking the certificate chain for portal A. The most obvious thing I can think of is that you are using internal CA signed certificates for your portals and portal B is pushing a new root/intermediate ca certificate that replaces the CA signing portal A's certificate, causing portal A to no longer validate. Replacing with a different CA would also break the browser from accessing/showing a secure connection.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you fix the PC so you can sign into portal A again.... Point a browser at portal A and then look at the certificate details. Specifically look at the certificate chain and the details of the CA certs used sign it. (Below I show my gateway address in the browser, which gives a 404 error - but the important part is the SSL certificate, not the page. The portal page will give something similar.)&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2022-07-16_163513.jpg" style="width: 394px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/42562i6D3B88FF2C7678F6/image-dimensions/394x541/is-moderation-mode/true?v=v2" width="394" height="541" role="button" title="2022-07-16_163513.jpg" alt="2022-07-16_163513.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Then compare the above CA certificate details on portal A to the details of the CA certificate on portal B. When the GP client works on portal A, can a browser successfully connect to portal B and does the SSL cert verify?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2022 17:16:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-doesnt-connect-to-any-portal-after-connecting-to/m-p/509407#M106050</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-07-20T17:16:59Z</dc:date>
    </item>
  </channel>
</rss>

