<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Global Protect - Could not connect to the Global Protect gateway. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-could-not-connect-to-the-global-protect-gateway/m-p/545995#M111611</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have an issue with Global protect connection for our customer.&lt;/P&gt;
&lt;P&gt;They are trying to connect via external PC/network and are having issues.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When they are trying fomr internal PC/network they have no issues at all.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a log from Global Protect app that customer send me.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you guys help me what could be the issue here ? I am running out of ideas. If you need more screen shots or logs from Palo Alto I can provide.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 14 Jun 2023 09:51:47 GMT</pubDate>
    <dc:creator>Jozef_Kostan</dc:creator>
    <dc:date>2023-06-14T09:51:47Z</dc:date>
    <item>
      <title>Global Protect - Could not connect to the Global Protect gateway.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-could-not-connect-to-the-global-protect-gateway/m-p/545995#M111611</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have an issue with Global protect connection for our customer.&lt;/P&gt;
&lt;P&gt;They are trying to connect via external PC/network and are having issues.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When they are trying fomr internal PC/network they have no issues at all.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a log from Global Protect app that customer send me.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you guys help me what could be the issue here ? I am running out of ideas. If you need more screen shots or logs from Palo Alto I can provide.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2023 09:51:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-could-not-connect-to-the-global-protect-gateway/m-p/545995#M111611</guid>
      <dc:creator>Jozef_Kostan</dc:creator>
      <dc:date>2023-06-14T09:51:47Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect - Could not connect to the Global Protect gateway.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-could-not-connect-to-the-global-protect-gateway/m-p/546018#M111619</link>
      <description>&lt;P&gt;You try to connect to GlobalProtect from inside or outside the network?&lt;/P&gt;
&lt;P&gt;Portal and gateway run on same interface on Palo?&lt;/P&gt;
&lt;P&gt;Portal loads when you try to access it with browser from same computer?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2023 12:39:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-could-not-connect-to-the-global-protect-gateway/m-p/546018#M111619</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-06-14T12:39:36Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect - Could not connect to the Global Protect gateway.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-could-not-connect-to-the-global-protect-gateway/m-p/546019#M111620</link>
      <description>&lt;P&gt;Hello Raido,&lt;/P&gt;
&lt;P&gt;1/ When trying to connect from customer network it is working.&amp;nbsp; When trying to connect via external network it is not working.&amp;nbsp; They told me thay have some external PCs that they tried and not working.&amp;nbsp; Right now they need a external consultant to be able to connect to Global Protect VPN and he cannot.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2/ Yes both run on same interface on Palo Alto.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3/ I tried from my personnal PC to get to vpnb.xxxxxxxxx.xx.com and was able to load the page.&amp;nbsp; Tried from my work PC and same was able to load the vpnb.xxxxxx.xx.com web page.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To add some info&amp;nbsp;&lt;/P&gt;
&lt;P&gt;a/ Before 23.5.2023 the external user was able to connect via external PC.&lt;/P&gt;
&lt;P&gt;b/ We discovered with server gus that the Azure MFA certificate on that RADIUS server expired on 21.5.2023 so we renew it ( around 2nd of June ) as we thouoght this was the issue.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;c/ since 23.5.2023 the user is having issues to connect.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Attaching another screen with user. Right now I think maybe it should work after the certificate renewal but looks like he locked himself on LDAP right now ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2023 12:50:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-could-not-connect-to-the-global-protect-gateway/m-p/546019#M111620</guid>
      <dc:creator>Jozef_Kostan</dc:creator>
      <dc:date>2023-06-14T12:50:56Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect - Could not connect to the Global Protect gateway.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-could-not-connect-to-the-global-protect-gateway/m-p/546021#M111622</link>
      <description>&lt;P&gt;From last screenshot.&lt;/P&gt;
&lt;P&gt;Portal login is with LDAP.&lt;/P&gt;
&lt;P&gt;Gateway login is with RADIUS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After 23.05 RADIUS gives timeout.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Go to Monitor &amp;gt; System and filter&amp;nbsp;( subtype eq auth ) evets.&lt;/P&gt;
&lt;P&gt;From Monitor &amp;gt; Traffic check if traffic is sent to RADIUS IP (in case this traffic passes Palo) and if there are return packets.&lt;/P&gt;
&lt;P&gt;If packets are sent but not returned then next step is to check RADIUS logs why it don't accept logins.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2023 12:57:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-could-not-connect-to-the-global-protect-gateway/m-p/546021#M111622</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-06-14T12:57:14Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect - Could not connect to the Global Protect gateway.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-could-not-connect-to-the-global-protect-gateway/m-p/546027#M111624</link>
      <description>&lt;P&gt;Hello Raido,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for the info:&lt;/P&gt;
&lt;P&gt;I am attaching log from system monitor.&amp;nbsp; So yeah looks like RADIUS server suddenly stopped working.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Becasue as you can see from picture it was all working and something happened to it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And one more thing. Server guys do not know why but the NPA event viewer is 0. There is no log in it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And I found this in the event logs :&lt;/P&gt;
&lt;P&gt;This is from 12.05.2023 last time the user was able to connect without issues:&lt;/P&gt;
&lt;P&gt;NPS Extension for Azure MFA: CID: edbe2393-a7fb-4287-bf4d-064c8870798c : Access Accepted for user rpa with Azure MFA response: Success and message: session 31057c66-4c0c-4f2d-8064-e7041572e131&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And very first failure try from 23.05.2023&lt;/P&gt;
&lt;P&gt;NPS Extension for Azure MFA: IP Whitelist not intialized:: ErrorCode:: REGISTRY_CONFIG_ERROR Msg:: Neither registry entry not default value found for key: IP_WHITELIST Enter ERROR_CODE @ &lt;A href="https://go.microsoft.com/fwlink/?linkid=846827" target="_blank"&gt;https://go.microsoft.com/fwlink/?linkid=846827&lt;/A&gt; for detailed troubleshooting steps. . This is not an error.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As I mentioned we renewed certificate on the RADIUS server for Azure MFA.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2023 13:21:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-could-not-connect-to-the-global-protect-gateway/m-p/546027#M111624</guid>
      <dc:creator>Jozef_Kostan</dc:creator>
      <dc:date>2023-06-14T13:21:16Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect - Could not connect to the Global Protect gateway.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-could-not-connect-to-the-global-protect-gateway/m-p/546035#M111626</link>
      <description>&lt;P&gt;If NPS don't log then try "auditpol /set /subcategory:”Network Policy Server” /success:enable /failure:enable"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://travelingpacket.com/2022/03/02/microsoft-nps-logs-not-showing-in-event-viewer/" target="_blank"&gt;https://travelingpacket.com/2022/03/02/microsoft-nps-logs-not-showing-in-event-viewer/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2023 14:28:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-could-not-connect-to-the-global-protect-gateway/m-p/546035#M111626</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-06-14T14:28:09Z</dc:date>
    </item>
  </channel>
</rss>

