<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect commit fail on PAN-OS 7.0 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-commit-fail-on-pan-os-7-0/m-p/17462#M12750</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dent,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you try this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check the 'Retrieve-Framed-IP-Address attribute from authentication server' box. This will then allow you to edit the authentication server IP pool. Delete the 192.168.168.0/24 pool that you have configured. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then deselect the 'Retrieve-Framed-IP-Address attribute from authentication server' box and try committing again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if this helps at all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 14 Jul 2015 23:35:26 GMT</pubDate>
    <dc:creator>bmorris1</dc:creator>
    <dc:date>2015-07-14T23:35:26Z</dc:date>
    <item>
      <title>GlobalProtect commit fail on PAN-OS 7.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-commit-fail-on-pan-os-7-0/m-p/17459#M12747</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;help me please.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;config ip pool for client access but commit fail&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;commit log message&lt;/SPAN&gt;&lt;/P&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="1" style="font-family: Tahoma, Arial, Helvetica, sans-serif; width: 98%; background-color: rgb(235, 237, 238);"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="font-size: 11px;" width="70"&gt;&lt;STRONG&gt;Operation&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD style="padding: 0 0 0 5px; font-size: 11px;"&gt; Commit&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="font-size: 11px;" width="70"&gt;&lt;STRONG&gt;Result&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD style="padding: 0 0 0 5px; font-size: 11px;"&gt; Failed&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD colspan="2" style="font-size: 11px;"&gt;&lt;BR /&gt;&lt;STRONG&gt;Details&lt;/STRONG&gt;&lt;SPAN class="commit_details" style="padding-left: 42px;"&gt;&lt;SPAN class="commit_details" style="padding-left: 42px;"&gt;missing ip pool from both dynamic ip pool and authentication server ip pool for config 'default' in gateway GP-Gateway (tunnel GP-Gateway-N)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;P class="commit_common" style="padding-left: 80px;"&gt;(Module: rasmgr)&lt;/P&gt;&lt;P class="commit_common" style="padding-left: 80px;"&gt;Commit failed&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000; font-size: 10pt; background-color: #ebedee; font-family: Tahoma, Arial, Helvetica, sans-serif;"&gt;rasmgr log message&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Tahoma, Arial, Helvetica, sans-serif; font-size: 11px; background-color: #ebedee;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.746 +0700 rasmgr: rasmgr phase 1 started, config size 11700&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.746 +0700 rasmgr: rasmgr phase 1 step 1 finished&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.747 +0700 GP-Gateway-N&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.747 +0700 Tunnel GW configuration:&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.747 +0700&amp;nbsp;&amp;nbsp; Tunnel Interface:tunnel.1&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.747 +0700&amp;nbsp;&amp;nbsp; Tunnel IP: 0.0.0.0 &lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.747 +0700&amp;nbsp;&amp;nbsp; DNS1: 0.0.0.0 &lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.747 +0700&amp;nbsp;&amp;nbsp; DNS2: 0.0.0.0 &lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.747 +0700&amp;nbsp;&amp;nbsp; DNS Suffix: tfg.co.th&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.747 +0700&amp;nbsp;&amp;nbsp; Egress Interface:ethernet1/11&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.747 +0700&amp;nbsp;&amp;nbsp; Accept Published Routes:0&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.747 +0700&amp;nbsp;&amp;nbsp; Anti-Replay:1&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.747 +0700&amp;nbsp;&amp;nbsp; Copy-TOS:0&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.747 +0700&amp;nbsp;&amp;nbsp; NATT enable:0&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.747 +0700&amp;nbsp;&amp;nbsp; Valid Networks:&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.747 +0700&amp;nbsp;&amp;nbsp; Tunnel Monitor:&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.747 +0700&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Action:0&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.747 +0700&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interval:0&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.747 +0700&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Threshold:0&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.747 +0700&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Enable:0&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.747 +0700&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Src IP: 0.0.0.0&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.747 +0700&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Dest IP: 0.0.0.0&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.747 +0700&amp;nbsp;&amp;nbsp; IPSEc Crypto Profile:&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.747 +0700&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Lifetime:0&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.747 +0700&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Lifetime unit:0&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.747 +0700&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Lifetime secs:0&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.747 +0700&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Lifesize:0&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.747 +0700&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Lifesize unit:0&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.747 +0700&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Lifesize bytes:0&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.747 +0700&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DHGroup:&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.747 +0700&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Encr:&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.747 +0700&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aes-128-cbc&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.747 +0700&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Auth:&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.747 +0700&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sha1&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.747 +0700 config 'conf1'&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.747 +0700 string(any); transformed string(any)&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.747 +0700 string(any); transformed string(any)&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.747 +0700 config '(null)'&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.747 +0700 string(any); transformed string(any)&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.747 +0700 string(any); transformed string(any)&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.748 +0700 Error:&amp;nbsp; sslvpn_parse_user_configs_ip_pool_exist(src/rasmgr_parse.c:1807): missing ip pool from both dynamic ip pool and authentication server ip pool for config 'default' in gateway GP-Gateway (tunnel GP-Gateway-N)&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.748 +0700 rasmgr: rasmgr phase 1 step 2 finished&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:29.748 +0700 rasmgr: rasmgr phase 1 finished with status -1&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:33.299 +0700 rasmgr: marking phase 1 aborted&lt;/P&gt;&lt;P&gt;2015-07-10 17:52:33.304 +0700 Error:&amp;nbsp; cfgagent_modify_callback(pan_cfgagent.c:83): Modify string (sw.mgmt.runtime.clients.rasmgr.err) error: USER (1)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Jul 2015 10:54:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-commit-fail-on-pan-os-7-0/m-p/17459#M12747</guid>
      <dc:creator>Dent</dc:creator>
      <dc:date>2015-07-09T10:54:30Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect commit fail on PAN-OS 7.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-commit-fail-on-pan-os-7-0/m-p/17460#M12748</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you check under GloblaProtect/Gateways/Client Configuration/Network settings, in your default profile and in Network Settings.&lt;/P&gt;&lt;P&gt;You should have IP Pool configured with range like 10.1.1.1-10.1.1.10. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you check the "&lt;SPAN style="color: #222222; font-family: Tahoma, Arial, Helvetica, sans-serif; font-size: 11px; background-color: #ebedee;"&gt;Retrieve Framed-IP-Address attribute from authentication server" &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;the aim is to delegate IP config for VPN user to internal DHCP server. Do you use it ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Does your config is ok ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;V.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Jul 2015 12:08:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-commit-fail-on-pan-os-7-0/m-p/17460#M12748</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2015-07-09T12:08:01Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect commit fail on PAN-OS 7.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-commit-fail-on-pan-os-7-0/m-p/17461#M12749</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; under GloblaProtect/Gateways/Client Configuration/Network settings I config follow a image.&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-0 jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/20304_pastedImage_0.png" style="max-height: 900px; max-width: 1200px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I try config ip pool to network range or network subnet. but it commit fail every.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;T_T&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Jul 2015 04:10:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-commit-fail-on-pan-os-7-0/m-p/17461#M12749</guid>
      <dc:creator>Dent</dc:creator>
      <dc:date>2015-07-10T04:10:45Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect commit fail on PAN-OS 7.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-commit-fail-on-pan-os-7-0/m-p/17462#M12750</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dent,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you try this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check the 'Retrieve-Framed-IP-Address attribute from authentication server' box. This will then allow you to edit the authentication server IP pool. Delete the 192.168.168.0/24 pool that you have configured. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then deselect the 'Retrieve-Framed-IP-Address attribute from authentication server' box and try committing again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if this helps at all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jul 2015 23:35:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-commit-fail-on-pan-os-7-0/m-p/17462#M12750</guid>
      <dc:creator>bmorris1</dc:creator>
      <dc:date>2015-07-14T23:35:26Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect commit fail on PAN-OS 7.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-commit-fail-on-pan-os-7-0/m-p/161746#M52597</link>
      <description>&lt;P&gt;I was searching the internet and found this post in Live community.&lt;/P&gt;&lt;P&gt;I too am getting the same error while configuring global protect. Any solution ????&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 17 Jun 2017 05:20:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-commit-fail-on-pan-os-7-0/m-p/161746#M52597</guid>
      <dc:creator>kunal_19</dc:creator>
      <dc:date>2017-06-17T05:20:39Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect commit fail on PAN-OS 7.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-commit-fail-on-pan-os-7-0/m-p/161971#M52622</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/62146"&gt;@kunal_19&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Can you share your software version that you have on your firewall along with a screenshot of your network settings tab under client settings on the agent tab on the gateway configuration screen.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2017 15:07:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-commit-fail-on-pan-os-7-0/m-p/161971#M52622</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-06-19T15:07:33Z</dc:date>
    </item>
  </channel>
</rss>

