<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect SSL error in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ssl-error/m-p/17975#M13088</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;1) Common Name on Portal is the IP, and I can &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://"&gt;https://&lt;/A&gt;&lt;SPAN&gt; into the Portal, put in username/password so I am passing this portion. 2) I have *just* changed my config so that my Portal AND my gateway are configured using only 1 outside IP (remember, my original plan was Portal and GW on 2 separate IP). I have my authentication in Portal set to local (eventually will do LDAP, and use certs, etc) but I am still troubleshooting. So I can get to my Portal, and authenticate, but I cannot get my VPN tunnel up, as I get the error. As for my rules, I do have a Internet (with my specific IP) to Internet Zone&amp;nbsp; ALLOWED at the top of my rulebase, with Log at Start enabled. I can see that my rule hitting for the Portal, and I see my rule hitting for attempting to communicate with my GW, but I get an Incomplete (so my handshake or similar is not working out)&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 12 Mar 2013 17:06:58 GMT</pubDate>
    <dc:creator>scantwell</dc:creator>
    <dc:date>2013-03-12T17:06:58Z</dc:date>
    <item>
      <title>Global Protect SSL error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ssl-error/m-p/17972#M13085</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok group I have a nice and simple question about trying to get GP up and running. Everything (I think) looks right, and configured, but I am not able to quite get my client connected to the Gateway&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(&lt;SPAN style="font-family: courier new,courier; font-size: 8pt;"&gt;T10944) 03/12/13 11:56:27:075 Debug( 742): File C:\Program Files\Palo Alto Networks\GlobalProtect\tca.cer exists. File is tca.cer &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 8pt;"&gt;(T10944) 03/12/13 11:56:27:075 Debug( 340): set trusted root ca file C:\Program Files\Palo Alto Networks\GlobalProtect\tca.cer &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 8pt;"&gt;(T10944) 03/12/13 11:56:27:075 Debug(3645): connect ssl. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 8pt;"&gt;(T10944) 03/12/13 11:56:48:075 Debug( 179): &lt;SPAN style="text-decoration: underline;"&gt;&lt;EM&gt;&lt;STRONG&gt;Failed to connect to 207.96.178.67 on 443 (error: 10051)&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;EM&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/STRONG&gt;&lt;/EM&gt;&lt;EM&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/EM&gt;&amp;lt;======&lt;SPAN style="text-decoration: underline;"&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 8pt;"&gt;(T10944) 03/12/13 11:56:48:075 Error( 296): Server Error: Connect to 207.96.178.67:443 Failed &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 8pt;"&gt;(T10944) 03/12/13 11:56:48:075 Error( 135): do_tcp_connect() &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 8pt;"&gt;(T10944) 03/12/13 11:56:48:075 Error(3663): ConnectSSL: Failed to connect to '207.96.178.67:443'. Disconnect ssl. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 8pt;"&gt;(T10944) 03/12/13 11:56:48:075 Debug(3710): returns 0.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 8pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 8pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 10pt;"&gt;Ok... So what does error 10051 mean?&amp;nbsp; And how do I troubleshoot it further?&amp;nbsp; I have a single FW, using&amp;nbsp; 2 Internet facing interfaces (one I used for Portal, other is for GW)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 10pt;"&gt;I have authenticated to the Portal and downloaded my agent software.&amp;nbsp; I have my configuration sent to "On Demand" and I when I attempt to connect these are the messages I have.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 10pt;"&gt;I have confirmed that I created a self-signed CA on my FW, and signed 3 certs (portal, GW, and agent)... still nothing....&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 10pt;"&gt;Thoughts... HELP... Anything???&amp;nbsp; All will be appreciated.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 10pt;"&gt;PA TAC.... if you have help, this would be most appreciated....&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 10pt;"&gt;I think I am missing something very small.&amp;nbsp; (maybe.&amp;nbsp; :smileysilly:)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Mar 2013 16:22:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ssl-error/m-p/17972#M13085</guid>
      <dc:creator>scantwell</dc:creator>
      <dc:date>2013-03-12T16:22:07Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect SSL error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ssl-error/m-p/17973#M13086</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Following steps would help you in identifying the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Confirm that the Common name on the certificate and the portal address address you are trying to reach from the client are the same&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Confirm the gateway certificate common name and the gateway ip/fqdn in the client config under the portal config match.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) Create an untrust to untrust zone allow rule, this will help you capture the sessions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Run show session all filter destination-port 443 destination &amp;lt;ip&amp;gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Mar 2013 16:35:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ssl-error/m-p/17973#M13086</guid>
      <dc:creator>dpalani</dc:creator>
      <dc:date>2013-03-12T16:35:19Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect SSL error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ssl-error/m-p/17974#M13087</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What does the 'Monitor' tab on the firewall say about this traffic?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure you check "Log at session start" and check "Log at session end", just for the sake of troubleshooting&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Mar 2013 16:35:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ssl-error/m-p/17974#M13087</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2013-03-12T16:35:36Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect SSL error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ssl-error/m-p/17975#M13088</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;1) Common Name on Portal is the IP, and I can &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://"&gt;https://&lt;/A&gt;&lt;SPAN&gt; into the Portal, put in username/password so I am passing this portion. 2) I have *just* changed my config so that my Portal AND my gateway are configured using only 1 outside IP (remember, my original plan was Portal and GW on 2 separate IP). I have my authentication in Portal set to local (eventually will do LDAP, and use certs, etc) but I am still troubleshooting. So I can get to my Portal, and authenticate, but I cannot get my VPN tunnel up, as I get the error. As for my rules, I do have a Internet (with my specific IP) to Internet Zone&amp;nbsp; ALLOWED at the top of my rulebase, with Log at Start enabled. I can see that my rule hitting for the Portal, and I see my rule hitting for attempting to communicate with my GW, but I get an Incomplete (so my handshake or similar is not working out)&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Mar 2013 17:06:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ssl-error/m-p/17975#M13088</guid>
      <dc:creator>scantwell</dc:creator>
      <dc:date>2013-03-12T17:06:58Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect SSL error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ssl-error/m-p/17976#M13089</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your original post says you have two interfaces facing the internet. Which one is the the default gateway to internet ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have any destination NAT configured on the firewall ? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Mar 2013 17:54:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ssl-error/m-p/17976#M13089</guid>
      <dc:creator>dpalani</dc:creator>
      <dc:date>2013-03-12T17:54:29Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect SSL error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ssl-error/m-p/17977#M13090</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Howdy again.&amp;nbsp; I have my GP-GW interface (1/1) that is public facing, with static route to my ISP as my default route (or route of last resort).&amp;nbsp; My GP-Portal interface (1/4) is hosting the portal.&amp;nbsp; I wondered if some sort of asymmetric routing was going on, so I finally configured my GP-GW to be both Portal AND the Gateway.&amp;nbsp; I am using local authentication.&amp;nbsp; In troubleshooting this, it seems that trying to connect to my Portal, when configured on 1/4 works fine.&amp;nbsp; If I update my configuration (and all settings) to use my 1/1 interface as my Portal, I cannot even connect to my Portal.&amp;nbsp; So I am thinking it is something related to my 1/1 interface, which otherwise works 99% (1% is GP, which is not working.&amp;nbsp; :P)&amp;nbsp; If anyone ever wants to help directly troubleshoot this with me, i.e. remote connection to my desktop, etc., I would be more than happy to oblige.&amp;nbsp; Like I said, if knew what error 10051 meant, it would better explain how/why this is going on.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Mar 2013 17:22:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ssl-error/m-p/17977#M13090</guid>
      <dc:creator>scantwell</dc:creator>
      <dc:date>2013-03-13T17:22:53Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect SSL error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ssl-error/m-p/17978#M13091</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looks like it is a asymmetric routing issue. To get more clarity can you run the following commands in cli and attach the outputs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show global-protect-gateway gateway name &amp;lt;g/w name&amp;gt;&lt;/P&gt;&lt;P&gt;show routing route&lt;/P&gt;&lt;P&gt;show interface all&lt;/P&gt;&lt;P&gt;show running pbf-policy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Deepak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Mar 2013 18:28:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ssl-error/m-p/17978#M13091</guid>
      <dc:creator>dpalani</dc:creator>
      <dc:date>2013-03-13T18:28:00Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect SSL error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ssl-error/m-p/17979#M13092</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It does not look like the error is related to certs imo... It seems like the GP agent cannot connect to the GP gateway IP on E1/1 after authenticating to the portal on E1/4 - there is no&amp;nbsp; asymmetrical&amp;nbsp; routing issue here. Seems like a sensible config since the portal only pushes down settings to the GP client and then "quits". The GP agent then decides which gateway to connect to based on the settings pushed down from the portal. Thus there cannot be a&amp;nbsp; asymmetrical&amp;nbsp; route issue since the portal and gateway are not linked in anyway. As you mentioned, changing the portal from E1/4 to E1/1 causes it to fail as well. How about trying to setup the GP portal and gateway on E1/4 as a test?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Mar 2013 19:39:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ssl-error/m-p/17979#M13092</guid>
      <dc:creator>Quinton</dc:creator>
      <dc:date>2013-03-13T19:39:04Z</dc:date>
    </item>
  </channel>
</rss>

