<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect &amp;quot;Server Certificate Verification Failed&amp;quot; Multiple Gateways in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-quot-server-certificate-verification-failed-quot/m-p/20440#M14907</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Network -&amp;gt; Global Protect -&amp;gt; Portals -&amp;gt; &amp;lt;profile name&amp;gt; -&amp;gt; Client Config -&amp;gt; &amp;lt;config name&amp;gt; -&amp;gt; Gateways -&amp;gt; External Gateways -&amp;gt; "Address" == &amp;lt;FQDN&amp;gt; &amp;amp;&amp;amp; != &amp;lt;IP Address&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Translation: Make sure that you use the Fully Qualified Domain Name (FQDN) in Gateway Certificate and NOT the IP address for the gateway in the "Address" field of External Gateways.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is not totally obvious to me as "Address" usually means "IP Address" and "URL" or "FQDN" or "Domain" usually means the domain name of something.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 21 Apr 2013 19:43:17 GMT</pubDate>
    <dc:creator>ManillaTechOps</dc:creator>
    <dc:date>2013-04-21T19:43:17Z</dc:date>
    <item>
      <title>Global Protect "Server Certificate Verification Failed" Multiple Gateways</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-quot-server-certificate-verification-failed-quot/m-p/20439#M14906</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are unable to get multiple gateways working correctly with Global Protect.&amp;nbsp; When we have one portal and one gateway, clients are able to successfully connect and establish a VPN tunnel.&amp;nbsp; With two gateways we get the following error from both the originally setup gateway and the gateway we are attempting to add: "Gateway x.x.x.x: Server Certificate Verification Failed" in the Global Protect Client -&amp;gt; Status -&amp;gt; Warnings/Errors dialogue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Setup information:&lt;/P&gt;&lt;P&gt;Portal Hardware: PA-2050&lt;/P&gt;&lt;P&gt;Portal OS: 5.0.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gateway 1: Same as Portal above&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gateway 2 Hardware: PA-200&lt;/P&gt;&lt;P&gt;Gateway 2 OS: 5.0.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Global Protect Portal License: YES&lt;/P&gt;&lt;P&gt;Global Protect Gateway 1 License: YES&lt;/P&gt;&lt;P&gt;Global Protect Gateway 2 License: YES&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Certificate Authority Information:&lt;/P&gt;&lt;P&gt;Microsoft Server CA 2012&lt;/P&gt;&lt;P&gt;Portal - CSR issued to MS CA&lt;/P&gt;&lt;P&gt;Gateway 1 - CSR issued to MS CA&lt;/P&gt;&lt;P&gt;Gateway 2 - CSR issued to MS CA&lt;/P&gt;&lt;P&gt;Clients - Machine Certificate pre-installed via GPO from MS CA&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 21 Apr 2013 19:23:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-quot-server-certificate-verification-failed-quot/m-p/20439#M14906</guid>
      <dc:creator>ManillaTechOps</dc:creator>
      <dc:date>2013-04-21T19:23:14Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect "Server Certificate Verification Failed" Multiple Gateways</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-quot-server-certificate-verification-failed-quot/m-p/20440#M14907</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Network -&amp;gt; Global Protect -&amp;gt; Portals -&amp;gt; &amp;lt;profile name&amp;gt; -&amp;gt; Client Config -&amp;gt; &amp;lt;config name&amp;gt; -&amp;gt; Gateways -&amp;gt; External Gateways -&amp;gt; "Address" == &amp;lt;FQDN&amp;gt; &amp;amp;&amp;amp; != &amp;lt;IP Address&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Translation: Make sure that you use the Fully Qualified Domain Name (FQDN) in Gateway Certificate and NOT the IP address for the gateway in the "Address" field of External Gateways.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is not totally obvious to me as "Address" usually means "IP Address" and "URL" or "FQDN" or "Domain" usually means the domain name of something.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 21 Apr 2013 19:43:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-quot-server-certificate-verification-failed-quot/m-p/20440#M14907</guid>
      <dc:creator>ManillaTechOps</dc:creator>
      <dc:date>2013-04-21T19:43:17Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect "Server Certificate Verification Failed" Multiple Gateways</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-quot-server-certificate-verification-failed-quot/m-p/20441#M14908</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;THANK YOU SO MUCH !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It was not obvious to me AT ALL. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you buy a certificate and you don't want any errors and have the Portal and Gateway fully certified by the external CA it simply won't work!&lt;/P&gt;&lt;P&gt;I just spent exactly 2h and 28 minutes figuring out why the heck I continue to receive "Server certificate verification failed" error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I even posted some screenshots here for help. &lt;/P&gt;&lt;P&gt;Then, I got to your post, changed the "ADDRESS" field which obviously is NOT address but FQDN and I'm in. &lt;/P&gt;&lt;P&gt;No Error, all connected just fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should get like 5 starts for this hint.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot Manilla.&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Mariusz&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Nov 2014 22:30:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-quot-server-certificate-verification-failed-quot/m-p/20441#M14908</guid>
      <dc:creator>Mariusz.pianka</dc:creator>
      <dc:date>2014-11-25T22:30:33Z</dc:date>
    </item>
  </channel>
</rss>

