<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Difficulties creating a secondary VPN tunnel in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/difficulties-creating-a-secondary-vpn-tunnel/m-p/25811#M18825</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have also seen the above authentication failure messages in case of ldap authentication due to mis-configuration. Most common one is that "sAMAccountName" attribute missing from the authentication profile. See below for detai&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;ls:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="14978" alt="test.png" class="image-0 jive-image" height="606" src="https://live.paloaltonetworks.com/legacyfs/online/14978_test.png" style="float: left; width: 1288px; height: 605.5400254129606px;" width="1288" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 15 Aug 2014 03:03:22 GMT</pubDate>
    <dc:creator>tshiv</dc:creator>
    <dc:date>2014-08-15T03:03:22Z</dc:date>
    <item>
      <title>Difficulties creating a secondary VPN tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/difficulties-creating-a-secondary-vpn-tunnel/m-p/25809#M18823</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm having trouble authenticating with a second VPN tunnel that I've created.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've created a new Portal and Gateway, &lt;EM&gt;almost&lt;/EM&gt; identical to the previous ones. Obviously with it's own external IP, certificate that fits the given domain.&lt;BR /&gt;Created a new Zone with a tunnel interface associated with it, which is also connected to a static route with the new GP IP range.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From GlobalProtect, I'm getting the following when I start logging:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;GetHttpResponse()...&lt;/P&gt;&lt;P&gt;(T1192) 08/14/14 10:39:46:593 Debug(1787): portal proxyparam is empty&lt;/P&gt;&lt;P&gt;(T1192) 08/14/14 10:39:46:593 Debug(1838): IPADDR=vpn._______.com,PORT=443,URL=/global-protect/getconfig.esp,POST=1,PROXY_AUTO=0,PROXY_CFGURL=NULL,PROXY=NULL,PROXY_BYPASS=NULL,PROXY_USER=NULL,PROXY_PASS=****,VERIFY_CERT=0,ADDITIONAL_CHECK=1&lt;/P&gt;&lt;P&gt;(T1192) 08/14/14 10:39:46:593 Debug( 734): Send response to client for request https_request&lt;/P&gt;&lt;P&gt;(T1192) 08/14/14 10:39:46:794 Debug(1886): receive pan_msg_ping, 3&lt;/P&gt;&lt;P&gt;(T1192) 08/14/14 10:39:56:673 Debug(1886): receive pan_msg_ping, 3&lt;/P&gt;&lt;P&gt;(T4196) 08/14/14 10:40:03:330 Debug( 407): HipMissingPatchThread: now is 1408005603, last hip check is 1408001201, hip check interval is 3600000&lt;/P&gt;&lt;P&gt;(T4196) 08/14/14 10:40:03:330 Debug( 412): HipMissingPatchThread: wait -820000 ms&lt;/P&gt;&lt;P&gt;(T4196) 08/14/14 10:40:03:330 Debug( 434): nSleep &amp;lt;= 0. m_tLastHipCheckEventWakeup is 1408001201, m_dwHipCheckInterval is 3600000, Now is 1408005603.&lt;/P&gt;&lt;P&gt;(T4196) 08/14/14 10:40:03:330 Debug( 358): CheckHipMissingPatchInOtherProcess()&lt;/P&gt;&lt;P&gt;(T4196) 08/14/14 10:40:03:330 Debug(&amp;nbsp; 63): pan_get_full_path(): full path in multibyte char is C:\Program Files\Palo Alto Networks\GlobalProtect\PanGpHipMp.exe&lt;/P&gt;&lt;P&gt;(T4196) 08/14/14 10:40:03:330 Debug( 324): CheckHipMissingPatchInOtherProcess(): Starting process PanGpHipMp.exe&lt;/P&gt;&lt;P&gt;(T1192) 08/14/14 10:40:06:705 Debug(1886): receive pan_msg_ping, 3&lt;/P&gt;&lt;P&gt;(T4196) 08/14/14 10:40:08:830 Error( 340): CheckHipMissingPatchInOtherProcess(): Wait timeout for process PanGpHipMp.exe&lt;/P&gt;&lt;P&gt;(T1192) 08/14/14 10:40:16:768 Debug(1886): receive pan_msg_ping, 3&lt;/P&gt;&lt;P&gt;(T1192) 08/14/14 10:40:16:768 Debug(2034): HTTP_RPC, len=0, result is &lt;/P&gt;&lt;P&gt;(NULL)...&lt;/P&gt;&lt;P&gt;(T1192) 08/14/14 10:40:16:768 Error(4279): pszXmlConfig is NULL. 8614&lt;/P&gt;&lt;P&gt;(T1192) 08/14/14 10:40:16:768 Debug(1426): close WinHttp close handle.&lt;/P&gt;&lt;P&gt;(T1192) 08/14/14 10:40:16:768 Info (3746): Skip reading cached portal config.&lt;/P&gt;&lt;P&gt;(T1192) 08/14/14 10:40:16:768 Debug(3754): portal status is Invalid portal.&lt;/P&gt;&lt;P&gt;(T1192) 08/14/14 10:40:16:768 Debug(3755): returns 0.&lt;/P&gt;&lt;P&gt;(T1192) 08/14/14 10:40:16:768 Debug(3284): ServerThread: ProcessServerPortal -- return SendResponseToClient(socket, PAN_SERVER_PORTAL)&lt;/P&gt;&lt;P&gt;(T1192) 08/14/14 10:40:16:768 Debug(3070): Set state to Disconnected&lt;/P&gt;&lt;P&gt;(T1192) 08/14/14 10:40:16:768 Debug( 734): Send response to client for request portal&lt;/P&gt;&lt;P&gt;(T4196) 08/14/14 10:40:17:835 Debug( 364): PanGpHipMp.exe exit for checking misssing patches.&lt;/P&gt;&lt;P&gt;(T4196) 08/14/14 10:40:17:835 Debug( 362): CheckHipMissingPatchInOtherProcess(): exits.&lt;/P&gt;&lt;P&gt;(T4196) 08/14/14 10:40:17:835 Debug( 441): Hip missing patch checking duration is 14&lt;/P&gt;&lt;P&gt;(T4196) 08/14/14 10:40:39:845 Debug( 407): HipMissingPatchThread: now is 1408005639, last hip check is 1408001201, hip check interval is 3600000&lt;/P&gt;&lt;P&gt;(T4196) 08/14/14 10:40:39:845 Debug( 412): HipMissingPatchThread: wait -860000 ms&lt;/P&gt;&lt;P&gt;(T4196) 08/14/14 10:40:39:845 Debug( 434): nSleep &amp;lt;= 0. m_tLastHipCheckEventWakeup is 1408001201, m_dwHipCheckInterval is 3600000, Now is 1408005639.&lt;/P&gt;&lt;P&gt;(T4196) 08/14/14 10:40:39:845 Debug( 358): CheckHipMissingPatchInOtherProcess()&lt;/P&gt;&lt;P&gt;(T4196) 08/14/14 10:40:39:845 Debug(&amp;nbsp; 63): pan_get_full_path(): full path in multibyte char is C:\Program Files\Palo Alto Networks\GlobalProtect\PanGpHipMp.exe&lt;/P&gt;&lt;P&gt;(T4196) 08/14/14 10:40:39:845 Debug( 324): CheckHipMissingPatchInOtherProcess(): Starting process PanGpHipMp.exe&lt;/P&gt;&lt;P&gt;(T4196) 08/14/14 10:40:45:353 Error( 340): CheckHipMissingPatchInOtherProcess(): Wait timeout for process PanGpHipMp.exe&lt;/P&gt;&lt;P&gt;(T4196) 08/14/14 10:40:49:980 Debug( 364): PanGpHipMp.exe exit for checking misssing patches.&lt;/P&gt;&lt;P&gt;(T4196) 08/14/14 10:40:49:980 Debug( 362): CheckHipMissingPatchInOtherProcess(): exits.&lt;/P&gt;&lt;P&gt;(T4196) 08/14/14 10:40:49:980 Debug( 441): Hip missing patch checking duration is 10&lt;/P&gt;&lt;P&gt;(T4196) 08/14/14 10:41:09:993 Debug( 407): HipMissingPatchThread: now is 1408005669, last hip check is 1408001201, hip check interval is 3600000&lt;/P&gt;&lt;P&gt;(T4196) 08/14/14 10:41:09:993 Debug( 412): HipMissingPatchThread: wait -888000 ms&lt;/P&gt;&lt;P&gt;(T4196) 08/14/14 10:41:09:993 Debug( 434): nSleep &amp;lt;= 0. m_tLastHipCheckEventWakeup is 1408001201, m_dwHipCheckInterval is 3600000, Now is 1408005669.&lt;/P&gt;&lt;P&gt;(T4196) 08/14/14 10:41:09:993 Debug( 358): CheckHipMissingPatchInOtherProcess()&lt;/P&gt;&lt;P&gt;(T4196) 08/14/14 10:41:09:993 Debug(&amp;nbsp; 63): pan_get_full_path(): full path in multibyte char is C:\Program Files\Palo Alto Networks\GlobalProtect\PanGpHipMp.exe&lt;/P&gt;&lt;P&gt;(T4196) 08/14/14 10:41:09:993 Debug( 324): CheckHipMissingPatchInOtherProcess(): Starting process PanGpHipMp.exe&lt;/P&gt;&lt;P&gt;(T4196) 08/14/14 10:41:15:500 Error( 340): CheckHipMissingPatchInOtherProcess(): Wait timeout for process PanGpHipMp.exe&lt;/P&gt;&lt;P&gt;(T4196) 08/14/14 10:41:19:402 Debug( 364): PanGpHipMp.exe exit for checking misssing patches.&lt;/P&gt;&lt;P&gt;(T4196) 08/14/14 10:41:19:402 Debug( 362): CheckHipMissingPatchInOtherProcess(): exits.&lt;/P&gt;&lt;P&gt;(T4196) 08/14/14 10:41:19:402 Debug( 441): Hip missing patch checking duration is 10&lt;/P&gt;&lt;P&gt;(T4196) 08/14/14 10:41:39:415 Debug( 407): HipMissingPatchThread: now is 1408005699, last hip check is 1408001201, hip check interval is 3600000&lt;/P&gt;&lt;P&gt;(T4196) 08/14/14 10:41:39:415 Debug( 412): HipMissingPatchThread: wait -918000 ms&lt;/P&gt;&lt;P&gt;(T4196) 08/14/14 10:41:39:415 Debug( 434): nSleep &amp;lt;= 0. m_tLastHipCheckEventWakeup is 1408001201, m_dwHipCheckInterval is 3600000, Now is 1408005699.&lt;/P&gt;&lt;P&gt;(T4196) 08/14/14 10:41:39:415 Debug( 358): CheckHipMissingPatchInOtherProcess()&lt;/P&gt;&lt;P&gt;(T4196) 08/14/14 10:41:39:415 Debug(&amp;nbsp; 63): pan_get_full_path(): full path in multibyte char is C:\Program Files\Palo Alto Networks\GlobalProtect\PanGpHipMp.exe&lt;/P&gt;&lt;P&gt;(T4196) 08/14/14 10:41:39:415 Debug( 324): CheckHipMissingPatchInOtherProcess(): Starting process PanGpHipMp.exe&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the system log in PAN I'm getting:&lt;/P&gt;&lt;P&gt;"GlobalProtect portal user authentication failed. Login from: 1.2.3.4, User name: user, Reason: Authentication failed: Invalid username or password , Auth type: profile"&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Did also recieve one error: "User 'user'' failed authentication.&amp;nbsp; Reason: User is not in allowlist From: 1.2.3.4" Even though I've defined the user in both the client config for the Portal, including in the authentication profile that the portal is associated with.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Anyone have suggestions to what the cause might be?&lt;BR /&gt;Last time I set up the GP I was instructed, so there's a chance that I've missed a few details.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Feel free to ask for more information if needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Appreciate the help!&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Aug 2014 09:24:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/difficulties-creating-a-secondary-vpn-tunnel/m-p/25809#M18823</guid>
      <dc:creator>pasmartin</dc:creator>
      <dc:date>2014-08-14T09:24:08Z</dc:date>
    </item>
    <item>
      <title>Re: Difficulties creating a secondary VPN tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/difficulties-creating-a-secondary-vpn-tunnel/m-p/25810#M18824</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is probably a problem with the LDAP authentication for the group or users assigned for the allow list.&amp;nbsp; Check out the troubleshooting process in this document to confirm the LDAP connection and naming conventions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-4706"&gt;GlobalProtect Login Fails When Using a Group in the Allow List &lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Aug 2014 21:31:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/difficulties-creating-a-secondary-vpn-tunnel/m-p/25810#M18824</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-08-14T21:31:32Z</dc:date>
    </item>
    <item>
      <title>Re: Difficulties creating a secondary VPN tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/difficulties-creating-a-secondary-vpn-tunnel/m-p/25811#M18825</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have also seen the above authentication failure messages in case of ldap authentication due to mis-configuration. Most common one is that "sAMAccountName" attribute missing from the authentication profile. See below for detai&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;ls:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="14978" alt="test.png" class="image-0 jive-image" height="606" src="https://live.paloaltonetworks.com/legacyfs/online/14978_test.png" style="float: left; width: 1288px; height: 605.5400254129606px;" width="1288" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Aug 2014 03:03:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/difficulties-creating-a-secondary-vpn-tunnel/m-p/25811#M18825</guid>
      <dc:creator>tshiv</dc:creator>
      <dc:date>2014-08-15T03:03:22Z</dc:date>
    </item>
  </channel>
</rss>

