<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GP Server Certificate Verification Failed in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/gp-server-certificate-verification-failed/m-p/141007#M48325</link>
    <description>&lt;P&gt;The certificate CN and the external GP gateway match as IP and IP / FQDN and FQDN?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Peter&lt;/P&gt;</description>
    <pubDate>Fri, 03 Feb 2017 19:05:58 GMT</pubDate>
    <dc:creator>sullivanpj2</dc:creator>
    <dc:date>2017-02-03T19:05:58Z</dc:date>
    <item>
      <title>GP Server Certificate Verification Failed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-server-certificate-verification-failed/m-p/140916#M48317</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I wanted to upgrade the Global Protect Version.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently, I have version 2.3.4 in use an everything works fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now I have a new mac with 10.12 and therefore I need version 3.1.1 of GP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I activated it on the firewall, installed it on the mac 10.12 and now there's is an error:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Server Certificate Verification Failed"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not able to connect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found the "FQDN" thing on the internet. Indeed, I have the ip address in the External Gateway field.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I had version 2.3.4 and it worked anyway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I'm not sure if this is my problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PAN OS: 7.0.7&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2017 14:07:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-server-certificate-verification-failed/m-p/140916#M48317</guid>
      <dc:creator>MPI-AE</dc:creator>
      <dc:date>2017-02-03T14:07:34Z</dc:date>
    </item>
    <item>
      <title>Re: GP Server Certificate Verification Failed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-server-certificate-verification-failed/m-p/140962#M48322</link>
      <description>&lt;P&gt;It's a known issue with the 2.3.x where it didn't really care and didn't complain about it. Just a side not on this as well I'm pretty sure you just broke GP. 3.1.1 requires the portal to be running PANos 7.1 or higher, since your running 7.0.7 this isn't going to work anyways so that may very well be your issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not all that sure that you need 3.1.1 to run GP on 10.12; I've got 3.0.3 running on our main GP and it connects to my iMac running the latest macOS perfectly fine.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2017 17:42:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-server-certificate-verification-failed/m-p/140962#M48322</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-02-03T17:42:44Z</dc:date>
    </item>
    <item>
      <title>Re: GP Server Certificate Verification Failed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-server-certificate-verification-failed/m-p/141007#M48325</link>
      <description>&lt;P&gt;The certificate CN and the external GP gateway match as IP and IP / FQDN and FQDN?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Peter&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2017 19:05:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-server-certificate-verification-failed/m-p/141007#M48325</guid>
      <dc:creator>sullivanpj2</dc:creator>
      <dc:date>2017-02-03T19:05:58Z</dc:date>
    </item>
    <item>
      <title>Re: GP Server Certificate Verification Failed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-server-certificate-verification-failed/m-p/141115#M48338</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Where can I find the information that GP 3.1.1 requires PAN OS 7.1 or higher?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Okay, so I will try GP 3.0.3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;GP 3.0.3 doesn't require PAN OS 7.1?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But the whole thing is strange.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I activated GP 3.1.1 on my PAN OS 7.0.7 PA-3020.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My other devices (Windows 7, Windows 10, Mac os x 10.11) all work fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;They did the automatic client upgrade from 2.3.4 to 3.1.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I mean they work, although I have PAN OS 7.0.7 ?!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But why does my mac with 10.12 doesn't connect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't know what to do now..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/55325"&gt;@sullivanpj2&lt;/a&gt;&lt;/P&gt;&lt;P&gt;What do you exactly mean?&lt;/P&gt;</description>
      <pubDate>Sat, 04 Feb 2017 11:01:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-server-certificate-verification-failed/m-p/141115#M48338</guid>
      <dc:creator>MPI-AE</dc:creator>
      <dc:date>2017-02-04T11:01:17Z</dc:date>
    </item>
    <item>
      <title>Re: GP Server Certificate Verification Failed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-server-certificate-verification-failed/m-p/141121#M48343</link>
      <description>&lt;P&gt;There's a "newer" verififcation check that PA added into GP (sometime in OS 2) that checks if the common name of the certificate and the globalprotect gateway match as IP or FQDN. For whatever reason, even if your DNS can resolve the FQDN, the PA will not allow them to be different. Here's the article but this is almost always what Server Certificate Verification Failed points too.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/GlobalProtect-Gateway-Certificate-Error-When-Trying-to-Use/ta-p/57043" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/GlobalProtect-Gateway-Certificate-Error-When-Trying-to-Use/ta-p/57043&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Double check these settings and let us know!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Peter&lt;/P&gt;</description>
      <pubDate>Sat, 04 Feb 2017 13:14:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-server-certificate-verification-failed/m-p/141121#M48343</guid>
      <dc:creator>sullivanpj2</dc:creator>
      <dc:date>2017-02-04T13:14:48Z</dc:date>
    </item>
    <item>
      <title>Re: GP Server Certificate Verification Failed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-server-certificate-verification-failed/m-p/141123#M48344</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/55325"&gt;@sullivanpj2&lt;/a&gt;&amp;nbsp;the additional verification setup had already been enabled on 2.3.4 if memory serves correctly; good thing to check and make sure that it was actually setup correctly though.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/50331"&gt;@MPI-AE&lt;/a&gt;&amp;nbsp;You can find the release notes either on device under the 'Device' tab, going to globalprotect client and then on the right where it actually gives you the option to download and activate the software package it actually has a 'release notes' link that will bring you directly to that software version's release notes. Alternatively they are available on the support.paloaltonetwork.com site under the Software Updates section.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe that you can use any GP version until you hit 3.1.x with a portal running on PAN OS 7.0.x, but you should really check the release notes before you ever install a new GP agent or install a new software version on PAN devices.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's a possibility that the upgrades worked because it only upgrades the newer files, or in other words it does an 'incremental' update; GP doesn't actually fully reinstall itself when you update the client. Before you really start troubleshooting your mac client I really recommend getting on a supported agent for your GP portal version.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 04 Feb 2017 13:24:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-server-certificate-verification-failed/m-p/141123#M48344</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-02-04T13:24:27Z</dc:date>
    </item>
    <item>
      <title>Re: GP Server Certificate Verification Failed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-server-certificate-verification-failed/m-p/141130#M48348</link>
      <description>&lt;P&gt;Okay you are right. I read the release notes and you need pan os 7.1 for GP 3.1.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I have to upgrade my firewall.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2017 08:19:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-server-certificate-verification-failed/m-p/141130#M48348</guid>
      <dc:creator>MPI-AE</dc:creator>
      <dc:date>2017-02-06T08:19:32Z</dc:date>
    </item>
    <item>
      <title>Re: GP Server Certificate Verification Failed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-server-certificate-verification-failed/m-p/143608#M48734</link>
      <description>&lt;P&gt;So I upgraded my firewall to 7.1.7.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, the mac with mac os x 10.12 still doesn't connect and says "Gateway Ext Gateway: Server Certificate Verification Failed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My other clients all work fine:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Windows 7&lt;/P&gt;&lt;P&gt;- Windows 10&lt;/P&gt;&lt;P&gt;- Mac os x 10.10&lt;/P&gt;&lt;P&gt;- Mac os x 10.11&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I'm wondering why only the mac with 10.12 is complaining?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS: I have checked the CN in the certificate. We are using an ip address.&lt;/P&gt;&lt;P&gt;This ip address is also in the external gateway field of the Portal.&lt;/P&gt;&lt;P&gt;So that matches.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2017 08:44:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-server-certificate-verification-failed/m-p/143608#M48734</guid>
      <dc:creator>MPI-AE</dc:creator>
      <dc:date>2017-02-17T08:44:07Z</dc:date>
    </item>
    <item>
      <title>Re: GP Server Certificate Verification Failed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-server-certificate-verification-failed/m-p/143855#M48773</link>
      <description>&lt;P&gt;PAN-OS 7.1.8 Addressed Issues&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;PAN-73291&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Fixed an issue where authentication failed for client certificates signed by a CA certificate that was not listed first in the Certificate Profile configured with client certificate authentication for GlobalProtect portals and gateways.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this my issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2017 14:39:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-server-certificate-verification-failed/m-p/143855#M48773</guid>
      <dc:creator>MPI-AE</dc:creator>
      <dc:date>2017-02-20T14:39:01Z</dc:date>
    </item>
    <item>
      <title>Re: GP Server Certificate Verification Failed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-server-certificate-verification-failed/m-p/144256#M48852</link>
      <description>&lt;P&gt;Global Protect version 3.1.5 solved my problem.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Feb 2017 06:53:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-server-certificate-verification-failed/m-p/144256#M48852</guid>
      <dc:creator>MPI-AE</dc:creator>
      <dc:date>2017-02-22T06:53:50Z</dc:date>
    </item>
    <item>
      <title>Re: GP Server Certificate Verification Failed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-server-certificate-verification-failed/m-p/148343#M49571</link>
      <description>&lt;P&gt;Have you tested with the latest GP version? Like on GP version 4.0 ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 19 Mar 2017 20:15:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-server-certificate-verification-failed/m-p/148343#M49571</guid>
      <dc:creator>RamBista1</dc:creator>
      <dc:date>2017-03-19T20:15:00Z</dc:date>
    </item>
    <item>
      <title>Re: GP Server Certificate Verification Failed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-server-certificate-verification-failed/m-p/148542#M49595</link>
      <description>&lt;P&gt;It did not fix my issue with PAN-OS 8.0 and the GP ver. 4.0. Anyone tested it yet?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Mar 2017 02:44:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-server-certificate-verification-failed/m-p/148542#M49595</guid>
      <dc:creator>RamBista1</dc:creator>
      <dc:date>2017-03-21T02:44:16Z</dc:date>
    </item>
    <item>
      <title>Re: GP Server Certificate Verification Failed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-server-certificate-verification-failed/m-p/149039#M49719</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/47849"&gt;@RamBista1&lt;/a&gt;I just started building out a GP VPN on a 220 with 8.0.1 myself and what I've learned is that I am getting this error with the Windows client, but not the iOS app which appears to work perfectly. Just wondering if you've tried the iOS app and seen the same or if you have the same problems with it.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 23:04:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-server-certificate-verification-failed/m-p/149039#M49719</guid>
      <dc:creator>bradk14</dc:creator>
      <dc:date>2017-03-22T23:04:02Z</dc:date>
    </item>
    <item>
      <title>Re: GP Server Certificate Verification Failed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-server-certificate-verification-failed/m-p/152192#M50349</link>
      <description>&lt;P&gt;I also seem to be having this issue but, oddly, only for two reported users so far. &amp;nbsp;There may be more than just haven't reported. &amp;nbsp;Both these users are getting an error saying the Server Verification Failed when GP attempts to connect to the gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My setup:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;One portal and multiple gateways used for various purposes. &amp;nbsp;Each of these has it's own loopback and IP addresses.&lt;/LI&gt;&lt;LI&gt;Portal and the gateway that most users are allowed to connect to both use the same wildcard cert.&lt;/LI&gt;&lt;LI&gt;Multiple client configs setup based on usernames/usergroups.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The wildcard cert being used for both the portal and the primary gateway is a leftover config from when the portal and gateway were on the same loopback interface. &amp;nbsp;I've since separated them out but, apparently, forgot to change the certificate over to the new one that was created specifically for the gateway's FQDN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The two users are both on Windows, however, one is on Windows 7 x64 and the other is on Windows Server 2012 R2.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2017 14:43:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-server-certificate-verification-failed/m-p/152192#M50349</guid>
      <dc:creator>jsalmans</dc:creator>
      <dc:date>2017-04-11T14:43:48Z</dc:date>
    </item>
    <item>
      <title>Re: GP Server Certificate Verification Failed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-server-certificate-verification-failed/m-p/153073#M50558</link>
      <description>&lt;P&gt;Just thought I'd reply back after finding the solution to my issue with Palo Alto's help today. &amp;nbsp;The client that was attempting the connection was a Windows 7 x64 Home Edition and was utilizing ECN:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://en.wikipedia.org/wiki/Explicit_Congestion_Notification" target="_self"&gt;https://en.wikipedia.org/wiki/Explicit_Congestion_Notification&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The end result was that GP would try to connect to the Portal a few times, get denied due to the ECN and CWR flags on the SYN packets a few times, then go back to a simple SYN without ECN packet and establish connection to the portal. &amp;nbsp;The gateway connection would attempt next and would fail due to the ECN and CWR flags again, however, unlike with the portal the GP client would not fail back to the simpler SYN packet and the connection would fail with the complaint about the Gateway Server Certificate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The workaround was to disable ECN on the Windows client by issuing the following command on an elevated command prompt:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;netsh int tcp set global ecncapability=disabled&lt;/PRE&gt;&lt;P&gt;After running this command, the client was able to connect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2017 19:24:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-server-certificate-verification-failed/m-p/153073#M50558</guid>
      <dc:creator>jsalmans</dc:creator>
      <dc:date>2017-04-18T19:24:54Z</dc:date>
    </item>
  </channel>
</rss>

