<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GP upgrade beyond 2.2.x in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/gp-upgrade-beyond-2-2-x/m-p/150250#M49915</link>
    <description>&lt;P&gt;Maybe not when you have your configuration upgraded. This is the first time I am seeing it working like this. No commit errors in your case? I have always seen it working with some profile. For the version, I'd say 3.1.4/5/6. They are the most common in my experience.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anurag&lt;/P&gt;</description>
    <pubDate>Wed, 29 Mar 2017 19:51:39 GMT</pubDate>
    <dc:creator>ansharma</dc:creator>
    <dc:date>2017-03-29T19:51:39Z</dc:date>
    <item>
      <title>GP upgrade beyond 2.2.x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-upgrade-beyond-2-2-x/m-p/150209#M49905</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm running GlobalProtect 2.2.1 on PANOS 7.0.7. I'm preparing to upgrade to 2.3 (and beyond) to finally support some newer client devices. This caveat in the 2.3 release notes made me pause:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;If your GlobalProtect 2.2 or earlier release configuration uses a gateway server certificate that is
not issued by a CA that is trusted by your endpoints (for example, self-signed certificates), then
you must add the CA for that certificate to the Trusted Root CA list in the portal client configuration
when upgrading to GlobalProtect 2.3 and later releases to ensure that the GlobalProtect agent
can connect to the GlobalProtect gateway.&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am using a self-signed cert (SSLVPNCert) produced by the firewall as CA on the Gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="gateway.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8552iCD946A6940DFCF2F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="gateway.png" alt="gateway.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(As an aside, I'm guessing that the SSL/TLS Service Profile used here was autogenerated during some upgrade that introduced the SSL/TLS Service Profile feature? Note that it does not appear in the list of &lt;SPAN&gt;SSL/TLS Service Profiles. Should this concern me?&lt;/SPAN&gt;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="blankprofile.png" style="width: 405px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8553i47F58257579EED3B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="blankprofile.png" alt="blankprofile.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The Portal uses the same cert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="portal.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8554i566BD914463F0F70/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="portal.png" alt="portal.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Portal Agent has the CA (MCVPN_CA) in the Trusted Root CA list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="portalagent.png" style="width: 795px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8555i112062661E771D90/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="portalagent.png" alt="portalagent.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The CA does not have the Trusted Root CA box checked under Usage.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cert.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8556i26B58A83A31FDD3F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Cert.png" alt="Cert.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am I good-to-go? Or, is the Trusted Root CA checkbox going to bite me? (If so, is it just a matter of clicking it and commiting?)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 17:39:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-upgrade-beyond-2-2-x/m-p/150209#M49905</guid>
      <dc:creator>MCmgt</dc:creator>
      <dc:date>2017-03-29T17:39:17Z</dc:date>
    </item>
    <item>
      <title>Re: GP upgrade beyond 2.2.x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-upgrade-beyond-2-2-x/m-p/150230#M49909</link>
      <description>&lt;P&gt;You'll likely need to install the certificate into the trusted certificates of your end-user devices through GPO to get this to function properly.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 18:43:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-upgrade-beyond-2-2-x/m-p/150230#M49909</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-03-29T18:43:55Z</dc:date>
    </item>
    <item>
      <title>Re: GP upgrade beyond 2.2.x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-upgrade-beyond-2-2-x/m-p/150233#M49910</link>
      <description>&lt;P&gt;Hi MCmgt,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The SSL/TLS profile cannot be empty. Please create one and use the certificate that you were using earlier (SSLVPNcert). This profile needs to be used in the portal and gateway. If SSLVPNcert is signed by the MCVPN_CA, then you are fine. Any particular reason, you aren't moving to a 3.1.x version?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anurag&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 19:19:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-upgrade-beyond-2-2-x/m-p/150233#M49910</guid>
      <dc:creator>ansharma</dc:creator>
      <dc:date>2017-03-29T19:19:36Z</dc:date>
    </item>
    <item>
      <title>Re: GP upgrade beyond 2.2.x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-upgrade-beyond-2-2-x/m-p/150235#M49912</link>
      <description>&lt;P&gt;But the SSL/TLS Profile &lt;EM&gt;can&lt;/EM&gt; be empty...because it works &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The goal is definitely &amp;gt;2.3 ... gotta get those MacOS 10.12 people off my case &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 19:39:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-upgrade-beyond-2-2-x/m-p/150235#M49912</guid>
      <dc:creator>MCmgt</dc:creator>
      <dc:date>2017-03-29T19:39:05Z</dc:date>
    </item>
    <item>
      <title>Re: GP upgrade beyond 2.2.x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-upgrade-beyond-2-2-x/m-p/150250#M49915</link>
      <description>&lt;P&gt;Maybe not when you have your configuration upgraded. This is the first time I am seeing it working like this. No commit errors in your case? I have always seen it working with some profile. For the version, I'd say 3.1.4/5/6. They are the most common in my experience.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anurag&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 19:51:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-upgrade-beyond-2-2-x/m-p/150250#M49915</guid>
      <dc:creator>ansharma</dc:creator>
      <dc:date>2017-03-29T19:51:39Z</dc:date>
    </item>
    <item>
      <title>Re: GP upgrade beyond 2.2.x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-upgrade-beyond-2-2-x/m-p/150266#M49917</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/51040"&gt;@ansharma&lt;/a&gt;&amp;nbsp;is actually right in this case this setup shouldn't be working without a SSL/TLS profile assigned, it would be intereseting to see your XML config and see if it's maybe in the reference but the GUI has stopped picking it up after an update or something?&amp;nbsp;&lt;/P&gt;&lt;P&gt;You will likely see this stop functing after upgrading the client if the certificate actually isn't being assigned to your portal.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 20:09:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-upgrade-beyond-2-2-x/m-p/150266#M49917</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-03-29T20:09:55Z</dc:date>
    </item>
    <item>
      <title>Re: GP upgrade beyond 2.2.x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-upgrade-beyond-2-2-x/m-p/150267#M49918</link>
      <description>&lt;P&gt;Sidenote: MCVPN_CA still needs to be trusted by your client machines. If they do not trust this CA then they will likely still give you an error.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 20:11:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-upgrade-beyond-2-2-x/m-p/150267#M49918</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-03-29T20:11:17Z</dc:date>
    </item>
  </channel>
</rss>

