<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Connect Linux Machine to GlobalProtect in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/connect-linux-machine-to-globalprotect/m-p/177249#M55300</link>
    <description>&lt;P&gt;Hi again,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems like the Linux Client will arrive "very soon" according to some sources I have &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 18 Sep 2017 10:07:46 GMT</pubDate>
    <dc:creator>Jonathan1984</dc:creator>
    <dc:date>2017-09-18T10:07:46Z</dc:date>
    <item>
      <title>Connect Linux Machine to GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/connect-linux-machine-to-globalprotect/m-p/176715#M55218</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is my first post, so please bear with me if this is the wrong forum of if this has been answered somewhere before..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am having issues connecting a Linux client to Globalprotect. I have tried to follow the following:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Connect-Linux-Machine-to-GlobalProtect/ta-p/77307" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Connect-Linux-Machine-to-GlobalProtect/ta-p/77307&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But that did not work, the client seems to be unable to speak to the server on port 500, I am getting a timeout everythime.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have also compiled strongswan for network-manager and it went well, but the client can't connect either. So here is the log:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;Sep 15 12:32:52 jonathan-ThinkPad-S1-Yoga NetworkManager[20036]: &amp;lt;info&amp;gt; [1505471572.5478] audit: op="connection-activate" uuid="8006b232-f14b-47c6-b398-f392f2cb2e12" name="IKE" pid=20454 uid=1000 result="success"&lt;BR /&gt;Sep 15 12:32:52 jonathan-ThinkPad-S1-Yoga NetworkManager[20036]: &amp;lt;info&amp;gt; [1505471572.5500] vpn-connection[0x1bfd7c0,8006b232-f14b-47c6-b398-f392f2cb2e12,"IKE",0]: Saw the service appear; activating connection&lt;BR /&gt;Sep 15 12:32:52 jonathan-ThinkPad-S1-Yoga NetworkManager[20036]: &amp;lt;info&amp;gt; [1505471572.6614] vpn-connection[0x1bfd7c0,8006b232-f14b-47c6-b398-f392f2cb2e12,"IKE",0]: VPN connection: (ConnectInteractive) reply received&lt;BR /&gt;Sep 15 12:32:52 jonathan-ThinkPad-S1-Yoga charon-nm: 05[CFG] received initiate for NetworkManager connection IKE&lt;BR /&gt;Sep 15 12:32:52 jonathan-ThinkPad-S1-Yoga charon-nm: 05[CFG] C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority is not self signed&lt;BR /&gt;Sep 15 12:32:52 jonathan-ThinkPad-S1-Yoga charon-nm: 05[CFG] E=contacto@procert.net.ve, L=Chacao, ST=Miranda, OU=Proveedor de Certificados PROCERT, O=Sistema Nacional de Certificacion Electronica, C=VE, CN=PSCProcert is not self signed&lt;BR /&gt;Sep 15 12:32:52 jonathan-ThinkPad-S1-Yoga charon-nm: 05[CFG] using CA certificate, gateway identity 'vpn.gateway.com'&lt;BR /&gt;Sep 15 12:32:52 jonathan-ThinkPad-S1-Yoga charon-nm: 05[IKE] initiating IKE_SA IKE[4] to xxx.xxx.xxx.xxx&lt;BR /&gt;Sep 15 12:32:52 jonathan-ThinkPad-S1-Yoga charon-nm: 05[ENC] generating IKE_SA_INIT request 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) N(FRAG_SUP) N(HASH_ALG) N(REDIR_SUP) ]&lt;BR /&gt;Sep 15 12:32:52 jonathan-ThinkPad-S1-Yoga charon-nm: 05[NET] sending packet: from 192.168.43.118[48175] to xxx.xxx.xxx.xxx[500] (794 bytes)&lt;BR /&gt;Sep 15 12:32:52 jonathan-ThinkPad-S1-Yoga NetworkManager[20036]: &amp;lt;info&amp;gt; [1505471572.9543] vpn-connection[0x1bfd7c0,8006b232-f14b-47c6-b398-f392f2cb2e12,"IKE",0]: VPN plugin: state changed: starting (3)&lt;BR /&gt;Sep 15 12:32:56 jonathan-ThinkPad-S1-Yoga charon-nm: 10[IKE] retransmit 1 of request with message ID 0&lt;BR /&gt;Sep 15 12:32:56 jonathan-ThinkPad-S1-Yoga charon-nm: 10[NET] sending packet: from 192.168.43.118[48175] to xxx.xxx.xxx.xxx[500] (794 bytes)&lt;BR /&gt;Sep 15 12:33:04 jonathan-ThinkPad-S1-Yoga charon-nm: 09[IKE] retransmit 2 of request with message ID 0&lt;BR /&gt;Sep 15 12:33:04 jonathan-ThinkPad-S1-Yoga charon-nm: 09[NET] sending packet: from 192.168.43.118[48175] to xxx.xxx.xxx.xxx[500] (794 bytes)&lt;BR /&gt;Sep 15 12:33:17 jonathan-ThinkPad-S1-Yoga charon-nm: 13[IKE] retransmit 3 of request with message ID 0&lt;BR /&gt;Sep 15 12:33:17 jonathan-ThinkPad-S1-Yoga charon-nm: 13[NET] sending packet: from 192.168.43.118[48175] to xxx.xxx.xxx.xxx[500] (794 bytes)&lt;BR /&gt;Sep 15 12:33:40 jonathan-ThinkPad-S1-Yoga charon-nm: 06[IKE] retransmit 4 of request with message ID 0&lt;BR /&gt;Sep 15 12:33:40 jonathan-ThinkPad-S1-Yoga charon-nm: 06[NET] sending packet: from 192.168.43.118[48175] to xxx.xxx.xxx.xxx[500] (794 bytes)&lt;BR /&gt;Sep 15 12:33:53 jonathan-ThinkPad-S1-Yoga NetworkManager[20036]: &amp;lt;warn&amp;gt; [1505471633.0047] vpn-connection[0x1bfd7c0,8006b232-f14b-47c6-b398-f392f2cb2e12,"IKE",0]: VPN connection: connect timeout exceeded.&lt;BR /&gt;Sep 15 12:33:53 jonathan-ThinkPad-S1-Yoga NetworkManager[20036]: libnm-glib-Message: Connect timer expired, disconnecting.&lt;BR /&gt;Sep 15 12:33:53 jonathan-ThinkPad-S1-Yoga charon-nm: 10[IKE] destroying IKE_SA in state CONNECTING without notification&lt;BR /&gt;Sep 15 12:33:53 jonathan-ThinkPad-S1-Yoga NetworkManager[20036]: &amp;lt;info&amp;gt; [1505471633.0087] vpn-connection[0x1bfd7c0,8006b232-f14b-47c6-b398-f392f2cb2e12,"IKE",0]: VPN plugin: state changed: stopping (5)&lt;BR /&gt;Sep 15 12:33:53 jonathan-ThinkPad-S1-Yoga NetworkManager[20036]: &amp;lt;warn&amp;gt; [1505471633.0088] vpn-connection[0x1bfd7c0,8006b232-f14b-47c6-b398-f392f2cb2e12,"IKE",0]: VPN plugin: failed: login-failed (0)&lt;BR /&gt;Sep 15 12:33:53 jonathan-ThinkPad-S1-Yoga NetworkManager[20036]: &amp;lt;info&amp;gt; [1505471633.0089] vpn-connection[0x1bfd7c0,8006b232-f14b-47c6-b398-f392f2cb2e12,"IKE",0]: VPN plugin: state changed: stopped (6)&lt;/PRE&gt;</description>
      <pubDate>Fri, 15 Sep 2017 11:04:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/connect-linux-machine-to-globalprotect/m-p/176715#M55218</guid>
      <dc:creator>Jonathan1984</dc:creator>
      <dc:date>2017-09-15T11:04:20Z</dc:date>
    </item>
    <item>
      <title>Re: Connect Linux Machine to GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/connect-linux-machine-to-globalprotect/m-p/176724#M55220</link>
      <description>&lt;P&gt;Hi&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is your request actually&amp;nbsp;reaching the firewall ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Check on the firewall end to verify if sessions are getting formed, and if packets are getting dropped. Use dataplane debugs or captures combined with global counters to check the same. Check security policies, NAT, etc. to make sure traffic is not getting dropped.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This might help :&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Troubleshooting-GlobalProtect/ta-p/75770" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Troubleshooting-GlobalProtect/ta-p/75770&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cheers !&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Kiwi.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2017 12:17:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/connect-linux-machine-to-globalprotect/m-p/176724#M55220</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2017-09-15T12:17:55Z</dc:date>
    </item>
    <item>
      <title>Re: Connect Linux Machine to GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/connect-linux-machine-to-globalprotect/m-p/176725#M55221</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thoose packets is actually not reaching the firewall for some reason, doing a "netstat addresstoportal 500" does send some packages so there is no issues with the network from what I can see. I have tested from several Linux distros, several connections and several machines. All have the same issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any plans for a Linux client for GlobalProtect?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2017 12:23:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/connect-linux-machine-to-globalprotect/m-p/176725#M55221</guid>
      <dc:creator>Jonathan1984</dc:creator>
      <dc:date>2017-09-15T12:23:54Z</dc:date>
    </item>
    <item>
      <title>Re: Connect Linux Machine to GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/connect-linux-machine-to-globalprotect/m-p/176726#M55222</link>
      <description>&lt;P&gt;Hi&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Currently there's nothing on the roadmap with regards to a Linux client for GlobalProtect.&lt;/P&gt;
&lt;P&gt;There is however an existing feature request for it (FR #&lt;SPAN&gt;3324).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I recommend that you reach out to your local SE and have him add your vote to this FR !&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2017 12:32:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/connect-linux-machine-to-globalprotect/m-p/176726#M55222</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2017-09-15T12:32:09Z</dc:date>
    </item>
    <item>
      <title>Re: Connect Linux Machine to GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/connect-linux-machine-to-globalprotect/m-p/177249#M55300</link>
      <description>&lt;P&gt;Hi again,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems like the Linux Client will arrive "very soon" according to some sources I have &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2017 10:07:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/connect-linux-machine-to-globalprotect/m-p/177249#M55300</guid>
      <dc:creator>Jonathan1984</dc:creator>
      <dc:date>2017-09-18T10:07:46Z</dc:date>
    </item>
  </channel>
</rss>

