<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic GlobalProtect client stopped working after upgrade from 8.0.7 to 8.1.2 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-stopped-working-after-upgrade-from-8-0-7-to/m-p/227187#M65381</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Errors: globalprotectgateway-config-fail, description contains 'GlobalProtect gateway client configuration failed. User name: , Client OS version: Microsoft Windows 10 Enterprise , 64-bit, error: Matching client config not found.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Once I removed the group from Gateway\Agent\Client Settings\User group, and selected any, users could login, no error.&lt;BR /&gt;But as soon as I add the group back (which is required by our company security), get the error again and users can't login.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This is a site location in Sydney, our main DC and Agent servers are in Oregon. But they do have a local AD server, and I do have that in the LDAP config.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Have anyone else had this problem?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 15 Aug 2018 17:26:53 GMT</pubDate>
    <dc:creator>Margit_Curtis</dc:creator>
    <dc:date>2018-08-15T17:26:53Z</dc:date>
    <item>
      <title>GlobalProtect client stopped working after upgrade from 8.0.7 to 8.1.2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-stopped-working-after-upgrade-from-8-0-7-to/m-p/227187#M65381</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Errors: globalprotectgateway-config-fail, description contains 'GlobalProtect gateway client configuration failed. User name: , Client OS version: Microsoft Windows 10 Enterprise , 64-bit, error: Matching client config not found.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Once I removed the group from Gateway\Agent\Client Settings\User group, and selected any, users could login, no error.&lt;BR /&gt;But as soon as I add the group back (which is required by our company security), get the error again and users can't login.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This is a site location in Sydney, our main DC and Agent servers are in Oregon. But they do have a local AD server, and I do have that in the LDAP config.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Have anyone else had this problem?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Aug 2018 17:26:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-stopped-working-after-upgrade-from-8-0-7-to/m-p/227187#M65381</guid>
      <dc:creator>Margit_Curtis</dc:creator>
      <dc:date>2018-08-15T17:26:53Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect client stopped working after upgrade from 8.0.7 to 8.1.2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-stopped-working-after-upgrade-from-8-0-7-to/m-p/227197#M65383</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/48134"&gt;@Margit_Curtis&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Did you make note of the &lt;A href="https://www.paloaltonetworks.com/documentation/81/pan-os/pan-os-release-notes/pan-os-8-1-release-information/changes-to-default-behavior/user-id-changes#id1798F60E0PL" target="_self"&gt;User-ID Changes&lt;/A&gt; that were included as part of the PAN-OS 8.1 upgrade? I would verify that the user-id that globalprotect is recieving is actually in the correct format and is as expected by your configuration.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Aug 2018 19:24:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-stopped-working-after-upgrade-from-8-0-7-to/m-p/227197#M65383</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-08-15T19:24:22Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect client stopped working after upgrade from 8.0.7 to 8.1.2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-stopped-working-after-upgrade-from-8-0-7-to/m-p/227209#M65386</link>
      <description>&lt;P&gt;Thanks you BPry, I'll check it out.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Aug 2018 21:25:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-stopped-working-after-upgrade-from-8-0-7-to/m-p/227209#M65386</guid>
      <dc:creator>Margit_Curtis</dc:creator>
      <dc:date>2018-08-15T21:25:51Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect client stopped working after upgrade from 8.0.7 to 8.1.2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-stopped-working-after-upgrade-from-8-0-7-to/m-p/227216#M65389</link>
      <description>&lt;P&gt;I'm using SamAccountName, and nothing else changed, besides that some of the attributes are in a slightly different location to configure. The configuration still looks correct, and I can browse and see the group and users.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Aug 2018 21:42:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-stopped-working-after-upgrade-from-8-0-7-to/m-p/227216#M65389</guid>
      <dc:creator>Margit_Curtis</dc:creator>
      <dc:date>2018-08-15T21:42:04Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect client stopped working after upgrade from 8.0.7 to 8.1.2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-stopped-working-after-upgrade-from-8-0-7-to/m-p/227312#M65415</link>
      <description>&lt;P&gt;I've noticed that user who logs on from Sydney doesn't show the groups when running:&amp;nbsp; show user ip-user-mapping ip x.x.x.x&lt;/P&gt;&lt;P&gt;IP address:&amp;nbsp;x.x.x.x (vsys1)&lt;BR /&gt;User: domain name\user name&lt;BR /&gt;From: GP&lt;BR /&gt;Idle Timeout: 1038s&lt;BR /&gt;Max. TTL: 1038s&lt;BR /&gt;Group(s): domain name\User name(3519)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But the user that's logon from Oregon does:&amp;nbsp;&lt;SPAN&gt;show user ip-user-mapping ip x.x.x.x&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;IP address: x.x.x.x (vsys1)&lt;BR /&gt;User: domainame\vpntest&lt;BR /&gt;From: GP&lt;BR /&gt;Idle Timeout: 10782s&lt;BR /&gt;Max. TTL: 10782s&lt;BR /&gt;Group(s): domainame\vpntest(3599)&lt;BR /&gt;cn=vpn-fulltunnel,ou=ouname,dc=domainname,dc=test(2147483989)&lt;BR /&gt;and all the other groups are listed where the user is member of...&lt;/P&gt;</description>
      <pubDate>Thu, 16 Aug 2018 17:27:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-stopped-working-after-upgrade-from-8-0-7-to/m-p/227312#M65415</guid>
      <dc:creator>Margit_Curtis</dc:creator>
      <dc:date>2018-08-16T17:27:31Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect client stopped working after upgrade from 8.0.7 to 8.1.2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-stopped-working-after-upgrade-from-8-0-7-to/m-p/227325#M65422</link>
      <description>&lt;P&gt;In both those clients, is the domain the same? You've listed them slightly differently ("domain name" versus "domainame") and I'm not sure if that's just a typo or an indication that it's a separate domain. If it is two separate domains, you'll need a separate LDAP server profile for each domain controller.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, ensure that both are referenced under Device &amp;gt; User Identification &amp;gt; Group Mapping Settings tab. You'll want to ensure that both DCs are pulling the correct groups into the Group Include List section of that group mapping.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Aug 2018 18:13:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-stopped-working-after-upgrade-from-8-0-7-to/m-p/227325#M65422</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2018-08-16T18:13:37Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect client stopped working after upgrade from 8.0.7 to 8.1.2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-stopped-working-after-upgrade-from-8-0-7-to/m-p/227329#M65425</link>
      <description>&lt;P&gt;They are on the same domain, just a hurried typing on my part.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Aug 2018 18:23:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-stopped-working-after-upgrade-from-8-0-7-to/m-p/227329#M65425</guid>
      <dc:creator>Margit_Curtis</dc:creator>
      <dc:date>2018-08-16T18:23:05Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect client stopped working after upgrade from 8.0.7 to 8.1.2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-stopped-working-after-upgrade-from-8-0-7-to/m-p/227997#M65576</link>
      <description>&lt;P&gt;This issue has been resloved, thank you for the comments.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem was the domain name. The users that worked, was domain\username --&amp;gt; without the suffix.&lt;BR /&gt;The users that didn't work, had the full domain name, domain.local\username --&amp;gt; with the suffix.&lt;/P&gt;&lt;P&gt;The solution was in the Authentication Profile to change the User Domain without the suffix.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Aug 2018 23:40:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-stopped-working-after-upgrade-from-8-0-7-to/m-p/227997#M65576</guid>
      <dc:creator>Margit_Curtis</dc:creator>
      <dc:date>2018-08-22T23:40:39Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect client stopped working after upgrade from 8.0.7 to 8.1.2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-stopped-working-after-upgrade-from-8-0-7-to/m-p/243394#M69599</link>
      <description>&lt;P&gt;Thanks for sharing.&amp;nbsp; We had this exact problem.&amp;nbsp; We are using AD groups to assign the GP Client config.&amp;nbsp; Since the domain was set incorrectly in the Authentication profile (was:&amp;nbsp; domain.local,&amp;nbsp; fixed:&amp;nbsp; domain), the UserID couldn't map the groups to that user account, so it couldn't match a GP Client config.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Dec 2018 20:04:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-stopped-working-after-upgrade-from-8-0-7-to/m-p/243394#M69599</guid>
      <dc:creator>svintinner</dc:creator>
      <dc:date>2018-12-14T20:04:00Z</dc:date>
    </item>
  </channel>
</rss>

