<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect External Gateway - saying only manual gateway exits in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-external-gateway-saying-only-manual-gateway-exits/m-p/292054#M77339</link>
    <description>&lt;P&gt;If you are looking at the GP Service logs and seeing these messages, then maybe it is something else.&lt;/P&gt;&lt;P&gt;There is a lot of logic programmed to test for all occurrences/scenarios, and sometimes I see logic tested and outputted, but does not hold true.&amp;nbsp; Like your example... the startup logic tests for external gateways, comments that they are manual, but in reality, they are not.&lt;/P&gt;&lt;P&gt;I am not saying it is an anomoly or bug.. it is just my understanding that some of this realtime checks are red herrings in troubleshooting the real issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think we would need to see more than a single log entry.. i need to see about 30 lines before and after to see exactly what the GP service is attempting to do.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would perhaps test with a on-demand config, using your ldap credentials, so that you can manual turn on/off, and continue testing/committing, and troubleshooting one change at a time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It may be easier to test, and then create a tech support file and open case with support through your support portal, and they can look at the logs in detail to assist you.&amp;nbsp; You would of course, need to include the zipped logs from the user in question as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 09 Oct 2019 02:28:16 GMT</pubDate>
    <dc:creator>S.Cantwell</dc:creator>
    <dc:date>2019-10-09T02:28:16Z</dc:date>
    <item>
      <title>Global Protect External Gateway - saying only manual gateway exits</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-external-gateway-saying-only-manual-gateway-exits/m-p/291497#M77280</link>
      <description>&lt;P&gt;All of the sudden, in our global protect setup(Pre-Logon-Always-On, internal host detection, we were able to switch between internal and external networks and Global Protect would always reconnect.&amp;nbsp; For about a month this has not been working.&amp;nbsp; I got around to looking at the logs and see the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(T14316) Debug(4604): All external gateways are manual only.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is not the case as we only have one external gateway configured and it is not set to manual.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The portal and gateway are configured on the same PAN 5250 device with PanOS8.1.9&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone seen this lately or know why the client is saying this even though it's not configured that way on the PAN?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2019 18:36:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-external-gateway-saying-only-manual-gateway-exits/m-p/291497#M77280</guid>
      <dc:creator>dpeterson4</dc:creator>
      <dc:date>2019-10-04T18:36:24Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect External Gateway - saying only manual gateway exits</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-external-gateway-saying-only-manual-gateway-exits/m-p/292054#M77339</link>
      <description>&lt;P&gt;If you are looking at the GP Service logs and seeing these messages, then maybe it is something else.&lt;/P&gt;&lt;P&gt;There is a lot of logic programmed to test for all occurrences/scenarios, and sometimes I see logic tested and outputted, but does not hold true.&amp;nbsp; Like your example... the startup logic tests for external gateways, comments that they are manual, but in reality, they are not.&lt;/P&gt;&lt;P&gt;I am not saying it is an anomoly or bug.. it is just my understanding that some of this realtime checks are red herrings in troubleshooting the real issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think we would need to see more than a single log entry.. i need to see about 30 lines before and after to see exactly what the GP service is attempting to do.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would perhaps test with a on-demand config, using your ldap credentials, so that you can manual turn on/off, and continue testing/committing, and troubleshooting one change at a time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It may be easier to test, and then create a tech support file and open case with support through your support portal, and they can look at the logs in detail to assist you.&amp;nbsp; You would of course, need to include the zipped logs from the user in question as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2019 02:28:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-external-gateway-saying-only-manual-gateway-exits/m-p/292054#M77339</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-10-09T02:28:16Z</dc:date>
    </item>
  </channel>
</rss>

