<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect 5.0.4 portal not found in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-5-0-4-portal-not-found/m-p/292055#M77340</link>
    <description>&lt;P&gt;Hello Jose&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am a little confused about some of the extra/unrelated info, and then confused about the configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this fails&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;@Server-PA&amp;gt; ping source 2xx.1xx.69.44 host 8.8.4.4&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;PING 8.8.4.4 (8.8.4.4) from 2xx.1xx.69.44 : 56(84) bytes of data.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;257 packets transmitted, 0 received, 100% packet loss, time 256151ms&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;then it is security policy, PBF, or routing table related.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;when you do the pings, do you see the traffic logs (at session end) showing on your FW?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What do they show as the reason traffic is not passing.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;if the logs show traffic is allowed, the security policy is ok, but policy based forwarding and/or routing table is not correct.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What happens if yo do a traceroute from the source IP to the 8.8.4.4, and follow the packet to see where/what hops it has.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The second issue that is confusing me, is that you say that eth1/1 has a web portal.... which implies (for me) a GP portal configured to use ether1/1.&amp;nbsp; So you are also trying to get traffic to hit a new portal/gateway on eth1/3?&amp;nbsp; Maybe, maybe not...&amp;nbsp; &amp;nbsp;this is why I am confused.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think it is better to provide some screen captures of interfaces, NAT policies, and your portal/gateway IPs, so that myself or whomever is assisting, can better assist you.&amp;nbsp; &amp;nbsp;For me, it is not very clear.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 09 Oct 2019 02:42:33 GMT</pubDate>
    <dc:creator>S.Cantwell</dc:creator>
    <dc:date>2019-10-09T02:42:33Z</dc:date>
    <item>
      <title>Global Protect 5.0.4 portal not found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-5-0-4-portal-not-found/m-p/290911#M77204</link>
      <description>&lt;P&gt;hello team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have this client running his ISP thru E1/3 (secondary ISP service), he wants to allow the Global Protect client thru this conection, however, after configure the portal and gateway in the PA-500, we test in the agent installed and we got the follow logs from the GP Client engine:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(T22764) 09/26/19 19:56:27:735 Debug(4523): No need to check gateway route since no tunnel.&lt;BR /&gt;(T22764) 09/26/19 19:56:30:758 Debug(5218): NetworkConnectionMonitorThread: m_state = 0, m_bOnDemand=0, m_bAgentEnabled=1, m_bJustResumed is 1,&lt;BR /&gt;m_bHibernate is 0, m_bAgentEnabled is 1, m_bDisconnect is 0, IsConnected() is 0, IsVPNInRetry() is 0.&lt;BR /&gt;(T22764) 09/26/19 19:56:30:758 Debug(4523): No need to check gateway route since no tunnel.&lt;BR /&gt;(T22764) 09/26/19 19:56:30:758 Debug(5235): NetworkConnectionMonitorThread: Detected route change, but skip network discovery.&lt;BR /&gt;(T22764) 09/26/19 19:56:34:723 Debug(5157): NetworkConnectionMonitorThread: route change detected. Wait for 3 seconds.&lt;BR /&gt;(T22764) 09/26/19 19:56:34:723 Debug(4523): No need to check gateway route since no tunnel.&lt;BR /&gt;(T22764) 09/26/19 19:56:37:725 Debug(5218): NetworkConnectionMonitorThread: m_state = 0, m_bOnDemand=0, m_bAgentEnabled=1, m_bJustResumed is 1,&lt;BR /&gt;m_bHibernate is 0, m_bAgentEnabled is 1, m_bDisconnect is 0, IsConnected() is 0, IsVPNInRetry() is 0.&lt;BR /&gt;(T22764) 09/26/19 19:56:37:725 Debug(4523): No need to check gateway route since no tunnel.&lt;BR /&gt;(T22764) 09/26/19 19:56:37:725 Debug(5235): NetworkConnectionMonitorThread: Detected route change, but skip network discovery.&lt;BR /&gt;(T22764) 09/26/19 19:56:40:571 Debug(5157): NetworkConnectionMonitorThread: route change detected. Wait for 3 seconds.&lt;BR /&gt;(T22764) 09/26/19 19:56:40:571 Debug(4523): No need to check gateway route since no tunnel.&lt;BR /&gt;(T5392) 09/26/19 19:56:42:041 Debug( 301): Received session change, event type 8, session 1&lt;BR /&gt;(T22764) 09/26/19 19:56:43:572 Debug(5218): NetworkConnectionMonitorThread: m_state = 0, m_bOnDemand=0, m_bAgentEnabled=1, m_bJustResumed is 1,&lt;BR /&gt;m_bHibernate is 0, m_bAgentEnabled is 1, m_bDisconnect is 0, IsConnected() is 0, IsVPNInRetry() is 0.&lt;BR /&gt;(T22764) 09/26/19 19:56:43:572 Debug(4523): No need to check gateway route since no tunnel.&lt;BR /&gt;(T22764) 09/26/19 19:56:43:572 Debug(5235): NetworkConnectionMonitorThread: Detected route change, but skip network discovery.&lt;BR /&gt;(T9888) 09/26/19 19:57:00:241 Info ( 246): HipCheckThread: got check hip event or time out.&lt;BR /&gt;(T9888) 09/26/19 19:57:00:241 Debug( 258): HipCheckThread: WAIT_TIMEOUT&lt;BR /&gt;(T9888) 09/26/19 19:57:00:241 Debug( 270): HipCheckThread: m_bHipPolicyReady is false, coninue;&lt;BR /&gt;(T9888) 09/26/19 19:57:00:241 Debug( 216): HipCheckThread: wait for hip check event for 3600000 ms);&lt;BR /&gt;(T22764) 09/26/19 20:08:59:228 Debug(5157): NetworkConnectionMonitorThread: route change detected. Wait for 3 seconds.&lt;BR /&gt;(T22764) 09/26/19 20:08:59:228 Debug(4523): No need to check gateway route since no tunnel.&lt;BR /&gt;(T22764) 09/26/19 20:09:02:230 Debug(5218): NetworkConnectionMonitorThread: m_state = 0, m_bOnDemand=0, m_bAgentEnabled=1, m_bJustResumed is 1,&lt;BR /&gt;m_bHibernate is 0, m_bAgentEnabled is 1, m_bDisconnect is 0, IsConnected() is 0, IsVPNInRetry() is 0.&lt;BR /&gt;(T22764) 09/26/19 20:09:02:230 Debug(4523): No need to check gateway route since no tunnel.&lt;BR /&gt;(T22764) 09/26/19 20:09:02:230 Debug(5235): NetworkConnectionMonitorThread: Detected route change, but skip network discovery.&lt;BR /&gt;(T22764) 09/26/19 20:09:02:373 Debug(5157): NetworkConnectionMonitorThread: route change detected. Wait for 3 seconds.&lt;BR /&gt;(T22764) 09/26/19 20:09:02:373 Debug(4523): No need to check gateway route since no tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in the PA using CLI we validate the conection between E1/3 (PA500) and the e1/4 from rhe RV20 Cisco from ISP and below is the ping results:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;@Server-PA&amp;gt; ping source 2xx.1xx.69.44 host 2xx.1xx.69.41&lt;BR /&gt;PING 2xx.1xx.69.41 (2xx.1xx.69.41) from 2xx.1xx.69.44 : 56(84) bytes of data.&lt;BR /&gt;64 bytes from 2xx.1xx.69.41: icmp_seq=1 ttl=255 time=1.08 ms&lt;BR /&gt;64 bytes from 2xx.1xx.69.41: icmp_seq=2 ttl=255 time=0.997 ms&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;^C&lt;BR /&gt;--- 2xx.1xx.69.41 ping statistics ---&lt;BR /&gt;8 packets transmitted, 8 received, 0% packet loss, time 7069ms&lt;BR /&gt;rtt min/avg/max/mdev = 0.997/2.856/15.404/4.743 ms&lt;BR /&gt;&amp;nbsp;@Server-PA&amp;gt;&lt;BR /&gt;&amp;nbsp;@Server-PA&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;@Server-PA&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;@Server-PA&amp;gt;&lt;BR /&gt;&amp;nbsp;@Server-PA&amp;gt; ping source 2xx.1xx.69.44 host 8.8.4.4&lt;BR /&gt;PING 8.8.4.4 (8.8.4.4) from 2xx.1xx.69.44 : 56(84) bytes of data.&lt;BR /&gt;^C&lt;BR /&gt;--- 8.8.4.4 ping statistics ---&lt;BR /&gt;257 packets transmitted, 0 received, 100% packet loss, time 256151ms&lt;/P&gt;&lt;P&gt;&amp;nbsp;@Server-PA&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;were the 2xx.1xx.69.41 is the GW router.&lt;/P&gt;&lt;P&gt;ISP provider said "you need to put our DNS servers IP's on the next device (in this case the PA-500) in order to get INternet traffic flow", we haven't tested this option , due the fact that the client has their own DNS servers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;by the way, client also has another IPS at E1/1 which has an specific NAT rule mapped to service 80,443 for their web portal servcies, we also pointed the in first try the GP thru that interface mapped to service :8443, and again Global protect message: Portal Not found.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any ideas how to solve this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cordially&lt;/P&gt;&lt;P&gt;jose&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2019 17:26:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-5-0-4-portal-not-found/m-p/290911#M77204</guid>
      <dc:creator>JoseEspinoza</dc:creator>
      <dc:date>2019-10-02T17:26:37Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect 5.0.4 portal not found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-5-0-4-portal-not-found/m-p/292055#M77340</link>
      <description>&lt;P&gt;Hello Jose&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am a little confused about some of the extra/unrelated info, and then confused about the configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this fails&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;@Server-PA&amp;gt; ping source 2xx.1xx.69.44 host 8.8.4.4&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;PING 8.8.4.4 (8.8.4.4) from 2xx.1xx.69.44 : 56(84) bytes of data.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;257 packets transmitted, 0 received, 100% packet loss, time 256151ms&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;then it is security policy, PBF, or routing table related.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;when you do the pings, do you see the traffic logs (at session end) showing on your FW?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What do they show as the reason traffic is not passing.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;if the logs show traffic is allowed, the security policy is ok, but policy based forwarding and/or routing table is not correct.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What happens if yo do a traceroute from the source IP to the 8.8.4.4, and follow the packet to see where/what hops it has.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The second issue that is confusing me, is that you say that eth1/1 has a web portal.... which implies (for me) a GP portal configured to use ether1/1.&amp;nbsp; So you are also trying to get traffic to hit a new portal/gateway on eth1/3?&amp;nbsp; Maybe, maybe not...&amp;nbsp; &amp;nbsp;this is why I am confused.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think it is better to provide some screen captures of interfaces, NAT policies, and your portal/gateway IPs, so that myself or whomever is assisting, can better assist you.&amp;nbsp; &amp;nbsp;For me, it is not very clear.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2019 02:42:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-5-0-4-portal-not-found/m-p/292055#M77340</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-10-09T02:42:33Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect 5.0.4 portal not found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-5-0-4-portal-not-found/m-p/292203#M77367</link>
      <description>&lt;P&gt;hello Steve&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;no, basically we have a Global Protect client using the E1/3 WAN interface, if I source a ping from the E1/3 I can reach the ISP router , If I sourced the ping from E1/3 to somewhere else in the internet like &lt;A href="http://www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt; that ping doesn't work.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If i try the GP client from a PC outside of the network, I got the message portal not found, in the debugs in the PA there is not any log that shows the GP client attempt to connect.&lt;/P&gt;&lt;P&gt;-directin&lt;/P&gt;&lt;P&gt;the ISP admin said that the interface have to have their DNS servers configured in order to allow bi-directional traffic, but our client can't change their internal DNS since their web hosting web page.&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope this clarify the issue, btw , yes routing is configured in the FW.&lt;/P&gt;&lt;P&gt;cordially&lt;/P&gt;&lt;P&gt;jose&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2019 22:35:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-5-0-4-portal-not-found/m-p/292203#M77367</guid>
      <dc:creator>JoseEspinoza</dc:creator>
      <dc:date>2019-10-09T22:35:35Z</dc:date>
    </item>
  </channel>
</rss>

