<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN client certificates rejected until firewall reboot in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-certificates-rejected-until-firewall-reboot/m-p/416146#M93380</link>
    <description>&lt;P&gt;Agreed.&amp;nbsp; I'll likely try it this weekend&lt;/P&gt;</description>
    <pubDate>Tue, 29 Jun 2021 23:32:26 GMT</pubDate>
    <dc:creator>fhewiufhwefhwe</dc:creator>
    <dc:date>2021-06-29T23:32:26Z</dc:date>
    <item>
      <title>VPN client certificates rejected until firewall reboot</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-certificates-rejected-until-firewall-reboot/m-p/416080#M93362</link>
      <description>&lt;P&gt;I had to reboot my firewall this morning because it erroneously rejected client certificates required by a VPN.&lt;/P&gt;&lt;P&gt;Firewall system logs show critical event "Out of memory condition detected, kill process 3" at 4:06am&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had the exact same issue on May 5th as well (and reporting to PA) where&amp;nbsp;&lt;SPAN&gt;Clients getting VPN certificate errors despite being nowhere near expiration and reinstalling certifications&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is anyone aware of a fix?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 20:24:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-certificates-rejected-until-firewall-reboot/m-p/416080#M93362</guid>
      <dc:creator>fhewiufhwefhwe</dc:creator>
      <dc:date>2021-06-29T20:24:13Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client certificates rejected until firewall reboot</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-certificates-rejected-until-firewall-reboot/m-p/416104#M93371</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/93469"&gt;@fhewiufhwefhwe&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I've ran into this a few times with 10.0 throughout various releases and haven't gotten an actual direct answer from support. I'd keep reporting it, because it's definitely a bug somewhere that they just don't appear to have enough data to track down yet.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 21:11:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-certificates-rejected-until-firewall-reboot/m-p/416104#M93371</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-06-29T21:11:08Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client certificates rejected until firewall reboot</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-certificates-rejected-until-firewall-reboot/m-p/416127#M93373</link>
      <description>&lt;P&gt;I also have seen this issue. Clients were not able to connect and they were presented with a message that a valid certificste is required. I also saw the out of memory logs. After that I installed PAN-OS 9.1.10 which has quite a few fixes for something that could result in this problem. So far the error did not happen again.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 22:12:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-certificates-rejected-until-firewall-reboot/m-p/416127#M93373</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2021-06-29T22:12:07Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client certificates rejected until firewall reboot</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-certificates-rejected-until-firewall-reboot/m-p/416130#M93374</link>
      <description>&lt;P&gt;Are either of you running in HA Pair?&amp;nbsp; I am wondering whether or not that might mitigate the issue in active-passive and/or active-active until there is a bug fix.&amp;nbsp; Both times this issue occurred early morning, and fortunately only two people were in the office by then.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 22:18:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-certificates-rejected-until-firewall-reboot/m-p/416130#M93374</guid>
      <dc:creator>fhewiufhwefhwe</dc:creator>
      <dc:date>2021-06-29T22:18:07Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client certificates rejected until firewall reboot</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-certificates-rejected-until-firewall-reboot/m-p/416131#M93375</link>
      <description>&lt;P&gt;I had the issue in a HA pair (active-passive). Actually we have more than 10 other firewall HA pairs where we use global protect, but so far (luckily) the issue only happened on one of them ...&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 22:25:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-certificates-rejected-until-firewall-reboot/m-p/416131#M93375</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2021-06-29T22:25:46Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client certificates rejected until firewall reboot</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-certificates-rejected-until-firewall-reboot/m-p/416132#M93376</link>
      <description>&lt;P&gt;Got it.&amp;nbsp; So the passive firewall took over while you rebooted the problematic active firewall, and users didn't have downtime during the reboot.&amp;nbsp; Is that correct?&amp;nbsp; How much time did it take to configure active-passive mode for the first time?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 22:29:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-certificates-rejected-until-firewall-reboot/m-p/416132#M93376</guid>
      <dc:creator>fhewiufhwefhwe</dc:creator>
      <dc:date>2021-06-29T22:29:22Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client certificates rejected until firewall reboot</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-certificates-rejected-until-firewall-reboot/m-p/416141#M93377</link>
      <description>&lt;P&gt;As long as you immediately reboot the firewall after the OOM systemlog, then yes you will be able to reduce the downtime to almost 0. Otherwise there will still be a timeframe where users are not able to connect.&lt;/P&gt;
&lt;P&gt;Setting up a HA pair on the firewallside is quite easy to do. The walkthrough with a step by step manual you can find here:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/high-availability/set-up-activepassive-ha/configure-activepassive-ha.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/high-availability/set-up-activepassive-ha/configure-activepassive-ha.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Depending on thw network setup you need to change some things there too.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What PAN-OS version do you currently run on this firewall?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 23:24:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-certificates-rejected-until-firewall-reboot/m-p/416141#M93377</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2021-06-29T23:24:24Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client certificates rejected until firewall reboot</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-certificates-rejected-until-firewall-reboot/m-p/416144#M93378</link>
      <description>&lt;P&gt;9.1.9&lt;/P&gt;&lt;P&gt;I tried upgrading to 10.0 a couple of times last year, but found it too buggy at the time.&amp;nbsp; Not sure if it stable enough to run production now, but I will likely wait at least a few more weeks before considering an upgrade.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 23:29:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-certificates-rejected-until-firewall-reboot/m-p/416144#M93378</guid>
      <dc:creator>fhewiufhwefhwe</dc:creator>
      <dc:date>2021-06-29T23:29:31Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client certificates rejected until firewall reboot</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-certificates-rejected-until-firewall-reboot/m-p/416145#M93379</link>
      <description>&lt;P&gt;I think you should consider an update to 9.1.10. Maybe the situation gets also better for you and maybe the issue is already completely resolved in this version&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 23:31:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-certificates-rejected-until-firewall-reboot/m-p/416145#M93379</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2021-06-29T23:31:15Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client certificates rejected until firewall reboot</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-certificates-rejected-until-firewall-reboot/m-p/416146#M93380</link>
      <description>&lt;P&gt;Agreed.&amp;nbsp; I'll likely try it this weekend&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 23:32:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-certificates-rejected-until-firewall-reboot/m-p/416146#M93380</guid>
      <dc:creator>fhewiufhwefhwe</dc:creator>
      <dc:date>2021-06-29T23:32:26Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client certificates rejected until firewall reboot</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-certificates-rejected-until-firewall-reboot/m-p/417113#M93512</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/93469"&gt;@fhewiufhwefhwe&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;did you do the update to 9.1.10 and if so, did the problem happen again since then?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 10:23:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-certificates-rejected-until-firewall-reboot/m-p/417113#M93512</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2021-07-05T10:23:17Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client certificates rejected until firewall reboot</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-certificates-rejected-until-firewall-reboot/m-p/417251#M93527</link>
      <description>&lt;P&gt;Updated, but the issue occurred between 30 and 50 days uptime after a memory error.&amp;nbsp; Within waiting two months or a reocurrence, I have no way to confirm that the issue has been fixed.&amp;nbsp; The release notes did not mention a similar issue.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jul 2021 13:51:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-certificates-rejected-until-firewall-reboot/m-p/417251#M93527</guid>
      <dc:creator>fhewiufhwefhwe</dc:creator>
      <dc:date>2021-07-06T13:51:36Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client certificates rejected until firewall reboot</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-certificates-rejected-until-firewall-reboot/m-p/417256#M93528</link>
      <description>&lt;P&gt;That could be an issue with time sync b/w MP and DP. You may need to check with NTP servers, if any. Reboot makes both MP and DP clock in sync and for more info follow below.&lt;/P&gt;&lt;P data-unlink="true"&gt;&lt;SPAN&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clh4CAC&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;PAN-160744&lt;/DIV&gt;&lt;P data-unlink="true"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-release-notes/pan-os-9-1-addressed-issues/pan-os-9-1-9-addressed-issues.html&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jul 2021 14:13:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-client-certificates-rejected-until-firewall-reboot/m-p/417256#M93528</guid>
      <dc:creator>asangra</dc:creator>
      <dc:date>2021-07-06T14:13:08Z</dc:date>
    </item>
  </channel>
</rss>

