08-23-2022 11:28 PM - edited 08-24-2022 10:05 PM
Hi Team,
I am getting below error while try to connect to GP.
When I am try to connect to the portal getting this error, any suggestions? before it was showing continue but not it is not showing.
Usually it will give the option to proceed anyway but it is not giving that option. After Reinstallation it is giving that option.
08-25-2022 11:47 PM
Hey @SubaMuthuram ,
Yes, but you will need to re-install GP agent again. Because you are in the "catch 22" right now - in order for the GP agent to get the new setting it needs to connect to GP portal, but it cannot because it still has the old setting which will not allow it to proceed with invalid certificate.
- Set "allow users to continue..." to yes under GP portal settings
- Re-install the GP to get the default behaviour and allow you to continue with invalid cert
- Any subsequent connection should allow you to continue with invalid cert
Although the above will definately solve your problem, I must say the proper way would be to use valid certificate which GP agent trust and leave the setting with default value of no (to block users connecting to portal with invalid certifcate), to prevent any possible man-in-the-middle.
08-25-2022 02:19 AM
Hi @SubaMuthuram ,
Did I understand it correctly ? After reinstalling GP your problem was resolved ?
Best,
-Kiwi.
08-25-2022 10:59 PM
Hi @SubaMuthuram ,
It sounds that like under the portal, agent config you are using either the default value (or specifically set it) for the option "Allow User to Continue with Invalid Portal Server certificate"
As you can imagine from the name it will not allow users to continue with connection if they don't trust the portal certificate.
Now there is a "Catch 22" - this is GP agent behaviour config which GP agent will receive from the portal on his fist connection.
When you manually re-install the GP agent application its default behaviour is restored, which will allow you to continue if you don't trust portal certificate. Once you connect and get the portal config from the firewall any subsequent connection will fail - because agent is now instructed to not continue if portal cert is invalid.
As described on the following link you could control this setting during installation - https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/globalprotect-apps/deploy-ap...
This way even the very first connection to portal will fail, because after installation agent default behaviour will be "don't proceed if cert is invalid"
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!