global protect error - Error(6986): Protocol error.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

global protect error - Error(6986): Protocol error.

L4 Transporter

Error(6986): Protocol error. Check server certificate. Failed to ssl connect to 'globalprotect.xyz.com:443', Disconect ssl and returns false.

SD-WAN | Cloud Networking | PCNSE | ICSI CNSS | MCNA | | CCNP | CCSA | SPSP | SPSX | F5-101 |
1 accepted solution

Accepted Solutions

Great to hear, glad it is working for you now.

-joe

LIVEcommunity team member
Stay Secure,
Joe
Don't forget to Like items if a post is helpful to you!

View solution in original post

4 REPLIES 4

L4 Transporter

(T4172) 12/01/16 11:52:11:749 Debug(1189): SSL3 alert write:fatal:unknown CA
(T4172) 12/01/16 11:52:11:749 Debug(1198): SSL_connect:error in error
(T4172) 12/01/16 11:52:11:749 Debug(1198): SSL_connect:error in error
(T4172) 12/01/16 11:52:11:749 Info ( 268): SSL connect failed (error:00000001:lib(0):func(0):reason(1))
(T4172) 12/01/16 11:52:11:749 Debug( 41): detailed SSL error info:
(T4172) 12/01/16 11:52:11:749 Debug( 44): *** error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed

SD-WAN | Cloud Networking | PCNSE | ICSI CNSS | MCNA | | CCNP | CCSA | SPSP | SPSX | F5-101 |

@fatboy1607,

I responded to your other thread asking about GlobalProtect.. with links that should help..

 

But I can tell you that the problem clearly states "unknown CA" when it is trying to verify the SSL Certificate.

So, clearly there is an issue when it comes to the SSL Certificate CA.

 

Please refer to those links and see if they might help.. 

-joe

LIVEcommunity team member
Stay Secure,
Joe
Don't forget to Like items if a post is helpful to you!

Great thanks for your those links  help  really helpfull.

 

I was seeing below errors also

-------------------------------------

 

(T4172) 12/01/16 11:51:20:523 Info (1259): File C:\Users\xyz\AppData\Local\Palo Alto Networks\GlobalProtect\PanPUAC_1de3dac2233344bb4142f29f152738e0.dat does not exist.
(T4172) 12/01/16 11:51:20:523 Error(5973): Failed to delete the file C:\Users\xyz\AppData\Local\Palo Alto Networks\GlobalProtect\PanPUAC_1de3dac2233344bb4142f29f152738e0.dat.
(T4172) 12/01/16 11:51:20:523 Info (1259): File C:\Users\xyz\AppData\Local\Palo Alto Networks\GlobalProtect\PanPortalCfg_1de3dac2233344bb4142f29f152738e0.dat does not exist.
(T4172) 12/01/16 11:51:20:524 Error(5992): Failed to delete the file C:\Users\xyz\AppData\Local\Palo Alto Networks\GlobalProtect\PanPortalCfg_1de3dac2233344bb4142f29f152738e0.dat.
(T4172) 12/01/16 11:51:20:524 Info (1259): File C:\Users\xyz\AppData\Local\Palo Alto Networks\GlobalProtect\PanPortalCfg.dat does not exist.
(T4172) 12/01/16 11:51:20:524 Error(6005): Failed to delete the file C:\Users\xyz\AppData\Local\Palo Alto Networks\GlobalProtect\PanPortalCfg.dat.
(T4172) 12/01/16 11:51:20:524 Debug(5763): No scep profile

 

 

I deleted  panPortalcfg file from location C:\Users\xyz\AppData\Local\Palo Alto Networks\GlobalProtect  rebooted system 

 

it created new panportalcf file and client was able to connect fine.

 

Thanks for your response.

SD-WAN | Cloud Networking | PCNSE | ICSI CNSS | MCNA | | CCNP | CCSA | SPSP | SPSX | F5-101 |

Great to hear, glad it is working for you now.

-joe

LIVEcommunity team member
Stay Secure,
Joe
Don't forget to Like items if a post is helpful to you!
  • 1 accepted solution
  • 4017 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!