Global Protect Gateway External: Could not connect to gateway. Please contact your IT administrator.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Global Protect Gateway External: Could not connect to gateway. Please contact your IT administrator.

Hello everyone. 

 

I wonder if anyone else has had this issue. 

 

I'm using Global Protect version 4.1.4 on Windows 10. Everytime I try to connect I get the error "Gateway External: Could not connect to gateway. Please contact your IT administrator"

 

gp.JPG

 

I'm baffled since I can connect to the portal no problem via web browser, tracert or ping. If I connect via mobile iOS or Android it works just fine.

 

Does anyone else experience the same problem.? Everything was fine since a couple of weeks ago. Did PAN update something or maybe Windows Update?

 

Any help is appreciated. 

 

Thanks!

11 REPLIES 11

Cyber Elite
Cyber Elite

GlobalProtect will connect to portal, get list of gateways and then connects to gateway.

Check your portal config what is external gateway setting.

If it uses correct URL.

Maybe cert was updated on portal config but not on gateway.

 

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Thanks for your reply @Raido_Rattameister. Everthing seems OK with the portal. Macs work just fine as well as iOS and Android devices. I get no issues with my PC running Windows 10 but some of my peers can't connect with the same version of Windows. It's a strange one. 

 

So far the only workaround we have is downgrading to version 3.1.1

 

 

Hi Same issue i am facing , there no proper solution so far .

i have asked palo alto they started the same story of Log collection and packet capture .....very discomfort with this product.

 

and i surprised one of the support team saying use downgraded version of GP client. Poor Product.

Before get in to this product , please rethink twice . They dont have enough support engineer to support or attend our cases.

 

 

Yup. The only way to make it work for me is to uninstall everything (certificate and Global Protect client v4.0) and then reinstall the certificate and install Global Protect version 3.1.1 then it connects on the first attempt BUT -and this is where it turns stranger than Stranger Things - it will only successfully connect that one time, if you disconnect and then try to reconnect a second time it won't work and you'll have to uninstall the certificate and reinstall it everytime you want to connect.

 

Definitely a thing of beauty.

 

Greetings from the upside down!

 

 

Yes , it wont work . Looks like issue is different.

i got a resolution to disable IPSEC VPN in Firewall, but still getting error . Another solution Remove Trust certificate and re add . But still issue is there. ticket still open... i will update once resolution get 

HI Super,

 

Did you get any reply from TAC about this issue.

 

Regards

Venky

Hello,

 

Did anyone find a resolution to this problem?

Hello Guys, 

 

Did you find the resolution?

L0 Member

I know the post is a little old but I had the same error. I found two issues in my config. One is I had a typo in my DNS in the GP network settings and the second which is likely the issue, I forgot to add TCP 1812 to the Windows firewall. That would stop all radius authentication from the PA so it may not be your issue but thought I would post here in case others have the same issue. My issue happened during a GP DUO setup, the standard setup worked fine without DUO and RADUIS authentication.

@Daniel_Gill 

 

Really appreciate your reply here with great info.

 

Regards

MP

Help the community: Like helpful comments and mark solutions.
  • 23653 Views
  • 11 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!