GlobalProtect Clientless VPN package update fails

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

GlobalProtect Clientless VPN package update fails

L3 Networker

Hello Community,

i have an issue with download the latest version of GlobalProtect Clientless VPN package update.

I have installed from scratch PANOS 8.0.0 and I have a valid Global Protect License but i'm not able to download the package from updates.paloaltonetowks.com. I'm able to download successfully all other Dynamic updates and Software.

 

Updates.PNG

 

Updates.PNG

 

I always see Last checked: never.

If i try to install it via CLI i have this error:

 

user@PA-3020> request global-protect-clientless-vpn upgrade download latest

Server error : No update information available

 

I have already tried to change the update server from updates.paloaltonetoworks.com to staticupdates.paloaltonetwork.com and tried to disable "Verify Update Server Identity" but the error remains.

Do you have any idea to resolve this issue?

 

Thanks in advance.

Jacopo 

1 accepted solution

Accepted Solutions

Hi All,

i opened a case and the issue was related of Palo Alto Updates portal.

 

Thanks for your time.

Jacopo

View solution in original post

9 REPLIES 9

Cyber Elite
Cyber Elite

Hi Jacopo

 

please click the 'check now' button at the bottom of the dynamic updates page, this loads the latest available images from the updates server:

2017-02-13_09-09-30.png

 

the CLI version is

> request content upgrade check

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Hi Reaper,

i have already tried to do "Check Now" and "request content upgrade check" without success.

I still see Never as Last Check. I tried to change Service Route Configuration without success.

 

Thanks.

Jacopo. 

hm.. as a last resort you could try restarting the management-server or rebooting the firewall and see if that helps, else you should reach out to support

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Hi Reaper,

i tried to restart management-server and reboot the firewall but the issue still there.

I tried to factory reset with PANOS 8.0.0 and reload the actual configuration without success.

I think i need to open a support ticket, can i open a ticket with an NFR appliance?

 

Thanks.

Jacopo.

ofcourse! please go ahead and create a support ticket. sounds like something is really stuck

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

2 things to check:

 

1. Do you have a valid GlobalProtect Gateway license (you said a GP license, but there used to be a Portal license and a Gateway license, only the Gateway is valid and will work for GP Clientless VPN).

2. Check your ms.log file when trying to get the update. You can run:

 

tail follow yes mp-log ms.log
--or--
less mp-log ms.log (shift+g to go to the end of the file)

That will tell you exactly what's happening beyond the error presented in the CLI. There tend to be a bunch of lines for each request (DNS lookup of the update site, connection, downloading, etc.) so you may need to do some scrolling.

 

You should see something along the lines of "File successfully downloaded" if it's there. 

Hi @gwesson,

I have GP Gateway license installed and i check ms.log file during dynamic updates and i found this error:

 

 

/opt/pancfg/mgmt/global/gpinfo.xml:1: parser error : Document is empty

^
2017-02-16 11:01:45.891 +0100 Error: pan_file_to_xml(pan_xml_utils.c:550): error parsing file /opt/pancfg/mgmt/global/gpinfo.xml
2017-02-16 11:01:45.891 +0100 Error: _get_content_version_info(pan_ops_content.c:681): Bad update information on disk

 

Do you have any idea to solve this error?

Thanks in advance.

Jacopo

 

@Jacopo_Vigano afraid not. It's not something I've seen before, but because you're getting an error I could recommend opening a case as @reaper mentioned. I'd reference this thread as well since you provided so much detail.

 

Best regards,

Greg

Hi All,

i opened a case and the issue was related of Palo Alto Updates portal.

 

Thanks for your time.

Jacopo

  • 1 accepted solution
  • 5782 Views
  • 9 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!