GlobalProtect Clientless VPN package update fails

Reply
Highlighted
L3 Networker

GlobalProtect Clientless VPN package update fails

Hello Community,

i have an issue with download the latest version of GlobalProtect Clientless VPN package update.

I have installed from scratch PANOS 8.0.0 and I have a valid Global Protect License but i'm not able to download the package from updates.paloaltonetowks.com. I'm able to download successfully all other Dynamic updates and Software.

 

Updates.PNG

 

Updates.PNG

 

I always see Last checked: never.

If i try to install it via CLI i have this error:

 

user@PA-3020> request global-protect-clientless-vpn upgrade download latest

Server error : No update information available

 

I have already tried to change the update server from updates.paloaltonetoworks.com to staticupdates.paloaltonetwork.com and tried to disable "Verify Update Server Identity" but the error remains.

Do you have any idea to resolve this issue?

 

Thanks in advance.

Jacopo 


Accepted Solutions
Highlighted
L3 Networker

Hi All,

i opened a case and the issue was related of Palo Alto Updates portal.

 

Thanks for your time.

Jacopo

View solution in original post


All Replies
Highlighted
L7 Applicator

Hi Jacopo

 

please click the 'check now' button at the bottom of the dynamic updates page, this loads the latest available images from the updates server:

2017-02-13_09-09-30.png

 

the CLI version is

> request content upgrade check

 

Tom Piens - PANgurus.com
Like my answer? check out my book! amazon.com/dp/1789956374
Highlighted
L3 Networker

Hi Reaper,

i have already tried to do "Check Now" and "request content upgrade check" without success.

I still see Never as Last Check. I tried to change Service Route Configuration without success.

 

Thanks.

Jacopo. 

Highlighted
L7 Applicator

hm.. as a last resort you could try restarting the management-server or rebooting the firewall and see if that helps, else you should reach out to support

Tom Piens - PANgurus.com
Like my answer? check out my book! amazon.com/dp/1789956374
Highlighted
L3 Networker

Hi Reaper,

i tried to restart management-server and reboot the firewall but the issue still there.

I tried to factory reset with PANOS 8.0.0 and reload the actual configuration without success.

I think i need to open a support ticket, can i open a ticket with an NFR appliance?

 

Thanks.

Jacopo.

Highlighted
L7 Applicator

ofcourse! please go ahead and create a support ticket. sounds like something is really stuck

Tom Piens - PANgurus.com
Like my answer? check out my book! amazon.com/dp/1789956374
Highlighted
L7 Applicator

2 things to check:

 

1. Do you have a valid GlobalProtect Gateway license (you said a GP license, but there used to be a Portal license and a Gateway license, only the Gateway is valid and will work for GP Clientless VPN).

2. Check your ms.log file when trying to get the update. You can run:

 

tail follow yes mp-log ms.log
--or--
less mp-log ms.log (shift+g to go to the end of the file)

That will tell you exactly what's happening beyond the error presented in the CLI. There tend to be a bunch of lines for each request (DNS lookup of the update site, connection, downloading, etc.) so you may need to do some scrolling.

 

You should see something along the lines of "File successfully downloaded" if it's there. 

Highlighted
L3 Networker

Hi @gwesson,

I have GP Gateway license installed and i check ms.log file during dynamic updates and i found this error:

 

 

/opt/pancfg/mgmt/global/gpinfo.xml:1: parser error : Document is empty

^
2017-02-16 11:01:45.891 +0100 Error: pan_file_to_xml(pan_xml_utils.c:550): error parsing file /opt/pancfg/mgmt/global/gpinfo.xml
2017-02-16 11:01:45.891 +0100 Error: _get_content_version_info(pan_ops_content.c:681): Bad update information on disk

 

Do you have any idea to solve this error?

Thanks in advance.

Jacopo

 

Highlighted
L7 Applicator

@Jacopo_Vigano afraid not. It's not something I've seen before, but because you're getting an error I could recommend opening a case as @reaper mentioned. I'd reference this thread as well since you provided so much detail.

 

Best regards,

Greg

Highlighted
L3 Networker

Hi All,

i opened a case and the issue was related of Palo Alto Updates portal.

 

Thanks for your time.

Jacopo

View solution in original post

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!