- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
12-02-2016 09:15 AM
Is it possible to use a single install of globalprotects with multi vpn connections? I know you can set it up on a cisco vpn client but I don't see a way to do it on the GP client except for manualy changing the portal and lately that hasn't worked and say there is a cert mismatch, it seems to only want to read one cert
12-02-2016 10:11 AM
I'm not positive if this is possible without manually entering in the address on GP as we still primarly use anyconnect for VPN. As far as the cert mismatch error I imagine that it's holding it's config file and trying to use the cert that it already negotiated for the other portal. Deleting out the PanPortalCfg.dat file in AppData will likely allow you to connect to another Portal again.
12-02-2016 11:09 AM
Thats good information thanks
12-02-2016 11:23 AM
I deleted call of these PanPortalCfg.dat and it still gave me the same error
12-02-2016 12:02 PM - edited 12-02-2016 12:10 PM
Did you restart after you deleted that file, if you didn't i've had it still stay in a locked position?
12-02-2016 12:38 PM
Yup restarted multiple times, uninstalled the gp client, went into cert management and deleted all the the globalprotect certs and it still says its there in the global protect client. I used to be able to manually put the portal in and get it to work for any vpn as long as I put my user in the security group associated with the portal but now it won't work
12-02-2016 01:10 PM
If you look at this link at step 8 it walks you through defining the gateways. Someone in your organization didn't enable this with just one gateway strictly allowed id they? That's actually how you would properly setup mulitiple gateways to all of your clients.
Little rusty on GlobalProtect configuration; we don't use it outside of on-demand connections for when we update the ASAs that sit behind the firewalls and I haven't touched the config of it for a while.
12-05-2016 05:52 AM
It appears that the palo is trying to match the certificate for our staff VPN with the contractor vpn. This vpn has been working for the last three months but I did upgrade the PA from 7.0.8 to 7.010 just last week but I don't remember seeing anything inthe release notes that said anything about this.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!