multi-vpn

Reply
Highlighted
L4 Transporter

multi-vpn

Is it possible to use a single install of globalprotects with multi vpn connections? I know you can set it up on a cisco vpn client but I don't see a way to do it on the GP client except for manualy changing the portal and lately that hasn't worked and say there is a cert mismatch, it seems to only want to read one cert

Highlighted
Cyber Elite

I'm not positive if this is possible without manually entering in the address on GP as we still primarly use anyconnect for VPN. As far as the cert mismatch error I imagine that it's holding it's config file and trying to use the cert that it already negotiated for the other portal. Deleting out the PanPortalCfg.dat file in AppData will likely allow you to connect to another Portal again. 

Highlighted
L4 Transporter


Thats good information thanks

Highlighted
L4 Transporter

I deleted call of these PanPortalCfg.dat  and it still gave me the same error

Highlighted
Cyber Elite

Did you restart after you deleted that file, if you didn't i've had it still stay in a locked position?

Highlighted
L4 Transporter

Yup restarted multiple times, uninstalled the gp client, went into cert management and deleted all the the globalprotect certs and it still says its there in the global protect client. I used to be able to manually put the portal in and get it to work for any vpn as long as I put my user in the security group associated with the portal but now it won't work

Highlighted
Cyber Elite

If you look at this link at step 8 it walks you through defining the gateways. Someone in your organization didn't enable this with just one gateway strictly allowed id they? That's actually how you would properly setup mulitiple gateways to all of your clients. 

 

Little rusty on GlobalProtect configuration; we don't use it outside of on-demand connections for when we update the ASAs that sit behind the firewalls and I haven't touched the config of it for a while. 

Highlighted
L4 Transporter

It appears that the palo is trying to match the certificate for our staff VPN with the contractor vpn.  This vpn has been working for the last three months but I did upgrade the PA from 7.0.8 to 7.010 just last week but I don't remember seeing anything inthe release notes that said anything about this.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!