Unable to connet via Global protect and ISE - "Matching client config not found"

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Unable to connet via Global protect and ISE - "Matching client config not found"

L2 Linker

Hello,

at the moment i'm authenticating users via the local database on palo alto firewall for vpn gp users; what 'id like to do is trying to authenticate vpn users via Cisco Ise.

I've configured local users on Ise and what i want to do is that when a user tries to login, ise checks if the user is present in the local group, and if present it sends a radius-accept packet back to the Palo alto firewall.

On ise side everything it's working but i'm receiving the "Matching client config not found" in the global protect:

 

MAerre_0-1736505371308.jpeg

 

this is the log from gp monitor:

 

MAerre_1-1736505393553.jpeg

 

and this is the actual rule:

 

MAerre_2-1736505414395.jpeg

what i can't understand is how to get the correct client config, because this setting is configured on the gateway tab but it's referred to only gp local database users.......

Did you face this issue? Do you know how to fix?

Furthermore how should the policy be configured? I can't use any filter in source ip/user because i don't know how to retrieve this data.

thank you

Regards

0 REPLIES 0
  • 54 Views
  • 0 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!