06-29-2021 01:24 PM
I had to reboot my firewall this morning because it erroneously rejected client certificates required by a VPN.
Firewall system logs show critical event "Out of memory condition detected, kill process 3" at 4:06am
I had the exact same issue on May 5th as well (and reporting to PA) where Clients getting VPN certificate errors despite being nowhere near expiration and reinstalling certifications
Is anyone aware of a fix?
06-29-2021 03:12 PM
I also have seen this issue. Clients were not able to connect and they were presented with a message that a valid certificste is required. I also saw the out of memory logs. After that I installed PAN-OS 9.1.10 which has quite a few fixes for something that could result in this problem. So far the error did not happen again.
06-29-2021 02:11 PM
I've ran into this a few times with 10.0 throughout various releases and haven't gotten an actual direct answer from support. I'd keep reporting it, because it's definitely a bug somewhere that they just don't appear to have enough data to track down yet.
06-29-2021 03:12 PM
I also have seen this issue. Clients were not able to connect and they were presented with a message that a valid certificste is required. I also saw the out of memory logs. After that I installed PAN-OS 9.1.10 which has quite a few fixes for something that could result in this problem. So far the error did not happen again.
06-29-2021 03:18 PM
Are either of you running in HA Pair? I am wondering whether or not that might mitigate the issue in active-passive and/or active-active until there is a bug fix. Both times this issue occurred early morning, and fortunately only two people were in the office by then.
06-29-2021 03:25 PM
I had the issue in a HA pair (active-passive). Actually we have more than 10 other firewall HA pairs where we use global protect, but so far (luckily) the issue only happened on one of them ...
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!