GP Connection Failed - gateway could not verify the server certiticate of the gateway.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

GP Connection Failed - gateway could not verify the server certiticate of the gateway.

L3 Networker

Hi All,

I have GP setup and working like a dream..... most of the times.

however i have a strange issue.. and seems to only affect Azure cloud PCs at the moment, normal users with laptops and desktops can connect no problem.

my certs are all valid and signed by an external CA.

 

however on Azure cloud PC's the connections are very intermittent.. works maybe 1/6 attempts. most of the time users get the error around unable to verify the certificate on the gateway.

pan-os running 10.1.10-h2

gp app version is 6.1.2

windows cloud PC running windows 365 enterprise, 2vCPU, 8gb and 256 GB SSD

 

tried deleting dat files on local drive, no luck.

tried unistall / reinstall GP app no luck.

tried with full admin rights, same issue.

tried installing the certs locally to the PC's in the certificate store.. no luck.

from these cloud PC's, i can log into the portal fine and no complaints about certificate

 

any ideas doubt there are much testing around these as yet.. might have to log a call with MS also.

 

thanks in adv

1 REPLY 1

L4 Transporter

Hello,

 

Do verify, is your Gateway certificate a public cert or just the portal? And do you Azure machines trust this public root/intermediate certificate? 

 

I would also check the GlobalProtect logs on the firewall gateway and see if there is any more error information that points to anything.

I would also check the clients GlobalProtect debug logs, specfically the pangps and pangpa logs, as there should be more information related to specifically what it didnt like.

 

Claw4609_0-1712332483560.png

 

  • 320 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!