PA Global Protect

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

PA Global Protect

L0 Member

I have 4 portals and 4 gateways (4 different PA fw/vm ) of a GlobalProtect. PA is integrated with azure (an azure app per each gateway).
I added one more new portal and one more new subnet to the one of the existing gateways, a new dns a-record and a new azure app.
ISSUE: Clients can't connect to this portal, it's getting stuck after connection attempt. There're "success" events on the azure log and PA log. Also, I get "Authentication Failed" error by using azure app from myapps.microsoft.com

1 REPLY 1

Community Team Member

Hi @V.Tolstorozhikh ,

 

This sounds less like a GP settings misconfiguration and more like a SAML configuration issue to me. That said, I’d still start by verifying that the new portal is referencing the correct SAML IdP Server Profile tied to the new Azure app you configured.

 

When you mention seeing successful connection attempts, I’m assuming that’s based on the system logs. If so, is the GlobalProtect client actually getting stuck after the login redirect without presenting an explicit error or failure?

 

You also mentioned seeing “Authentication Failed” when launching the app from myapps.microsoft.com. In most cases, that behavior points back to the Azure enterprise app itself rather than GlobalProtect.

 

From the symptoms, it looks like the client is successfully redirecting to Entra ID for authentication (which would explain the “success” events), but the flow is breaking when Entra attempts to send the SAML response back to the portal, or the portal is rejecting the assertion.

 

In that case, I’d double-check that the ACS and Entity ID configured on the Azure app exactly match what the portal is expecting (including things like :443 if applicable), as even small mismatches there can cause this behavior.

 

As a final sanity check, I’d re-export and re-import the metadata, then open the XML and confirm the EntityID, ACS/Reply URL, and signing certificate all match what the portal expects.

 

 

LIVEcommunity team member
Stay Secure,
Jay
Don't forget to Like items if a post is helpful to you!

Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.
  • 150 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!