Unable to select publish applications after PAN OS upgrade

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Unable to select publish applications after PAN OS upgrade

L1 Bithead

Hi Everyone. 

I am having an issue in selecting the publish appliations in clientless vpn apps. 

Prior to the recent firewall upgrade , I was able to use published apps configured for Clientless VPN, and now it is not working. I get error message 404 page not found whenever I select a published application.

Here is a summary of my issue. 

I can login to the portal successfully
Download Global Protect files successfully
Select published apps unsuccessfully (not working)

 

anyone have this issue lately please let me know, i am suspecting that this might be a bug in Pan OS, my current OS version is 10.2.2. 

 

Any help in this regard will be highly appreciated. 

 

Thank you in Advance. 

 

1 accepted solution

Accepted Solutions

L0 Member

Ran into this issue as well, when we moved over to 10.2.2.   There is something wrong with 95-239 and 10.2.2.   We rolled the clientless application down to panup-all-gp-89-207, (no reason other than the date looked good.) once manually installing file from the GUI, we installed the older version and turned off the schedule updates. Once panup-all-gp-89-207 was marked as currently installed all our clientless apps came live again. 

View solution in original post

9 REPLIES 9

Cyber Elite
Cyber Elite

@GQMerdian,

What release were you running prior just so we know how many major versions you jumped. PAN-OS 10.2.2 doesn't have any known issues with clientless VPN. 

L1 Bithead

I'm having the same issue.  I upgraded from 10.1.5 to 10.2.2

Thank you for your reply. We upgraded from 10.2.0 to 10.2.2.

L2 Linker

was having the same issue, just try to disable clientless VPN commit and enabled > commit

 

make sure the clear browser cookies etc as well.

 

L0 Member

We are having the same issue, we migrated from PA-850 (OS 9.1.7) to PA-460 (OS 10.2.2), the published app shows "404 page not found". I tried disabling the Clineless App option on the portal per the suggestion above and re-enabling it, still the same issue. 

Any other suggestions?

Hello

I will recommend you open the case with support. So far when i worked with support we performed the following tasks:

 

added a static entry to application in clientless vpn setting as we were not able to see DNS cache entries
reverted back the version of Global protect clientless vpn  under dynamic updates and tested the access which didn't work. 
added a secondary test application to clientless vpn settings which also didn't work
monitored traffic logs from user source IP and it showed the action drop by default policy
added a test rule allowing the application access from SSL VPN zone after that applications worked. 
upgraded back the GP clientless vpn under dynamic updates to recent version 
tested the application access and observed the DNS cache entries in palo alto cli logs. 

L3 Networker

Are the apps published based on users or user groups? If so, check if setting the user to 'all' helps.

 

I've seen a similar User-ID issue which I believe will be fixed in 10.2.3.

Sr. Technical Support Engineer, Strata

L0 Member
Hello. We had the same situation here. We went back to version 1.1.6-h6 and it didn't fix it. So we suspect it could be something else. We did more tests and found that the license had a problem. Maybe it got corrupted. We reapplied it and it started working again.
Maybe it will help you too.

L0 Member

Ran into this issue as well, when we moved over to 10.2.2.   There is something wrong with 95-239 and 10.2.2.   We rolled the clientless application down to panup-all-gp-89-207, (no reason other than the date looked good.) once manually installing file from the GUI, we installed the older version and turned off the schedule updates. Once panup-all-gp-89-207 was marked as currently installed all our clientless apps came live again. 

  • 1 accepted solution
  • 4512 Views
  • 9 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!