hey @GOMEZZZ I know it's been a while since you'v made this post, but I hope this message finds you well. Based on the PanGPS logs you've previously posted, the Agent is unable to verify the server certificate used for the Gateway SSL/TLS profile. Common issues for this would include CN mismatch, as mentioned before by other community members, and incorrect certificate deployment: eg the Agent is unable to follow the full chain. A quick way to test this is using your local browser to connect and reviewing the output messages. Could you please confirm the following: 1. The root (and intermediate if applicable) CA(s) used to sign the imported Portal/Gateway certificate are deployed in the correct directories on the endpoint 2. The server certificate used for the Portal/Gateway has the correct CN (and SAN if applicable) attribute I've included documentation discussing the certificate deployment options for GlobalProtect below for your reference also. https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/get-started/enable-ssl-between-globalprotect-components/deploy-server-certificates-to-the-globalprotect-components.html -Cheers
... View more