Getting error message "An active GP Gateway license is required for this feature" when updating the content.

Getting error message "An active GP Gateway license is required for this feature" when updating the content.

2431
Created On 03/14/22 17:30 PM - Last Modified 08/15/25 21:54 PM


Symptom


  • When trying content updates, system logs (show log system) report "An active GP Gateway license is required for this feature"
  • The logs are generated every hour.
xxxx/02/05 12:50:07 high     general        general 0  Retrieving Content 'GPclient' info failed with error 'An active GP Gateway license is required for this feature'
xxxx/02/05 11:50:07 high     general        general 0  Retrieving Content 'GPclient' info failed with error 'An active GP Gateway license is required for this feature'


Environment


  • Palo Alto Firewalls
  • Supported PAN-OS
  • GlobalProtect (GP) Gateway


Cause


  • The system logs indicate a scheduled update occurred at the same time, with an 'Auto update agent...' message appearing in the logs.
xxxx/02/05 12:50:07 info     general        general 0  Auto update agent found no new GPclient updates
xxxx/02/05 12:50:07 high     general        general 0  Retrieving Content 'GPclient' info failed with error 'An active GP Gateway license is required for this feature'
.....
xxxx/02/05 11:50:07 info     general        general 0  Auto update agent found no new GPclient updates
xxxx/02/05 11:50:07 high     general        general 0  Retrieving Content 'GPclient' info failed with error 'An active GP Gateway license is required for this feature'

 

  • "Checking the scheduled updates in the running configuration file (opt/pancfg/mgmt/saved-configs/running-config.xml) reveals a scheduled update for 'global-protect-clientless-vpn'.

  • The same can been seen on the GUI by navigating to Device> Dynamic Updates.
          <update-schedule>
......
    <global-protect-clientless-vpn>
              <recurring>
                <hourly>
                  <at>50</at>
                  <action>download-and-install</action>
                </hourly>
              </recurring>
            </global-protect-clientless-vpn>

          </update-schedule>

  • When using "show system setting ssl-decrypt memory" to check the current version of Clientless VPN, no clientless VPN is configured on the Firewall (Refer Troubleshoot Clientless VPN)
> show system setting ssl-decrypt memory
proxy uses shared allocator
SSL certificate cache:
        Current Entries: 0
        Allocated 0, Freed 

 

  • Since there is no "GP Clientless VPN" on this firewall, there there should not be a license for it either
  • This can be confirmed by using "request license info" There is no license for "GP Gateway",
> request license info
Current PDT Date: March 07, 2022
....

License entry:
Feature: Premium
Description: 24 x 7 phone support; advanced replacement hardware service
Serial: 011901041127
Authcode: 80792808
Issued: March 02, 2021
Expires: February 24, 2024
Expired?: no

 

  • The above outputs confirm the issue is due to scheduled dynamic update is set for the "GP Clientless VPN" client, but there is no actual "GP Clientless VPN" in used.


Resolution


  1. Manually delete the scheduled update from the GUI under Device> Dynamic Updates.
  2. This can also be done using the CLI command below,
>configure
# delete deviceconfig system update-schedule global-protect-clientless-vpn
# commit


 



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004NcMCAU&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language