Getting error message "An active GP Gateway license is required for this feature" when updating the content.
2431
Created On 03/14/22 17:30 PM - Last Modified 08/15/25 21:54 PM
Symptom
- When trying content updates, system logs (show log system) report "An active GP Gateway license is required for this feature"
- The logs are generated every hour.
xxxx/02/05 12:50:07 high general general 0 Retrieving Content 'GPclient' info failed with error 'An active GP Gateway license is required for this feature'
xxxx/02/05 11:50:07 high general general 0 Retrieving Content 'GPclient' info failed with error 'An active GP Gateway license is required for this feature'Environment
- Palo Alto Firewalls
- Supported PAN-OS
- GlobalProtect (GP) Gateway
Cause
- The system logs indicate a scheduled update occurred at the same time, with an 'Auto update agent...' message appearing in the logs.
xxxx/02/05 12:50:07 info general general 0 Auto update agent found no new GPclient updates
xxxx/02/05 12:50:07 high general general 0 Retrieving Content 'GPclient' info failed with error 'An active GP Gateway license is required for this feature'
.....
xxxx/02/05 11:50:07 info general general 0 Auto update agent found no new GPclient updates
xxxx/02/05 11:50:07 high general general 0 Retrieving Content 'GPclient' info failed with error 'An active GP Gateway license is required for this feature'
-
"Checking the scheduled updates in the running configuration file (
opt/pancfg/mgmt/saved-configs/running-config.xml) reveals a scheduled update for 'global-protect-clientless-vpn'. - The same can been seen on the GUI by navigating to Device> Dynamic Updates.
<update-schedule>
......
<global-protect-clientless-vpn>
<recurring>
<hourly>
<at>50</at>
<action>download-and-install</action>
</hourly>
</recurring>
</global-protect-clientless-vpn>
</update-schedule>
- When using "show system setting ssl-decrypt memory" to check the current version of Clientless VPN, no clientless VPN is configured on the Firewall (Refer Troubleshoot Clientless VPN)
> show system setting ssl-decrypt memory
proxy uses shared allocator
SSL certificate cache:
Current Entries: 0
Allocated 0, Freed
- Since there is no "GP Clientless VPN" on this firewall, there there should not be a license for it either
- This can be confirmed by using "request license info" There is no license for "GP Gateway",
> request license info
Current PDT Date: March 07, 2022
....
License entry:
Feature: Premium
Description: 24 x 7 phone support; advanced replacement hardware service
Serial: 011901041127
Authcode: 80792808
Issued: March 02, 2021
Expires: February 24, 2024
Expired?: no
- The above outputs confirm the issue is due to scheduled dynamic update is set for the "GP Clientless VPN" client, but there is no actual "GP Clientless VPN" in used.
Resolution
- Manually delete the scheduled update from the GUI under Device> Dynamic Updates.
- This can also be done using the CLI command below,
>configure
# delete deviceconfig system update-schedule global-protect-clientless-vpn
# commit