GlobalProtect upgrade was not successfully completed in Prisma Access.

GlobalProtect upgrade was not successfully completed in Prisma Access.

3270
Created On 03/15/24 08:20 AM - Last Modified 02/05/25 08:31 AM


Symptom


  • The setting "Allow User to Upgrade GlobalProtect App" is configured other than "Disallow" and "Internal".
  • GlobalProtect Potal FQDN and the FQDNs "pan-gp-client.s3.amazonaws.com" and "pan-gp-client.s3.dualstack.us-west-2.amazonaws.com" are allowed by security policies with FQDN address objects.
  • However, GlobalProtect upgrade was not completed.


Environment


  • Prisma Access
  • GlobalProtect


Cause


The  FQDNs "pan-gp-client.s3.amazonaws.com" and "pan-gp-client.s3.dualstack.us-west-2.amazonaws.com"  can age out quickly and IP resolutions can change frequently since the TTL is very short.



Resolution


  1. In order to allow the traffic, create a security policy with a custom URL category that contains the GlobalProtect Potal FQDN and "pan-gp-client.s3.amazonaws.com" and "pan-gp-client.s3.dualstack.us-west-2.amazonaws.com"
  2. When using the custom URL category, PAN-OS checks the SNI (Server Name Indication) in the TLS Client Hello to identify the destination. This allows the traffic to match the security policy.


Additional Information


  • PAN-OS honors each FQDN's TTL.
  • The TTL for the FQDNs "pan-gp-client.s3.amazonaws.com" and "pan-gp-client.s3.dualstack.us-west-2.amazonaws.com" is very short (5 seconds).
  • This means that the relevant IP address might not have been cached in Prisma Access by the time the traffic arrives.
  • As a result, the traffic may not match the security policy.
Sample output of dig command is below.
$ dig pan-gp-client.s3.amazonaws.com @8.8.8.8

; <<>> DiG 9.11.4-P2-RedHat-9.11.4-26.P2.el7_9.14 <<>> pan-gp-client.s3.amazonaws.com @8.8.8.8
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 22452
;; flags: qr rd ra; QUERY: 1, ANSWER: 9, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 512
;; QUESTION SECTION:
;pan-gp-client.s3.amazonaws.com.        IN      A

;; ANSWER SECTION:
pan-gp-client.s3.amazonaws.com. 20606 IN CNAME  s3-us-west-2-w.amazonaws.com.
s3-us-west-2-w.amazonaws.com. 5 IN      A       52.92.132.17               <<<<<<<<<<  TTL is 5sec
s3-us-west-2-w.amazonaws.com. 5 IN      A       52.92.148.201
s3-us-west-2-w.amazonaws.com. 5 IN      A       52.92.149.121
s3-us-west-2-w.amazonaws.com. 5 IN      A       52.92.211.233
s3-us-west-2-w.amazonaws.com. 5 IN      A       52.92.139.121
s3-us-west-2-w.amazonaws.com. 5 IN      A       52.92.211.81
s3-us-west-2-w.amazonaws.com. 5 IN      A       52.92.235.41
s3-us-west-2-w.amazonaws.com. 5 IN      A       52.218.229.243

;; Query time: 12 msec
;; SERVER: 8.8.8.8#53(8.8.8.8)
;; WHEN: Fri Mar 15 01:22:15 PDT 2024
;; MSG SIZE  rcvd: 216


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008XZdCAM&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail