GlobalProtect upgrade was not successfully completed in Prisma Access.
3270
Created On 03/15/24 08:20 AM - Last Modified 02/05/25 08:31 AM
Symptom
- The setting "Allow User to Upgrade GlobalProtect App" is configured other than "Disallow" and "Internal".
- GlobalProtect Potal FQDN and the FQDNs "pan-gp-client.s3.amazonaws.com" and "pan-gp-client.s3.dualstack.us-west-2.amazonaws.com" are allowed by security policies with FQDN address objects.
- However, GlobalProtect upgrade was not completed.
Environment
- Prisma Access
- GlobalProtect
Cause
The FQDNs "pan-gp-client.s3.amazonaws.com" and "pan-gp-client.s3.dualstack.us-west-2.amazonaws.com" can age out quickly and IP resolutions can change frequently since the TTL is very short.
Resolution
- In order to allow the traffic, create a security policy with a custom URL category that contains the GlobalProtect Potal FQDN and "pan-gp-client.s3.amazonaws.com" and "pan-gp-client.s3.dualstack.us-west-2.amazonaws.com"
- When using the custom URL category, PAN-OS checks the SNI (Server Name Indication) in the TLS Client Hello to identify the destination. This allows the traffic to match the security policy.
Additional Information
- PAN-OS honors each FQDN's TTL.
- The TTL for the FQDNs "pan-gp-client.s3.amazonaws.com" and "pan-gp-client.s3.dualstack.us-west-2.amazonaws.com" is very short (5 seconds).
- This means that the relevant IP address might not have been cached in Prisma Access by the time the traffic arrives.
- As a result, the traffic may not match the security policy.
Sample output of dig command is below.
$ dig pan-gp-client.s3.amazonaws.com @8.8.8.8
; <<>> DiG 9.11.4-P2-RedHat-9.11.4-26.P2.el7_9.14 <<>> pan-gp-client.s3.amazonaws.com @8.8.8.8
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 22452
;; flags: qr rd ra; QUERY: 1, ANSWER: 9, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 512
;; QUESTION SECTION:
;pan-gp-client.s3.amazonaws.com. IN A
;; ANSWER SECTION:
pan-gp-client.s3.amazonaws.com. 20606 IN CNAME s3-us-west-2-w.amazonaws.com.
s3-us-west-2-w.amazonaws.com. 5 IN A 52.92.132.17 <<<<<<<<<< TTL is 5sec
s3-us-west-2-w.amazonaws.com. 5 IN A 52.92.148.201
s3-us-west-2-w.amazonaws.com. 5 IN A 52.92.149.121
s3-us-west-2-w.amazonaws.com. 5 IN A 52.92.211.233
s3-us-west-2-w.amazonaws.com. 5 IN A 52.92.139.121
s3-us-west-2-w.amazonaws.com. 5 IN A 52.92.211.81
s3-us-west-2-w.amazonaws.com. 5 IN A 52.92.235.41
s3-us-west-2-w.amazonaws.com. 5 IN A 52.218.229.243
;; Query time: 12 msec
;; SERVER: 8.8.8.8#53(8.8.8.8)
;; WHEN: Fri Mar 15 01:22:15 PDT 2024
;; MSG SIZE rcvd: 216