Issues connecting to GlobalProtect Cloud Gateways if name 'Prisma Access' or address 'gpcloudservice.com' is changed

Issues connecting to GlobalProtect Cloud Gateways if name 'Prisma Access' or address 'gpcloudservice.com' is changed

4084
Created On 06/21/22 06:43 AM - Last Modified 02/07/25 20:59 PM


Symptom


  • On Panorama WebUI, the external gateway "name" and/or "address" underĀ 'Mobile_User_Template' > GlobalProtect > GlobalProtect Portal Configuration > Agent > External Gateway, is changed
  • This causes connectivity issues with GlobalProtect gateway.

On Panorama WebUI, the 'Mobile_User_Template' > GlobalProtect > GlobalProtect Portal Configuration > Agent > External Gateway, the default name of 'Prisma Access' and the address 'gpcloudservice.com' should not be changed, as it needs to use that name in order for the Prisma Access Cloud Users to connect to the Cloud Gateways.
Screen Shot 2022-06-21 at 15.19.49.png


Environment


  • Prisma Access
  • GlobalProtect


Cause


  • The default name of 'Prisma Access' and the address 'gpcloudservice.com' should not be changed
  • Changing it to any other name will prevent Cloud users from connecting to GlobalProtect Cloud Gateways.
  • You will see the following errors in the GP Client logs installed at the end-user machines if it is changed.

PanGPS.log:
  • When changing the name, the user connects to the cloud portal but fails to receive the Cloud Gateway address FQDN.
  • It receives the gateway address as 'gpcloudservice.com', which is not resolvable to an actual Cloud Gateway.
(P1544-T2244)Debug(3484): 06/20/22 21:14:00:116 ----Gateway Pre-login starts----
(P1544-T2244)Debug(11474): 06/20/22 21:14:00:116 Check cert of server gpcloudservice.com
(P1544-T2244)Debug( 858): 06/20/22 21:14:00:116 SSL connecting to gpcloudservice.com
(P1544-T2244)Debug( 324): 06/20/22 21:14:00:116 host is FQDN: gpcloudservice.com
(P1544-T2244)Error( 837): 06/20/22 21:14:00:116 getaddrinfo for fqdn gpcloudservice.com failed, 0.
(P1544-T2244)Debug( 565): 06/20/22 21:14:00:116 getaddrinfo of gpcloudservice.com failed with error 11001, <EF><BF><BD><EF><BF><BD><EF><BF><BD><CC><82>
<E6><82><A4><EF><BF><BD><C8><83>z<EF><BF><BD>X<EF><BF><BD>g<EF><BF><BD><CD><95>s<EF><BF><BD><EF><BF><BD><EF><BF><BD><C5><82><EF><BF><BD><EF><BF><BD>B
(P1544-T2244)Debug( 863): 06/20/22 21:14:00:116 do_tcp_connect() failed
(P1544-T2244)Error(11522): 06/20/22 21:14:00:116 ConnectSSL: Failed to connect to 'gpcloudservice.com:443'. Disconnect ssl.
(P1544-T2244)Debug(11535): 06/20/22 21:14:00:116 Cannot get server cert of gpcloudservice.com
(P1544-T2244)Debug(6216): 06/20/22 21:14:00:116 Try use ipv6 true for gateway gpcloudservice.com.
(P1544-T2244)Debug(6043): 06/20/22 21:14:00:116 Set perfer ipv6 to false for gpcloudservice.com
(P1544-T2244)Debug(6222): 06/20/22 21:14:00:116 Already tried ipv4
(P1544-T2244)Debug(6237): 06/20/22 21:14:00:116 pretunnel latency (manual gateway) is 1
(P1544-T2244)Error(3535): 06/20/22 21:14:00:116 Failed to connect to gateway gpcloudservice.com.
(P1544-T2244)Debug(5590): 06/20/22 21:14:00:116 Show Gateway PrismaAccess: The network connection is unreachable or the gateway is unresponsive. Check the network connection and reconnect.
(P1544-T2244)Info (2639): 06/20/22 21:14:00:116 Failed to retrieve info for gateway gpcloudservice.com.
(P1544-T2244)Debug(2650): 06/20/22 21:14:00:116 tunnel to gpcloudservice.com is not created.
(P1544-T2244)Debug( 610): 06/20/22 21:14:00:116 Do not retry ipv6. The remote host does not exists.
(P1544-T2244)Error(6115): 06/20/22 21:14:00:116 NetworkDiscoverThread: failed to discover external network.
(P1544-T2244)Debug(7151): 06/20/22 21:14:00:116 --Set state to Disconnected
  • When changing the address, the user tries to connect the portal address to connect to the gateway.
(P2192-T4304)Debug(3484): 06/13/22 14:17:09:417 ----Gateway Pre-login starts----
(P2192-T4304)Debug(11367): 06/13/22 14:17:09:417 Check cert of server x.x.x.x <<<< GPPT address
(P2192-T4304)Debug( 788): 06/13/22 14:17:09:417 SSL connecting to x.x.x.x
(P2192-T4304)Debug( 564): 06/13/22 14:17:09:433 Network is reachable
(P2192-T4304)Debug(3616): 06/13/22 14:17:10:687 Login to gateway (null) prismaaccessaddress.gpcloudservice.com without ipv6


Resolution


  1. Revert the External Gateway name back to the 'default' name i. e 'Prisma Access' on the Panorama WebGUI under 'Mobile_User_Template' > GlobalProtect > GlobalProtect Portal Configuration > Agent > External Gateway > Name
  2. Revert the External Gateway address back to the 'default' address i. e 'gpcloudservice.com' on the Panorama WebGUI under 'Mobile_User_Template' > GlobalProtect > GlobalProtect Portal Configuration > Agent > External Gateway > Prisma Access > Address


Additional Information


https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClDWCA0

Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000Cq79CAC&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail