错误:无法连接到 GlobalProtect 网关。 请联系您的 IT 管理员。

错误:无法连接到 GlobalProtect 网关。 请联系您的 IT 管理员。

50308
Created On 10/28/20 23:07 PM - Last Modified 03/26/21 18:45 PM


Symptom


  • GlobalProtect 代理错误: 无法连接到 GlobalProtect 网关。 请联系您的 IT 管理员。
  • PANGPA.log显示以下情况:
(T13736)Debug( 101): 10/26/20 09:20:06:110 connect failed with 5 seconds timeout.
(T13736)Debug( 599): 10/26/20 09:20:06:110 Failed to connect to <Portal/Gateway IP address/FQDN> on 443 with return value -1 and socket error 0(0)
(T13736)Debug( 784): 10/26/20 09:20:06:110 do_tcp_connect() failed
(T13736)Error(10527): 10/26/20 09:20:06:110 ConnectSSL: Failed to connect to '<Portal/Gateway IP address/FQDN>'. Disconnect ssl.
(T13736)Debug(10540): 10/26/20 09:20:06:110 Cannot get server cert of <Portal/Gateway IP address/FQDN>
(T13736)Debug(6060): 10/26/20 09:20:06:110 Already tried both ipv4 and ipv6 for gateway <Gateway IP address/FQDN>
(T13736)Debug(6070): 10/26/20 09:20:06:110 pretunnel latency (manual gateway) is 1
(T13736)Error(3473): 10/26/20 09:20:06:110 Failed to connect to gateway <Gateway IP address/FQDN>.
(T13736)Debug(5447): 10/26/20 09:20:06:110 Show Gateway GW01: Could not connect to the GlobalProtect gateway. Please contact your IT administrator.
(T13736)Info (2619): 10/26/20 09:20:06:110 Failed to retrieve info for gateway <Gateway IP address/FQDN>

 


Environment


  • PA-3020
  • PANOS 8.1.16
  • 全球保护版本:5.1.5


Cause


  • 证书状态显示:已过期
用户添加的图像


Resolution


解决方案1
==>> Root certificate 
=====>>Intermediate certificate
=====================>>GlobalProtect
  • 首先续订根证书。
  • 续期中级证书第二。
  • 最后续订 GlobalProtect 证书。
  1. 设备证书管理下的> 证书>证书>选择>证书
  2. 使用集团 Policy 对象将证书导入客户证书存储或向客户推送证书( GPO ) 
解决方案2 

 



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HBO5CAO&lang=zh_CN&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language