Password change via GlobalProtect occasionally fails

Password change via GlobalProtect occasionally fails

9134
Created On 03/27/24 00:02 AM - Last Modified 08/27/24 22:31 PM


Symptom


  • GlobalProtect configured with Radius Authentication and  "Allow users to change password after expiry" is enabled (Device > Server Profiles > RADIUS > [profile-name])
  • When the password is expired, GlobalProtect App display the password expiry message to change the password.
  • When the password change is attempted it fails with the message “Authentication Failed. Enter login credentials”.
  • Note: The correct password is entered when attempting the change.
image.png          image.png


Environment


  • GlobalProtect (GP) App
  • supported GP App versions
  • Radius authentication configured on Portal
  • LDAP authentication configured on Gateway


Cause


  • This issue is caused by the timeout of the GlobalProtect Agent(GPA).
  • PanGPA.log reports timeout messages.
WINHTTP_CALLBACK_STATUS_REQUEST_ERROR, error=0x2ee2, result=1, dwCertificateError=0
get WINHTTP_CALLBACK_STATUS_REQUEST_ERROR while waitting for header, error=12002, 00600070, ERROR_WINHTTP_TIMEOUT!

 


Resolution


  1. Change the TCP handshake timeout from default (10 sec) to 60 sec.
  2. This can be changed using GUI: Device > Setup > Session > Session Timeouts
  3. Click "OK" and Commit the changes.
image.png
 
 


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000Xi09CAC&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language