Globalprotect 'portal-getconfig' event fails when a user or group is configured under portal Config Selection Criteria.
29308
Created On 08/31/22 13:45 PM - Last Modified 03/08/23 08:48 AM
Symptom
- Under Monitor > GlobalProtect Logs we could notice 'portal-getconfig' Event is failing because of error message "Failed to get Client Configuration."
- From the gpsvc.log we could see below warn message,
{"level":"warn","task":"41-5","time":"2022-05-18T12:21:09.154798735-07:00","message":"GetPortalConfig: no client config found for domain "} <<<<<<<<<<<<<<<<<<
{"level":"warn","task":"41-5","time":"2022-05-18T12:21:09.154921851-07:00","message":"GetPortalConfig: no client config found for &{ServerIp:<IP address> User:user1 Domain:(empty_domain) ClientOs:Windows SerialNo:VMware-42 01 5d 0b 5e 4c 23 a9-20 36 71 9f 3c d7 fd 08 PeerSerialNo: SkipCc:false DomainInAuthProf: DomainInCertProf: CscSupport:true CscData: NeedSatConfig:false NeedClientlessConfig:false}, portal Portal_test"}
{"level":"error","task":"41-5","time":"2022-05-18T12:21:09.155061892-07:00","message":"gpGetconfig: Failed to get portal config"} <<<<<<<<<<<<<<<<<<
Environment
- PAN OS 10.2.0 and above.
- Global Protect portal and gateway configured with User/UserGroup Config Selection Criteria.
Cause
- This could happen when Global Protect portal is configured with User/User group.
Resolution
- The workaround for the issue is to remove any user or group configured under portal Config Selection Criteria.
- Go to Network > GlobalProtect Portal > Agent > Config > Config Selection Criteria and remove the user or groups called.