Why is the Prisma Browser Remote Connection app / Secure Agentless Access (SAA) App is not accessible with "Internal failure connecting to remote server" error?
2441
Created On 05/23/25 00:23 AM - Last Modified 07/02/26 00:48 AM
Symptom
- Prisma Browser is being used.
- When trying to use "Remote Connection App" or "Secure Agentless Access App", error message "Internal failure connecting to remote server" is seen.
Environment
- Prisma Access(SASE)
- Supported PAN-OS
- Prisma Browser
- Secure Agentless Access (SAA)
Cause
- DNS resolution failure for private applications.
- Remote Connection App or the SAA app is defined with FQDN
- Mobile User's Gateway's tunnel.1 IP (One of the IP from Mobile User's Client IP Pool), cannot resolve that fqdn,
- This causes the error as displayed in the screenshot below.
Resolution
- The FQDNs need to be resolved from the Mobile User's Subnet. This subnet is configured in the Strata Cloud Manager > Configuration > NGFW and Prisma Access > Configuration scope: GlobalProtect > Setup > Infrastructure > Infrastructure Settings > Client IP Pool.
- If the FQDNs are internal, configure the internal domains and DNS servers. These settings are located under the Client DNS above the Client IP Pool section.
- For a Panorama-managed Prisma Access, the Mobile Users' Client IP pools are configured in the Mobile Users Onboarding > IP Pools section. The DNS servers are configured in the Network Services section.
- Refer Set Up GlobalProtect Mobile Users for more details.