GlobalProtect App fails to connect to Portal or Gateway after upgrade to macOS Sequoia 15.x
3624
Created On 10/21/25 08:46 AM - Last Modified 12/10/25 03:09 AM
Symptom
- GlobalProtect users are experiencing connection issues on macOS Sequoia 15.x following an upgrade
- The client fails to connect to the Portal, returning the error: 'Cannot connect to the network. The portal is unresponsive
- When using the Portal's cached configuration (bypassing the initial error), the same issue occurs when attempting to connect to the Gateway, showing the error: 'The network connection is unreachable or the gateway is unresponsive
- PanGPS logs display "Connection error Error Domain=NSURLErrorDomain Code=-1200 "An SSL error has occurred and a secure connection to the server cannot be made."
Environment
- Palo Alto Firewalls
- Prisma Access Firewalls
- Supported PAN-OS
- GlobalProtect App
- macOS: Sequoia 15.4.x or higher
Cause
- This issue has become widespread in environments where the certificate used for GlobalProtect server-side authentication is a root CA certificate
- Accessing the Portal also fails when using the Safari web browser due to a recent OS update.
Resolution
The root cause is an OS change of the default behavior.To fix the issue, use the security best practices:
- Avoid using a root CA as server cert for the GlobalProtect TLS/SSL service profile.
- Use a server cert (end entity/leaf cert) instead.
- Ensure that the server certificate contains the proper ExtendedKeyUsage x509 extension for the intended use: TLS server authentication.
Additional Information
N/A