Palo Alto Networks Certified Network Security Engineer (PCNSE)Manage and OperateMedium

A security engineer is troubleshooting an issue where a new GlobalProtect gateway is not establishing VPN tunnels with remote users. The firewall's system logs show 'SSL handshake failed' messages. Upon checking the gateway configuration, the engineer notices that the server certificate configured for the GlobalProtect gateway is signed by an internal Certificate Authority (CA) that is not trusted by the remote user devices. What is the most probable cause of the SSL handshake failure?

  1. AThe root CA certificate of the internal CA is not installed on the user devices.
  2. BThe GlobalProtect gateway is using a self-signed certificate.
  3. CThe user devices are attempting to connect using an unsupported SSL/TLS version.
  4. DThe GlobalProtect client software is outdated.
Show answer & explanation

Correct answer: A. The root CA certificate of the internal CA is not installed on the user devices.

For an SSL handshake to succeed, the client must trust the server's certificate. If the server certificate is signed by an internal CA, the client devices must have the internal CA's root certificate installed in their trusted root store to validate the certificate chain.

Why the other options are wrong

  • B. While a self-signed certificate would also lead to trust issues, the question states it's signed by an 'internal Certificate Authority', implying a PKI, but one whose root isn't distributed.
  • C. Unsupported SSL/TLS versions could cause handshake failures, but the problem description specifically mentions an internal CA not trusted, making certificate trust a more direct cause.
  • D. Outdated client software might cause various issues, but 'SSL handshake failed' specifically points to certificate trust or protocol negotiation, not typically just client version.

SSL Handshake Failure (Certificate Trust)

An SSL handshake fails when a client cannot validate the server's identity, often due to the server's certificate being signed by an untrusted Certificate Authority (CA) or the certificate being expired/invalid.

  • Clients need to trust the CA that issued the server's certificate.
  • Root CA certificates must be distributed to client devices for internal CAs.
  • Failure prevents encrypted communication.

Memory trick: SSL Handshake Fails when Trust is Broken or Protocols Don't Match.

More Manage and Operate questions