Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootMedium
A network administrator is configuring a new GlobalProtect VPN portal and gateway. Users are able to connect to the portal and download the GlobalProtect client, but they are unable to establish a VPN tunnel to the gateway. The client logs show 'Failed to connect to gateway' and 'SSL negotiation failed'. Which of the following is the MOST likely cause?
- AThe authentication profile on the gateway is misconfigured, preventing user authentication.
- BThe GlobalProtect gateway's public IP address is incorrect in the portal configuration.
- CThe SSL/TLS Service Profile on the gateway is configured with unsupported cipher suites or an invalid certificate.
- DThe security policy on the firewall is blocking traffic to the GlobalProtect gateway port.
Show answer & explanationAnswer & explanation
Correct answer: C. The SSL/TLS Service Profile on the gateway is configured with unsupported cipher suites or an invalid certificate.
The 'SSL negotiation failed' error specifically points to an issue with the SSL/TLS handshake between the GlobalProtect client and the gateway. This is commonly caused by an invalid certificate or a mismatch in supported cipher suites in the SSL/TLS Service Profile.
Why the other options are wrong
- A. Authentication issues would typically occur *after* a successful SSL negotiation, resulting in an 'authentication failed' error, not an SSL negotiation failure.
- B. If the gateway's public IP was incorrect, the client wouldn't even attempt an SSL negotiation; it would fail to reach the gateway's address.
- D. If security policy was blocking traffic to the gateway port, the client would likely experience a connection timeout or a reset, not specifically an 'SSL negotiation failed' error, which implies a connection was made but the handshake failed.
GlobalProtect SSL Failure
GlobalProtect 'SSL negotiation failed' usually points to issues with the SSL/TLS Service Profile on the gateway, such as certificate problems or cipher suite mismatches.
- Occurs during SSL handshake.
- Check gateway's SSL/TLS Service Profile.
- Certificate validity and trust are critical.
Memory trick: You can knock on the gate, but if the guard's ID is bad, you're not getting in.