yuezk / GlobalProtect-openconnect

A GlobalProtect VPN client for Linux, written in Rust, based on OpenConnect and Tauri, supports SSO with MFA, Yubikey, and client certificate authentication, etc.
GNU General Public License v3.0
1.38k stars 155 forks source link

Cannot connect to school server anymore. #421

Closed Mork7 closed 1 month ago

Mork7 commented 2 months ago

Describe the bug I am trying to connect to my school servers, I am using Linux so I found this program and it was working great for the summer! Randomly now, I cannot connect.

Expected behavior To connect to school servers using global protect vpn.

Logs

[2024-09-09T20:08:52Z INFO gpauth::auth_window] Got auth data from headers
[2024-09-09T20:08:52Z INFO gpgui::portal_connector] Performing gateway login, gateway: g**********a...
[2024-09-09T20:08:52Z INFO gpapi::gateway::login] Perform gateway login, user_agent: PAN GlobalProtect/6.0.1-19 (Linux Linux Mint 21.3)
[2024-09-09T20:08:52Z INFO gpgui::portal_connector] Gateway login succeeded, gateway: g**********a
[2024-09-09T20:08:52Z INFO gpgui::portal_connector] Connecting to the gateway...
[2024-09-09T20:08:52Z INFO openconnect::ffi] openconnect version: v8.20-1
[2024-09-09T20:08:52Z INFO openconnect::ffi] User agent: PAN GlobalProtect/6.0.1-19 (Linux Linux Mint 21.3)
[2024-09-09T20:08:52Z INFO openconnect::ffi] VPNC script: /usr/share/vpnc-scripts/vpnc-script
[2024-09-09T20:08:52Z INFO openconnect::ffi] OS: linux
[2024-09-09T20:08:52Z INFO openconnect::ffi] CSD_USER: 1000
[2024-09-09T20:08:52Z INFO openconnect::ffi] CSD_WRAPPER: (null)
[2024-09-09T20:08:52Z INFO openconnect::ffi] RECONNECT_TIMEOUT: 300
[2024-09-09T20:08:52Z INFO openconnect::ffi] MTU: 0
[2024-09-09T20:08:52Z INFO openconnect::ffi] DISABLE_IPV6: 0
[2024-09-09T20:08:52Z INFO openconnect::ffi] NO_DTLS: 0
[2024-09-09T20:08:52Z INFO openconnect::ffi] POST https://[**********]/ssl-vpn/getconfig.esp
[2024-09-09T20:08:52Z INFO openconnect::ffi] Connected to [**********]:443
[2024-09-09T20:08:52Z INFO openconnect::ffi] SSL negotiation with [**********]
[2024-09-09T20:08:52Z INFO openconnect::ffi] Connected to HTTPS on [**********] with ciphersuite (TLS1.2)-(ECDHE-SECP256R1)-(RSA-SHA256)-(AES-256-GCM)
[2024-09-09T20:08:52Z INFO openconnect::ffi] Tunnel timeout (rekey interval) is 180 minutes.
[2024-09-09T20:08:52Z INFO openconnect::ffi] Idle timeout is 180 minutes.
[2024-09-09T20:08:52Z WARN openconnect::ffi] Did not receive ESP keys and matching gateway in GlobalProtect config; tunnel will be TLS only.
[2024-09-09T20:08:52Z WARN openconnect::ffi] No IP address received. Aborting
[2024-09-09T20:08:52Z WARN openconnect::ffi] Failed to parse server response
[2024-09-09T20:08:52Z WARN openconnect::ffi] openconnect_make_cstp_connection failed
[2024-09-09T20:08:52Z WARN gpgui::portal_connector] Failed to connect to the gateway: g**********a

Environment:

Mork7 commented 2 months ago

I used Nordvpn first to see what happens when I try to connect from the external gateway (I'm at the school) and it connected. So there must be some problem when connecting from the internal gateway, this might be a problem with the school server? If that makes sense then I will close the issue and bring it up to IT team.

yuezk commented 2 months ago

Hi, @Mork7 can you help clear the cached credentials to see if it works? If it doesn't work, please send me the full log so I can understand the flow. Thanks.

image
Mork7 commented 1 month ago

I tried to clear credentials and even uninstalled and reinstalled, didn't work. Here is the full log (I believe).

[2024-09-18T15:09:48Z INFO gpservice::cli] gpservice started: 2.3.7 (2024-08-16) [2024-09-18T15:09:48Z INFO gpservice::ws_server] WS server listening on port: 42267 [2024-09-18T15:09:48Z INFO gpapi::process::gui_launcher] Version check passed: 2.3.7 [2024-09-18T15:09:48Z INFO gpapi::process::gui_launcher] Launching gpgui [2024-09-18T15:09:48Z INFO gpgui::cli] gpgui started: 2.3.7 (2024-08-16) [2024-09-18T15:09:48Z INFO gpgui::config::private_data] Loaded config key from keyring [2024-09-18T15:09:48Z INFO gpgui::app::app_initializer] App initialized [2024-09-18T15:09:48Z INFO gpgui::ws_connector] Connecting to WS server [2024-09-18T15:09:48Z INFO gpgui::ws_connector] Received ping [2024-09-18T15:09:48Z INFO gpgui::ws_connector] Connected to WS server [2024-09-18T15:09:48Z INFO gpservice::handlers] New client connected [2024-09-18T15:09:48Z INFO gpservice::ws_server] Sending current VPN state to new client [2024-09-18T15:09:48Z INFO gpapi::utils::window] Window raised after 1 attempts [2024-09-18T15:09:50Z INFO gpgui::handlers::subscription] Sending the init event to client: main [2024-09-18T15:09:50Z INFO gpgui::handlers::subscription] Sent the init event to client: main [2024-09-18T15:09:51Z INFO gpgui::portal_connector] Connecting to the portal: s**a... [2024-09-18T15:09:51Z INFO gpgui::portal_connector] Trying to connect the gateway directly... [2024-09-18T15:09:51Z INFO gpgui::portal_connector] Failed to connect the gateway directly: Internal host detection is enabled, can't connect the gateway directly [2024-09-18T15:09:51Z INFO gpgui::portal_connector] Trying to connect portal with cached credential... [2024-09-18T15:09:51Z INFO gpgui::portal_connector] Fetching the portal config... [2024-09-18T15:09:51Z INFO gpapi::portal::config] Retrieve the portal config, user_agent: PAN GlobalProtect/6.0.1-19 (Linux Linux Mint 21.3) [2024-09-18T15:09:51Z WARN gpapi::portal::config] GP response error: reason=auth-failed, status=512 , body= [2024-09-18T15:09:51Z INFO gpgui::portal_connector] Failed to connect portal with cached credential: Cached credential is stale, please try again [2024-09-18T15:09:51Z INFO gpgui::portal_connector] Trying to connect the portal with prelogin... [2024-09-18T15:09:51Z INFO gpgui::portal_connector] Performing portal prelogin... [2024-09-18T15:09:51Z INFO gpapi::portal::prelogin] Portal prelogin with user_agent: PAN GlobalProtect/6.0.1-19 (Linux Linux Mint 21.3) [2024-09-18T15:09:51Z INFO gpapi::portal::prelogin] Perform prelogin, user_agent: PAN GlobalProtect/6.0.1-19 (Linux Linux Mint 21.3) [2024-09-18T15:09:51Z INFO gpgui::portal_connector] Authenticating portal... [2024-09-18T15:09:51Z INFO gpgui::portal_connector] Launching SAML authentication... [2024-09-18T15:09:51Z INFO gpauth::cli] gpauth started: 2.3.7 (2024-08-16) [2024-09-18T15:09:51Z INFO gpauth::auth_window] Open auth window, user_agent: PAN GlobalProtect/6.0.1-19 (Linux Linux Mint 21.3) [2024-09-18T15:09:51Z INFO gpauth::auth_window] Auth window user agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 [2024-09-18T15:09:51Z INFO gpauth::auth_window] Load the SAML request as URI... [2024-09-18T15:09:52Z INFO gpauth::auth_window] Loaded uri: https://l**********m/12f933b3-3d61-4b19-9a4d-689021de8cc9/saml2?SAMLRequest=l**********%3D&RelayState=Q**********x [2024-09-18T15:09:52Z INFO gpauth::auth_window] Trying to read auth data from response headers... [2024-09-18T15:09:52Z INFO gpauth::auth_window] No saml-auth-status header found [2024-09-18T15:09:52Z INFO gpauth::auth_window] No auth data found in headers, trying to read from body... [2024-09-18T15:09:52Z INFO gpauth::auth_window] Failed to read auth data from body: No auth data found [2024-09-18T15:09:52Z INFO gpauth::auth_window] No auth data found, it may not be the /SAML20/SP/ACS endpoint [2024-09-18T15:09:52Z INFO gpauth::auth_window] Raise window in 1 second(s) [2024-09-18T15:09:52Z INFO gpauth::auth_window] Raise window cancelled [2024-09-18T15:09:52Z WARN gpauth::auth_window] Failed to load uri: https://s**********a/SAML20/SP/ACS with error: Load request cancelled [2024-09-18T15:09:52Z INFO gpauth::auth_window] Loaded uri: https://s**********a/SAML20/SP/ACS [2024-09-18T15:09:52Z INFO gpauth::auth_window] Trying to read auth data from response headers... [2024-09-18T15:09:52Z INFO gpauth::auth_window] Got auth data from headers [2024-09-18T15:09:52Z INFO gpgui::portal_connector] Fetching the portal config... [2024-09-18T15:09:52Z INFO gpapi::portal::config] Retrieve the portal config, user_agent: PAN GlobalProtect/6.0.1-19 (Linux Linux Mint 21.3) [2024-09-18T15:09:52Z INFO gpapi::portal::config] Found internal-host-detection, performing DNS lookup [2024-09-18T15:09:52Z INFO gpapi::gateway::parse_gateways] Try to parse the internal gateways... [2024-09-18T15:09:52Z INFO gpgui::portal_connector] Retrieved 1 gateway(s) from the portal, updating... [2024-09-18T15:09:52Z INFO gpgui::portal_connector] Performing gateway login, gateway: g**a... [2024-09-18T15:09:52Z INFO gpapi::gateway::login] Perform gateway login, user_agent: PAN GlobalProtect/6.0.1-19 (Linux Linux Mint 21.3) [2024-09-18T15:09:52Z WARN gpapi::gateway::login] GP response error: reason=, status=512 , body= [2024-09-18T15:09:52Z INFO gpgui::portal_connector] Gateway login failed: Gateway login error: [2024-09-18T15:09:52Z INFO gpgui::portal_connector] Gateway prelogin, gateway: g**a... [2024-09-18T15:09:52Z INFO gpapi::portal::prelogin] Gateway prelogin with user_agent: PAN GlobalProtect/6.0.1-19 (Linux Linux Mint 21.3) [2024-09-18T15:09:52Z INFO gpapi::portal::prelogin] Perform prelogin, user_agent: PAN GlobalProtect/6.0.1-19 (Linux Linux Mint 21.3) [2024-09-18T15:09:52Z INFO gpgui::portal_connector] Authenticating gateway... [2024-09-18T15:09:52Z INFO gpgui::portal_connector] Launching SAML authentication... [2024-09-18T15:09:52Z INFO gpauth::cli] gpauth started: 2.3.7 (2024-08-16) [2024-09-18T15:09:52Z INFO gpauth::auth_window] Open auth window, user_agent: PAN GlobalProtect/6.0.1-19 (Linux Linux Mint 21.3) [2024-09-18T15:09:53Z INFO gpauth::auth_window] Auth window user agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 [2024-09-18T15:09:53Z INFO gpauth::auth_window] Load the SAML request as URI... [2024-09-18T15:09:53Z INFO gpauth::auth_window] Loaded uri: https://l**********m/12f933b3-3d61-4b19-9a4d-689021de8cc9/saml2?SAMLRequest=j**********%3D&RelayState=R**********x [2024-09-18T15:09:53Z INFO gpauth::auth_window] Trying to read auth data from response headers... [2024-09-18T15:09:53Z INFO gpauth::auth_window] No saml-auth-status header found [2024-09-18T15:09:53Z INFO gpauth::auth_window] No auth data found in headers, trying to read from body... [2024-09-18T15:09:53Z INFO gpauth::auth_window] Failed to read auth data from body: No auth data found [2024-09-18T15:09:53Z INFO gpauth::auth_window] No auth data found, it may not be the /SAML20/SP/ACS endpoint [2024-09-18T15:09:53Z INFO gpauth::auth_window] Raise window in 1 second(s) [2024-09-18T15:09:53Z INFO gpauth::auth_window] Raise window cancelled [2024-09-18T15:09:53Z WARN gpauth::auth_window] Failed to load uri: https://g**********a/SAML20/SP/ACS with error: Load request cancelled [2024-09-18T15:09:53Z INFO gpauth::auth_window] Loaded uri: https://g**********a/SAML20/SP/ACS [2024-09-18T15:09:53Z INFO gpauth::auth_window] Trying to read auth data from response headers... [2024-09-18T15:09:53Z INFO gpauth::auth_window] Got auth data from headers [2024-09-18T15:09:53Z INFO gpgui::portal_connector] Performing gateway login, gateway: g**a... [2024-09-18T15:09:53Z INFO gpapi::gateway::login] Perform gateway login, user_agent: PAN GlobalProtect/6.0.1-19 (Linux Linux Mint 21.3) [2024-09-18T15:09:53Z INFO gpgui::portal_connector] Gateway login succeeded, gateway: g**a [2024-09-18T15:09:53Z INFO gpgui::portal_connector] Connecting to the gateway... [2024-09-18T15:09:53Z INFO openconnect::ffi] openconnect version: v8.20-1 [2024-09-18T15:09:53Z INFO openconnect::ffi] User agent: PAN GlobalProtect/6.0.1-19 (Linux Linux Mint 21.3) [2024-09-18T15:09:53Z INFO openconnect::ffi] VPNC script: /usr/share/vpnc-scripts/vpnc-script [2024-09-18T15:09:53Z INFO openconnect::ffi] OS: linux [2024-09-18T15:09:53Z INFO openconnect::ffi] CSD_USER: 1000 [2024-09-18T15:09:53Z INFO openconnect::ffi] CSD_WRAPPER: (null) [2024-09-18T15:09:53Z INFO openconnect::ffi] RECONNECT_TIMEOUT: 300 [2024-09-18T15:09:53Z INFO openconnect::ffi] MTU: 0 [2024-09-18T15:09:53Z INFO openconnect::ffi] DISABLE_IPV6: 0 [2024-09-18T15:09:53Z INFO openconnect::ffi] NO_DTLS: 0 [2024-09-18T15:09:53Z INFO openconnect::ffi] POST https://[**********]/ssl-vpn/getconfig.esp

[2024-09-18T15:09:53Z INFO openconnect::ffi] SSL negotiation with [**] [2024-09-18T15:09:53Z INFO openconnect::ffi] Connected to HTTPS on [**] with ciphersuite (TLS1.2)-(ECDHE-SECP256R1)-(RSA-SHA256)-(AES-256-GCM) [2024-09-18T15:09:53Z INFO openconnect::ffi] Tunnel timeout (rekey interval) is 180 minutes. [2024-09-18T15:09:53Z INFO openconnect::ffi] Idle timeout is 180 minutes. [2024-09-18T15:09:53Z WARN openconnect::ffi] Did not receive ESP keys and matching gateway in GlobalProtect config; tunnel will be TLS only. [2024-09-18T15:09:53Z WARN openconnect::ffi] No IP address received. Aborting [2024-09-18T15:09:53Z WARN openconnect::ffi] Failed to parse server response [2024-09-18T15:09:53Z WARN openconnect::ffi] openconnect_make_cstp_connection failed [2024-09-18T15:09:53Z WARN gpgui::portal_connector] Failed to connect to the gateway: g**a [2024-09-18T15:10:00Z INFO gpgui::portal_connector] Connecting to the portal: s**a... [2024-09-18T15:10:00Z INFO gpgui::portal_connector] Trying to connect the gateway directly... [2024-09-18T15:10:00Z INFO gpgui::portal_connector] Failed to connect the gateway directly: No credential found [2024-09-18T15:10:00Z INFO gpgui::portal_connector] Trying to connect portal with cached credential... [2024-09-18T15:10:00Z INFO gpgui::portal_connector] Failed to connect portal with cached credential: No cached credential found for the portal [2024-09-18T15:10:00Z INFO gpgui::portal_connector] Trying to connect the portal with prelogin... [2024-09-18T15:10:00Z INFO gpgui::portal_connector] Performing portal prelogin... [2024-09-18T15:10:00Z INFO gpapi::portal::prelogin] Portal prelogin with user_agent: PAN GlobalProtect/6.0.1-19 (Linux Linux Mint 21.3) [2024-09-18T15:10:00Z INFO gpapi::portal::prelogin] Perform prelogin, user_agent: PAN GlobalProtect/6.0.1-19 (Linux Linux Mint 21.3) [2024-09-18T15:10:00Z INFO gpgui::portal_connector] Authenticating portal... [2024-09-18T15:10:00Z INFO gpgui::portal_connector] Launching SAML authentication... [2024-09-18T15:10:00Z INFO gpauth::cli] gpauth started: 2.3.7 (2024-08-16) [2024-09-18T15:10:00Z INFO gpauth::auth_window] Open auth window, user_agent: PAN GlobalProtect/6.0.1-19 (Linux Linux Mint 21.3) [2024-09-18T15:10:00Z INFO gpauth::auth_window] Cookies cleared in 8 ms [2024-09-18T15:10:00Z INFO gpauth::auth_window] Auth window user agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 [2024-09-18T15:10:00Z INFO gpauth::auth_window] Load the SAML request as URI... [2024-09-18T15:10:02Z INFO gpauth::auth_window] Loaded uri: https://l**********m/12f933b3-3d61-4b19-9a4d-689021de8cc9/saml2?SAMLRequest=l**********%3D&RelayState=T**********x [2024-09-18T15:10:02Z INFO gpauth::auth_window] Trying to read auth data from response headers... [2024-09-18T15:10:02Z INFO gpauth::auth_window] No saml-auth-status header found [2024-09-18T15:10:02Z INFO gpauth::auth_window] No auth data found in headers, trying to read from body... [2024-09-18T15:10:02Z INFO gpauth::auth_window] Failed to read auth data from body: No auth data found [2024-09-18T15:10:02Z INFO gpauth::auth_window] No auth data found, it may not be the /SAML20/SP/ACS endpoint [2024-09-18T15:10:02Z INFO gpauth::auth_window] Raise window in 1 second(s) [2024-09-18T15:10:03Z INFO gpapi::utils::window] Window raised after 2 attempts [2024-09-18T15:10:15Z INFO gpauth::auth_window] Loaded uri: https://l**********m/12f933b3-3d61-4b19-9a4d-689021de8cc9/login [2024-09-18T15:10:15Z INFO gpauth::auth_window] Trying to read auth data from response headers... [2024-09-18T15:10:15Z INFO gpauth::auth_window] No saml-auth-status header found [2024-09-18T15:10:15Z INFO gpauth::auth_window] No auth data found in headers, trying to read from body... [2024-09-18T15:10:15Z INFO gpauth::auth_window] Failed to read auth data from body: No auth data found [2024-09-18T15:10:15Z INFO gpauth::auth_window] No auth data found, it may not be the /SAML20/SP/ACS endpoint [2024-09-18T15:10:26Z INFO gpauth::auth_window] Loaded uri: https://l**********m/common/SAS/ProcessAuth [2024-09-18T15:10:26Z INFO gpauth::auth_window] Trying to read auth data from response headers... [2024-09-18T15:10:26Z INFO gpauth::auth_window] No saml-auth-status header found [2024-09-18T15:10:26Z INFO gpauth::auth_window] No auth data found in headers, trying to read from body... [2024-09-18T15:10:26Z INFO gpauth::auth_window] Failed to read auth data from body: No auth data found [2024-09-18T15:10:26Z INFO gpauth::auth_window] No auth data found, it may not be the /SAML20/SP/ACS endpoint [2024-09-18T15:10:30Z INFO gpauth::auth_window] Loaded uri: https://l**********m/kmsi [2024-09-18T15:10:30Z INFO gpauth::auth_window] Trying to read auth data from response headers... [2024-09-18T15:10:30Z INFO gpauth::auth_window] No saml-auth-status header found [2024-09-18T15:10:30Z INFO gpauth::auth_window] No auth data found in headers, trying to read from body... [2024-09-18T15:10:30Z INFO gpauth::auth_window] Failed to read auth data from body: No auth data found [2024-09-18T15:10:30Z INFO gpauth::auth_window] No auth data found, it may not be the /SAML20/SP/ACS endpoint [2024-09-18T15:10:30Z WARN gpauth::auth_window] Failed to load uri: https://s**********a/SAML20/SP/ACS with error: Load request cancelled [2024-09-18T15:10:30Z INFO gpauth::auth_window] Loaded uri: https://s**********a/SAML20/SP/ACS [2024-09-18T15:10:30Z INFO gpauth::auth_window] Trying to read auth data from response headers... [2024-09-18T15:10:30Z INFO gpauth::auth_window] Got auth data from headers [2024-09-18T15:10:30Z INFO gpgui::portal_connector] Fetching the portal config... [2024-09-18T15:10:30Z INFO gpapi::portal::config] Retrieve the portal config, user_agent: PAN GlobalProtect/6.0.1-19 (Linux Linux Mint 21.3) [2024-09-18T15:10:30Z INFO gpapi::portal::config] Found internal-host-detection, performing DNS lookup [2024-09-18T15:10:30Z INFO gpapi::gateway::parse_gateways] Try to parse the internal gateways... [2024-09-18T15:10:30Z INFO gpgui::portal_connector] Retrieved 1 gateway(s) from the portal, updating... [2024-09-18T15:10:30Z INFO gpgui::portal_connector] Performing gateway login, gateway: g**a... [2024-09-18T15:10:30Z INFO gpapi::gateway::login] Perform gateway login, user_agent: PAN GlobalProtect/6.0.1-19 (Linux Linux Mint 21.3) [2024-09-18T15:10:30Z WARN gpapi::gateway::login] GP response error: reason=, status=512 , body= [2024-09-18T15:10:30Z INFO gpgui::portal_connector] Gateway login failed: Gateway login error: [2024-09-18T15:10:30Z INFO gpgui::portal_connector] Gateway prelogin, gateway: g**a... [2024-09-18T15:10:30Z INFO gpapi::portal::prelogin] Gateway prelogin with user_agent: PAN GlobalProtect/6.0.1-19 (Linux Linux Mint 21.3) [2024-09-18T15:10:30Z INFO gpapi::portal::prelogin] Perform prelogin, user_agent: PAN GlobalProtect/6.0.1-19 (Linux Linux Mint 21.3) [2024-09-18T15:10:30Z INFO gpgui::portal_connector] Authenticating gateway... [2024-09-18T15:10:30Z INFO gpgui::portal_connector] Launching SAML authentication... [2024-09-18T15:10:30Z INFO gpauth::cli] gpauth started: 2.3.7 (2024-08-16) [2024-09-18T15:10:30Z INFO gpauth::auth_window] Open auth window, user_agent: PAN GlobalProtect/6.0.1-19 (Linux Linux Mint 21.3) [2024-09-18T15:10:31Z INFO gpauth::auth_window] Auth window user agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 [2024-09-18T15:10:31Z INFO gpauth::auth_window] Load the SAML request as URI... [2024-09-18T15:10:31Z INFO gpauth::auth_window] Loaded uri: https://l**********m/12f933b3-3d61-4b19-9a4d-689021de8cc9/saml2?SAMLRequest=j**********C&RelayState=c**********x [2024-09-18T15:10:31Z INFO gpauth::auth_window] Trying to read auth data from response headers... [2024-09-18T15:10:31Z INFO gpauth::auth_window] No saml-auth-status header found [2024-09-18T15:10:31Z INFO gpauth::auth_window] No auth data found in headers, trying to read from body... [2024-09-18T15:10:31Z INFO gpauth::auth_window] Failed to read auth data from body: No auth data found [2024-09-18T15:10:31Z INFO gpauth::auth_window] No auth data found, it may not be the /SAML20/SP/ACS endpoint [2024-09-18T15:10:31Z INFO gpauth::auth_window] Raise window in 1 second(s) [2024-09-18T15:10:31Z INFO gpauth::auth_window] Raise window cancelled [2024-09-18T15:10:31Z WARN gpauth::auth_window] Failed to load uri: https://g**********a/SAML20/SP/ACS with error: Load request cancelled [2024-09-18T15:10:31Z INFO gpauth::auth_window] Loaded uri: https://g**********a/SAML20/SP/ACS [2024-09-18T15:10:31Z INFO gpauth::auth_window] Trying to read auth data from response headers... [2024-09-18T15:10:31Z INFO gpauth::auth_window] Got auth data from headers [2024-09-18T15:10:31Z INFO gpgui::portal_connector] Performing gateway login, gateway: g**a... [2024-09-18T15:10:31Z INFO gpapi::gateway::login] Perform gateway login, user_agent: PAN GlobalProtect/6.0.1-19 (Linux Linux Mint 21.3) [2024-09-18T15:10:31Z INFO gpgui::portal_connector] Gateway login succeeded, gateway: g**a [2024-09-18T15:10:31Z INFO gpgui::portal_connector] Connecting to the gateway... [2024-09-18T15:10:31Z INFO openconnect::ffi] openconnect version: v8.20-1 [2024-09-18T15:10:31Z INFO openconnect::ffi] User agent: PAN GlobalProtect/6.0.1-19 (Linux Linux Mint 21.3) [2024-09-18T15:10:31Z INFO openconnect::ffi] VPNC script: /usr/share/vpnc-scripts/vpnc-script [2024-09-18T15:10:31Z INFO openconnect::ffi] OS: linux [2024-09-18T15:10:31Z INFO openconnect::ffi] CSD_USER: 1000 [2024-09-18T15:10:31Z INFO openconnect::ffi] CSD_WRAPPER: (null) [2024-09-18T15:10:31Z INFO openconnect::ffi] RECONNECT_TIMEOUT: 300 [2024-09-18T15:10:31Z INFO openconnect::ffi] MTU: 0 [2024-09-18T15:10:31Z INFO openconnect::ffi] DISABLE_IPV6: 0 [2024-09-18T15:10:31Z INFO openconnect::ffi] NO_DTLS: 0 [2024-09-18T15:10:31Z INFO openconnect::ffi] POST https://[**********]/ssl-vpn/getconfig.esp

[2024-09-18T15:10:31Z INFO openconnect::ffi] SSL negotiation with [**] [2024-09-18T15:10:31Z INFO openconnect::ffi] Connected to HTTPS on [**] with ciphersuite (TLS1.2)-(ECDHE-SECP256R1)-(RSA-SHA256)-(AES-256-GCM) [2024-09-18T15:10:31Z INFO openconnect::ffi] Tunnel timeout (rekey interval) is 180 minutes. [2024-09-18T15:10:31Z INFO openconnect::ffi] Idle timeout is 180 minutes. [2024-09-18T15:10:31Z WARN openconnect::ffi] Did not receive ESP keys and matching gateway in GlobalProtect config; tunnel will be TLS only. [2024-09-18T15:10:31Z WARN openconnect::ffi] No IP address received. Aborting [2024-09-18T15:10:31Z WARN openconnect::ffi] Failed to parse server response [2024-09-18T15:10:31Z WARN openconnect::ffi] openconnect_make_cstp_connection failed [2024-09-18T15:10:31Z WARN gpgui::portal_connector] Failed to connect to the gateway: g**a [2024-09-18T15:10:34Z INFO gpgui::portal_connector] Connecting to the portal: s**a... [2024-09-18T15:10:34Z INFO gpgui::portal_connector] Trying to connect the gateway directly... [2024-09-18T15:10:34Z INFO gpgui::portal_connector] Failed to connect the gateway directly: Internal host detection is enabled, can't connect the gateway directly [2024-09-18T15:10:34Z INFO gpgui::portal_connector] Trying to connect portal with cached credential... [2024-09-18T15:10:34Z INFO gpgui::portal_connector] Fetching the portal config... [2024-09-18T15:10:34Z INFO gpapi::portal::config] Retrieve the portal config, user_agent: PAN GlobalProtect/6.0.1-19 (Linux Linux Mint 21.3) [2024-09-18T15:10:34Z WARN gpapi::portal::config] GP response error: reason=auth-failed, status=512 , body= [2024-09-18T15:10:34Z INFO gpgui::portal_connector] Failed to connect portal with cached credential: Cached credential is stale, please try again [2024-09-18T15:10:34Z INFO gpgui::portal_connector] Trying to connect the portal with prelogin... [2024-09-18T15:10:34Z INFO gpgui::portal_connector] Performing portal prelogin... [2024-09-18T15:10:34Z INFO gpapi::portal::prelogin] Portal prelogin with user_agent: PAN GlobalProtect/6.0.1-19 (Linux Linux Mint 21.3) [2024-09-18T15:10:34Z INFO gpapi::portal::prelogin] Perform prelogin, user_agent: PAN GlobalProtect/6.0.1-19 (Linux Linux Mint 21.3) [2024-09-18T15:10:34Z INFO gpgui::portal_connector] Authenticating portal... [2024-09-18T15:10:34Z INFO gpgui::portal_connector] Launching SAML authentication... [2024-09-18T15:10:34Z INFO gpauth::cli] gpauth started: 2.3.7 (2024-08-16) [2024-09-18T15:10:34Z INFO gpauth::auth_window] Open auth window, user_agent: PAN GlobalProtect/6.0.1-19 (Linux Linux Mint 21.3) [2024-09-18T15:10:34Z INFO gpauth::auth_window] Auth window user agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 [2024-09-18T15:10:34Z INFO gpauth::auth_window] Load the SAML request as URI... [2024-09-18T15:10:34Z INFO gpauth::auth_window] Loaded uri: https://l**********m/12f933b3-3d61-4b19-9a4d-689021de8cc9/saml2?SAMLRequest=l**********%3D&RelayState=d**********x [2024-09-18T15:10:34Z INFO gpauth::auth_window] Trying to read auth data from response headers... [2024-09-18T15:10:34Z INFO gpauth::auth_window] No saml-auth-status header found [2024-09-18T15:10:34Z INFO gpauth::auth_window] No auth data found in headers, trying to read from body... [2024-09-18T15:10:34Z INFO gpauth::auth_window] Failed to read auth data from body: No auth data found [2024-09-18T15:10:34Z INFO gpauth::auth_window] No auth data found, it may not be the /SAML20/SP/ACS endpoint [2024-09-18T15:10:34Z INFO gpauth::auth_window] Raise window in 1 second(s) [2024-09-18T15:10:34Z INFO gpauth::auth_window] Raise window cancelled [2024-09-18T15:10:35Z WARN gpauth::auth_window] Failed to load uri: https://s**********a/SAML20/SP/ACS with error: Load request cancelled [2024-09-18T15:10:35Z INFO gpauth::auth_window] Loaded uri: https://s**********a/SAML20/SP/ACS [2024-09-18T15:10:35Z INFO gpauth::auth_window] Trying to read auth data from response headers... [2024-09-18T15:10:35Z INFO gpauth::auth_window] Got auth data from headers [2024-09-18T15:10:35Z INFO gpgui::portal_connector] Fetching the portal config... [2024-09-18T15:10:35Z INFO gpapi::portal::config] Retrieve the portal config, user_agent: PAN GlobalProtect/6.0.1-19 (Linux Linux Mint 21.3) [2024-09-18T15:10:35Z INFO gpapi::portal::config] Found internal-host-detection, performing DNS lookup [2024-09-18T15:10:35Z INFO gpapi::gateway::parse_gateways] Try to parse the internal gateways... [2024-09-18T15:10:35Z INFO gpgui::portal_connector] Retrieved 1 gateway(s) from the portal, updating... [2024-09-18T15:10:35Z INFO gpgui::portal_connector] Performing gateway login, gateway: g**a... [2024-09-18T15:10:35Z INFO gpapi::gateway::login] Perform gateway login, user_agent: PAN GlobalProtect/6.0.1-19 (Linux Linux Mint 21.3) [2024-09-18T15:10:35Z WARN gpapi::gateway::login] GP response error: reason=, status=512 , body= [2024-09-18T15:10:35Z INFO gpgui::portal_connector] Gateway login failed: Gateway login error: [2024-09-18T15:10:35Z INFO gpgui::portal_connector] Gateway prelogin, gateway: g**a... [2024-09-18T15:10:35Z INFO gpapi::portal::prelogin] Gateway prelogin with user_agent: PAN GlobalProtect/6.0.1-19 (Linux Linux Mint 21.3) [2024-09-18T15:10:35Z INFO gpapi::portal::prelogin] Perform prelogin, user_agent: PAN GlobalProtect/6.0.1-19 (Linux Linux Mint 21.3) [2024-09-18T15:10:35Z INFO gpgui::portal_connector] Authenticating gateway... [2024-09-18T15:10:35Z INFO gpgui::portal_connector] Launching SAML authentication... [2024-09-18T15:10:35Z INFO gpauth::cli] gpauth started: 2.3.7 (2024-08-16) [2024-09-18T15:10:35Z INFO gpauth::auth_window] Open auth window, user_agent: PAN GlobalProtect/6.0.1-19 (Linux Linux Mint 21.3) [2024-09-18T15:10:35Z INFO gpauth::auth_window] Auth window user agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 [2024-09-18T15:10:35Z INFO gpauth::auth_window] Load the SAML request as URI... [2024-09-18T15:10:35Z INFO gpauth::auth_window] Loaded uri: https://l**********m/12f933b3-3d61-4b19-9a4d-689021de8cc9/saml2?SAMLRequest=j**********%3D&RelayState=f**********x [2024-09-18T15:10:35Z INFO gpauth::auth_window] Trying to read auth data from response headers... [2024-09-18T15:10:35Z INFO gpauth::auth_window] No saml-auth-status header found [2024-09-18T15:10:35Z INFO gpauth::auth_window] No auth data found in headers, trying to read from body... [2024-09-18T15:10:35Z INFO gpauth::auth_window] Failed to read auth data from body: No auth data found [2024-09-18T15:10:35Z INFO gpauth::auth_window] No auth data found, it may not be the /SAML20/SP/ACS endpoint [2024-09-18T15:10:35Z INFO gpauth::auth_window] Raise window in 1 second(s) [2024-09-18T15:10:35Z INFO gpauth::auth_window] Raise window cancelled [2024-09-18T15:10:36Z WARN gpauth::auth_window] Failed to load uri: https://g**********a/SAML20/SP/ACS with error: Load request cancelled [2024-09-18T15:10:36Z INFO gpauth::auth_window] Loaded uri: https://g**********a/SAML20/SP/ACS [2024-09-18T15:10:36Z INFO gpauth::auth_window] Trying to read auth data from response headers... [2024-09-18T15:10:36Z INFO gpauth::auth_window] Got auth data from headers [2024-09-18T15:10:36Z INFO gpgui::portal_connector] Performing gateway login, gateway: g**a... [2024-09-18T15:10:36Z INFO gpapi::gateway::login] Perform gateway login, user_agent: PAN GlobalProtect/6.0.1-19 (Linux Linux Mint 21.3) [2024-09-18T15:10:36Z INFO gpgui::portal_connector] Gateway login succeeded, gateway: g**a [2024-09-18T15:10:36Z INFO gpgui::portal_connector] Connecting to the gateway... [2024-09-18T15:10:36Z INFO openconnect::ffi] openconnect version: v8.20-1 [2024-09-18T15:10:36Z INFO openconnect::ffi] User agent: PAN GlobalProtect/6.0.1-19 (Linux Linux Mint 21.3) [2024-09-18T15:10:36Z INFO openconnect::ffi] VPNC script: /usr/share/vpnc-scripts/vpnc-script [2024-09-18T15:10:36Z INFO openconnect::ffi] OS: linux [2024-09-18T15:10:36Z INFO openconnect::ffi] CSD_USER: 1000 [2024-09-18T15:10:36Z INFO openconnect::ffi] CSD_WRAPPER: (null) [2024-09-18T15:10:36Z INFO openconnect::ffi] RECONNECT_TIMEOUT: 300 [2024-09-18T15:10:36Z INFO openconnect::ffi] MTU: 0 [2024-09-18T15:10:36Z INFO openconnect::ffi] DISABLE_IPV6: 0 [2024-09-18T15:10:36Z INFO openconnect::ffi] NO_DTLS: 0 [2024-09-18T15:10:36Z INFO openconnect::ffi] POST https://[**********]/ssl-vpn/getconfig.esp

[2024-09-18T15:10:36Z INFO openconnect::ffi] SSL negotiation with [**] [2024-09-18T15:10:36Z INFO openconnect::ffi] Connected to HTTPS on [**] with ciphersuite (TLS1.2)-(ECDHE-SECP256R1)-(RSA-SHA256)-(AES-256-GCM) [2024-09-18T15:10:36Z INFO openconnect::ffi] Tunnel timeout (rekey interval) is 180 minutes. [2024-09-18T15:10:36Z INFO openconnect::ffi] Idle timeout is 180 minutes. [2024-09-18T15:10:36Z WARN openconnect::ffi] Did not receive ESP keys and matching gateway in GlobalProtect config; tunnel will be TLS only. [2024-09-18T15:10:36Z WARN openconnect::ffi] No IP address received. Aborting [2024-09-18T15:10:36Z WARN openconnect::ffi] Failed to parse server response [2024-09-18T15:10:36Z WARN openconnect::ffi] openconnect_make_cstp_connection failed [2024-09-18T15:10:36Z WARN gpgui::portal_connector] Failed to connect to the gateway: g**a [2024-09-18T15:11:02Z INFO gpapi::utils::window] Window raised after 1 attempts [2024-09-18T15:11:03Z INFO gpgui::handlers::subscription] Sending the init event to client: settings [2024-09-18T15:11:03Z INFO gpgui::handlers::subscription] Sent the init event to client: settings****

yuezk commented 1 month ago

Hi @Mork7, let's use CLI for quick troubleshooting, try the following commands and see if it helps.

  1. Try sudo -E gpclient connect <portal> --as-gateway
  2. Try sudo -E gpclient connect <portal> --disable-ipv6
Mork7 commented 1 month ago

1. sudo -E gpclient connect --as-gateway

mork@mork-msi:~$ sudo -E gpclient connect securelogin.uwindsor.ca --as-gateway
[2024-09-23T15:49:15Z INFO  gpclient::cli] gpclient started: 2.3.7 (2024-08-16)
[2024-09-23T15:49:15Z INFO  gpclient::connect] Treating the server as a gateway
[2024-09-23T15:49:15Z INFO  gpclient::connect] Performing the gateway authentication...
[2024-09-23T15:49:15Z INFO  gpapi::portal::prelogin] Gateway prelogin with user_agent: PAN GlobalProtect
[2024-09-23T15:49:15Z INFO  gpapi::portal::prelogin] Perform prelogin, user_agent: PAN GlobalProtect
[2024-09-23T15:49:15Z WARN  gpapi::portal::prelogin] Parse response error, response: <?xml version="1.0" encoding="UTF-8" ?>
    <prelogin-response>
    <status>Error</status>
    <ccusername></ccusername>
    <autosubmit></autosubmit>
    <msg>GlobalProtect gateway does not exist</msg>
    <newmsg></newmsg>
    <license></license>
    <authentication-message></authentication-message>
    <username-label></username-label>
    <password-label></password-label>
    <panos-version>1</panos-version>
    <saml-default-browser>yes</saml-default-browser>
    <krb-norm-username></krb-norm-username>
    <krb-auth-status>0</krb-auth-status>
    <cas-auth></cas-auth>
    <saml-auth-status>0</saml-auth-status>
    <saml-auth-method></saml-auth-method>
    <saml-request-timeout></saml-request-timeout>
    <saml-request-id></saml-request-id>
    <saml-request></saml-request>
    <auth-api>no</auth-api><region></region>
    </prelogin-response>

Error: Prelogin error: GlobalProtect gateway does not exist

--

2. sudo -E gpclient connect --disable-ipv6

mork@mork-msi:~$ sudo -E gpclient connect securelogin.uwindsor.ca --disable-ipv6[2024-09-23T15:49:37Z INFO  gpclient::cli] gpclient started: 2.3.7 (2024-08-16)
[2024-09-23T15:49:37Z INFO  gpapi::portal::prelogin] Portal prelogin with user_agent: PAN GlobalProtect
[2024-09-23T15:49:37Z INFO  gpapi::portal::prelogin] Perform prelogin, user_agent: PAN GlobalProtect
[2024-09-23T15:49:37Z INFO  gpauth::cli] gpauth started: 2.3.7 (2024-08-16)
[2024-09-23T15:49:37Z INFO  gpauth::auth_window] Open auth window, user_agent: PAN GlobalProtect

** (gpauth:5303): WARNING **: 11:49:37.606: webkit_settings_set_enable_offline_web_application_cache is deprecated and does nothing.
[2024-09-23T15:49:38Z INFO  gpauth::auth_window] Auth window user agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15
[2024-09-23T15:49:38Z INFO  gpauth::auth_window] Load the SAML request as URI...
[2024-09-23T15:49:38Z INFO  gpauth::auth_window] Loaded uri: https://l**********m/12f933b3-3d61-4b19-9a4d-689021de8cc9/saml2?SAMLRequest=l**********%3D&RelayState=b**********x
[2024-09-23T15:49:38Z INFO  gpauth::auth_window] Trying to read auth data from response headers...
[2024-09-23T15:49:38Z INFO  gpauth::auth_window] No saml-auth-status header found
[2024-09-23T15:49:38Z INFO  gpauth::auth_window] No auth data found in headers, trying to read from body...
[2024-09-23T15:49:38Z INFO  gpauth::auth_window] Failed to read auth data from body: No auth data found
[2024-09-23T15:49:38Z INFO  gpauth::auth_window] No auth data found, it may not be the /SAML20/SP/ACS endpoint
[2024-09-23T15:49:38Z INFO  gpauth::auth_window] Raise window in 1 second(s)
[2024-09-23T15:49:38Z INFO  gpauth::auth_window] Raise window cancelled
[2024-09-23T15:49:38Z INFO  gpauth::auth_window] Loaded uri: https://s**********a/SAML20/SP/ACS
[2024-09-23T15:49:38Z INFO  gpauth::auth_window] Trying to read auth data from response headers...
[2024-09-23T15:49:38Z INFO  gpauth::auth_window] Got auth data from headers
[2024-09-23T15:49:38Z INFO  gpapi::portal::config] Retrieve the portal config, user_agent: PAN GlobalProtect
[2024-09-23T15:49:38Z INFO  gpapi::portal::config] Found internal-host-detection, performing DNS lookup
[2024-09-23T15:49:38Z INFO  gpapi::gateway::parse_gateways] Try to parse the internal gateways...
[2024-09-23T15:49:38Z INFO  gpclient::connect] Connecting to the only available gateway: gw-campus-internal (gwd1.net.uwindsor.ca)
[2024-09-23T15:49:38Z INFO  gpapi::gateway::login] Perform gateway login, user_agent: PAN GlobalProtect
[2024-09-23T15:49:38Z WARN  gpapi::gateway::login] GP response error: reason=<none>, status=512 <unknown status code>, body=<html>
      <head></head>
      <body>
      var respStatus = "Error";
      var respMsg = "Authentication failure: Invalid username or password";
      thisForm.inputStr.value = "";
    </body>
    </html>
[2024-09-23T15:49:38Z INFO  gpclient::connect] Gateway login failed: Gateway login error: <none>
[2024-09-23T15:49:38Z INFO  gpclient::connect] Performing the gateway authentication...
[2024-09-23T15:49:38Z INFO  gpapi::portal::prelogin] Gateway prelogin with user_agent: PAN GlobalProtect
[2024-09-23T15:49:38Z INFO  gpapi::portal::prelogin] Perform prelogin, user_agent: PAN GlobalProtect
[2024-09-23T15:49:38Z INFO  gpauth::cli] gpauth started: 2.3.7 (2024-08-16)
[2024-09-23T15:49:38Z INFO  gpauth::auth_window] Open auth window, user_agent: PAN GlobalProtect

** (gpauth:5415): WARNING **: 11:49:38.906: webkit_settings_set_enable_offline_web_application_cache is deprecated and does nothing.
[2024-09-23T15:49:39Z INFO  gpauth::auth_window] Auth window user agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15
[2024-09-23T15:49:39Z INFO  gpauth::auth_window] Load the SAML request as URI...
[2024-09-23T15:49:39Z INFO  gpauth::auth_window] Loaded uri: https://l**********m/12f933b3-3d61-4b19-9a4d-689021de8cc9/saml2?SAMLRequest=j**********%3D&RelayState=c**********x
[2024-09-23T15:49:39Z INFO  gpauth::auth_window] Trying to read auth data from response headers...
[2024-09-23T15:49:39Z INFO  gpauth::auth_window] No saml-auth-status header found
[2024-09-23T15:49:39Z INFO  gpauth::auth_window] No auth data found in headers, trying to read from body...
[2024-09-23T15:49:39Z INFO  gpauth::auth_window] Failed to read auth data from body: No auth data found
[2024-09-23T15:49:39Z INFO  gpauth::auth_window] No auth data found, it may not be the /SAML20/SP/ACS endpoint
[2024-09-23T15:49:39Z INFO  gpauth::auth_window] Raise window in 1 second(s)
[2024-09-23T15:49:39Z INFO  gpauth::auth_window] Loaded uri: https://g**********a/SAML20/SP/ACS
[2024-09-23T15:49:39Z INFO  gpauth::auth_window] Trying to read auth data from response headers...
[2024-09-23T15:49:39Z INFO  gpauth::auth_window] Got auth data from headers
Unhandled network process message 'NetworkStorageManager_DisconnectFromStorageArea'
Unhandled network process message 'NetworkStorageManager_DisconnectFromStorageArea'
[2024-09-23T15:49:39Z INFO  gpapi::gateway::login] Perform gateway login, user_agent: PAN GlobalProtect
[2024-09-23T15:49:40Z INFO  openconnect::ffi] openconnect version: v8.20-1
[2024-09-23T15:49:40Z INFO  openconnect::ffi] User agent: PAN GlobalProtect
[2024-09-23T15:49:40Z INFO  openconnect::ffi] VPNC script: /usr/share/vpnc-scripts/vpnc-script
[2024-09-23T15:49:40Z INFO  openconnect::ffi] OS: linux
[2024-09-23T15:49:40Z INFO  openconnect::ffi] CSD_USER: 1000
[2024-09-23T15:49:40Z INFO  openconnect::ffi] CSD_WRAPPER: (null)
[2024-09-23T15:49:40Z INFO  openconnect::ffi] RECONNECT_TIMEOUT: 300
[2024-09-23T15:49:40Z INFO  openconnect::ffi] MTU: 0
[2024-09-23T15:49:40Z INFO  openconnect::ffi] DISABLE_IPV6: 1
[2024-09-23T15:49:40Z INFO  openconnect::ffi] NO_DTLS: 0
[2024-09-23T15:49:40Z INFO  openconnect::ffi] POST https://gwd1.net.uwindsor.ca/ssl-vpn/getconfig.esp
[2024-09-23T15:49:40Z INFO  openconnect::ffi] Connected to 137.207.93.89:443
[2024-09-23T15:49:40Z INFO  openconnect::ffi] SSL negotiation with gwd1.net.uwindsor.ca
[2024-09-23T15:49:40Z INFO  openconnect::ffi] Connected to HTTPS on gwd1.net.uwindsor.ca with ciphersuite (TLS1.2)-(ECDHE-SECP256R1)-(RSA-SHA256)-(AES-256-GCM)
[2024-09-23T15:49:40Z INFO  openconnect::ffi] Tunnel timeout (rekey interval) is 180 minutes.
[2024-09-23T15:49:40Z INFO  openconnect::ffi] Idle timeout is 180 minutes.
[2024-09-23T15:49:40Z WARN  openconnect::ffi] Did not receive ESP keys and matching gateway in GlobalProtect config; tunnel will be TLS only.
[2024-09-23T15:49:40Z WARN  openconnect::ffi] No IP address received. Aborting
[2024-09-23T15:49:40Z WARN  openconnect::ffi] Failed to parse server response
[2024-09-23T15:49:40Z WARN  openconnect::ffi] openconnect_make_cstp_connection failed
Mork7 commented 1 month ago

This actually worked: sudo -E gpclient connect gwc1.net.uwindsor.ca --as-gateway.

This is the server I connect to when successful, so I tried to put it in here and it worked,

yuezk commented 1 month ago

Thanks for your feedback. This may related to server-side configuration. For the GlobalProtect VPN, a portal could have multiple gateways. For the auth part, will first auth the portal to get the gateway list, then choose a gateway to connect to. However, it is possible to connect to the gateway directly if we know the gateway address.

Glad it works for you and the --as-gateway parameter is supported for both the CLI and the GUI (see below).

image

I'm closing it.