Global Protect Clientless VPN and 10.2

Hey all,

I’ve updated my PA-440 (home/lab/nfr) to 10.2.1 to give it a run and see how it goes. I noticed my Clientless VPN Apps don’t work, all of them return a 404 response, irrespective of being FQDN or IP address.

I cannot see anything in the GP nor System logs, when doing the CLI debugging/pcaps I get nothing, not a single hit.

Going to raise a TAC case, but being “standard” support, I expect it’ll be 3-5 years before it’s tended to.

Just curious if anyone else is running 10.2.X and has come across this too?

Cheers

Download and Install a previous clientless vpn content package. Delete the previous one, download and install the most recent one again.
Let me know if it works. Pretty sure it will :wink:

Im having the same issue. I upgraded my PA-800 to 10.2.2.h2 and my apps return a 404 error. Im going to try your solution of installing the previous clientless cpn content package. I spent hours on a call with support today and they couldn’t even figure it out. If this fix does work dor me tomorrow, should I upgrade my pan-os back up to 10.2.x ? Im thinking of just leaving it on 10.1.6 for now until palo puts out a more stable release. I also noticed that 10.2.2.2h made my PA run very sluggish, meaning that gui pages would take a while to load. This sluggishness stopped when I downgraded back down to 10.1.6. Regardless, for now im just needing my clientless apps to work again…

this has still not been fixed and it seems the revert dynamic content back and forth does not work now either (10.2.4-h3)

Has this been fixed in the later 10.2.x releases?

I’ll give it a crack.

Does it get corrupted in the upgrade?

Edit: you were right. that fixed it. many thanks :slight_smile:

Thank you. This helped me today. Still not fixed then.

Be ready to do this every time you submit config changes until PA releases the fix :wink:

Oh joy :joy:
Baffles me that developers always seem to break something whilst fixing something else.

It’s almost like agile isn’t a valid development life cycle method. (I have a strong hatred for agile)

e that developers always seem to break something whilst fixing something else.

It’s almost like agile isn’t a valid development life cycle metho

I hate it with a passion as well. must have been invented by a manager not a technician.