(Windows only) Connect Before Logon (CBL) does not connect when the GlobalProtect portal uses full-chain certificate verification and the portal and gateways are hosted on Prisma Access. When full-chain-cert-verify is enabled, all gateway connection attempts fail with the error "The network connection is unreachable or the gateway is unresponsive. Check the network connection and reconnect." When full-chain-cert-verify is disabled, a server certificate error prompt appears for the portal on each CBL attempt; after accepting the prompt, users must enter credentials a second time.
Workaround: Disable full-chain-cert-verify on the GlobalProtect portal. Note that users will encounter a server certificate error prompt on each CBL attempt and must enter their credentials twice to complete the connection.
|