PCNSE Secure Access and VPN Practice Question
A GlobalProtect user can successfully authenticate to the portal but cannot connect to the internal gateway. The portal and gateway are configured on the same firewall. What is the most likely cause?
⚠ Common exam trap
Candidates often assume the issue is a zone mismatch or license problem, but the portal and gateway can be in different zones and licenses are not required for basic gateway connectivity, so the incorrect gateway IP address in the portal configuration is the precise cause.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Incorrect gateway IP address in portal configuration
When the portal and gateway are on the same firewall, the portal configuration must specify the correct IP address or FQDN for the gateway. If the gateway IP address in the portal configuration is incorrect, the client will successfully authenticate to the portal but then fail to establish a tunnel to the gateway because it cannot reach the gateway at the specified address. This is the most common cause of this symptom.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
User not assigned a license
Why it's wrong here
GlobalProtect licensing is not enforced per user for gateway connections; authentication to the portal already proves credentials work. Licence checks apply to subscriptions and capacity, not gateway selection. The likely cause is a gateway configuration or agent setting mismatch, such as an unreachable internal gateway address.
- ✓
Incorrect gateway IP address in portal configuration
Why this is correct
The portal hands the client the gateway address to connect to; if that configured address is wrong, authentication succeeds but the tunnel to the internal gateway fails. This matches the stem's symptom of portal success with gateway failure on the same firewall.
- ✗
Gateway interface not in the same zone as portal
Why it's wrong here
Portal and gateway zones need not match; GlobalProtect permits separate zones and interfaces for each. Zone separation is tempting because it is a valid design for isolating portal and gateway traffic, where it would be the correct configuration.
- ✗
Gateway MTU mismatch
Why it's wrong here
An MTU mismatch degrades or drops tunnel traffic after the connection establishes; it does not prevent the gateway connection itself. MTU is tempting because it causes intermittent GlobalProtect failures in paths with reduced MTU, where it would be the correct diagnosis.
Go deeper
Related to this question
About these practice questions
One of 319 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.