<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article GlobalProtect: Initial Set Up in GlobalProtect Articles</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-articles/globalprotect-initial-set-up/ta-p/322232</link>
    <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="GlobalProtect: Initial Setup" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25087iA6CCC1726BC8160E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="GlobalProtect Initial Setup.png" alt="GlobalProtect: Initial Setup" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;GlobalProtect: Initial Setup&lt;/span&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN&gt;In my blog, "&lt;/SPAN&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Blogs/GlobalProtect-Overview/ba-p/322170" target="_self"&gt;GlobalProtect: Overview&lt;/A&gt;&lt;SPAN&gt;," I provided a synopsis of the GlobalProtect series and overall objectives, including a description of each article in this series. I would recommend starting there prior to moving forward.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN&gt;In this post, I will cover the initial setup of GlobalProtect, which includes a portal, external gateway, and user authentication via local database. You can see a diagram of the environment&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/Blogs/GlobalProtect-Overview/ba-p/322170?lightbox-message-images-322170=25053i4232C172B9024D26" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;&lt;SPAN&gt;&lt;STRONG&gt;Part I - Initial Setup&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Navigate to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Device&lt;/STRONG&gt; &lt;STRONG&gt;&amp;gt;&lt;/STRONG&gt; &lt;STRONG&gt;GlobalProtect Client&lt;/STRONG&gt;&amp;nbsp;then download and activate the latest version (5.0.8 is a TAC-preferred version at the time of this blog post)&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI&gt;Navigate to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Network &amp;gt; Network Profiles &amp;gt; Interface Mgmt &amp;gt; Add&lt;/STRONG&gt;&amp;nbsp;and create a management profile to apply to the tunnel interface to which remote users will connect&lt;BR /&gt;
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;Enable&amp;nbsp;&lt;EM&gt;Response Pages&lt;/EM&gt;&lt;I&gt;&lt;BR /&gt;&lt;/I&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;NOTE:&lt;/STRONG&gt;&amp;nbsp;It is not required to enable&amp;nbsp;&lt;EM&gt;Response Pages&lt;/EM&gt;, but this feature will be used in a subsequent article&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Click &lt;STRONG&gt;OK&amp;nbsp;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;I&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Interface Management Profile - Response Pages" style="width: 600px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25056i7C813B0E3B78C94C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Interface Management Profile - Response Pages.png" alt="Interface Management Profile - Response Pages" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Interface Management Profile - Response Pages&lt;/span&gt;&lt;/span&gt;&lt;/I&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Navigate to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Network &amp;gt; Zones &amp;gt; Add&lt;/STRONG&gt;&amp;nbsp;and create a new&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Layer 3&lt;/STRONG&gt;&amp;nbsp;security zone for your GlobalProtect users&lt;/LI&gt;
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;Provide a name (e.g.,&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;gp&lt;/I&gt;)&lt;/LI&gt;
&lt;LI&gt;Set&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Type&lt;/STRONG&gt;&amp;nbsp;to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;Layer3&lt;/I&gt;&lt;/LI&gt;
&lt;LI&gt;Check the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Enable User Identification&lt;/STRONG&gt;&amp;nbsp;box&lt;/LI&gt;
&lt;LI&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;OK&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Zone - Enable User Identification" style="width: 640px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25058i819A4AD5BBEF81D8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Zone - Enable User Identification.png" alt="Zone - Enable User Identification" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Zone - Enable User Identification&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Navigate to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Network &amp;gt; Interfaces &amp;gt; Tunnel &amp;gt; Add&lt;/STRONG&gt;&amp;nbsp;and create a new tunnel interface&lt;/LI&gt;
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;Assign the interface a number (e.g., &lt;EM&gt;1&lt;/EM&gt;)&lt;/LI&gt;
&lt;LI&gt;Assign the interface to the appropriate&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Virtual Router&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Assign the interface to the appropriate&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Security Zone&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;I&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Tunnel Interface - Config" style="width: 640px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25059i5B9846E2A392E0D3/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Tunnel Interface - Config.png" alt="Tunnel Interface - Config" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Tunnel Interface - Config&lt;/span&gt;&lt;/span&gt;&lt;/I&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Navigate to the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;IPv4&amp;nbsp;&lt;/STRONG&gt;tab and assign a subnet to be used for your mobile users&lt;/LI&gt;
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;&lt;STRONG&gt;NOTE:&lt;/STRONG&gt;&amp;nbsp;It should be a unique network. Also, note that an IP address on this interface is not a requirement.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Tunnel Interface - IPv4" style="width: 640px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25060iDA8A1A18CCDE759A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Tunnel Interface - IPv4.png" alt="Tunnel Interface - IPv4" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Tunnel Interface - IPv4&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Navigate to the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Advanced&amp;nbsp;&lt;/STRONG&gt;tab and apply the&amp;nbsp;&lt;EM&gt;Management Profile&lt;/EM&gt;&amp;nbsp;created for the tunnel interface above&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;OK&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Tunnel Interface - Advanced" style="width: 699px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25160iCC5B45AFD418FF92/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="tunnel interface.PNG" alt="Tunnel Interface - Advanced" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Tunnel Interface - Advanced&lt;/span&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Navigate to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Device &amp;gt; Certificate Management &amp;gt; Certificates &amp;gt; Generate&lt;/STRONG&gt;&amp;nbsp;and create a trusted root certificate&lt;/LI&gt;
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;&lt;STRONG&gt;NOTE:&lt;/STRONG&gt;&amp;nbsp;In this series of posts, we will be using self-signed certificates. It is recommended to use third-party certificates in a production environment, but self-signed certificates will work as well.&lt;/LI&gt;
&lt;LI&gt;Enter a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;Certificate Name&lt;/I&gt;&lt;/LI&gt;
&lt;LI&gt;Enter the management IP of the firewall for the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;Common Name&lt;/I&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;UL class="lia-list-style-type-square"&gt;
&lt;LI&gt;Check the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Certificate Authority&lt;/STRONG&gt;&amp;nbsp;box&lt;/LI&gt;
&lt;LI&gt;Enter information in other fields if desired (optional)&lt;/LI&gt;
&lt;LI&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Generate&lt;BR /&gt;&lt;/STRONG&gt;&lt;I&gt;&lt;/I&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;I&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Generate Certificate - Local Certificate Authority" style="width: 399px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25061i1F45CF2F83772154/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Generate Certificate - Local Certificate Authority .png" alt="Generate Certificate - Local Certificate Authority" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Generate Certificate - Local Certificate Authority&lt;/span&gt;&lt;/span&gt;&lt;/I&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Select the certificate you just created, and check the &lt;STRONG&gt;Trusted Root CA&lt;/STRONG&gt;&amp;nbsp;box&lt;/LI&gt;
&lt;LI&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;OK&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;I&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Certificate Information - Trusted Root CA" style="width: 599px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25062iA389791D292C90E2/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Certificate Information - Trusted Root CA.png" alt="Certificate Information - Trusted Root CA" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Certificate Information - Trusted Root CA&lt;/span&gt;&lt;/span&gt;&lt;/I&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Navigate to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Device &amp;gt;&amp;nbsp;Certificate Management &amp;gt;&amp;nbsp;Certificates &amp;gt; Generate&lt;/STRONG&gt;&amp;nbsp;and a create certificate for GlobalProtect
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;Enter a&amp;nbsp;&lt;I&gt;Certificate&amp;nbsp;Name&lt;/I&gt;&lt;/LI&gt;
&lt;LI&gt;Enter the IP address or the DNS name of the interface to which remote users will connect for&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;Common Name&lt;/I&gt;
&lt;UL class="lia-list-style-type-square"&gt;
&lt;LI&gt;&lt;STRONG&gt;NOTE:&lt;/STRONG&gt;&amp;nbsp;In this series of posts, we will be using the public IP address for the common name (represented by&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;1.1.1.1&lt;/I&gt;), and it is recommended to use a DNS name in a production environment but IP addresses will work as well&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;Select the certificate previously created under "Signed By"&lt;/LI&gt;
&lt;LI&gt;Enter information in other fields if desired (optional)&lt;/LI&gt;
&lt;LI&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Generate&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Generate Certificate - Cryptographic Settings" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25063i42EEE9A6E03E97A0/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Generate Certificate - Cryptographic Settings.png" alt="Generate Certificate - Cryptographic Settings" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Generate Certificate - Cryptographic Settings&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Navigate to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Device &amp;gt;&amp;nbsp;Certificate Management &amp;gt;&amp;nbsp;SSL/TLS Service Profile &amp;gt; Add&lt;/STRONG&gt;&lt;/LI&gt;
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;Enter a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;Name&lt;/I&gt;&lt;/LI&gt;
&lt;LI&gt;Select the &lt;EM&gt;Certificate&lt;/EM&gt; previously created&lt;/LI&gt;
&lt;LI&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;OK&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;I&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SSL/TSL Service Profile" style="width: 399px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25064i562C90205CD383F0/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="SSL:TSL Service Profile.png" alt="SSL/TSL Service Profile" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;SSL/TSL Service Profile&lt;/span&gt;&lt;/span&gt;&lt;/I&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Navigate to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Device &amp;gt; Local User Database &amp;gt; Users &amp;gt; Add&lt;/STRONG&gt;&lt;/LI&gt;
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;Enter a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;Name&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/I&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;Password&lt;/I&gt;&lt;/LI&gt;
&lt;LI&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;OK&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Local User Database" style="width: 505px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25065i8891F650031418EB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Local User Database.png" alt="Local User Database" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Local User Database&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Navigate to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Device &amp;gt; Authentication Profile &amp;gt; Add&lt;/STRONG&gt;&lt;/LI&gt;
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;Enter a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;Name&lt;/I&gt;&lt;/LI&gt;
&lt;LI&gt;Select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;Local Database&lt;/EM&gt; for&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Type&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Authentication Profile" style="width: 598px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25066i8E2BE25F783588E8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Authentication Profile.png" alt="Authentication Profile" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Authentication Profile&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;UL class="lia-list-style-type-disc"&gt;
&lt;LI&gt;Navigate to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Advanced &amp;gt;&amp;nbsp;Add&lt;/STRONG&gt;
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;Select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;All&lt;/I&gt;&lt;/LI&gt;
&lt;LI&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;OK&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Authentication Profile - Advanced Tab" style="width: 599px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25067i8616DE18640CA644/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Authentication Profile - Advanced Tab.png" alt="Authentication Profile - Advanced Tab" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Authentication Profile - Advanced Tab&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Navigate to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Network &amp;gt; GlobalProtect &amp;gt; Gateway &amp;gt; Add&lt;/STRONG&gt;
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;In the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;General&lt;/STRONG&gt;&amp;nbsp;tab
&lt;UL class="lia-list-style-type-square"&gt;
&lt;LI&gt;Enter a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;Name&lt;/I&gt;&lt;/LI&gt;
&lt;LI&gt;Select the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;interface&lt;/STRONG&gt;&amp;nbsp;to which remote users will connect&lt;/LI&gt;
&lt;LI&gt;Select the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;IPv4 Address&lt;/STRONG&gt;&amp;nbsp;of the interface
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;NOTE:&lt;/STRONG&gt;&amp;nbsp;If your interface is assigned an IP address via DHCP, then you will not have an option to select an&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;IPv4 Address&lt;/I&gt;. Just leave this field set to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;None&lt;/I&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GlobalProtect Gateway Configuration" style="width: 640px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25068iFD79370E5868DD1C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="GlobalProtect Gateway Configuration.png" alt="GlobalProtect Gateway Configuration" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;GlobalProtect Gateway Configuration&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;In the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Authentication&lt;/STRONG&gt;&amp;nbsp;tab
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;Select the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;SSL/TLS Service Profile&amp;nbsp;&lt;/STRONG&gt;previously&amp;nbsp;created&lt;/LI&gt;
&lt;LI&gt;Under&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Client Authentication&lt;/STRONG&gt;&amp;nbsp;click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Add&lt;/STRONG&gt;
&lt;UL class="lia-list-style-type-square"&gt;
&lt;LI&gt;Enter a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;Name&lt;/I&gt;&lt;/LI&gt;
&lt;LI&gt;Select the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Authentication Profile&lt;/STRONG&gt;&amp;nbsp;previously created&lt;/LI&gt;
&lt;LI&gt;Click&amp;nbsp;&lt;STRONG&gt;OK&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="GlobalProtect Gateway Configuration - Authentication Profile" style="width: 640px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25069i67D5EDC718D1F232/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="GlobalProtect Gateway Configuration - Authentication Profile.png" alt="GlobalProtect Gateway Configuration - Authentication Profile" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;GlobalProtect Gateway Configuration - Authentication Profile&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;In the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Agent&amp;nbsp;&lt;/STRONG&gt;tab
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;In the&amp;nbsp;&lt;STRONG&gt;Tunnel Settings&lt;/STRONG&gt; tab
&lt;UL class="lia-list-style-type-square"&gt;
&lt;LI&gt;Enable&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Tunnel Mode&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Select the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Tunnel Interface&lt;/STRONG&gt;&amp;nbsp;previously created&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GlobalProtect Gateway Configuration - Tunnel Settings Tab" style="width: 640px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25070i5E40A0A708FEF642/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="GlobalProtect Gateway Configuration - Tunnel Settings Tab.png" alt="GlobalProtect Gateway Configuration - Tunnel Settings Tab" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;GlobalProtect Gateway Configuration - Tunnel Settings Tab&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;In the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Client Settings&lt;/STRONG&gt;&amp;nbsp;tab
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Add&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;In the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Config Selection Criteria&lt;/STRONG&gt;&amp;nbsp;tab, enter a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;Name&lt;/I&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;I&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Configs - Config Selection Criteria" style="width: 640px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25071iCF329F22D1280FAD/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Configs - Config Selection Criteria.png" alt="Configs - Config Selection Criteria" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Configs - Config Selection Criteria&lt;/span&gt;&lt;/span&gt;&lt;/I&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;In the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;IP Pools&lt;/STRONG&gt; tab
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;&lt;STRONG&gt;Add&lt;/STRONG&gt;&amp;nbsp;an&amp;nbsp;&lt;I&gt;IP Pool&lt;/I&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Configs - IP Pools" style="width: 640px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25072iF3D28D00FD723B99/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Configs - IP Pools.png" alt="Configs - IP Pools" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Configs - IP Pools&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;In the&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Split Tunnel&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;tab&lt;/SPAN&gt;
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;&lt;STRONG&gt;Add&lt;/STRONG&gt;&amp;nbsp;an access route to the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;Include&lt;/EM&gt;&amp;nbsp;section
&lt;UL class="lia-list-style-type-square"&gt;
&lt;LI&gt;&lt;STRONG&gt;NOTE:&lt;/STRONG&gt;&amp;nbsp;In this series of posts we will be routing all traffic through the tunnel. It is recommended to tunnel all traffic in a production environment to ensure consistent protection.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;OK&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Configs - Split Tunnel" style="width: 748px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25152iC67CDA0B62D7BABC/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="split tunnel.PNG" alt="Configs - Split Tunnel" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Configs - Split Tunnel&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;In the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Network Services&lt;/STRONG&gt;&amp;nbsp;tab
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;Enter values for&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;Primary DNS&lt;/I&gt;&amp;nbsp;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;Secondary DNS&lt;/I&gt;&lt;/LI&gt;
&lt;LI&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;OK&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;I&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GlobalProtect Gateway Configuration - Network Services" style="width: 640px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25073iF9C03D751B24082F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="GlobalProtect Gateway Configuration - Network Services.png" alt="GlobalProtect Gateway Configuration - Network Services" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;GlobalProtect Gateway Configuration - Network Services&lt;/span&gt;&lt;/span&gt;&lt;/I&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Navigate&lt;/SPAN&gt;&lt;I&gt;&lt;SPAN&gt; to&lt;/SPAN&gt;&lt;/I&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Network &amp;gt; GlobalProtect &amp;gt; Portal &amp;gt; Add&lt;/STRONG&gt;
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;In the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;General&lt;/STRONG&gt;&amp;nbsp;tab
&lt;UL class="lia-list-style-type-square"&gt;
&lt;LI&gt;Enter a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;Name&lt;/I&gt;&lt;/LI&gt;
&lt;LI&gt;Select the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Interface&amp;nbsp;&lt;/STRONG&gt;to which remote users will connect&lt;/LI&gt;
&lt;LI&gt;Select the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;IP Address&lt;/STRONG&gt;&amp;nbsp;of the interface&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GlobalProtect Portal Configuration - General" style="width: 640px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25074i84926C544F1952DA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="GlobalProtect Portal Configuration - General.png" alt="GlobalProtect Portal Configuration - General" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;GlobalProtect Portal Configuration - General&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;In the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Authentication&lt;/STRONG&gt;&amp;nbsp;tab
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;Select the&amp;nbsp;&lt;I&gt;SSL/TLS Service Profile&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/I&gt;previously created&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GlobalProtect Portal Configuration - Authentication" style="width: 640px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25075iBDEC05D32BBD1577/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="GlobalProtect Portal Configuration - Authentication.png" alt="GlobalProtect Portal Configuration - Authentication" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;GlobalProtect Portal Configuration - Authentication&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Under&amp;nbsp;&lt;STRONG&gt;Client Authentication&lt;/STRONG&gt;&amp;nbsp;click&amp;nbsp;&lt;STRONG&gt;Add&lt;/STRONG&gt;
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;Enter a&amp;nbsp;&lt;I&gt;Name&lt;/I&gt;&lt;/LI&gt;
&lt;LI&gt;Select the&amp;nbsp;&lt;I&gt;Authentication Profile&lt;/I&gt;&amp;nbsp;previously created&lt;/LI&gt;
&lt;LI&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;OK&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Client Authentication - Portal Authentication" style="width: 478px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25076i22D5E70E270D825D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Client Authentication - Portal Authentication.png" alt="Client Authentication - Portal Authentication" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Client Authentication - Portal Authentication&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;In the&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Agent&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;tab&lt;/SPAN&gt;
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Add&lt;/STRONG&gt;&amp;nbsp;under&amp;nbsp;&lt;I&gt;Configs&lt;/I&gt;
&lt;UL class="lia-list-style-type-square"&gt;
&lt;LI&gt;In the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Authentication&lt;/STRONG&gt;&amp;nbsp;tab
&lt;UL class="lia-list-style-type-disc"&gt;
&lt;LI&gt;Enter a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;Name&lt;/I&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Configs - Authentication Tab" style="width: 640px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25077i433FAC81B9B674D3/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Configs - Authentication Tab.png" alt="Configs - Authentication Tab" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Configs - Authentication Tab&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;In the&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Internal&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;tab&lt;/SPAN&gt;
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;Enable&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Internal Host Detection IPv4&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Enter an&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;IP Address&lt;/I&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;of resource that is always available internally&lt;/LI&gt;
&lt;LI&gt;Enter the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;Hostname&lt;/I&gt;&amp;nbsp;of the IP address to which it resolves
&lt;UL class="lia-list-style-type-square"&gt;
&lt;LI&gt;&lt;STRONG&gt;NOTE:&lt;/STRONG&gt;&amp;nbsp;Internal Host Detection uses a reverse lookup to determine whether or not a device is on the internal network in order to establish a VPN tunnel. See&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A title="Palo Alto Networks DNS Proxy | Palo Alto Networks" href="https://networkwiki.blogspot.com/2020/03/palo-alto-networks-dns-proxy.html" target="_blank" rel="noopener"&gt;this post&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;for additional details if you do not have an internal DNS server.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Configs - Internal Tab" style="width: 640px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25078i0A4BAE74665241C1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Configs - Internal Tab.png" alt="Configs - Internal Tab" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Configs - Internal Tab&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;In the&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;External&lt;/STRONG&gt;&amp;nbsp;&lt;SPAN&gt;tab&lt;/SPAN&gt;
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;Add an&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;External Gateway&lt;/I&gt;&amp;nbsp;
&lt;UL class="lia-list-style-type-square"&gt;
&lt;LI&gt;Enter a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;Name&lt;/I&gt;&lt;/LI&gt;
&lt;LI&gt;Enter the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;Address&lt;/I&gt;&amp;nbsp;to which remote users will connect&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Configs - External Tab" style="width: 640px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25079i485642DEF663B2F9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Configs - External Tab.png" alt="Configs - External Tab" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Configs - External Tab&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;In the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;App&amp;nbsp;&lt;/STRONG&gt;tab
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;Change the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;Connect Method&lt;/I&gt;&amp;nbsp;to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;On-demand&lt;/I&gt;&lt;/LI&gt;
&lt;LI&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;OK&lt;/STRONG&gt;
&lt;UL class="lia-list-style-type-square"&gt;
&lt;LI&gt;&lt;STRONG&gt;NOTE:&lt;/STRONG&gt;&lt;I&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/I&gt;In subsequent posts, we will be setting the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;Connect Method&lt;/I&gt;&amp;nbsp;to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;User-Logon (Always On)&lt;/I&gt;, as that is the recommended best practice&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Configs - App Tab" style="width: 640px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25080i313A97494526C0D2/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Configs - App Tab.png" alt="Configs - App Tab" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Configs - App Tab&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Back in the&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Agent&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;tab, click&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Add&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;under&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;Trusted Root CA&lt;/I&gt;
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;Add the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;Root CA&lt;/I&gt;&lt;/LI&gt;
&lt;LI&gt;Check the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;Install in Local Root Certificate Store&lt;/I&gt;
&lt;UL class="lia-list-style-type-square"&gt;
&lt;LI&gt;&lt;STRONG&gt;NOTE:&lt;/STRONG&gt;&amp;nbsp;Selecting this option will transparently install the trusted root CA so that we can test&amp;nbsp;&lt;I&gt;SSL Forward Proxy&lt;/I&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;decryption in the future. It is not required in order for GlobalProtect to function.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;OK&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GlobalProtect Portal Configuration - Agent Tab" style="width: 640px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25082iB828AEE30F6243BA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="GlobalProtect Configuration - Agent Tab.png" alt="GlobalProtect Portal Configuration - Agent Tab" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;GlobalProtect Portal Configuration - Agent Tab&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Navigate to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Policies &amp;gt; NAT&lt;/STRONG&gt;&amp;nbsp;and add the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;gp&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/I&gt;zone you created previously to your source NAT rule so that users in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;gp&lt;/I&gt;&amp;nbsp;zone can get out to the Internet&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Policies - NAT - Add GP Zone" style="width: 640px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25083iDD203779EFFB208F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Policies - NAT - Add GP Zone.png" alt="Policies - NAT - Add GP Zone" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Policies - NAT - Add GP Zone&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Navigate to&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Policies &amp;gt; Security&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;and add security policy rules so that users in the&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;gp&lt;/I&gt;&lt;SPAN&gt;&amp;nbsp;zone can access internal as well as public resources&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Policies - Security - Add Security Policy" style="width: 640px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25084i46B7E7EFA8AFA672/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Policies - Security - Add Security Policy.png" alt="Policies - Security - Add Security Policy" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Policies - Security - Add Security Policy&lt;/span&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Navigate to&amp;nbsp;&lt;STRONG&gt;Policies &amp;gt; Security&amp;nbsp;&lt;/STRONG&gt;and add a security policy rule that allows remote users to access GlobalProtect portal&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Policies - Security - Add Security Policy for Remote Users" style="width: 640px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25085i456AD29881B89381/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Policies - Security - Add Security Policy for Remote Users.png" alt="Policies - Security - Add Security Policy for Remote Users" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Policies - Security - Add Security Policy for Remote Users&lt;/span&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;STRONG&gt;Commit&lt;/STRONG&gt;&amp;nbsp;the configuration&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN&gt;You should now be able to log into the portal, download and install the GlobalProtect App, and test connectivity.&lt;BR /&gt;&lt;BR /&gt;In my next post, "&lt;A title="GlobalProtect: Expanded Setup | LIVEcommunity | Palo Alto Networks" href="https://live.paloaltonetworks.com/t5/General-Articles/GlobalProtect-Expanded-Setup/ta-p/322234" target="_self"&gt;GlobalProtect: Expanded Setup&lt;/A&gt;," we will make changes to the configuration to include different forms of authentication and add an internal gateway.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/DIV&gt;</description>
    <pubDate>Thu, 07 Jul 2022 20:57:38 GMT</pubDate>
    <dc:creator>SpencerMitchell</dc:creator>
    <dc:date>2022-07-07T20:57:38Z</dc:date>
    <item>
      <title>GlobalProtect: Initial Set Up</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-articles/globalprotect-initial-set-up/ta-p/322232</link>
      <description>&lt;P&gt;Learn more about&amp;nbsp;&lt;SPAN&gt;the initial setup of GlobalProtect, including a portal, external gateway, and user authentication via local database.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jul 2022 20:57:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-articles/globalprotect-initial-set-up/ta-p/322232</guid>
      <dc:creator>SpencerMitchell</dc:creator>
      <dc:date>2022-07-07T20:57:38Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect: Initial Set Up</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-articles/globalprotect-initial-set-up/tac-p/322765#M15</link>
      <description>&lt;P&gt;Great explanation!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2020 23:02:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-articles/globalprotect-initial-set-up/tac-p/322765#M15</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2020-04-14T23:02:11Z</dc:date>
    </item>
  </channel>
</rss>

