<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: easiest way to move users to 2nd gateway for maintenance on 1st in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/easiest-way-to-move-users-to-2nd-gateway-for-maintenance-on-1st/m-p/394313#M1074</link>
    <description>&lt;P&gt;The easiest way is simply shutting the gateway down&lt;/P&gt;&lt;P&gt;GlobalProtect will automatically fail over to the other gateway&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Alternatively if there is time to prepare you could set the config refresh time very short and when the day comes just remove one gateway and wait for the config refresh to force everyone over&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 26 Mar 2021 12:52:15 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2021-03-26T12:52:15Z</dc:date>
    <item>
      <title>easiest way to move users to 2nd gateway for maintenance on 1st</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/easiest-way-to-move-users-to-2nd-gateway-for-maintenance-on-1st/m-p/394308#M1073</link>
      <description>&lt;P&gt;We have an Azure implementation of Palo Alto/GlobalProtect.&lt;/P&gt;&lt;P&gt;We use an Azure LoadBalancer point to 2 Palo Alto firewalls for GP portal connectivity.&lt;/P&gt;&lt;P&gt;Then based on the received config we send the user to the direct interface address of one of the 2 firewalls for gateway connectivity.&lt;/P&gt;&lt;P&gt;No HA, no failover.&amp;nbsp;&lt;/P&gt;&lt;P&gt;What would be the easiest way to have users connect only or migrate to the 2nd gateway ?&lt;/P&gt;&lt;P&gt;I know i can change portal configuration but that does not immediately move users to the second.&lt;/P&gt;&lt;P&gt;Also i can not set the portal/gateway in "maintenance".&lt;/P&gt;&lt;P&gt;How do you guys solve handle this ?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 12:47:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/easiest-way-to-move-users-to-2nd-gateway-for-maintenance-on-1st/m-p/394308#M1073</guid>
      <dc:creator>sebastianvd</dc:creator>
      <dc:date>2021-03-26T12:47:48Z</dc:date>
    </item>
    <item>
      <title>Re: easiest way to move users to 2nd gateway for maintenance on 1st</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/easiest-way-to-move-users-to-2nd-gateway-for-maintenance-on-1st/m-p/394313#M1074</link>
      <description>&lt;P&gt;The easiest way is simply shutting the gateway down&lt;/P&gt;&lt;P&gt;GlobalProtect will automatically fail over to the other gateway&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Alternatively if there is time to prepare you could set the config refresh time very short and when the day comes just remove one gateway and wait for the config refresh to force everyone over&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 12:52:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/easiest-way-to-move-users-to-2nd-gateway-for-maintenance-on-1st/m-p/394313#M1074</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-03-26T12:52:15Z</dc:date>
    </item>
    <item>
      <title>Re: easiest way to move users to 2nd gateway for maintenance on 1st</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/easiest-way-to-move-users-to-2nd-gateway-for-maintenance-on-1st/m-p/394318#M1075</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;shutting down is breaking a users connectivity so not the cleanest option in my opinion.&lt;/P&gt;&lt;P&gt;The second, set the config refresh time... When connected to a gateway and the config changes, will the gateway switch ?&lt;/P&gt;&lt;P&gt;Or only at connection setup ?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 12:57:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/easiest-way-to-move-users-to-2nd-gateway-for-maintenance-on-1st/m-p/394318#M1075</guid>
      <dc:creator>sebastianvd</dc:creator>
      <dc:date>2021-03-26T12:57:05Z</dc:date>
    </item>
    <item>
      <title>Re: easiest way to move users to 2nd gateway for maintenance on 1st</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/easiest-way-to-move-users-to-2nd-gateway-for-maintenance-on-1st/m-p/394406#M1080</link>
      <description>&lt;P&gt;I just set the gateway tunnel to max user 1, this allows existing connections to carry on but new connections will be denied and forced to next gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have about 8k user base so upsetting 1 user is a low percentage.&amp;nbsp; you can be really clever and set the timeout to 20 days, connect yourself and stop GP service, then reduce timeout back to normal so you will be the last connected...&amp;nbsp; &amp;nbsp;prob not worth the hassle though for 1 user, especially if it's someone you can't bear...&amp;nbsp; &amp;nbsp; Djagetme......&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 17:19:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/easiest-way-to-move-users-to-2nd-gateway-for-maintenance-on-1st/m-p/394406#M1080</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-03-26T17:19:01Z</dc:date>
    </item>
    <item>
      <title>Re: easiest way to move users to 2nd gateway for maintenance on 1st</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/easiest-way-to-move-users-to-2nd-gateway-for-maintenance-on-1st/m-p/395082#M1098</link>
      <description>&lt;P&gt;Setting the gateway to max 1, when will existing users be connected to the other gateway?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 07:48:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/easiest-way-to-move-users-to-2nd-gateway-for-maintenance-on-1st/m-p/395082#M1098</guid>
      <dc:creator>sebastianvd</dc:creator>
      <dc:date>2021-03-31T07:48:43Z</dc:date>
    </item>
    <item>
      <title>Re: easiest way to move users to 2nd gateway for maintenance on 1st</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/easiest-way-to-move-users-to-2nd-gateway-for-maintenance-on-1st/m-p/395096#M1099</link>
      <description>&lt;P&gt;They will connect to the other gateway when they make a new connection, or of their existing connection times out or you manually log them off from the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have tried a few of the other options and this has been the smoothest and least complicated for our setup. perhaps not for others...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;removing the gateway from the agent will work as suggested by&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp; but for us with users "always on" it's quite surprising how many cannot connect to the portal on startup due to wifi or lan not ready and when GP then uses cached portal config for connection it still has the old gateway configured.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but of course,,, if you need to do this in an emergency then just shut the gateway down&amp;nbsp; and leave the phone off the hook....&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 08:34:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/easiest-way-to-move-users-to-2nd-gateway-for-maintenance-on-1st/m-p/395096#M1099</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-03-31T08:34:13Z</dc:date>
    </item>
  </channel>
</rss>

