<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LSVPN Portal Redundancy in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/lsvpn-portal-redundancy/m-p/321737#M13</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;I have 1 site in NYC and a site in Dallas each with HA pairs(active/standby).&amp;nbsp; &amp;nbsp; I have 2 ISP's at each site and was planning to have the NYC site have one portal and one gateway and the Dallas site have the other portal and one gateway.&amp;nbsp; So each portal would have both of the gateways configured for each satellite.&amp;nbsp; The portals would use one ISP at each site.&amp;nbsp; Does this make sense?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 08 Apr 2020 23:06:29 GMT</pubDate>
    <dc:creator>eridavis</dc:creator>
    <dc:date>2020-04-08T23:06:29Z</dc:date>
    <item>
      <title>LSVPN Portal Redundancy</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/lsvpn-portal-redundancy/m-p/321540#M9</link>
      <description>&lt;P&gt;I successfully setup LSVPN with a single portal , 2 gateways and some satellites.&amp;nbsp; I realized that if my portal goes down for any reason, then the gateways are useless since the satellite needs the portal to get to the gateways.&amp;nbsp; Any ideas on how best to setup a 2nd portal?&amp;nbsp; &amp;nbsp; Currently, my portal is on one of the gateways.&amp;nbsp; I was thinking i can setup the 2nd portal on the other gateway.&amp;nbsp; Can I reuse the same certificate that was generated on the first portal or do i need a new cert?&amp;nbsp; The 2nd portal would have the same gateways as the 1st portal.&amp;nbsp; Or is there a way to make the satellite cache the portal cert for an extended period so i don't need to create a 2nd portal?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2020 15:35:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/lsvpn-portal-redundancy/m-p/321540#M9</guid>
      <dc:creator>eridavis</dc:creator>
      <dc:date>2020-04-09T15:35:56Z</dc:date>
    </item>
    <item>
      <title>Re: LSVPN Portal Redundancy</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/lsvpn-portal-redundancy/m-p/321580#M10</link>
      <description>&lt;P&gt;By default the portal configuration is cached for 24 hours. So the real question here is if you would be hosting the secondary portal on a different physical device or not, or on a different ISP. With an Active/Passive setup the reason to setup a secondary portal for redundancy sake would really be up to if you have multiple ISPs. If you don't, you won't gain a lot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So things to think about.&lt;/P&gt;&lt;P&gt;1) Hardware Failure.&lt;/P&gt;&lt;P&gt;If you have an Active/Passive HA setup this isn't that big of an issue, your passive unit would take over.&lt;/P&gt;&lt;P&gt;If you don't have an HA setup do you have another piece of hardware a truly redundant set of portal and gateway could live on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) ISP Failure.&lt;/P&gt;&lt;P&gt;If you don't have a secondary ISP then this obviously isn't something you could fix. But if you do, I like to have a portal on each route, so if one ISP connection is down you can still connect to the other.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2020 15:07:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/lsvpn-portal-redundancy/m-p/321580#M10</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-04-08T15:07:17Z</dc:date>
    </item>
    <item>
      <title>Re: LSVPN Portal Redundancy</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/lsvpn-portal-redundancy/m-p/321737#M13</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;I have 1 site in NYC and a site in Dallas each with HA pairs(active/standby).&amp;nbsp; &amp;nbsp; I have 2 ISP's at each site and was planning to have the NYC site have one portal and one gateway and the Dallas site have the other portal and one gateway.&amp;nbsp; So each portal would have both of the gateways configured for each satellite.&amp;nbsp; The portals would use one ISP at each site.&amp;nbsp; Does this make sense?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2020 23:06:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/lsvpn-portal-redundancy/m-p/321737#M13</guid>
      <dc:creator>eridavis</dc:creator>
      <dc:date>2020-04-08T23:06:29Z</dc:date>
    </item>
    <item>
      <title>Re: LSVPN Portal Redundancy</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/lsvpn-portal-redundancy/m-p/537237#M3859</link>
      <description>&lt;P&gt;Greetings. Although this is from 2020, I have similar situation.&lt;/P&gt;
&lt;P&gt;Eridavis- sorry for jumping into your thread.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Looking to replace cisco ezvpn solution with LSVPN. 2 gateways each @ different DCs with its own ISP. Can I have redundant portal (different IP) portals so satellite will authenticate by any available portal (or always portal1 if there is priority). This helps incase if primary portal not available. Or One portal only and able to set the authentication timer longer..say 3years?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2023 13:01:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/lsvpn-portal-redundancy/m-p/537237#M3859</guid>
      <dc:creator>SPCAPLP</dc:creator>
      <dc:date>2023-03-31T13:01:45Z</dc:date>
    </item>
  </channel>
</rss>

