<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DHCP address assignment for Global Protect VPN in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dhcp-address-assignment-for-global-protect-vpn/m-p/427391#M1621</link>
    <description>&lt;P&gt;Ok, I added the L3 interface and added the VLAN to my switches and committed all changes. I can connect to VPN by computer but not by an app on my iPhone (I do have the correct licensing for the GP app). The error I get is " The network connection is unreachable or the gateway is unresponsive.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, when I have a laptop successfully connected to the VPN, I can't seem to get to any VLAN's on my network. I do have the VLAN's identified in the split tunnel. I tried adding the VLA's individually as well as specifying 0.0.0.0/0 to no avail.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any thoughts or suggestions?&lt;/P&gt;</description>
    <pubDate>Tue, 17 Aug 2021 17:47:02 GMT</pubDate>
    <dc:creator>RussMc</dc:creator>
    <dc:date>2021-08-17T17:47:02Z</dc:date>
    <item>
      <title>DHCP address assignment for Global Protect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dhcp-address-assignment-for-global-protect-vpn/m-p/423175#M1578</link>
      <description>&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am working on a PA-220 LAB, in preparation for a PA 820 rollout. I have setup and configured my Global protect VPN. When it comes to DHCP, I know I can't use my DHCP servers but have to rely on DHCP from the firewall. That is OK. My question is this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For my VPN users, If I create a DHCP scope in Network&amp;gt;GatewayS&amp;gt;MyGateway&amp;gt;Agent&amp;gt;Client Settings&amp;gt;Configs&amp;gt;IP Pools&amp;gt;IP Pool, and the DHCP addresses are not sub set of an existing Ethernet Interface\sub-interface, will I have to create a layer 3 sub interface so the VPN traffic is routed correctly? IE; all Interfaces\sub interfaces are 10.0.x.x and I want VPN addresses to be 192.168.x.x. Will I need to create a layer 3 interface for the 192.168.x.x so traffic flows correctly?&lt;/P&gt;&lt;P&gt;I am sure this is simple but I want to make sure I do it correctly in the building\testing stage&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jul 2021 18:13:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dhcp-address-assignment-for-global-protect-vpn/m-p/423175#M1578</guid>
      <dc:creator>RussMc</dc:creator>
      <dc:date>2021-07-29T18:13:51Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP address assignment for Global Protect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dhcp-address-assignment-for-global-protect-vpn/m-p/423373#M1579</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/188254"&gt;@RussMc&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes you will need a L3 interface and a zone if you want to land the tunnel in a isolated zone.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jul 2021 09:30:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dhcp-address-assignment-for-global-protect-vpn/m-p/423373#M1579</guid>
      <dc:creator>laurence64</dc:creator>
      <dc:date>2021-07-30T09:30:52Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP address assignment for Global Protect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dhcp-address-assignment-for-global-protect-vpn/m-p/423417#M1581</link>
      <description>&lt;P&gt;Thank you. I will add it and test this weekend.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jul 2021 14:41:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dhcp-address-assignment-for-global-protect-vpn/m-p/423417#M1581</guid>
      <dc:creator>RussMc</dc:creator>
      <dc:date>2021-07-30T14:41:42Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP address assignment for Global Protect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dhcp-address-assignment-for-global-protect-vpn/m-p/427391#M1621</link>
      <description>&lt;P&gt;Ok, I added the L3 interface and added the VLAN to my switches and committed all changes. I can connect to VPN by computer but not by an app on my iPhone (I do have the correct licensing for the GP app). The error I get is " The network connection is unreachable or the gateway is unresponsive.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, when I have a laptop successfully connected to the VPN, I can't seem to get to any VLAN's on my network. I do have the VLAN's identified in the split tunnel. I tried adding the VLA's individually as well as specifying 0.0.0.0/0 to no avail.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any thoughts or suggestions?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Aug 2021 17:47:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dhcp-address-assignment-for-global-protect-vpn/m-p/427391#M1621</guid>
      <dc:creator>RussMc</dc:creator>
      <dc:date>2021-08-17T17:47:02Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP address assignment for Global Protect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dhcp-address-assignment-for-global-protect-vpn/m-p/427408#M1622</link>
      <description>&lt;P&gt;You will need to add a security policy allowing traffic from the GP tunnel zone to your lan interface zone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Aug 2021 20:00:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dhcp-address-assignment-for-global-protect-vpn/m-p/427408#M1622</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-08-17T20:00:42Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP address assignment for Global Protect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dhcp-address-assignment-for-global-protect-vpn/m-p/427483#M1625</link>
      <description>&lt;P&gt;Absolutely as&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;says, you need to treat the Global protect environment as you would any other so&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Tunnel interface that lands either in your inside network or a DMZ or wherever you want&lt;/LI&gt;&lt;LI&gt;Zone for the Tunnel interface&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Rules allowing your users to access the resources they need using Zones and policies&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;NAT rules if you want to go out to the internet through the Firewall (as opposed to breakout locally)&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Using the 0.0.0.0/0 route will tunnel everything back to the Gateway so you may want to just use the subnets that you require.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Aug 2021 07:26:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dhcp-address-assignment-for-global-protect-vpn/m-p/427483#M1625</guid>
      <dc:creator>laurence64</dc:creator>
      <dc:date>2021-08-18T07:26:52Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP address assignment for Global Protect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dhcp-address-assignment-for-global-protect-vpn/m-p/427534#M1628</link>
      <description>&lt;P&gt;For testing purposes, I have the tunnel added to my untrusted (Internet) zone and set on my gateway configuration. In the past, this has worked just fine with all applicable VLAN's added to the split tunnel.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Aug 2021 14:36:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dhcp-address-assignment-for-global-protect-vpn/m-p/427534#M1628</guid>
      <dc:creator>RussMc</dc:creator>
      <dc:date>2021-08-18T14:36:11Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP address assignment for Global Protect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dhcp-address-assignment-for-global-protect-vpn/m-p/427552#M1629</link>
      <description>&lt;P&gt;Are the vlans you mentioned external or internal&lt;/P&gt;</description>
      <pubDate>Wed, 18 Aug 2021 15:48:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dhcp-address-assignment-for-global-protect-vpn/m-p/427552#M1629</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-08-18T15:48:39Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP address assignment for Global Protect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dhcp-address-assignment-for-global-protect-vpn/m-p/427559#M1631</link>
      <description>&lt;P&gt;All internal.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Aug 2021 16:12:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dhcp-address-assignment-for-global-protect-vpn/m-p/427559#M1631</guid>
      <dc:creator>RussMc</dc:creator>
      <dc:date>2021-08-18T16:12:39Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP address assignment for Global Protect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dhcp-address-assignment-for-global-protect-vpn/m-p/427765#M1632</link>
      <description>&lt;P&gt;OK, I have the VPN client working now on the client PC's &amp;amp; MAC's. I forwent adding the tunnel&amp;nbsp;&lt;SPAN&gt;to my untrusted (Internet) zone and went with Mick's suggestion. I created a new zone, configured the tunnel, and added a security policy and access to the VLAN's works just fine. The only issue I have is our iPhones will not connect to the VPN. I still get the following error:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Gateway &amp;lt;My Gateway&amp;gt;: The network connection is unreachable or the gateway is unresponsive. Check the network connection and reconnect.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Could this be caused by the self signed certificate I am using for testing (I will have a real, valid cert in production)? If this is the case, I guess I am looking for validation since I ran out of time until this weekend to do more testing. I found this article:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://medium.com/collaborne-engineering/self-signed-certificates-in-ios-apps-ff489bf8b96e" target="_blank"&gt;https://medium.com/collaborne-engineering/self-signed-certificates-in-ios-apps-ff489bf8b96e&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;Thoughts on if will resolve the issue?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Aug 2021 13:11:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dhcp-address-assignment-for-global-protect-vpn/m-p/427765#M1632</guid>
      <dc:creator>RussMc</dc:creator>
      <dc:date>2021-08-19T13:11:24Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP address assignment for Global Protect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dhcp-address-assignment-for-global-protect-vpn/m-p/427891#M1636</link>
      <description>&lt;P&gt;Do you have the required gateway subscription for mobile devices?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ios works differently from windoze with cert stuff... i only have trusted certs so cannot test but when i use ip address for portal i get ...&lt;/P&gt;&lt;P&gt;the network is unreachable or the portal is unresponsive....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;not sure why you get the gateway error....&lt;/P&gt;&lt;P&gt;anyhows... try the fix yo have as you will need to trust your ssigned cert...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;laters...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Aug 2021 20:22:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dhcp-address-assignment-for-global-protect-vpn/m-p/427891#M1636</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-08-19T20:22:40Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP address assignment for Global Protect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dhcp-address-assignment-for-global-protect-vpn/m-p/428112#M1641</link>
      <description>&lt;P&gt;I have the required licensing for mobile devices.&lt;/P&gt;&lt;P&gt;From Safari, Chrome, and Firefox, from an iPhone, I can hit the VPN gateway (by IP) and login just fine. Once I do, I see the links to download the appropriate client, though you can't on an idevice... This means all but the App is working fine.&lt;/P&gt;&lt;P&gt;I have the cert loaded and trusted in my device and will test this weekend and report back on Monday. Thank you for all the help and advice.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Aug 2021 15:24:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dhcp-address-assignment-for-global-protect-vpn/m-p/428112#M1641</guid>
      <dc:creator>RussMc</dc:creator>
      <dc:date>2021-08-20T15:24:37Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP address assignment for Global Protect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dhcp-address-assignment-for-global-protect-vpn/m-p/428499#M1647</link>
      <description>&lt;P&gt;The testing over the weekend was successful. Creating a L3 interface for the VPN traffic, then creating a zone\rules for the traffic to flow and then, installing the cert and trusting it on the iDevice worked perfectly. I was then able to navigate where my rules permitted. I will be obtaining a true, trusted cert for the production rollout. Thanks and Kudos to&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;&amp;amp;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163815"&gt;@laurence64&lt;/a&gt;&amp;nbsp;for all the help.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 15:06:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dhcp-address-assignment-for-global-protect-vpn/m-p/428499#M1647</guid>
      <dc:creator>RussMc</dc:creator>
      <dc:date>2021-08-23T15:06:37Z</dc:date>
    </item>
  </channel>
</rss>

