<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Globalprotect: Multiple gateway on the same firewall in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-multiple-gateway-on-the-same-firewall/m-p/428436#M1786</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/179077"&gt;@rabbyx7xafc&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;That is correct, and if you think about it make sense. When you selecting IP address for GP gateway portal, you are telling the firewall on what socket to listen for connections. You cannot configure network socket with FQDN, right.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Take one step back to how GP works:&lt;/P&gt;&lt;P&gt;1. When user (aka gp client) wants to connect he will make a connection to the portal first.&lt;/P&gt;&lt;P&gt;2. User puts FQDN in the GP client, it resolves to an IP and then it tries to connect to that IP&lt;/P&gt;&lt;P&gt;3. Once connected and authenticated to the portal gp client will download instructions/settings for&amp;nbsp; GP application behaviour and how to establish the VPN tunnel. This will include the GP gateway (the endpoint to which the gp client will try to establish vpn tunnel)&lt;/P&gt;&lt;P&gt;4. In here your should put the FQDN for your GP gateway.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Astardzhiev_0-1629709063928.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35835iF02CF78CFC510EF1/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Astardzhiev_0-1629709063928.png" alt="Astardzhiev_0-1629709063928.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;GP client will get this FQDN and again resolve it to get the IP to which it should connect.&lt;/P&gt;&lt;P&gt;In most cases people tend to use same IP and FQDN for gateway and portal, but again depends on your setup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now back to your question - how to configure redundancy for your GlobalProtect. If you notice above, in order for your VPN to work you need to have redundency for both portal and gateway.&lt;/P&gt;&lt;P&gt;From what I understand you are using two different ISPs, so my suggestions would be:&lt;/P&gt;&lt;P&gt;1. Create two separate GP deployments (portal and gateway). Each one associated with public IP from each ISP. When creating your DNS entry you need to use DNS failover service, which will monitor status for both GPs and resolve the FQDN to the primary and if it is down to the secondary ISP ip address.&lt;/P&gt;&lt;P&gt;2. Get public IP range that is assigned to your. Run BGP with both ISP and advertise this range to both ISP. Configure some IP addresses&amp;nbsp; as loopback interfaces and use those for one portal and gateway. Configure your GP FQDN to resolve to this one. So the DNS will always resolve to same IP, but if your ISP one is down BGP will advetise your public range via ISP two.&lt;/P&gt;&lt;P&gt;2.&lt;/P&gt;</description>
    <pubDate>Mon, 23 Aug 2021 09:28:27 GMT</pubDate>
    <dc:creator>aleksandar.astardzhiev</dc:creator>
    <dc:date>2021-08-23T09:28:27Z</dc:date>
    <item>
      <title>Globalprotect: Multiple gateway on the same firewall</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-multiple-gateway-on-the-same-firewall/m-p/428395#M1782</link>
      <description>&lt;P&gt;Hello good people.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are planning globalprotect redundancy on our PA-3050 with multiple ISP. Here is our scenario:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1 Portal&lt;/P&gt;&lt;P&gt;1 Gateway&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What we wanna do:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1 Portal&amp;nbsp;&lt;/P&gt;&lt;P&gt;2 Gateway&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;our existing gateway is going through tunnel mode via tunnel.1&lt;/P&gt;&lt;P&gt;what I want to know is that, can I run my second gateway via the same tunnel tunnel.1? or Do i need to create a new tunnel?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks in advance guys!&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 07:19:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-multiple-gateway-on-the-same-firewall/m-p/428395#M1782</guid>
      <dc:creator>rabbyx7xafc</dc:creator>
      <dc:date>2021-08-23T07:19:04Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect: Multiple gateway on the same firewall</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-multiple-gateway-on-the-same-firewall/m-p/428423#M1783</link>
      <description>&lt;P&gt;Hi&amp;nbsp; &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/179077"&gt;@rabbyx7xafc&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You shouldn't be able to use two differnt gateways associated with same tunnel interface.&lt;/P&gt;&lt;P&gt;Put it this way - if you imagine that tunnel.1 is just a simple IPsec tunnel (site to site), using two gateways is like building site to site with two different peers using same interface and routes. What I am trying to say is that firewall will not be able to determen which gateway should it use, because you will have two different IP pools associated with same interface.&lt;BR /&gt;&lt;BR /&gt;What you could to is:&lt;BR /&gt;- Create two separate gateways each assosiated with different tunnel interface, different IP pool. You could use the same SSL certificate and configure, so your GP portal use one FQDN for GP gateway and have your DNS to resolve it with primary and backup IP. Or configure GP portal to send two gateways with different priority and let the gp client detect when there is issue with primary&lt;/P&gt;&lt;P&gt;- Assing the GP gateway and portal IP address to loopback IP. Configure BGP with both of your ISP and advertise it from both. Configure single GP portal and gateway using the loopback. Leave the failover to the BGP and the ISPs&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 07:51:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-multiple-gateway-on-the-same-firewall/m-p/428423#M1783</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2021-08-23T07:51:30Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect: Multiple gateway on the same firewall</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-multiple-gateway-on-the-same-firewall/m-p/428425#M1784</link>
      <description>&lt;P&gt;okay got it! but here is my confusion. I don't see any option to use FQDN for setting up the GP portal! its only IPv4 or IPv6. As i'm seeking redundancy, how can I ensure that if my GP Portal is dependant on IP only, and if that ISP goes down, so does GP portal.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 08:07:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-multiple-gateway-on-the-same-firewall/m-p/428425#M1784</guid>
      <dc:creator>rabbyx7xafc</dc:creator>
      <dc:date>2021-08-23T08:07:55Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect: Multiple gateway on the same firewall</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-multiple-gateway-on-the-same-firewall/m-p/428427#M1785</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="gp.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35833i8268C98FC931658E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="gp.PNG" alt="gp.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;as seen here, no option to choose FQDN&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 08:09:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-multiple-gateway-on-the-same-firewall/m-p/428427#M1785</guid>
      <dc:creator>rabbyx7xafc</dc:creator>
      <dc:date>2021-08-23T08:09:38Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect: Multiple gateway on the same firewall</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-multiple-gateway-on-the-same-firewall/m-p/428436#M1786</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/179077"&gt;@rabbyx7xafc&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;That is correct, and if you think about it make sense. When you selecting IP address for GP gateway portal, you are telling the firewall on what socket to listen for connections. You cannot configure network socket with FQDN, right.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Take one step back to how GP works:&lt;/P&gt;&lt;P&gt;1. When user (aka gp client) wants to connect he will make a connection to the portal first.&lt;/P&gt;&lt;P&gt;2. User puts FQDN in the GP client, it resolves to an IP and then it tries to connect to that IP&lt;/P&gt;&lt;P&gt;3. Once connected and authenticated to the portal gp client will download instructions/settings for&amp;nbsp; GP application behaviour and how to establish the VPN tunnel. This will include the GP gateway (the endpoint to which the gp client will try to establish vpn tunnel)&lt;/P&gt;&lt;P&gt;4. In here your should put the FQDN for your GP gateway.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Astardzhiev_0-1629709063928.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35835iF02CF78CFC510EF1/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Astardzhiev_0-1629709063928.png" alt="Astardzhiev_0-1629709063928.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;GP client will get this FQDN and again resolve it to get the IP to which it should connect.&lt;/P&gt;&lt;P&gt;In most cases people tend to use same IP and FQDN for gateway and portal, but again depends on your setup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now back to your question - how to configure redundancy for your GlobalProtect. If you notice above, in order for your VPN to work you need to have redundency for both portal and gateway.&lt;/P&gt;&lt;P&gt;From what I understand you are using two different ISPs, so my suggestions would be:&lt;/P&gt;&lt;P&gt;1. Create two separate GP deployments (portal and gateway). Each one associated with public IP from each ISP. When creating your DNS entry you need to use DNS failover service, which will monitor status for both GPs and resolve the FQDN to the primary and if it is down to the secondary ISP ip address.&lt;/P&gt;&lt;P&gt;2. Get public IP range that is assigned to your. Run BGP with both ISP and advertise this range to both ISP. Configure some IP addresses&amp;nbsp; as loopback interfaces and use those for one portal and gateway. Configure your GP FQDN to resolve to this one. So the DNS will always resolve to same IP, but if your ISP one is down BGP will advetise your public range via ISP two.&lt;/P&gt;&lt;P&gt;2.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 09:28:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-multiple-gateway-on-the-same-firewall/m-p/428436#M1786</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2021-08-23T09:28:27Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect: Multiple gateway on the same firewall</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-multiple-gateway-on-the-same-firewall/m-p/428438#M1787</link>
      <description>&lt;P&gt;ok got it. can you make one thing clear? is this true that if the ISP im using for GP PORTAL goes down, it doesnt matter as long as the GP gateway behind that portal are up? i just read that GP PORTAL just initially sends the client info regarding how to connect to GW. after thaat, it wont matter that GP portal ip is up or not. is this correct?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 10:43:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-multiple-gateway-on-the-same-firewall/m-p/428438#M1787</guid>
      <dc:creator>rabbyx7xafc</dc:creator>
      <dc:date>2021-08-23T10:43:16Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect: Multiple gateway on the same firewall</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-multiple-gateway-on-the-same-firewall/m-p/428440#M1788</link>
      <description>&lt;P&gt;Hey &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/179077"&gt;@rabbyx7xafc&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;If GP Gateway is UP, your currently connected users will continue to work normally, but most probably users will not be able to establish new connections.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am saying "most probably" because by design gp client will cache the settings and when restarted it will first try to use the "last known" working settings and gateway and connect straight to the GP gateway (without any attempts to connect to GP portal). I am not 100% sure, but I believe this is only valid for Always-On VPN connection. With One-Demand (I believe) it will always try to connect to portal and only after successful connection it will try to connect to the GP gateways.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Don't forget also that, once user is connected to GP gateway it will periodically connect to GP portal to check if there is change in the application config. Not sure what was the default, but something like every 6-8 hours. I am not sure what will happen if user is connected to GP gateway and try to refresh portal config - I assume nothing, user should stay connected without issues but still good to have it in mind.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you planning to use the GP with Always-On or On-Demand mode?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 11:16:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-multiple-gateway-on-the-same-firewall/m-p/428440#M1788</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2021-08-23T11:16:54Z</dc:date>
    </item>
  </channel>
</rss>

